Pseudo IMSI Privacy in Telecommunications Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Attackers can track users by obtaining their International Mobile Subscriber Identity (IMSI) during the registration and communication process in telecommunications networks, and existing encryption methods are vulnerable to distributed denial-of-service (DDoS) attacks.
Innovation Solution
Incorporating a Trust Indicator (TrI) field in the communication process between user devices and networks, where the user device verifies the trust indicator from the serving network and encrypts the IMSI accordingly, using a pseudo IMSI that changes with each registration to limit the attacker's tracking ability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If the IMSI is transmitted in plaintext during registration, then the registration process is simple and fast, but attackers can obtain and track users by monitoring the IMSI
Solution Approach 1:
The patent creates a pseudo-IMSI as a copy of the real IMSI for transmission during registration. This pseudo-IMSI contains a subset of the real IMSI digits, allowing attackers to potentially infer the real IMSI but not fully track the user. The real IMSI is never transmitted, instead a derived copy is used to protect the original information.
Solution Approach 2:
The patent transforms the IMSI by selecting a subset of digits to create the pseudo-IMSI. This parameter change (from complete IMSI to partial pseudo-IMSI) reduces the information available to attackers while maintaining enough similarity for network identification purposes.
2Loss of information
If the IMSI is encrypted with the destination device's public key, then the IMSI is protected from attackers, but the destination device must decrypt and process every encrypted IMSI, making it vulnerable to DDoS attacks
Solution Approach 1:
The patent extracts only the necessary identifying digits from the IMSI to create the pseudo-IMSI, rather than transmitting or decrypting the complete IMSI. This extraction reduces the processing burden on the HLR/HSS while maintaining identification capability, thereby reducing DDoS vulnerability.
Solution Approach 2:
Instead of processing the complete IMSI, the system performs partial action by using only a subset of IMSI digits. This partial processing approach maintains security and identification functionality while significantly reducing the computational load on the HLR/HSS during authentication.
3Loss of information
If a static pseudo-IMSI is used for registration, then user tracking is reduced, but the pseudo-IMSI remains useful to attackers over time for continued tracking
Solution Approach 1:
The patent makes the pseudo-IMSI dynamic by regenerating it each time the user registers with the network. This dynamic approach ensures that even if an attacker obtains a pseudo-IMSI at one time, it becomes invalid after re-registration, preventing long-term tracking while maintaining user identification capability.
Data Source
AI summary
Techniques are disclosed for enhancing mobile subscriber privacy in telecommunications networks. In some embodiments, in the course of a registration process, a user device and an associated telecommunications network exchange trust indicators (TrIs), and respectively verify them. The user device and telecommunications network also transmit personally identifiable information (PII), such as an International Mobile Subscriber Identity (IMSI), in an encrypted form, and use a pseudo IMSI in place of the IMSI for the duration of the session.


