Temporary Identifier Generation for 5G Privacy Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication systems, there is a need to protect user privacy by preventing unnecessary leakage of private information, as current systems often have full-time access to users' private data, compromising their privacy.

Innovation Solution

A method and apparatus are introduced to generate and use temporary identifiers based on permanent user identifiers (SUPI) within the network, ensuring that only essential information is shared, thereby protecting user privacy by limiting access to sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If permanent user identifiers (SUPI) are transmitted in clear text for authentication, then authentication reliability is improved, but user privacy is compromised due to information leakage

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiduser privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a concealed identifier (SUCI) as an intermediary between the user's permanent identifier (SUPI) and the network. The SUCI is generated by encrypting the SUPI using a one-way hash function with a salt value, allowing the network to verify authentication without directly accessing the plain-text SUPI, thus preventing privacy leakage while maintaining authentication reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of the user identifier in a concealed form (SUCI) that can be transmitted over the air interface. This copy contains all necessary information for authentication verification but is protected against unauthorized disclosure, allowing the system to work with identifier copies rather than requiring transmission of the original sensitive SUPI

Inventive Principle:
Principle #26Copying

2Productivity

If full-time access to users' private information is maintained for network operations, then network operation efficiency is improved, but user privacy protection deteriorates

Engineering Contradiction:
Improvenetwork operation efficiencyVSAvoiduser privacy
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent extracts only the essential authentication information needed for network operations while removing the sensitive permanent identifier (SUPI) from transmission. The concealed identifier (SUCI) contains sufficient data for authentication and network operations but excludes the user's private information, allowing efficient network operations without full-time access to sensitive data

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms the user identifier from its original form (SUPI) into a different parameter representation (SUCI) through one-way hashing and salting. This parameter transformation maintains the functional properties needed for authentication and network operations while fundamentally changing the form to prevent privacy leakage

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240236667A1Method and device for protecting privacy in wireless communication system
Publication Date: 2024.07.11 SAMSUNG ELECTRONICS CO LTD
  • US20240236667A1 patent drawing
  • US20240236667A1 patent drawing
  • US20240236667A1 patent drawing

AI summary

The present disclosure relates to a 5G communication system or a 6G communication system for supporting higher data rates beyond a 4G communication system such as long term evolution (LTE). A method performed by a first network entity in a wireless communication system includes receiving an authentication acquisition response message including a subscription permanent identifier (SUPI) of a user equipment (UE) from a second network entity, generating a temporary identifier for the UE based on the SUPI, and transmitting an authentication response message including the temporary identifier to a third network entity, wherein the temporary identifier includes a variable filed which is generated as a random variable.