LTE IMSI Authentication via Asymmetric Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The vulnerability of International Mobile Station Identity (IMSI) exposure in LTE networks poses security risks, leading to potential tracking and privacy infringement of User Equipment (UE) during initial attach operations, which has not been adequately addressed by existing LTE technology upgrades.

Innovation Solution

A security authentication technique involving a computer program that acquires IMSI and location information from a controlled device, generates hash values, encrypts them using asymmetric key algorithms, and transmits encrypted data through secure channels to a home subscriber server for authentication, ensuring the IMSI is protected from exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IMSI is transmitted in plain text for LTE network authentication, then network access is enabled, but security vulnerability and privacy infringement occur

Engineering Contradiction:
Improvenetwork authentication reliabilityVSAvoidIMSI exposure vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary encryption mechanism between the UE and HSS. Instead of transmitting IMSI in plain text, the system uses encrypted identity representation and secure authentication vectors (AUTHENTICATION REQUEST, AUTHENTICATION RESPONSE) as intermediaries to convey authentication information without exposing the actual IMSI value over the air interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a secure copy mechanism where the actual IMSI is replaced by encrypted identity tokens and authentication vectors. The HSS stores the original IMSI securely, while the network uses copied authentication data (authentication vectors, encrypted identities) for verification, preventing exposure of the master identity copy during transmission.

Inventive Principle:
Principle #26Copying

2Length of moving object

If LTE network is used for drone communication, then operation range is expanded, but IMSI exposure vulnerability persists

Engineering Contradiction:
Improvedrone operation rangeVSAvoidIMSI exposure to third-party attacks
Core Design Contradiction:
Length of moving objectVSObject-affected harmful factors

Solution Approach 1:

For drone communication over LTE networks, the patent applies intermediary encryption mechanisms where drone identities are protected through encrypted authentication vectors and secure token-based verification. This allows drones to operate over extended LTE ranges while preventing third-party interception and tracking of their actual IMSI values.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary security measures by pre-configuring secure authentication credentials and encryption keys in drones before deployment. The system performs preliminary authentication setup where secure context is established beforehand, preventing potential IMSI exposure attacks during actual drone operations over the network.

Inventive Principle:
Principle #9Preliminary anti-action

3Adaptability or versatility

If existing LTE security measures are maintained, then network compatibility is preserved, but security vulnerability remains unaddressed

Engineering Contradiction:
ImproveLTE network compatibilityVSAvoidsecurity protection reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges traditional LTE authentication protocols with enhanced encryption mechanisms. It combines existing EPS-AKA (Evolved Packet System-Authentication and Key Agreement) procedures with additional layers of identity protection and secure context management, maintaining compatibility with legacy LTE infrastructure while addressing security vulnerabilities through integrated protective measures.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a composite security framework that layers multiple protection mechanisms over the LTE authentication stack. It combines encrypted identity representation, secure authentication vectors, integrity protection, and confidential data transmission protocols to form a multi-layered security structure that maintains LTE compatibility while providing robust protection against IMSI exposure attacks.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS11838755B2Techniques for secure authentication of the controlled devices
Publication Date: 2023.12.05 KOREA UNIV RES & BUSINESS FOUND
  • US11838755B2 patent drawing
  • US11838755B2 patent drawing
  • US11838755B2 patent drawing

AI summary

According to an exemplary embodiment of the present disclosure, a computer program stored in a computer readable storage medium is disclosed. The computer program includes commands which cause a processor of a control device to execute steps below, the steps including: acquiring International Mobile Station Identity (IMSI) related to a Subscriber Identity Module (SIM) and location information of a controlled device from the controlled device; calculating a hash value obtained by hashing the IMSI by using a hash function; generating first signature data in which the hash value and the location information are encrypted with a private key of the control device by using an asymmetric key algorithm; generating first encryption data obtained by encrypting the first signature data with a public key of a home subscriber server by using the asymmetric key algorithm; and transmitting a connection request message including the first encryption data to the home subscriber server.