User Equipment Identity Request Control for 5G Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5G communication systems face challenges in protecting user equipment (UE) privacy, particularly in managing identity requests to prevent synchronization failures and denial-of-service (DoS) attacks, where UE is repeatedly asked to provide its identity due to out-of-sync conditions or malicious attacks, leading to potential exposure of subscription identities.

Innovation Solution

Implementing a method in user equipment to control identity responses based on a count of previous identity requests, where the UE determines whether to respond or use out-of-band mechanisms by comparing the request count to a permissible number specified in an identity control policy, thereby preventing excessive identity revelations and mitigating DoS attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user equipment responds to all identity requests to ensure proper network authentication and identity management, then network connectivity and authentication reliability are improved, but subscription identity privacy is compromised and the system becomes vulnerable to denial-of-service attacks

Engineering Contradiction:
Improveauthentication reliabilityVSAvoididentity privacy exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing an identity control policy before identity requests occur. This policy pre-defines the maximum number of identity responses permitted and sets up counting mechanisms in advance, enabling the UE to make automated decisions about responding to identity requests without real-time complex evaluation, thus protecting identity privacy while maintaining authentication reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by counting the number of identity requests received and comparing this count against the permissible number defined in the identity control policy. This feedback loop enables dynamic control of identity responses, where the UE adjusts its behavior based on the accumulated request count, preventing excessive identity revelations while ensuring proper authentication

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If user equipment limits the number of identity responses to protect privacy and prevent DoS attacks, then identity privacy and system security are improved, but network authentication reliability may deteriorate due to synchronization failures

Engineering Contradiction:
Improveidentity privacy protectionVSAvoidauthentication reliability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing an identity control policy before identity requests occur. This policy pre-defines the maximum number of identity responses permitted and sets up counting mechanisms in advance, enabling the UE to make automated decisions about responding to identity requests without real-time complex evaluation, thus protecting identity privacy while maintaining authentication reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by counting the number of identity requests received and comparing this count against the permissible number defined in the identity control policy. This feedback loop enables dynamic control of identity responses, where the UE adjusts its behavior based on the accumulated request count, preventing excessive identity revelations while ensuring proper authentication

Inventive Principle:
Principle #23Feedback

3Ease of operation

If user equipment automatically responds to identity requests without control mechanisms, then authentication process simplicity is improved, but the system becomes vulnerable to repeated identity requests from out-of-sync conditions and malicious attacks

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements self-service by enabling the user equipment to autonomously control its own identity response behavior. The UE maintains an internal counter and identity control policy, automatically deciding whether to respond to identity requests based on the current count versus permissible number, without requiring external control or complex real-time evaluation, thus maintaining simplicity while providing security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms by counting the number of identity requests received and comparing this count against the permissible number defined in the identity control policy. This feedback loop enables dynamic control of identity responses, where the UE adjusts its behavior based on the accumulated request count, preventing excessive identity revelations while ensuring proper authentication

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10171993B2Identity request control for user equipment
Publication Date: 2019.01.01 NOKIA OF AMERICA CORP
  • US10171993B2 patent drawing
  • US10171993B2 patent drawing
  • US10171993B2 patent drawing

AI summary

Techniques are provided for protecting the privacy of user equipment during identity request operations in a communication system. In one example, a method includes receiving a current identity request at given user equipment of a communication system. The method further includes making a determination at the given user equipment whether or not to respond to the current identity request in a manner requested based on a count of previous identity requests received by the given user equipment.