P-GUTI Segmentation for Mobile Network Location Tracking Deterrence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile virtual network operators (MVNOs) face increased susceptibility to location tracking and attacks due to enhanced connectivity, which exposes UE devices to greater signaling traffic and potential security vulnerabilities, particularly during network switches and hand-offs.

Innovation Solution

Implementing a pseudo-Globally Unique Temporary Identifier (p-GUTI) in paging messages, using nonces in attach request and security mode command messages, and integrity protecting attach request and tracking area update messages to deter location tracking and prevent impersonation and replay attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If MVNO subscribers access multiple MNO spectrums for enhanced connectivity, then cellular coverage and connectivity are improved, but signaling traffic increases and security vulnerabilities are exposed

Engineering Contradiction:
Improvecellular coverageVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The GUTI identifier is segmented into multiple components (MME_ID, M-TMSI) and further divided between two core network devices. The first core network device holds MME_ID while the second holds M-TMSI, so that neither device alone can fully identify the UE device, preventing tracking attacks while maintaining connectivity across multiple networks

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A pseudo-GUTI identifier is introduced as an intermediary that masks the real GUTI. This pseudo-identifier is generated by combining information from both core network devices and is used in paging messages, allowing the system to maintain security while enabling enhanced connectivity across multiple MNO spectrums

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If paging messages include GUTI for location tracking, then network can locate UE devices, but location tracking attacks are enabled

Engineering Contradiction:
Improvelocation trackingVSAvoidlocation tracking attacks
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The GUTI identifier is segmented into multiple components (MME_ID, M-TMSI) and further divided between two core network devices. The first core network device holds MME_ID while the second holds M-TMSI, so that neither device alone can fully identify the UE device, preventing tracking attacks while maintaining connectivity across multiple networks

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A pseudo-GUTI identifier is created as a copy that serves the same functional purpose as the real GUTI in paging messages but does not reveal the actual UE identity. This copy is generated by combining information from both core network devices and is used instead of the real GUTI in paging messages, allowing location tracking functionality while preventing tracking attacks

Inventive Principle:
Principle #26Copying

3Ease of operation

If attach request messages are sent in clear text for network attachment, then connection establishment is simplified, but sensitive information is exposed to eavesdroppers

Engineering Contradiction:
Improveconnection establishmentVSAvoidinformation exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Integrity protection and encryption are applied preliminarily to attach request messages before they are transmitted. This prevents eavesdropping and replay attacks by ensuring that any modification or interception of the message can be detected, while still allowing straightforward connection establishment through the protected messaging protocol

Inventive Principle:
Principle #9Preliminary anti-action

4Reliability

If security measures like encryption are implemented, then security is improved, but message complexity and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidmessage complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security context information including encryption keys and integrity protection parameters are established in advance during the initial attach procedure. This preliminary action allows subsequent messages to be protected without adding significant complexity, as the security framework is already in place and can be reused for multiple communications

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10154369B2Deterrence of user equipment device location tracking
Publication Date: 2018.12.11 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10154369B2 patent drawing
  • US10154369B2 patent drawing
  • US10154369B2 patent drawing

AI summary

Examples include deterrence of user equipment (UE) device location tracking. Some examples include a core network device of a telecommunication network having a processing resource and a machine-readable storage medium with instructions executable by the processing resource to receive a first service request message from the UE device that includes a pseudo-Globally Unique Temporary Identifier (p-GUTI), to send a paging message that includes the p-GUTI, and to receive a second service request message from the UE device that includes a new p-GUTI based on the p-GUTI of the first service request message matching the p-GUTI of the paging message.