Privacy Token System for Mobile Identity Concealment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile communication systems fail to adequately privatize data, making it possible to attribute sensitive information to specific entities in case of a data breach, especially with the increasing use of IoT devices and connected vehicles.

Innovation Solution

A method that uses dynamic International Mobile Subscriber Identity (IMSI) and Mobile Station International Subscriber Directory Number (MSISDN) via a privacy token system, where the International Mobile Equipment Identity (IMEI) is concealed from Mobile Network Operators (MNOs), and privacy tokens with predefined validity periods are obtained from a token database, such as a blockchain ledger, to establish anonymous communications sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If the IMEI is concealed from the MNO to ensure privacy, then the anonymity of the UE is improved, but the ability to establish communication sessions and perform billing is worsened

Engineering Contradiction:
ImproveUE identity visibility to MNOVSAvoidcommunication session establishment
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent introduces a privacy token as an intermediary between the UE and MNO. The privacy token contains an IMSI that the MNO can use for communication sessions and billing, while the actual UE identity (IMEI) remains concealed. The privacy token acts as a mediator that enables necessary operations without revealing sensitive identity information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the identity information into multiple components: the permanent UE identity (IMEI) that remains concealed, the privacy token that provides temporary identification, and the IMSI within the token that enables network operations. This segmentation allows different functions to be performed with different levels of identity exposure.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If a privacy token with predefined validity period is used, then the privacy protection is improved, but the complexity of token management and renewal is worsened

Engineering Contradiction:
Improvedata attribution capabilityVSAvoidtoken renewal process
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements periodic action by setting predefined validity periods for privacy tokens. Tokens are automatically renewed before expiration, creating a periodic cycle of token issuance and renewal. This ensures continuous privacy protection while maintaining a structured management approach.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent applies preliminary action by obtaining new privacy tokens before the current tokens expire. The renewal process is initiated in advance, ensuring there is always a valid token available and preventing communication interruptions due to token expiration.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If dynamic IMSI and MSISDN are reassigned to privacy tokens, then the anonymity against data breaches is improved, but the difficulty of tracking communications for billing is worsened

Engineering Contradiction:
Improvecommunication attribution to UEVSAvoidbilling transaction tracking
Core Design Contradiction:
Loss of informationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms where the MNO receives billing transaction messages that reference the privacy token. The system maintains the ability to track which UE generated which billing transactions through the token reference, even though the dynamic IMSI and MSISDN prevent direct attribution. The feedback loop allows billing to be processed while maintaining privacy.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The privacy token serves as an intermediary that bridges the gap between anonymous communication and billable services. The token's IMSI and MSISDN enable communication tracking for billing purposes, while the token's association with the UE (managed through the blockchain ledger and token server) ensures proper chargeback to the correct subscriber without exposing identity information.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If the MNO obtains privacy tokens via an Intermediate Token Server without direct database access, then the security against MNO compromise is improved, but the speed of token retrieval is worsened

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidtoken retrieval time
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent introduces an Intermediate Token Server as a mediator between the MNO and the blockchain ledger. This intermediary layer enhances security by preventing direct access to the token database by the MNO, reducing the attack surface in case of MNO compromise. The Intermediate Token Server handles token retrieval requests, maintaining both security and operational functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11223957B1Method of privatizing mobile communications using dynamic IMSI and MSISDN
Publication Date: 2022.01.11 SYNIVERSE TECHNOLOGIES LLC
  • US11223957B1 patent drawing
  • US11223957B1 patent drawing
  • US11223957B1 patent drawing

AI summary

A method of privatizing mobile communications using a dynamic International Mobile Subscriber Identity (IMSI) and Mobile Station International Subscriber Director Number (MSISDN). A first privacy token having an associated IMSI and MSISDN is provided to a User Equipment (UE). The first privacy token has a predefined validity period. The IMSI and MSISDN assigned to the privacy token are shared with a plurality of Mobile Network Operators (MNOs), while the International Mobile Equipment Identity (IMEI) of the UE remains concealed. A communications session for the UE can be established based on the first privacy token during the validity period thereof. Upon expiration of the validity period, the first privacy token and the associated IMSI and MSISDN are released to the token database, and their association with one another is deleted. The UE is then provided with a second privacy token having a different associated IMSI and MSISDN.