Subscriber Identity Concealment via Encrypted Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network technologies lack effective mechanisms to conceal subscriber identities from access network providers, allowing for potential tracking and correlation of user sessions.

Innovation Solution

The implementation of a method where first identity data associated with a client device is encrypted using second identity data, creating an encrypted version that is provided to an access network, thereby concealing identifiers over signaling links.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If subscriber identity data is transmitted in clear text over signaling links, then network authentication and authorization can be performed, but user privacy is compromised and sessions can be correlated and tracked by access providers

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidprivacy loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an identity encryption mechanism that acts as an intermediary between the clear text identity data and the access network. The subscriber's identity is encrypted using a public key or hash function before transmission, creating a pseudonymous identifier that preserves authentication functionality while preventing direct correlation and tracking by access providers

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the identity data from its original clear text form into an encrypted form using cryptographic parameters. This parameter change maintains the uniqueness and authenticity verification capabilities of the original identity while rendering it unreadable and uncorrelatable by unauthorized parties

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If encrypted identity data is used to conceal subscriber identities, then user privacy is protected, but network providers lose the ability to directly identify and correlate user sessions

Engineering Contradiction:
Improveprivacy lossVSAvoidsession correlation precision
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The encrypted identity acts as a mediator that preserves session uniqueness and authenticity verification while preventing direct correlation. The encryption mechanism maintains the ability to distinguish between different subscribers through cryptographic verification without enabling direct identification or tracking by access network providers

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If clear text identity data is transmitted, then network access control can be implemented, but intermediate proxies can track and correlate user sessions

Engineering Contradiction:
Improvenetwork access controlVSAvoidsession tracking
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent introduces encrypted identity data as an intermediary that maintains network access control functionality while eliminating session tracking capabilities. The encryption mechanism allows proxies and access points to verify and control access without being able to read or correlate the actual subscriber identities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The transformation of identity data from clear text to encrypted form changes the parameter of readability from accessible to inaccessible. This maintains the functional parameter of access control verification while eliminating the harmful capability of session tracking and correlation by intermediate proxies

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250031034A1Subscriber Identity Concealment From Access Network Provider
Publication Date: 2025.01.23 CISCO TECHNOLOGY INC
  • US20250031034A1 patent drawing
  • US20250031034A1 patent drawing
  • US20250031034A1 patent drawing

AI summary

Subscriber identity concealment from an access network provider may be provided. A computing device may receive first identity data associated with a client device. Then the first identity data associated with the client device may be encrypted using second identity data to create an encrypted version of the first identity data associated with the client device. The encrypted version of the first identity data associated with the client device may be provided to an access network.