UE Identifier Security via Temporary Key Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication systems, there is a need to enhance the security of user equipment (UE) identifiers to prevent leakage and malicious use, especially in V2X communication networks where identifier protection is crucial to prevent unintended purposes such as vehicle tracking or issuing speed tickets.

Innovation Solution

A method involving a temporary key and ticket system is implemented, where a user equipment (UE) requests a temporary key from a mobile network operator (MNO) to encrypt its identifier, verifies the ticket's validity, and receives an encrypted subpool from a pseudonym certification authority (PCA), allowing secure decryption and use of the identifier for network connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If UE identifiers are transmitted in clear text for network connection, then network connection establishment is simplified, but identifier security and confidentiality are compromised

Engineering Contradiction:
Improveidentifier securityVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-distributing encryption keys to UEs through a secure key distribution mechanism. Before actual identifier transmission, UEs are provisioned with encryption capabilities and keys, enabling them to encrypt identifiers on-demand. This preliminary setup allows secure identifier transmission without requiring complex real-time key management during connection establishment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary key distribution mechanism that mediates between the network and UEs for secure key distribution. This intermediary system handles the complex key management tasks, allowing UEs to encrypt identifiers securely without the network needing to manage individual UE keys directly. The intermediary abstracts the complexity from the core network while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If identifier encryption is implemented for all UEs, then identifier confidentiality is enhanced, but network overhead and processing burden increase

Engineering Contradiction:
Improveidentifier confidentialityVSAvoidnetwork processing overhead
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The patent applies local quality by implementing selective encryption based on UE characteristics and network conditions. Not all UEs encrypt their identifiers at all times - instead, encryption is applied locally to specific UEs that require enhanced privacy protection or are in specific network contexts. This selective approach maintains confidentiality for those who need it while reducing overall network processing overhead.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent utilizes parameter changes by dynamically adjusting encryption parameters such as key selection, encryption algorithm choice, and identifier format based on network conditions, UE capabilities, and privacy requirements. This flexibility allows the system to optimize between security and processing overhead by changing parameters rather than always applying maximum encryption.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If temporary encryption keys are distributed to UEs, then identifier security is improved, but key management complexity and security risks increase

Engineering Contradiction:
Improveidentifier protectionVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements periodic action through time-limited encryption keys that are valid only for specific time periods or until certain conditions are met. Keys are automatically invalidated after their有效期 expires, forcing periodic key updates. This periodic key rotation limits the window of opportunity for key compromise while simplifying key management compared to permanent keys, as expired keys are automatically discarded.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent applies discarding and recovering by systematically invalidating and discarding used encryption keys after their purpose is fulfilled or time expires. Old keys are discarded to eliminate security risks, while new keys are generated and distributed as needed. This systematic key lifecycle management reduces key management complexity by automatically removing obsolete keys rather than maintaining large key inventories.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS10548005B2Method for security of user equipment connection identifier in wireless communication system and apparatus therefor
Publication Date: 2020.01.28 LG ELECTRONICS INC
  • US10548005B2 patent drawing
  • US10548005B2 patent drawing
  • US10548005B2 patent drawing

AI summary

Disclosed herein is a method for security of an identifier of a user equipment (UE) used when a network connection is established in a wireless communication system, which may include: requesting, to a mobile network operator (MNO), a temporary key used to encrypt the identifier and a ticket for authenticating an authority to access the identifier; receiving the temporary key and the ticket from the MNO; verifying a validity of the ticket; transmitting the ticket to a pseudonym certification authority (PCA) when the ticket is valid; receiving, from the PCA, a subpool which corresponds to the ticket and is encrypted with the temporary key, wherein the encrypted subpool includes a pair of the identifier and the encryption key; and receiving, from the PCA, a subpool which corresponds to the ticket and is encrypted with the temporary key, wherein the encrypted subpool includes a pair of the identifier and the encryption key; and acquiring the identifier by decrypting the encrypted identifier subpool using the temporary key.