LTE Network Element IMSI Discovery via Fake Service Reject
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In LTE wireless communication systems, there is no standard method for a radio access network element, such as an eNode B, to request and obtain the permanent subscriber identity (IMSI) of a wireless communication unit due to security design limitations, which restricts access control and tracking within the network.
Innovation Solution
A method and network element that prompts the wireless communication unit to provide its permanent subscriber identity by generating a response message with a cause code, allowing the network element to store and use the IMSI for access control, and subsequently receive a new temporary identity from the core network, enabling association of subsequent requests with the discovered IMSI without breaching LTE security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If LTE security design is implemented to protect subscriber identity, then security is improved, but the network element cannot request or obtain the permanent subscriber identity (IMSI)
Solution Approach 1:
The patent introduces a temporary identity (TMSI) as an intermediary between the network element and the permanent subscriber identity (IMSI). The network element stores the TMSI received from the UE during initial attachment, and uses this TMSI for subsequent identification purposes. This intermediary mechanism allows the network to identify subscribers without directly accessing or storing the IMSI, thus maintaining security while enabling necessary identification functions.
Solution Approach 2:
The patent segments the subscriber identification process into two parts: the permanent identity (IMSI) that remains protected and the temporary identity (TMSI) that is used for network operations. By separating these functions, the system maintains security of the IMSI while enabling the network element to perform identification and tracking operations using the less sensitive TMSI.
2Reliability
If the network element cannot access the permanent subscriber identity, then security is maintained, but access control and tracking capabilities are limited
Solution Approach 1:
The temporary identity (TMSI) serves as a mediator that enables access control and tracking functions without requiring direct access to the permanent IMSI. The network element can store and process the TMSI to identify subscribers, control access, and track movements, while the IMSI remains protected and inaccessible to the network element.
Solution Approach 2:
The system creates a copy of the subscriber identity in the form of a temporary identity (TMSI) that can be freely processed and stored by the network element. This copy allows the network to perform identification and tracking operations without handling the original permanent identity (IMSI), thus maintaining security while enabling necessary network functions.
3Adaptability or versatility
If standard User Equipment is used without modification, then compatibility is improved, but the network element cannot determine subscriber identity
Solution Approach 1:
The patent enables the network element to perform subscriber identity determination through self-service mechanisms by storing and processing the temporary identity (TMSI) that the UE provides during initial attachment. The network element uses this self-provided TMSI for subsequent identification operations, eliminating the need for UE modification while maintaining compatibility with standard equipment.
Solution Approach 2:
The temporary identity (TMSI) acts as an intermediary that standard User Equipment provides during initial network attachment. This intermediary identity allows the network element to determine and track subscriber identity without requiring the UE to provide or modify its permanent IMSI, thus maintaining compatibility with standard equipment while enabling identity determination.
Data Source
AI summary
A radio access network element (101) obtains a permanent subscriber identity (IMSI) of a User Equipment (103) in an LTE wireless communication system (100) by sending a “fake” service reject message to a User Equipment which has attempted to attach to a cell (102) in a request for services message which includes its S-TMSI. The reject message may include a cause code which results in the UE attempting to attach again, this time using its IMSI. The fake service reject message may be generated in a an eNode B serving one or more macrocells or a evolved Home Node B serving a small cell.


