Aviz Networks Details Deterministic Irreversible Masking for Session Records
Aviz Networks’ ASN approach describes deterministic, irreversible masking for mobile network session records, replacing sensitive subscriber and device identifiers with fixed-length tokens while preserving correlation for downstream analytics and operations.
Research Overview
The vendor frames the problem as session records moving across mobile network components and potentially reaching systems such as analytics tools, security monitoring platforms, data lakes, and partner dashboards. It argues that keeping raw identifiers visible at system boundaries creates risk once exports leave the operator’s control.
The post outlines a tokenization model intended to support analytics and troubleshooting without making sensitive identifiers readable in downstream environments. It also contrasts the approach with packet-level masking that operates on payload bytes.
Key Findings
The method masks subscriber and device-related fields by substituting original values with fixed-length tokens immediately before records leave the system. It states that the same original value always maps to the same token, enabling joins and trend analysis across exported data.
The post says tokens cannot be reversed and that it does not rely on configurable system values or reverse lookup tables to recover original identifiers such as IMSI, MSISDN, IMEI, or IP addresses. It also describes controlling which fields are masked during export based on a client configuration.
Technical Breakdown
The vendor describes deterministic tokenization as computing a fixed-length token through a deterministic transformation of the source value. It states that non-sensitive values remain unchanged, while sensitive fields are replaced.
ASN-level privacy is described as masking aggregated session records rather than masking each packet byte by byte. The post asserts this preserves session context needed for cross-session and cross-protocol correlation and allows masking of specific semantics such as MSISDN, IMSI, IMEI, and subscriber IP.
Operational Impact
The post outlines scenarios where masked exports can be used, including third-party analytics sharing, regulatory and audit reporting, and cross-team troubleshooting across a defined privacy boundary. It says external teams continue to see the same masked subscriber across hops from gateway to gateway and tower to tower without seeing subscriber identity.
It also describes using masked records for long-term data lake storage for warehouse capacity planning and trend analysis, citing a reduced exposure in the event of a storage compromise because raw identities are not recorded. The vendor positions token-based correlation as maintaining analytical utility compared with approaches such as deleting fields.
Blog Signals brief: The vendor describes deterministic, irreversible masking for mobile network session records that replaces sensitive identifiers with fixed-length tokens while preserving correlation for downstream analytics and operational use. This fact-based summary of the vendor blog is intended to support enterprise decision-makers evaluating data export controls for security, compliance, and analytics workflows.
Source: aviznetworks.com, by Guruprasad Hegde.