Authentication Failure Message Concealment Against Linkability Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Linkability attacks in authentication procedures between user equipment and a network allow attackers to detect the presence of a victim subscriber in a monitored area by intercepting and replaying authentication request messages, compromising user untraceability.
Innovation Solution
Conceal the cause value of message authentication code or synchronization failure within the authentication failure message using a cryptographic function, allowing only the unified data management (UDM) to de-conceal it, thereby masking the reason for failure and mitigating linkability attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If authentication failure cause values are transmitted in clear text, then authentication failure messages can be easily processed and understood by network entities, but attackers can intercept and analyze these messages to perform linkability attacks and detect user presence
Solution Approach 1:
The patent introduces an intermediary encryption mechanism that transforms the authentication failure cause value from a readable format to an encrypted format. The cause value is encrypted using a cryptographic function with a secret key before being transmitted in the authentication failure message. This intermediary step prevents attackers from directly reading and analyzing the cause values, thereby mitigating linkability attacks while still allowing authorized network entities to decrypt and process the messages when needed
2Object-affected harmful factors
If authentication failure cause values are encrypted, then user untraceability is enhanced and linkability attacks are mitigated, but only authorized entities can de-conceal and process the authentication failure messages
Solution Approach 1:
The patent applies local quality by differentiating access rights for different network entities. The authentication failure cause value is encrypted with specific properties that allow only certain authorized entities (those possessing the appropriate decryption key) to de-conceal and process the message. This selective accessibility protects user untraceability while ensuring that legitimate network entities can still perform necessary processing when they have the proper credentials
Data Source
Figure 1
Figure 2
Figure 3
AI summary
There is provided an apparatus comprising at least one processor; and at least one memory including computer code, the at least one memory and the computer code configured to, with the at least one processor, cause the apparatus to perform: receiving, from a user equipment, a message comprising at least a nonce and an authentication token; detecting a message authentication code failure or a synchronization failure based on the message; concealing a cause value corresponding to the message authentication code failure or the synchronization failure into an authentication failure message; and transmitting the authentication failure message to the user equipment.