Pseudonymous Identifier Encryption for V2X Lawful Interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for securing user equipment identifiers in wireless communication systems, particularly for V2X communication, fail to adequately prevent unauthorized use and ensure lawful interception procedures can be autonomously performed across networks, especially during roaming.
Innovation Solution
The method involves using pseudonymous mobile subscriber IDs (PMSIs) for V2X communication, where the IMSI is encrypted with a temporary key, and a message is transmitted to request retransmission if the IMSI received from the user equipment does not match the one from the home network, allowing for lawful enforcement agencies to request PMSI subpools from a pseudonym certification authority in the serving network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If PMSI is used for V2X communication to enhance security and prevent identifier leakage, then user privacy protection is improved, but lawful interception capability deteriorates
Solution Approach 1:
The patent introduces a Lawful Interception Function (LIF) as an intermediary component that mediates between the PMSI-based privacy protection system and law enforcement agencies. The LIF receives intercepted PMSI data, decrypts it using secure keys, and forwards relevant information to authorized entities, thereby enabling lawful interception without compromising the overall security architecture or user privacy protection.
Solution Approach 2:
The patent segments the identifier system into multiple components: IMSI (original identifier), PMSI (pseudonymous identifier for V2X), and LIF (lawful interception function). This segmentation allows different functions to operate independently - PMSI provides privacy protection for normal V2X communication, while LIF handles lawful interception requirements, resolving the contradiction between privacy and law enforcement access.
2Extent of automation
If PMSI with temporary key encryption is implemented in roaming networks, then autonomous lawful interception is enabled, but network complexity increases
Solution Approach 1:
The LIF is designed as a universal function that operates across different networks and scenarios. It can handle lawful interception requests from any serving network regardless of the home network, supporting both roaming and non-roaming scenarios. This multi-functionality enables autonomous operation without requiring complex home network involvement in each interception case.
Solution Approach 2:
The patent implements preliminary actions by pre-configuring the LIF with necessary cryptographic keys and authorization information before interception is needed. The serving network can autonomously invoke the LIF using pre-established trust relationships and key management mechanisms, avoiding the need for complex real-time coordination with home networks during actual interception operations.
3Object-affected harmful factors
If IMSI verification message is transmitted to prevent unauthorized use, then security against malicious purposes is improved, but communication overhead increases
Solution Approach 1:
The patent applies local quality by implementing IMSI verification selectively rather than universally. The serving network verifies IMSI information locally when there is suspicion of unauthorized use or abnormal behavior, rather than continuously verifying all PMSI assignments. This targeted approach enhances security against malicious purposes while minimizing unnecessary message transmission overhead during normal operations.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for securing an identifier of a user equipment used when connecting to a network connection in a wireless communication system, according to an embodiment of the present invention, may comprise the steps of: receiving, from the user equipment, a message requesting a first ticket for authenticating a right to access the identifier in a serving network of the user equipment, wherein the message includes information on a second ticket for authenticating a right to access the identifier in a home network of the user equipment; transmitting the information on the second ticket to a mobility management entity (MME) of the home network; receiving, from the MME of the home network, identification information of the user equipment that is determined on the basis of the information on the second ticket; and transmitting, to the terminal, information on the first ticket and a temporary key used to encrypt the identifier in the serving network, on the basis of the identification information.