Privacy Mobile Subscriber Identity for Wireless Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The international mobile subscriber identity (IMSI) is vulnerable to eavesdropping and tracking during wireless communication network attach procedures, as it is either included in plaintext in initial attach requests or must be provided for authentication, rendering it susceptible to monitoring and dependent on the trustworthiness of the serving network.
Innovation Solution
A privacy mobile subscriber identity (PMSI) is used instead of IMSI in initial attach messages, with a unique PMSI being derived and managed by both the user equipment (UE) and the server, ensuring that IMSI is not required between them, and the PMSI is updated and synchronized to protect identity privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IMSI is used for network authentication, then network access is enabled, but identity privacy is compromised due to eavesdropping and tracking vulnerabilities
Solution Approach 1:
The patent introduces PMSI as an intermediary identifier that mediates between the UE and serving network. Instead of directly using IMSI for authentication, the PMSI serves as a protective layer that allows authentication to proceed while preventing direct exposure of the IMSI to potential eavesdroppers and malicious network elements.
Solution Approach 2:
The patent creates a copy mechanism where PMSI acts as a temporary copy or representation of the IMSI. The PMSI can be derived from or associated with the IMSI but serves as a substitute during network attach procedures, allowing the system to work with a copy rather than the original sensitive identifier.
2Ease of operation
If IMSI is transmitted in plaintext during attach procedure, then network registration is completed, but security against monitoring is severely weakened
Solution Approach 1:
The patent changes the parameter being transmitted during network registration. Instead of transmitting the IMSI in plaintext, the system transmits the PMSI which can be encrypted or obfuscated. This parameter change maintains the functionality of network registration while improving security against monitoring.
3Reliability
If multiple network elements store IMSI for authentication purposes, then authentication capability is enhanced, but trust dependency increases
Solution Approach 1:
The PMSI acts as an intermediary that reduces trust dependency. By using PMSI instead of IMSI across multiple network elements, the system maintains authentication capability while reducing the need to trust each network element with the actual IMSI. The PMSI serves as a proxy that preserves functionality while minimizing trust requirements.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
Systems and techniques are disclosed to protect a user equipment's international mobile subscriber identity by providing a privacy mobile subscriber identity instead. In an attach attempt to a serving network, the UE provides the PMSI instead of IMSI, protecting the IMSI from exposure. The PMSI is determined between a home network server and the UE so that intermediate node elements in the serving network do not have knowledge of the relationship between the PMSI and the IMSI. Upon receipt of the PMSI in the attach request, the server generates a next PMSI to be used in a subsequent attach request and sends the next PMSI to the UE for confirmation. The UE confirms the next PMSI to synchronize between the UE and server and sends an acknowledgment token to the server. The UE and the server then each update local copies of the current and next PMSI values.