Secure Identifier Generation for 5G User Equipment Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security management of user equipment identifiers in 5G communication networks faces challenges due to the exposure of public subscription identifiers, which can lead to security and privacy risks when shared with external entities.

Innovation Solution

Generating a secure identifier by encrypting the public subscription identifier associated with user equipment and using it for verification in subsequent requests from external entities, ensuring the identifier's validity and confidentiality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If public subscription identifiers are shared with external entities for identification purposes, then external entities can access and identify user equipment, but security and privacy risks increase due to potential unauthorized access and misuse

Engineering Contradiction:
Improveexternal entity access to user identificationVSAvoidsecurity and privacy risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secure identifier as an intermediary between the public subscription identifier and external entities. This secure identifier acts as a mediator that allows external entities to identify user equipment without direct exposure of the original public subscription identifier, thereby maintaining security while enabling external access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of the public subscription identifier in the form of a secure identifier. This copy contains the necessary identification information for external entities to recognize and verify user equipment, while the original public subscription identifier remains protected within the network.

Inventive Principle:
Principle #26Copying

2Object-affected harmful factors

If public subscription identifiers are protected through encryption and kept internal to the network, then security and privacy are enhanced, but external entities cannot directly access or verify user equipment identification

Engineering Contradiction:
Improvesecurity and privacy protectionVSAvoidexternal entity verification capability
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The secure identifier serves as an intermediary that bridges the gap between internal security requirements and external verification needs. It allows the network to maintain encrypted protection of public subscription identifiers while providing external entities with a verifiable identification mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the public subscription identifier into a secure identifier with different parameters - specifically, it is network-internal and encrypted rather than public and unencrypted. This parameter change enables the identifier to function differently: protected within the network while still allowing external verification through its unique properties.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If a secure identifier system is implemented to protect public subscription identifiers, then security is improved, but system complexity increases due to additional encryption and verification mechanisms

Engineering Contradiction:
Improveidentifier securityVSAvoidencryption and verification system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent extracts the essential identification function from the public subscription identifier and places it into a separate secure identifier. This extraction allows the security mechanisms to operate independently on the secure identifier, simplifying the overall system architecture by separating identification from authentication functions.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11956627B2Securing user equipment identifier for use external to communication network
Publication Date: 2024.04.09 NOKIA TECHNOLOGIES OY
  • US11956627B2 patent drawing
  • US11956627B2 patent drawing
  • US11956627B2 patent drawing

AI summary

Techniques for securing an identifier of user equipment for a request external to a communication network are disclosed. For example, a method comprises receiving, at a network entity, a request for identification information for user equipment from an entity external to a communication network to which the network entity belongs. The network entity generates a secure identifier for the user equipment, wherein the secure identifier comprises an encrypted form of a public subscription identifier associated with the user equipment. The network entity sends the secure identifier to the external entity. The network entity receives the secure identifier in a subsequent request from the external entity. The network entity utilizes the received secure identifier to confirm the received secure identifier corresponds to the user equipment.