Variable Subscriber Identifier Management for Privacy Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication technologies fail to effectively protect user privacy by preventing unauthorized entities from tracking and profiling user behavior through unique device identifiers, leading to potential privacy violations.
Innovation Solution
The implementation of variable subscriber identifiers (V-SubIds) that change periodically, which are generated during authentication and used instead of static unique device identifiers, masking the user's identity from unauthorized entities and applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static unique device identifiers are used, then device identification is simplified, but user privacy is compromised due to tracking and profiling
Solution Approach 1:
The patent implements dynamic identifier generation where the device identifier changes based on the serving gateway. Instead of using a static unique device identifier, the system generates identifiers dynamically during authentication processes, ensuring that different gateways receive different identifiers for the same device, thereby preventing cross-gateway tracking while maintaining identification functionality
Solution Approach 2:
The patent segments the identifier generation process by gateway. Each serving gateway maintains its own identifier space and generates identifiers independently. This segmentation ensures that identifiers from different gateways are not comparable or linkable, effectively isolating tracking capabilities within each gateway while preserving overall device identification within that gateway's domain
2Object-affected harmful factors
If variable subscriber identifiers are implemented, then user privacy is protected, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary authentication server that mediates between the device and the network. This server handles the complex identifier generation and management tasks, including receiving authentication requests, generating appropriate identifiers based on gateway information, and returning them to the network. This intermediary approach centralizes the complexity in a dedicated component rather than distributing it throughout the system
Solution Approach 2:
The system implements self-service through automated identifier generation during the authentication process itself. The authentication server automatically generates the appropriate identifier without requiring manual intervention or complex external coordination. The identifier is generated as a natural part of the authentication flow, leveraging existing authentication data and gateway information
3Object-affected harmful factors
If dynamic identifiers are used during communication, then tracking is prevented, but identifier consistency across sessions is reduced
Solution Approach 1:
The patent applies local quality by ensuring identifier consistency within each gateway's domain while allowing variability across different gateways. For a given serving gateway, the identifier generation process maintains consistency based on that gateway's specific context and the device's authentication credentials. This local consistency enables reliable device identification within each gateway's network domain while the overall system benefits from variability across gateways that prevents tracking
Data Source
AI summary
A system and methodology that facilitates management and utilization of variable subscriber identifiers (V-SubIds) for protecting subscriber privacy is disclosed herein. In one aspect, an Anonymous Customer Reference (ACR) component receives a V-SubId, which is a short-lived subscriber identifier that is to be inserted in a communication messages transmitted from a user equipment instead of a unique device identifier (UDID) of the user equipment. On expiration of the V-SubId, a new V-SubId is received and utilized in subsequent communication messages transmitted from the user equipment. Further, trusted systems/applications can exchange the V-SubId for a subscriber identifier (SubId) associated with the user equipment. Furthermore, untrusted systems/applications can exchange, based on user authorization, the V-SubId for an application-specific ACR that remains static and/or valid for a predefined time period. Moreover, the application-specific ACR is utilized as a device identifier for the user equipment in subsequent communication messages for the predefined time period.


