Privacy Module for Wireless Authentication Identity Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication systems face privacy risks due to the insecure transmission of international mobile subscriber identities (IMSI), which can be intercepted by third parties, compromising user location privacy.
Innovation Solution
Implementing a privacy mobile subscriber identity (PMSI) that is different from IMSI for authentication, allowing the user equipment (UE) to request initialization and generate a new identity for each attachment procedure, with the privacy module communicating with the universal subscriber identity module (USIM) to maintain and encrypt the PMSI for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the UE uses IMSI for authentication, then the authentication procedure can be completed, but the user privacy is compromised due to IMSI interception risks
Solution Approach 1:
The patent segments the authentication process into two phases: initial authentication using IMSI, and subsequent authentication using a temporary identity (TMSI). This segmentation allows the system to use different identity types for different purposes, reducing privacy exposure while maintaining authentication reliability.
Solution Approach 2:
The patent introduces TMSI as an intermediary identity that mediates between the permanent IMSI and the network. The TMSI acts as a temporary placeholder that protects the IMSI from direct exposure during routine authentication, thus reducing privacy risks while maintaining system functionality.
2Object-affected harmful factors
If the UE requests initialization of additional mobile subscriber identity, then privacy is protected through temporary identities, but the device complexity increases due to multiple identity management
Solution Approach 1:
The patent implements dynamic identity management where the UE can switch between IMSI and TMSI based on operational needs. The system dynamically requests initialization of additional identities when privacy protection is needed and releases them when not required, reducing the burden of permanent complex identity management.
Solution Approach 2:
The patent employs a strategy where temporary identities (TMSI) are discarded after use and new ones are generated as needed. This approach avoids the complexity of permanently managing multiple identities while still providing privacy protection during critical authentication phases.
3Device complexity
If the USIM does not support storage of alternative identity, then the device structure remains simple, but the privacy protection capability is reduced
Solution Approach 1:
The patent introduces a privacy module as an intermediary layer between the USIM and the network. This module manages temporary identities in memory when the USIM cannot store them, providing privacy protection without requiring modifications to the USIM structure.
Solution Approach 2:
The patent creates a functional copy of the identity management capability in the privacy module, which can generate and manage TMSI even when the USIM lacks storage capacity. This copying approach preserves privacy protection functionality while maintaining USIM structural simplicity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods, systems, and devices for wireless communication are described. A user equipment (UE) may perform authentication procedures using an alternative identity (e.g., a privacy mobile subscriber identity (PMSI)) instead of an international mobile subscriber identity (IMSI) to protect the privacy of the user. If the UE does not have a PMSI, it may include a request for a PMSI initialization in an attach request. In some cases, the PMSI may be used once, and a new PMSI may be generated for the next attachment procedure. In some cases, a universal subscriber identity module (USIM) of the UE may not support storage of a PMSI. So a privacy module of the UE may communicate with the USIM according to the USIMs capabilities and may maintain a PMSI separately for communication with the network.