PRUK ID Substitution for Relay Terminal Privacy Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the context of wearable devices connected to networks via relay terminals, the international mobile subscriber identity (IMSI) is easily obtainable, leading to privacy concerns and potential fraud when the relay terminal is compromised.
Innovation Solution
The method involves using a proximity service relay user key identity (PRUK ID) to replace the IMSI, ensuring that the IMSI is not directly transmitted, thereby preventing interception by the relay terminal, and employing encryption and integrity protection mechanisms to secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the relay terminal is used to enable remote terminal to access network, then transmission efficiency is improved, but IMSI privacy is compromised
Solution Approach 1:
The patent introduces a privacy protection mechanism where the relay terminal acts as an intermediary that obtains the remote terminal's IMSI through encrypted communication with the network side, rather than directly accessing the unencrypted IMSI. The relay terminal requests IMSI information from the network side system through a secure channel, decrypting it using a shared key, thus preventing direct IMSI exposure while maintaining network access functionality.
2Ease of operation
If the IMSI is transmitted in unencrypted NAS message, then communication simplicity is maintained, but security protection is insufficient
Solution Approach 1:
The patent changes the parameter of message encryption by introducing encryption for NAS messages containing IMSI information. The network side system and relay terminal share an encryption key, and the IMSI is encrypted before transmission through the relay terminal. This maintains the simplicity of the communication protocol while significantly enhancing security protection against IMSI interception.
3Device complexity
If the relay terminal directly obtains IMSI, then authentication is simplified, but fraud risk increases
Solution Approach 1:
The patent uses the network side system as an intermediary that manages the authentication process securely. Instead of the relay terminal directly obtaining the IMSI, the network side system verifies the relay terminal's identity and then provides the encrypted IMSI information. This intermediary approach simplifies the relay terminal's authentication while preventing fraud by ensuring only authorized terminals can access IMSI data through secure channels.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
Embodiments of this application relate to a method and a device for protecting privacy. The method includes: sending, by a remote terminal, a first message to a mobility management entity by using a relay terminal, where the first message includes first identity information of the remote terminal, and the first message is used by the mobility management entity to obtain an international mobile subscriber identity IMSI of the remote terminal based on the first identity information of the remote terminal, where the first identity information is a proximity service relay user key identity PRUK ID. Because the first identity information is used to replace the IMSI, interception of the IMSI by the relay terminal is avoided, and user privacy is protected.