Terminal Device Application-Specific Identity Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network technologies often disclose real identity information of users, compromising their privacy as network side devices analyze and track user behavior across different applications, leading to potential malicious use.
Innovation Solution
A method where a terminal device generates unique encryption results for each application using a preset encryption algorithm, including the terminal device's identity and application-specific information, to ensure distinct identification and authentication for network access, preventing cross-analysis of user behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the terminal device uses a single identity (IMEI/IMSI) for network access across all applications, then network communication stability is improved, but user privacy is compromised as network devices can track and deduce real identity information
Solution Approach 1:
The patent segments the single identity into multiple application-specific identities. Each application generates a unique encryption result by combining the terminal identity with application-specific information through encryption. This allows the terminal to maintain stable communication for each application while preventing cross-application tracking, as each application's encryption result is distinct and cannot be correlated to reveal the real identity.
Solution Approach 2:
The patent introduces encryption results as an intermediary between the terminal identity and network communication. Instead of directly exposing the real identity (IMEI/IMSI) to network devices, the encryption result serves as a mediator that enables authentication and communication while concealing the actual identity. This intermediary layer prevents network devices from deducing real identity information.
2Ease of operation
If the terminal device reports real identity information to network side devices, then authentication and network access are simplified, but the risk of identity disclosure and malicious use increases
Solution Approach 1:
The patent creates encrypted copies of the terminal identity for each application instead of using the real identity directly. The encryption result is a derived representation that maintains the necessary authentication functionality while eliminating the risk associated with exposing the actual identity. Network devices authenticate using these encrypted copies rather than the real identity information.
3Stability of the object's composition
If the terminal device uses the same identity across multiple applications, then device identification is consistent, but network devices can create behavioral profiles and deduce user habits
Solution Approach 1:
The patent segments the identity into application-specific components where each application receives a unique encryption result. This segmentation maintains consistency within each application context while preventing cross-application correlation. The encryption result for each application is derived from the terminal identity combined with application-specific information, ensuring stability within each application while preventing behavioral profiling across applications.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the present invention disclose a method, a terminal device, and a network device, for improving information security and relate to the field of electronic information technologies, which can prevent real identity information of a user from being disclosed, thereby protecting individual privacy of the user. The method of the present invention includes: acquiring, by a terminal device, a key, an identity of the terminal device, and identification information of one or more applications on the terminal device, where identification information of different applications on the terminal device is different from each other, and the identity of the terminal device includes: an international mobile equipment identity IMEI and/or an international mobile subscriber identity IMSI; generating, for identification information of one application by using a preset encryption algorithm according to the identity of the terminal device and the key, an encryption result corresponding to the application; and when the application runs on the terminal device, accessing a network by using the encryption result corresponding to the application. The present invention is applicable to protecting information security of a terminal device accessing a network.