Temporary ID Management for Wireless Network Privacy and Billing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current EAP technologies fail to provide effective privacy protection, accounting, and authorization in cross-domain wireless networks, particularly in public wireless environments where malicious access points can compromise user identity and lead to unauthorized charges.

Innovation Solution

A method and system that utilize a short-term certificate issued by an ID management server to establish a secure channel between a mobile device and an access point, enabling anonymous temporary ID management while ensuring accounting and authorization, with the ID management server recording the relationship between temporary and real IDs to prevent unauthorized use and charges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If a temporary ID is used to protect user privacy in cross-domain wireless networks, then user anonymity is improved, but the ability to perform accounting and authorization deteriorates

Engineering Contradiction:
Improveuser privacyVSAvoidaccounting and authorization
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent segments the authentication and accounting functions by introducing an ID management server that separately manages temporary IDs and real IDs. The temporary ID is used for authentication in the visited network to protect privacy, while the real ID is stored securely in the ID management server for accurate accounting and authorization. This segmentation allows both privacy protection and reliable billing to coexist.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The ID management server acts as an intermediary between the visited network and the home network. It receives authentication requests containing temporary IDs, resolves them to real IDs, and performs accounting and authorization operations. This intermediary mechanism enables the temporary ID system to maintain both anonymity for users and accountability for billing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Duration of action of moving object

If a long-term temporary ID is used for extended network access, then user convenience is improved, but the risk of identity compromise and unauthorized charges increases

Engineering Contradiction:
Improvenetwork access durationVSAvoididentity compromise risk
Core Design Contradiction:
Duration of action of moving objectVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic temporary ID generation where IDs are created with specific validity periods. The system can issue temporary IDs for different durations based on service requirements, and automatically revokes them after expiration. This dynamic approach allows long-term network access through sequential ID issuance while minimizing the exposure window for each individual ID.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system treats temporary IDs as disposable credentials that are generated, used, and discarded. Each temporary ID has a limited lifecycle and is invalidated after use or expiration. This approach allows the system to issue numerous short-lived IDs for extended access periods, reducing the impact of any single ID compromise while maintaining continuous service.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Adaptability or versatility

If multiple network operators are integrated to support cross-domain authentication, then network versatility is improved, but system complexity increases

Engineering Contradiction:
Improvecross-domain network supportVSAvoidsystem integration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The ID management server is designed as a universal component that can serve multiple network operators and support various authentication protocols. It implements a standardized interface for temporary ID resolution and accounting operations, allowing different home networks and visited networks to interoperate without requiring complex bilateral agreements between each operator pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary ID management server that simplifies multi-operator integration by centralizing the temporary ID resolution function. Instead of requiring direct trust and communication channels between every pair of network operators, the ID management server acts as a universal mediator that handles authentication and accounting requests from any participating network, reducing integration complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8694772B2Method and system for managing network identity
Publication Date: 2014.04.08 IND TECH RES INST
  • US8694772B2 patent drawing
  • US8694772B2 patent drawing
  • US8694772B2 patent drawing

AI summary

A method and a system for managing network identity are provided. The method and the system realize a management mechanism of temporary identification (ID) and real ID, which simultaneously achieves functionalities such as anonymity, accounting, and authorization. A short-term certificate and a corresponding public/private key pair are used to protect a temporary ID usable for accounting. This protection prevents the temporary ID from theft. The user generates a digital signature in the reply to a charge schedule statement from the visited network. This procedure is incorporated into an existing authentication framework based on Transport Layer Security (TLS) in order to provide an undeniable payment mechanism. The payment mechanism is applicable in an environment of multiple network operators and reduces the difficulty of integrating network operators. The method and the system do not have to consult a certificate revocation list (CRL) for authentication and thus are able to shorten authentication time.