Encrypting IMSI with Public Key Cryptography for Wi-Fi Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems expose the International Mobile Subscriber Identity (IMSI) during authentication processes, compromising user privacy, especially in active attacks, as EAP clients often send the permanent identity in the clear.
Innovation Solution
Implementing public key cryptography to encrypt the IMSI at the EAP method layer, where the wireless device uses the authentication server's public key to encrypt the IMSI, and the server decrypts it using its private key, with the option to provide a key identifier for key location, ensuring confidentiality and protecting against passive and active attackers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the EAP client sends the permanent identity (IMSI) during authentication, then authentication can be completed, but user privacy is compromised and the IMSI is exposed in clear form
Solution Approach 1:
The patent applies preliminary action by pre-configuring the wireless device with the authentication server's public key before the authentication process. This allows the device to encrypt the IMSI in advance before transmission, ensuring that the permanent identity is never sent in clear form while still enabling successful authentication when the server decrypts it with its private key.
Solution Approach 2:
The patent introduces public key cryptography as an intermediary mechanism between the wireless device and the authentication server. The public key acts as a mediator that allows the IMSI to be transmitted in encrypted form, preventing direct exposure of the permanent identity while maintaining the authentication function. The encryption layer serves as the intermediary that protects the IMSI during transmission.
2Object-affected harmful factors
If public key cryptography is implemented to encrypt the IMSI, then user privacy and security are enhanced, but the authentication system complexity increases
Solution Approach 1:
The patent applies self-service by having the wireless device autonomously perform the encryption of the IMSI using the pre-configured public key. The device automatically manages the encryption process without requiring additional manual configuration or complex key management infrastructure, reducing the overall system complexity while maintaining security.
Solution Approach 2:
The public key is pre-configured in the wireless device before authentication occurs, eliminating the need for complex real-time key distribution mechanisms. This preliminary setup simplifies the authentication process by having the encryption capability already in place, reducing the complexity burden during the actual authentication exchange.
Data Source
AI summary
This disclosure relates to techniques for performing Wi-Fi authentication in a wireless communication system. Public key cryptography may be used to enhance the confidentiality of the user's permanent identity in transit. In some embodiments, a RSA-OAEP(SHA-256) encryption scheme may be used to protect the permanent identity when the EAP client needs to send the user's permanent identity to the server in the absence of pseudonym or fast re-authentication identity. In some embodiments, a server certificate is used to authenticate a iWLAN tunnel to protect an IMSI during setup of a Wi-Fi call. Using the methods described herein on both or either of the EAP client and server side may offer improved privacy protection.


