5G UE Registration With One-Time Identifiers for Identity Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
5G networks face challenges in protecting user privacy due to the exposure of permanent user and equipment identifiers to all core network components, which can lead to privacy leakage and security threats from compromised components within the core network.
Innovation Solution
Implementing a registration method using one-time identifiers (OTIs) that change frequently, limiting access to permanent identifiers to a small number of trusted components in the core network, and using encryption to manage temporary identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If permanent user identifiers are exposed to all core network components for service delivery, then network services can operate seamlessly, but user privacy is compromised and security risks increase
Solution Approach 1:
The patent segments the identifier system into permanent identifiers (stored only in trusted components) and temporary identifiers (used for communication). This segmentation allows service operations to proceed using temporary identifiers while permanent identifiers remain protected in segmented, restricted locations.
Solution Approach 2:
The patent introduces temporary identifiers as intermediaries between user equipment and core network components. These intermediaries enable service delivery without direct exposure of permanent identifiers, acting as a mediator that protects user privacy while maintaining service functionality.
2Reliability
If permanent identifiers are stored in multiple core network components for service access, then service reliability is improved, but security vulnerabilities increase due to more attack surfaces
Solution Approach 1:
The patent segments identifier storage across different components: permanent identifiers are segmented and stored only in trusted components (UDM, UE), while temporary identifiers are distributed to service components (AMF, SMF, PCF). This segmentation maintains service reliability through available identifiers while reducing security threats by limiting permanent identifier exposure.
Solution Approach 2:
The patent employs temporary identifiers that are short-lived and disposable, replacing permanent identifiers in communication. These temporary identifiers can be freely distributed to service components without compromising security, as they expire and are replaced, unlike permanent identifiers that would create persistent security risks.
3Object-affected harmful factors
If temporary identifiers are used frequently for registration, then user anonymity is maintained, but system complexity increases due to identifier management
Solution Approach 1:
The patent implements self-service mechanisms where the UE autonomously generates and manages temporary identifiers, and trusted components automatically update them during registration. This self-service approach maintains anonymity through frequent identifier changes while reducing the burden of manual identifier management.
Solution Approach 2:
The patent employs periodic identifier updates during registration processes. Temporary identifiers are refreshed at regular intervals or upon specific events (registration, mobility), maintaining anonymity through periodic changes while following structured protocols that manage complexity through predictability.
Data Source
AI summary
A user equipment (UE) uses a one-time identifier to identify itself in a registration request sent to a trusted core network (CN) node. The one-time identifier is in the form of a first temporary identifier. The trusted CN node registers the UE, generates a next temporary identifier, and sends a random challenge to the UE. The UE uses the random challenge to generate a copy of the next temporary identifier and stores the next temporary identifier in a memory. Then, until a next registration, the UE and the trusted CN node use the first temporary identifier to identify the UE when communicating with each other and with other trusted and untrusted CN nodes. In the next registration event, the UE uses the next temporary identifier to identity itself to the trusted CN node. A true identity of the UE is not detectable by an untrusted node that may become compromised.


