Authentication Failure Message Concealment Against Linkability Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Linkability attacks in authentication procedures between user equipment and a network allow attackers to detect the presence of a victim subscriber in a monitored area by intercepting and replaying authentication request messages, compromising user untraceability.

Innovation Solution

Conceal the cause value of message authentication code or synchronization failure within the authentication failure message using a cryptographic function, allowing only the unified data management (UDM) to de-conceal it, thereby masking the reason for failure and mitigating linkability attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authentication failure cause values are transmitted in clear text, then authentication failure messages can be easily processed and understood by network entities, but attackers can intercept and analyze these messages to perform linkability attacks and detect user presence

Engineering Contradiction:
Improveauthentication failure message processingVSAvoidlinkability attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary encryption mechanism that transforms the authentication failure cause value from a readable format to an encrypted format. The cause value is encrypted using a cryptographic function with a secret key before being transmitted in the authentication failure message. This intermediary step prevents attackers from directly reading and analyzing the cause values, thereby mitigating linkability attacks while still allowing authorized network entities to decrypt and process the messages when needed

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If authentication failure cause values are encrypted, then user untraceability is enhanced and linkability attacks are mitigated, but only authorized entities can de-conceal and process the authentication failure messages

Engineering Contradiction:
Improveuser untraceabilityVSAvoidauthentication failure message processing
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent applies local quality by differentiating access rights for different network entities. The authentication failure cause value is encrypted with specific properties that allow only certain authorized entities (those possessing the appropriate decryption key) to de-conceal and process the message. This selective accessibility protects user untraceability while ensuring that legitimate network entities can still perform necessary processing when they have the proper credentials

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4047971B1Prevention of linkability attacks
Publication Date: 2026.03.25 NOKIA TECHNOLOGIES OY
  • EP4047971B1 patent drawingFigure 1
  • EP4047971B1 patent drawingFigure 2
  • EP4047971B1 patent drawingFigure 3

AI summary

There is provided an apparatus comprising at least one processor; and at least one memory including computer code, the at least one memory and the computer code configured to, with the at least one processor, cause the apparatus to perform: receiving, from a user equipment, a message comprising at least a nonce and an authentication token; detecting a message authentication code failure or a synchronization failure based on the message; concealing a cause value corresponding to the message authentication code failure or the synchronization failure into an authentication failure message; and transmitting the authentication failure message to the user equipment.