Encrypting IMEI for Secure GRUU Generation in IMS Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In IP Multimedia Subsystem (IMS) networks, identifying a specific user device while maintaining user privacy is challenging, especially when a mobile equipment identity (IMEI) is exposed during registration processes, which is a concern in GSM, UMTS, and LTE networks.

Innovation Solution

A network entity, such as a Serving Call Session Control Function, encrypts the international mobile equipment identity (IMEI) to generate a Globally Routable User Agent Uniform Resource Identifier (GRUU) that includes the user's identity in clear text form, ensuring the IMEI remains secure and private.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If IMEI is used as instance identifier in GRUU generation, then device identification capability is improved, but user privacy is compromised due to IMEI exposure

Engineering Contradiction:
Improvedevice identification capabilityVSAvoiduser privacy exposure
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an encryption mechanism as an intermediary between the IMEI and the GRUU. The IMEI is encrypted using a key derived from the user's authentication credentials, creating a protected representation that maintains device identification capability while preventing direct exposure of the IMEI. This intermediary transformation resolves the contradiction by allowing device identification through the encrypted form without compromising user privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If IMEI is encrypted to protect privacy, then user privacy is improved, but device identification capability may be degraded

Engineering Contradiction:
Improveuser privacy protectionVSAvoiddevice identification capability
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The patent transforms the IMEI from its original plaintext form into an encrypted representation by changing its parameter state through cryptographic operations. The encryption uses keys derived from authentication credentials, transforming the IMEI into a form that protects privacy while maintaining its unique identification properties. The encrypted IMEI can still be used to uniquely identify the device through the GRUU mechanism.

Inventive Principle:
Principle #35Parameter changes

3Speed

If clear text user identity is included in GRUU, then routing capability is improved, but security is worsened due to identity exposure

Engineering Contradiction:
Improverouting capabilityVSAvoidsecurity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments the user identity information into two parts: the user's public identity (which can be in clear text for routing purposes) and the device-specific IMEI (which is encrypted for security). This segmentation allows the GRUU to contain both elements - the clear text user identity enables efficient routing while the encrypted IMEI portion maintains security. The two segments serve different functions and can coexist in the same identifier.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2329632B1Hiding a device identity
Publication Date: 2018.10.24 NOKIA TECHNOLOGIES OY
  • EP2329632B1 patent drawingFigure 1
  • EP2329632B1 patent drawingFigure 2
  • EP2329632B1 patent drawingFigure 3

AI summary

The present invention relates to hiding a device identifier (IMEI) in a communication system. Identifying a device is done by indicating an international mobile equipment identity (IMEI) as an instance identifier of the device of a user. Generating aglobally routable user agent uniform resource identifier (GRUU) for the user is done by encrypting the instance identifier so that the GRUU comprises an identity of the user and the encrypted instance identifier.