Temporary Identity Storage in WLAN User Equipment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The storage procedures for temporary identities in WLAN user equipment (UE) are not standardized, which complicates user identity privacy in Inter-working Wireless Local Area Networks (I-WLAN) and the 3GPP system, as they lack clear guidelines on how to handle and store temporary identities received during Extensible Authentication Protocol (EAP) authentication.
Innovation Solution
A method and system for storing temporary identities in WLAN UE, where successful authentication leads to valid identities being stored in either the Subscriber Identity Module (USIM) or mobile equipment (ME), with previously stored identities being overwritten, and a 'deleted' value is used to indicate invalid identities, ensuring secure and standardized temporary identity management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If temporary identities are stored in WLAN UE without standardized procedures, then user identity privacy can be maintained through pseudonyms, but the lack of clear storage guidelines creates implementation complexity and inconsistency across systems
Solution Approach 1:
The patent applies parameter changes by specifying exact storage locations (USIM or ME) and data file identifiers ('AF') for temporary identities. It defines precise conditions under which pseudonyms are stored, overwritten, or deleted based on authentication outcomes and file availability, transforming the vague parameter of 'storage location' into specific, standardized parameters that resolve implementation inconsistency while maintaining privacy through pseudonym usage
2Reliability
If temporary identities are stored in USIM when appropriate data files are available, then secure standardized storage is achieved, but previously stored identities must be overwritten which may cause loss of historical identity data
Solution Approach 1:
The patent applies discarding and recovering by systematically overwriting previously stored pseudonyms in the 'AF' data file when new temporary identities are received after successful authentication. This standardized discarding process, while causing loss of historical identity data, ensures consistent privacy protection across all users and resolves the contradiction by making the information loss acceptable in exchange for achieving storage standardization and reliability
3Adaptability or versatility
If temporary identities are stored in mobile equipment when USIM data files are unavailable, then storage flexibility is maintained, but security may be compromised compared to USIM storage
Solution Approach 1:
The patent applies intermediary by using the 'AF' (Authentication Failure) data file as an intermediate storage location when USIM is unavailable. This intermediary storage in ME provides a fallback option that maintains adaptability and storage flexibility, while still preserving security through standardized procedures for pseudonym management, thus resolving the contradiction between flexibility and security
Data Source
AI summary
A temporary-identity-storage method for user equipment includes receiving authentication challenge information and at least one temporary identity, processing the authentication challenge information, and determining whether the processing step results in successful authentication. The user equipment includes mobile equipment and a subscriber identity module. Responsive to a determination that the authentication was successful, the received at least one temporary identity is considered to be valid. If the received at least one temporary identity is at least one pseudonym and an appropriate data file to the store the at least one pseudonym is available in the subscriber identity module, the at least one pseudonym is stored and any previously-stored pseudonym is over-written in the subscriber identity module. If the received at least one temporary identity is at least one pseudonym and an appropriate data file to the store the at least one pseudonym is not available in the subscriber identity module, the at least one pseudonym is stored and any previously-stored pseudonym is over-written in the mobile equipment. This Abstract is provided to comply with rules requiring an Abstract that allows a searcher or other reader to quickly ascertain subject matter of the technical disclosure. This Abstract is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. 37 CFR 1.72(b).


