Temporary ID Management for Wireless Network Privacy and Billing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current EAP technologies fail to provide effective privacy protection, accounting, and authorization in cross-domain wireless networks, particularly in public wireless environments where malicious access points can compromise user identity and lead to unauthorized charges.
Innovation Solution
A method and system that utilize a short-term certificate issued by an ID management server to establish a secure channel between a mobile device and an access point, enabling anonymous temporary ID management while ensuring accounting and authorization, with the ID management server recording the relationship between temporary and real IDs to prevent unauthorized use and charges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If a temporary ID is used to protect user privacy in cross-domain wireless networks, then user anonymity is improved, but the ability to perform accounting and authorization deteriorates
Solution Approach 1:
The patent segments the authentication and accounting functions by introducing an ID management server that separately manages temporary IDs and real IDs. The temporary ID is used for authentication in the visited network to protect privacy, while the real ID is stored securely in the ID management server for accurate accounting and authorization. This segmentation allows both privacy protection and reliable billing to coexist.
Solution Approach 2:
The ID management server acts as an intermediary between the visited network and the home network. It receives authentication requests containing temporary IDs, resolves them to real IDs, and performs accounting and authorization operations. This intermediary mechanism enables the temporary ID system to maintain both anonymity for users and accountability for billing.
2Duration of action of moving object
If a long-term temporary ID is used for extended network access, then user convenience is improved, but the risk of identity compromise and unauthorized charges increases
Solution Approach 1:
The patent implements dynamic temporary ID generation where IDs are created with specific validity periods. The system can issue temporary IDs for different durations based on service requirements, and automatically revokes them after expiration. This dynamic approach allows long-term network access through sequential ID issuance while minimizing the exposure window for each individual ID.
Solution Approach 2:
The system treats temporary IDs as disposable credentials that are generated, used, and discarded. Each temporary ID has a limited lifecycle and is invalidated after use or expiration. This approach allows the system to issue numerous short-lived IDs for extended access periods, reducing the impact of any single ID compromise while maintaining continuous service.
3Adaptability or versatility
If multiple network operators are integrated to support cross-domain authentication, then network versatility is improved, but system complexity increases
Solution Approach 1:
The ID management server is designed as a universal component that can serve multiple network operators and support various authentication protocols. It implements a standardized interface for temporary ID resolution and accounting operations, allowing different home networks and visited networks to interoperate without requiring complex bilateral agreements between each operator pair.
Solution Approach 2:
The patent introduces an intermediary ID management server that simplifies multi-operator integration by centralizing the temporary ID resolution function. Instead of requiring direct trust and communication channels between every pair of network operators, the ID management server acts as a universal mediator that handles authentication and accounting requests from any participating network, reducing integration complexity.
Data Source
AI summary
A method and a system for managing network identity are provided. The method and the system realize a management mechanism of temporary identification (ID) and real ID, which simultaneously achieves functionalities such as anonymity, accounting, and authorization. A short-term certificate and a corresponding public/private key pair are used to protect a temporary ID usable for accounting. This protection prevents the temporary ID from theft. The user generates a digital signature in the reply to a charge schedule statement from the visited network. This procedure is incorporated into an existing authentication framework based on Transport Layer Security (TLS) in order to provide an undeniable payment mechanism. The payment mechanism is applicable in an environment of multiple network operators and reduces the difficulty of integrating network operators. The method and the system do not have to consult a certificate revocation list (CRL) for authentication and thus are able to shorten authentication time.


