Terminal Identifier Resolution for Privacy-Safe Authorization Checks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 4G mobile communication systems, transmitting a subscription permanent identifier over the air interface in plaintext exposes user privacy during device-to-device communication, especially when a remote device communicates indirectly through a relay device.

Innovation Solution

A method involving key management and unified data management network elements to obtain and manage anonymous or temporary identifiers, performing authorization checks without directly using the subscription permanent identifier, ensuring secure communication parameters are established while protecting user privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the subscription permanent identifier is transmitted over the air interface in plaintext, then the authorization check and service control can be performed, but user privacy is exposed

Engineering Contradiction:
Improveauthorization checkVSAvoiduser privacy exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a key management network element as an intermediary between the relay device and the unified data management network element. This intermediary receives the anonymous identifier from the relay device, retrieves the corresponding subscription permanent identifier securely, performs the authorization check, and returns only the authorization result and secure communication parameters without exposing the subscription permanent identifier to the relay device or transmitting it over the air interface in plaintext

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the anonymous identifier or temporary identifier is used instead of subscription permanent identifier, then user privacy is protected, but the authorization check process becomes more complex

Engineering Contradiction:
Improveuser privacy protectionVSAvoidauthorization check process
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The key management network element maintains a local mapping between anonymous identifiers and subscription permanent identifiers, enabling it to autonomously resolve identifiers and perform authorization checks without requiring complex coordination between multiple network elements. The system self-manages the identifier resolution process, reducing overall system complexity while protecting user privacy

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12543037B2Method for obtaining identifier of terminal device, apparatus, and system
Publication Date: 2026.02.03 HUAWEI TECH CO LTD
  • US12543037B2 patent drawing
  • US12543037B2 patent drawing
  • US12543037B2 patent drawing

AI summary

A method for obtaining an identifier of a terminal device includes a key management network element receiving, from a first terminal device, a first key request including a first identifier, where the first identifier is an anonymous identifier or a temporary identifier of a second terminal device. The key management network element sends, to a unified data management network element, a first request including the first identifier. The unified data management network element determines a SUPI of the second terminal device based on the first identifier, and sends, to the key management network element, a first response including the SUPI. In response to an authorization check performed on the second terminal device based on the SUPI succeeds, the key management network element sends a first key response to the first terminal device, where the first key response includes a secure communication parameter.