Terminal Device Application-Specific Identity Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network technologies often disclose real identity information of users, compromising their privacy as network side devices analyze and track user behavior across different applications, leading to potential malicious use.

Innovation Solution

A method where a terminal device generates unique encryption results for each application using a preset encryption algorithm, including the terminal device's identity and application-specific information, to ensure distinct identification and authentication for network access, preventing cross-analysis of user behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the terminal device uses a single identity (IMEI/IMSI) for network access across all applications, then network communication stability is improved, but user privacy is compromised as network devices can track and deduce real identity information

Engineering Contradiction:
Improvenetwork communication stabilityVSAvoiduser privacy infringement
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the single identity into multiple application-specific identities. Each application generates a unique encryption result by combining the terminal identity with application-specific information through encryption. This allows the terminal to maintain stable communication for each application while preventing cross-application tracking, as each application's encryption result is distinct and cannot be correlated to reveal the real identity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces encryption results as an intermediary between the terminal identity and network communication. Instead of directly exposing the real identity (IMEI/IMSI) to network devices, the encryption result serves as a mediator that enables authentication and communication while concealing the actual identity. This intermediary layer prevents network devices from deducing real identity information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the terminal device reports real identity information to network side devices, then authentication and network access are simplified, but the risk of identity disclosure and malicious use increases

Engineering Contradiction:
Improvenetwork access simplicityVSAvoididentity disclosure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent creates encrypted copies of the terminal identity for each application instead of using the real identity directly. The encryption result is a derived representation that maintains the necessary authentication functionality while eliminating the risk associated with exposing the actual identity. Network devices authenticate using these encrypted copies rather than the real identity information.

Inventive Principle:
Principle #26Copying

3Stability of the object's composition

If the terminal device uses the same identity across multiple applications, then device identification is consistent, but network devices can create behavioral profiles and deduce user habits

Engineering Contradiction:
Improveidentity consistencyVSAvoiduser behavioral privacy
Core Design Contradiction:
Stability of the object's compositionVSLoss of information

Solution Approach 1:

The patent segments the identity into application-specific components where each application receives a unique encryption result. This segmentation maintains consistency within each application context while preventing cross-application correlation. The encryption result for each application is derived from the terminal identity combined with application-specific information, ensuring stability within each application while preventing behavioral profiling across applications.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2963958B1Network device, terminal device and information security improving method
Publication Date: 2019.12.18 HUAWEI TECH CO LTD
  • EP2963958B1 patent drawingFigure 1
  • EP2963958B1 patent drawingFigure 2
  • EP2963958B1 patent drawingFigure 3

AI summary

Embodiments of the present invention disclose a method, a terminal device, and a network device, for improving information security and relate to the field of electronic information technologies, which can prevent real identity information of a user from being disclosed, thereby protecting individual privacy of the user. The method of the present invention includes: acquiring, by a terminal device, a key, an identity of the terminal device, and identification information of one or more applications on the terminal device, where identification information of different applications on the terminal device is different from each other, and the identity of the terminal device includes: an international mobile equipment identity IMEI and/or an international mobile subscriber identity IMSI; generating, for identification information of one application by using a preset encryption algorithm according to the identity of the terminal device and the key, an encryption result corresponding to the application; and when the application runs on the terminal device, accessing a network by using the encryption result corresponding to the application. The present invention is applicable to protecting information security of a terminal device accessing a network.