Encrypted Authentication Responses to Prevent Wireless User Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems are vulnerable to user tracking and authentication failures due to malicious nodes replaying authentication requests, which can compromise user privacy and security.

Innovation Solution

Implementing encryption and decryption methods for failure values and identifiers in the authentication process, including generating new authentication identifiers and random numbers to secure user authentication and prevent tracking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication requests are transmitted without encryption, then the authentication process is simple and fast, but user privacy and security are compromised due to malicious node tracking

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary encryption layer between the terminal and network node. The failure value is encrypted using a first encryption algorithm before being sent to the network node, and the network node decrypts it using a corresponding decryption algorithm. This intermediary encryption mechanism protects the authentication process from malicious tracking while maintaining structured communication flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the authentication response by changing its parameter state through encryption. The failure value, which originally contains authentication status information, is transformed into an encrypted form that preserves the information content while changing its security properties. This allows the system to maintain authentication functionality while enhancing security through parameter transformation.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If encryption is applied to failure values and identifiers, then user tracking is prevented and privacy is protected, but processing time and computational overhead increase

Engineering Contradiction:
Improveuser privacy protectionVSAvoidauthentication processing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent applies preliminary encryption actions to the failure value before transmission. By encrypting the failure value in advance at the terminal side using the first encryption algorithm, the system ensures that sensitive information is protected before it enters the communication channel, preventing potential tracking and information leakage during transmission and processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates an encrypted copy of the failure value that can be transmitted and processed separately from the original sensitive data. The encrypted failure value serves as a functional copy that maintains the necessary information for authentication verification while eliminating the security risks associated with transmitting plain-text sensitive information.

Inventive Principle:
Principle #26Copying

3Productivity

If authentication identifiers are reused, then the authentication process is efficient, but malicious nodes can replay authentication requests to track users

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidreplay attack vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by encrypting the failure value before transmission. This pre-encryption measure prevents malicious nodes from capturing and replaying authentication requests, as the encrypted content cannot be meaningfully replicated or reused by unauthorized parties. The encryption serves as a preventive countermeasure against replay attacks.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent treats each authentication transaction as a disposable, short-lived event with unique encrypted parameters. The encrypted failure value is generated fresh for each authentication attempt and is designed to be used only once, preventing replay attacks. This approach sacrifices the reusability of authentication identifiers to eliminate security vulnerabilities.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentEP3912377B1Method and device for preventing user tracking, storage medium and electronic device
Publication Date: 2025.09.10 ZTE CORP
  • EP3912377B1 patent drawingFigure 1
  • EP3912377B1 patent drawingFigure 2
  • EP3912377B1 patent drawingFigure 3

AI summary

Methods, systems, and devices related to related to digital wireless communication, and more specifically, to techniques related to securing a user authentication procedure. In one exemplary aspect, a method for wireless communication includes transmitting an authentication message from a network node. The method also includes determining a failure value indicating a reason for failure of the authentication message. The method also includes encrypting the failure value and an identifier. The method also includes transmitting an encrypted response message to the network node. In another exemplary aspect, a method for wireless communication includes transmitting an authentication message to a terminal. The method also includes receiving an encrypted response message from the terminal. The method also includes decrypting the encrypted response message to determine the failure value and the indicator.