EP3662691B1

Interfaces for privacy management as service or function

Abstract

This record has no abstract on file.

EP3662691B1, drawing sheet 1
Sheet 1 of 8

Term

11.8 yearsleft in the term

Expires 27 July 2038.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

14 claims: 6 independent, 8 dependent

  1. 1
    A method comprising:in a home network of a communication system, provisioning one or more cryptographic key pairs for utilization by subscribers of the home network to conceal subscriber identifiers provided to one or more access points in the communication system;and managing the one or more cryptographic key pairs utilizing an element or function in the home network of the communication system, wherein managing the one or more cryptographic key pairs comprises: receiving one or more requests for subscriber identifier decryption related to one or more of the cryptographic key pairs, wherein each of the one or more requests comprises an encrypted subscriber identifier and a cryptographic key pair identifier identifying a cryptographic key pair used to encrypt the subscriber identifier;determining a validity of a given cryptographic key pair identified by the cryptographic key pair identifier for each respective request;decrypting the encrypted subscriber identifier based on the determining, wherein the decrypting is performed utilizing a private key associated with the cryptographic key pair identifier for each respective request;and providing a response comprising a decrypted subscriber identifier to each respective request based on the determining and the decrypting, wherein at least one of the responses comprises information related to one or more updates for one or more cryptographic key pairs.
  2. 7
    The method of any preceding claim, wherein determining the validity of the given cryptographic key pair comprises:identifying the cryptographic key pair identifier in the request;determining the validity of the given cryptographic key pair identified by the cryptographic key pair identifier;and generating a response indicating the validity of the given cryptographic key pair.
  3. 9
    The method of any preceding claim, comprising requesting, from a key database, a private key of a given cryptographic key pair identified by the cryptographic key pair identifier in the respective request.
  4. 10
    An apparatus comprising a processor operatively coupled to a memory and configured to perform the steps of:provisioning one or more cryptographic key pairs for utilization by subscribers of the home network to conceal subscriber identifiers provided to one or more access points in the communication system;and managing the one or more cryptographic key pairs utilizing an element or function in the home network of the communication system, wherein managing the one or more cryptographic key pairs comprises: receiving one or more requests for subscriber identifier decryption related to one or more of the cryptographic key pairs, wherein each of the one or more requests comprises an encrypted subscriber identifier and a cryptographic key pair identifier identifying a cryptographic key pair used to encrypt the subscriber identifier;determining a validity of a given cryptographic key pair identified by the cryptographic key pair identifier for each respective request;decrypting the encrypted subscriber identifier based on the determining, wherein the decrypting is performed utilizing a private key associated with the cryptographic key pair identifier for each respective request;and providing a response comprising a decrypted subscriber identifier to each respective request based on the determining and the decrypting, wherein at least one of the responses comprises information related to one or more updates for one or more cryptographic key pairs.
  5. 11
    A method comprising:in user equipment, storing one or more public keys associated with one or more cryptographic key pairs, the cryptographic key pairs being provisioned by a home network of a communication system for use by subscribers of the home network to conceal subscriber identifiers provided to one or more access points in the communication network;interfacing with an element or function of the home network of the communication system for management of the one or more public keys stored in the user equipment, wherein the interfacing comprises: providing one or more requests for subscriber identifier decryption related to one or more of the cryptographic key pairs, wherein each of the one or more requests comprises an encrypted subscriber identifier and a cryptographic key pair identifier identifying a cryptographic key pair used to encrypt the subscriber identifier;and receiving a response to each respective request based on a determination of a validity of a given cryptographic key pair identified by the cryptographic key pair identifier and a decryption of the encrypted subscriber identifier utilizing a private key associated with the cryptographic key pair identifier, wherein at least one of the responses comprises a decrypted subscriber identifier and information related to one or more updates for one or more cryptographic key pairs.
  6. 14
    An apparatus comprising a processor operatively coupled to a memory and configured to perform the steps of:storing one or more public keys associated with one or more cryptographic key pairs, the cryptographic key pairs being provisioned by a home network of a communication system for use by subscribers of the home network to conceal subscriber identifiers provided to one or more access points in the communication network;interfacing with an element or function of the home network of the communication system for management of the one or more public keys stored in the user equipment, wherein the interfacing comprises: providing one or more requests for subscriber identifier decryption related to one or more of the cryptographic key pairs, wherein each of the one or more requests comprises an encrypted subscriber identifier and a cryptographic key pair identifier identifying a cryptographic key pair used to encrypt the subscriber identifier;and receiving a response to each respective request based on a determination of a validity of a given cryptographic key pair identified by the cryptographic key pair identifier and a decryption of the encrypted subscriber identifier utilizing a private key associated with the cryptographic key pair identifier, wherein at least one of the responses comprises a decrypted subscriber identifier and information related to one or more updates for one or more cryptographic key pairs.