LTE Network Element IMSI Discovery via Fake Service Reject

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In LTE wireless communication systems, there is no standard method for a radio access network element, such as an eNode B, to request and obtain the permanent subscriber identity (IMSI) of a wireless communication unit due to security design limitations, which restricts access control and tracking within the network.

Innovation Solution

A method and network element that prompts the wireless communication unit to provide its permanent subscriber identity by generating a response message with a cause code, allowing the network element to store and use the IMSI for access control, and subsequently receive a new temporary identity from the core network, enabling association of subsequent requests with the discovered IMSI without breaching LTE security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If LTE security design is implemented to protect subscriber identity, then security is improved, but the network element cannot request or obtain the permanent subscriber identity (IMSI)

Engineering Contradiction:
ImprovesecurityVSAvoidaccess to IMSI
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a temporary identity (TMSI) as an intermediary between the network element and the permanent subscriber identity (IMSI). The network element stores the TMSI received from the UE during initial attachment, and uses this TMSI for subsequent identification purposes. This intermediary mechanism allows the network to identify subscribers without directly accessing or storing the IMSI, thus maintaining security while enabling necessary identification functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the subscriber identification process into two parts: the permanent identity (IMSI) that remains protected and the temporary identity (TMSI) that is used for network operations. By separating these functions, the system maintains security of the IMSI while enabling the network element to perform identification and tracking operations using the less sensitive TMSI.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the network element cannot access the permanent subscriber identity, then security is maintained, but access control and tracking capabilities are limited

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control and tracking
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The temporary identity (TMSI) serves as a mediator that enables access control and tracking functions without requiring direct access to the permanent IMSI. The network element can store and process the TMSI to identify subscribers, control access, and track movements, while the IMSI remains protected and inaccessible to the network element.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a copy of the subscriber identity in the form of a temporary identity (TMSI) that can be freely processed and stored by the network element. This copy allows the network to perform identification and tracking operations without handling the original permanent identity (IMSI), thus maintaining security while enabling necessary network functions.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If standard User Equipment is used without modification, then compatibility is improved, but the network element cannot determine subscriber identity

Engineering Contradiction:
ImprovecompatibilityVSAvoidsubscriber identity determination
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent enables the network element to perform subscriber identity determination through self-service mechanisms by storing and processing the temporary identity (TMSI) that the UE provides during initial attachment. The network element uses this self-provided TMSI for subsequent identification operations, eliminating the need for UE modification while maintaining compatibility with standard equipment.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The temporary identity (TMSI) acts as an intermediary that standard User Equipment provides during initial network attachment. This intermediary identity allows the network element to determine and track subscriber identity without requiring the UE to provide or modify its permanent IMSI, thus maintaining compatibility with standard equipment while enabling identity determination.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9654979B2Network elements, wireless communication system and methods therefor
Publication Date: 2017.05.16 MAVENIR IPA UK LTD
  • US9654979B2 patent drawing
  • US9654979B2 patent drawing
  • US9654979B2 patent drawing

AI summary

A radio access network element (101) obtains a permanent subscriber identity (IMSI) of a User Equipment (103) in an LTE wireless communication system (100) by sending a “fake” service reject message to a User Equipment which has attempted to attach to a cell (102) in a request for services message which includes its S-TMSI. The reject message may include a cause code which results in the UE attempting to attach again, this time using its IMSI. The fake service reject message may be generated in a an eNode B serving one or more macrocells or a evolved Home Node B serving a small cell.