Encrypting IMEI for Secure GRUU Generation in IMS Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In IP Multimedia Subsystem (IMS) networks, identifying a specific user device while maintaining user privacy is challenging, especially when a mobile equipment identity (IMEI) is exposed during registration processes, which is a concern in GSM, UMTS, and LTE networks.
Innovation Solution
A network entity, such as a Serving Call Session Control Function, encrypts the international mobile equipment identity (IMEI) to generate a Globally Routable User Agent Uniform Resource Identifier (GRUU) that includes the user's identity in clear text form, ensuring the IMEI remains secure and private.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If IMEI is used as instance identifier in GRUU generation, then device identification capability is improved, but user privacy is compromised due to IMEI exposure
Solution Approach 1:
The patent introduces an encryption mechanism as an intermediary between the IMEI and the GRUU. The IMEI is encrypted using a key derived from the user's authentication credentials, creating a protected representation that maintains device identification capability while preventing direct exposure of the IMEI. This intermediary transformation resolves the contradiction by allowing device identification through the encrypted form without compromising user privacy.
2Object-affected harmful factors
If IMEI is encrypted to protect privacy, then user privacy is improved, but device identification capability may be degraded
Solution Approach 1:
The patent transforms the IMEI from its original plaintext form into an encrypted representation by changing its parameter state through cryptographic operations. The encryption uses keys derived from authentication credentials, transforming the IMEI into a form that protects privacy while maintaining its unique identification properties. The encrypted IMEI can still be used to uniquely identify the device through the GRUU mechanism.
3Speed
If clear text user identity is included in GRUU, then routing capability is improved, but security is worsened due to identity exposure
Solution Approach 1:
The patent segments the user identity information into two parts: the user's public identity (which can be in clear text for routing purposes) and the device-specific IMEI (which is encrypted for security). This segmentation allows the GRUU to contain both elements - the clear text user identity enables efficient routing while the encrypted IMEI portion maintains security. The two segments serve different functions and can coexist in the same identifier.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention relates to hiding a device identifier (IMEI) in a communication system. Identifying a device is done by indicating an international mobile equipment identity (IMEI) as an instance identifier of the device of a user. Generating aglobally routable user agent uniform resource identifier (GRUU) for the user is done by encrypting the instance identifier so that the GRUU comprises an identity of the user and the encrypted instance identifier.