Enriched Mobile Identifier for Privacy Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile networking environments, the inclusion of device identifiers in service requests raises privacy concerns and can lead to user profiling, as these identifiers are often transmitted in clear, potentially violating privacy laws and allowing third parties to build user profiles.
Innovation Solution
A new 'enriched' identifier is introduced, comprising a data string that identifies the user's home operator and an opaque unique identifier that only the home operator can decode, replacing or supplementing traditional identifiers like MSISDN, ensuring the user's privacy by obscuring their identity while allowing network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device identifiers (MSISDN, IMSI) are included in mobile service requests, then network operators can identify users and provide services, but user privacy is compromised and third parties can build user profiles
Solution Approach 1:
The patent segments the device identifier into two distinct parts: a first part that identifies the home network operator and a second part that obfuscates the actual device identity. This segmentation allows the system to maintain necessary identification capabilities while preventing direct exposure of user privacy information to third parties and foreign networks.
Solution Approach 2:
The patent introduces an intermediary mechanism where the home network operator acts as a mediator between the mobile device and foreign networks. The enriched identifier enables the home network to authenticate users while foreign networks only see the obfuscated second part, preventing direct privacy violations without compromising service provision.
2Object-affected harmful factors
If device identifiers are removed from service requests to protect privacy, then user profiling is prevented, but network operators cannot identify users or their home operators
Solution Approach 1:
The identifier is segmented such that the first part maintains home operator identification capability while the second part provides user-specific obfuscation. This allows the system to answer the home network's identification needs without exposing raw user identifiers to foreign networks.
Solution Approach 2:
Different parts of the enriched identifier serve different functions: the first part has the quality of being publicly readable for home operator identification, while the second part has the quality of being privately encoded for user-specific obfuscation. Each part has locally optimized properties suited to its specific purpose.
3Ease of operation
If traditional identifiers are used in clear text, then network services can be accessed, but third parties can decode and use identifiers to build profiles
Solution Approach 1:
The patent extracts the sensitive user identification information from the service request by separating it into an obfuscated second part that is only meaningful to the home network. This extraction prevents third parties from decoding and utilizing user profiles while maintaining service access through the enriched identifier structure.
Data Source
AI summary
A mobile device identifier (such as an MSISDN) that typically accompanies a mobile device request is replaced with an “enriched” identifier that exposes the mobile device user's home operator but obfuscates the mobile device's (and, thus, the device user's) identity. In one embodiment, the identifier comprises a first part, and a second part. The first part comprises a data string that identifies (either directly or through a database lookup) the mobile device user's home operator. The second part, however, is an opaque data string, such as a one-time-use unique identifier (UID) or a value that is otherwise derived as a function of the MSISDN (or the like). The opaque data string encodes the mobile device's identity in a manner that preferably can be recovered only by the user's home operator (or an entity authorized thereby). When the mobile device user roams into a foreign network, that network receives the enriched identifier in lieu of an MSISDN. The foreign network uses the first part to identify the mobile device user's home network, e.g., to determine whether to permit the requested access (or to provide some other value-added service). The foreign network, however, cannot decode the second part; thus, the mobile device's identity (as well as the identity of the mobile device user) remains obscured. This ensures that the user's privacy is maintained, while preventing third parties from building a profile of the device based on the requests that include the MSISDN or similar identifier.


