Network Monitoring Node for Subscriber Device Identifier Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

LTE networks' enhanced security features hinder effective network analytics, such as device analytics and UE tracking, by obscuring UE identifiers, and conventional methods to bypass this are not universally applicable.

Innovation Solution

Implementing network monitoring nodes that map temporary UE identifiers to subscriber and device identifiers in real-time across various network tap points, without compromising security, by receiving and decrypting authentication and data messages, and deriving encryption keys to correlate UE traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If LTE networks use temporary identifiers to protect UE identification during radio interface transmission, then security against interception is improved, but network analytics capability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork analytics capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary system comprising a network tap, message inspector, and mapping database that mediates between the encrypted temporary identifiers and the analytics system. The message inspector intercepts authentication messages, extracts permanent identifiers, and the mapping database correlates temporary identifiers with permanent ones, enabling analytics without exposing security vulnerabilities or requiring changes to LTE security protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts permanent identifiers (IMSI, IMEI) from authentication messages during the authentication phase, separating the identification function from the temporary identifier usage. This extraction occurs once during authentication, allowing the system to maintain temporary identifiers for security while having permanent identifiers available for analytics purposes

Inventive Principle:
Principle #2Taking out (Extraction)

2Loss of information

If conventional approaches solicit information from MME vendors to bypass security features, then network analytics capability is improved, but device complexity and vendor dependency increase

Engineering Contradiction:
Improvenetwork analytics capabilityVSAvoidvendor dependency
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements a self-service approach where the network operator deploys their own monitoring infrastructure (network tap, message inspector, mapping database) to extract identifiers from authentication messages. This eliminates dependency on vendor support, as the system uses standard LTE authentication protocols that all vendors must implement, allowing operators to independently capture analytics data without soliciting information from MME vendors

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9686675B2Systems, methods and devices for deriving subscriber and device identifiers in a communication network
Publication Date: 2017.06.20 NETSCOUT SYSTEMS TEXAS LLC
  • US9686675B2 patent drawing
  • US9686675B2 patent drawing
  • US9686675B2 patent drawing

AI summary

A network monitoring node receives one or more data messages regarding User Equipment (UE) from one or more network interfaces for a communication session in the communication network continuously in real-time, determines a subscriber identification (ID) associated with the UE from the one or more data messages regarding the UE, and determines an equipment identification (ID) associated with the UE from the one or more data messages regarding the UE. The network monitoring node further receives a base-key associated with the UE from the one or more data messages regarding the UE, derives a decryption key from the base-key, decrypts a temporary ID associated with the UE from the one or more data messages regarding the UE based on the decryption key, maps the temporary ID with the subscriber ID for the UE, and the subscriber ID with the equipment ID for the UE, and assigns data messages for all further communication sessions to the UE based on the mapping. The Subscriber ID and Equipment ID are preferably assigned to all further communication sessions for that UE. It updates the mapping when changes to the temporary ID or equipment ID occur.