Privacy Mobile Subscriber Identity for Wireless Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The international mobile subscriber identity (IMSI) is vulnerable to eavesdropping and tracking during wireless communication network attach procedures, as it is either included in plaintext in initial attach requests or must be provided for authentication, rendering it susceptible to monitoring and dependent on the trustworthiness of the serving network.

Innovation Solution

A privacy mobile subscriber identity (PMSI) is used instead of IMSI in initial attach messages, with a unique PMSI being derived and managed by both the user equipment (UE) and the server, ensuring that IMSI is not required between them, and the PMSI is updated and synchronized to protect identity privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IMSI is used for network authentication, then network access is enabled, but identity privacy is compromised due to eavesdropping and tracking vulnerabilities

Engineering Contradiction:
Improvenetwork authenticationVSAvoididentity privacy vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces PMSI as an intermediary identifier that mediates between the UE and serving network. Instead of directly using IMSI for authentication, the PMSI serves as a protective layer that allows authentication to proceed while preventing direct exposure of the IMSI to potential eavesdroppers and malicious network elements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy mechanism where PMSI acts as a temporary copy or representation of the IMSI. The PMSI can be derived from or associated with the IMSI but serves as a substitute during network attach procedures, allowing the system to work with a copy rather than the original sensitive identifier.

Inventive Principle:
Principle #26Copying

2Ease of operation

If IMSI is transmitted in plaintext during attach procedure, then network registration is completed, but security against monitoring is severely weakened

Engineering Contradiction:
Improvenetwork registrationVSAvoidmonitoring vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent changes the parameter being transmitted during network registration. Instead of transmitting the IMSI in plaintext, the system transmits the PMSI which can be encrypted or obfuscated. This parameter change maintains the functionality of network registration while improving security against monitoring.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple network elements store IMSI for authentication purposes, then authentication capability is enhanced, but trust dependency increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidtrust dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The PMSI acts as an intermediary that reduces trust dependency. By using PMSI instead of IMSI across multiple network elements, the system maintains authentication capability while reducing the need to trust each network element with the actual IMSI. The PMSI serves as a proxy that preserves functionality while minimizing trust requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3846514B1Identity privacy in wireless networks
Publication Date: 2024.10.02 QUALCOMM INC
  • EP3846514B1 patent drawingFigure 1
  • EP3846514B1 patent drawingFigure 2~3
  • EP3846514B1 patent drawingFigure 4

AI summary

Systems and techniques are disclosed to protect a user equipment's international mobile subscriber identity by providing a privacy mobile subscriber identity instead. In an attach attempt to a serving network, the UE provides the PMSI instead of IMSI, protecting the IMSI from exposure. The PMSI is determined between a home network server and the UE so that intermediate node elements in the serving network do not have knowledge of the relationship between the PMSI and the IMSI. Upon receipt of the PMSI in the attach request, the server generates a next PMSI to be used in a subsequent attach request and sends the next PMSI to the UE for confirmation. The UE confirms the next PMSI to synchronize between the UE and server and sends an acknowledgment token to the server. The UE and the server then each update local copies of the current and next PMSI values.