Encrypted Authentication Responses to Prevent Wireless User Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems are vulnerable to user tracking and authentication failures due to malicious nodes replaying authentication requests, which can compromise user privacy and security.
Innovation Solution
Implementing encryption and decryption methods for failure values and identifiers in the authentication process, including generating new authentication identifiers and random numbers to secure user authentication and prevent tracking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication requests are transmitted without encryption, then the authentication process is simple and fast, but user privacy and security are compromised due to malicious node tracking
Solution Approach 1:
The patent introduces an intermediary encryption layer between the terminal and network node. The failure value is encrypted using a first encryption algorithm before being sent to the network node, and the network node decrypts it using a corresponding decryption algorithm. This intermediary encryption mechanism protects the authentication process from malicious tracking while maintaining structured communication flow.
Solution Approach 2:
The patent transforms the authentication response by changing its parameter state through encryption. The failure value, which originally contains authentication status information, is transformed into an encrypted form that preserves the information content while changing its security properties. This allows the system to maintain authentication functionality while enhancing security through parameter transformation.
2Loss of information
If encryption is applied to failure values and identifiers, then user tracking is prevented and privacy is protected, but processing time and computational overhead increase
Solution Approach 1:
The patent applies preliminary encryption actions to the failure value before transmission. By encrypting the failure value in advance at the terminal side using the first encryption algorithm, the system ensures that sensitive information is protected before it enters the communication channel, preventing potential tracking and information leakage during transmission and processing.
Solution Approach 2:
The patent creates an encrypted copy of the failure value that can be transmitted and processed separately from the original sensitive data. The encrypted failure value serves as a functional copy that maintains the necessary information for authentication verification while eliminating the security risks associated with transmitting plain-text sensitive information.
3Productivity
If authentication identifiers are reused, then the authentication process is efficient, but malicious nodes can replay authentication requests to track users
Solution Approach 1:
The patent applies preliminary anti-action by encrypting the failure value before transmission. This pre-encryption measure prevents malicious nodes from capturing and replaying authentication requests, as the encrypted content cannot be meaningfully replicated or reused by unauthorized parties. The encryption serves as a preventive countermeasure against replay attacks.
Solution Approach 2:
The patent treats each authentication transaction as a disposable, short-lived event with unique encrypted parameters. The encrypted failure value is generated fresh for each authentication attempt and is designed to be used only once, preventing replay attacks. This approach sacrifices the reusability of authentication identifiers to eliminate security vulnerabilities.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods, systems, and devices related to related to digital wireless communication, and more specifically, to techniques related to securing a user authentication procedure. In one exemplary aspect, a method for wireless communication includes transmitting an authentication message from a network node. The method also includes determining a failure value indicating a reason for failure of the authentication message. The method also includes encrypting the failure value and an identifier. The method also includes transmitting an encrypted response message to the network node. In another exemplary aspect, a method for wireless communication includes transmitting an authentication message to a terminal. The method also includes receiving an encrypted response message from the terminal. The method also includes decrypting the encrypted response message to determine the failure value and the indicator.