Device authentication method and device

By using the timestamp comparison mechanism in 5G ultra-intensive networks, the security threats of illegal small base stations and the low efficiency of frequent authentication are solved, rapid authentication is achieved, and user network experience is improved.

CN116156500BActive Publication Date: 2025-08-15DATANG MOBILE COMM EQUIP CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202111392897.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-23
Publication Date
2025-08-15
Estimated Expiration
2041-11-23

AI Technical Summary

Technical Problem

In 5G ultra-intensive networks, the prior art is difficult to effectively prevent security threats from illegal small base stations, and the frequent security authentication between user equipment and access nodes is inefficient, affecting the user network experience.

Method used

Through the comparison mechanism between the first and second timestamps sent by the LSC device of the local service center, the target access node AP and the terminal determine the legal terminal when the timestamps are consistent, and achieve rapid authentication and authentication.

Benefits of technology

It improves the authentication efficiency between the terminal and the access node, prevents illegal access, and improves the user's network experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116156500B_ABST
    Figure CN116156500B_ABST
Patent Text Reader

Abstract

The present invention provides a device authentication method and apparatus to address the issue of device authentication in a user-centric ultra-dense network. The method includes: a target access node (AP) obtaining a first timestamp sent by a local service center (LSC) device and a second timestamp sent by a terminal, wherein the second timestamp is sent by the LSC device to the terminal, and the first and second timestamps are timestamps sent by the LSC device based on an AP handover event; and when the first and second timestamps are consistent, the target AP determines that the terminal is an access terminal of the target AP.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technology, and in particular to a device authentication method and apparatus. Background Art

[0002] In ultra-dense scenarios of the 5G era, various small base stations, also known as access points (APs), will be deployed at least ten times the number of existing sites. This large number of small base stations, coupled with their future adoption of plug-and-play solutions, will make their management more difficult and their security more difficult to guarantee. Due to the existence of illegal or untrusted small base stations (APs), if user-centric ultra-dense networks (UUDNs) still rely on a one-time, two-way authentication between the core network and the user, the security threat to user equipment (UE) from illegal small base stations cannot be ruled out, meaning that user access security cannot be guaranteed. More importantly, if small base stations and UEs use traditional authentication methods, each user UE and each access point (AP) must undergo access authentication. Due to the constant mobility of user UEs, frequent handoffs between UEs and APs will lead to security authentication inefficiencies, directly reducing the user's network experience. Summary of the Invention

[0003] The purpose of the present invention is to provide a device authentication method and apparatus to solve the problem of how to authenticate devices in a user-centric ultra-dense network.

[0004] In order to achieve the above object, the present invention provides a device authentication method, comprising:

[0005] The target access node AP obtains a first timestamp sent by a local service center LSC device and a second timestamp sent by the terminal, where the second timestamp is sent by the LSC device to the terminal, and the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event;

[0006] When the first timestamp is consistent with the second timestamp, the target AP determines that the terminal is an access terminal of the target AP.

[0007] Optionally, before the target access node AP obtains the first timestamp sent by the local service center LSC device, the method further includes:

[0008] The target AP obtains a first AP switching request sent by the LSC device, where the first AP switching request is used to request the terminal to switch from the source AP to the target AP;

[0009] The target AP sends verification information to the LSC device according to the first AP switching request;

[0010] The first timestamp is sent to the target AP after the LSC determines that the target AP is a legitimate AP based on the verification information.

[0011] Optionally, the verification information includes identification information of the target AP and password information corresponding to the identification information;

[0012] Before the target AP obtains the first AP switching request sent by the LSC device, the method further includes:

[0013] Send identification information and public key certificate to LSC device;

[0014] Acquire cryptographic information corresponding to the identification information and sent by the LSC, wherein the cryptographic information is encrypted using the public key certificate.

[0015] Optionally, the method of the embodiment of the present invention further includes:

[0016] Sending the first timestamp to the terminal.

[0017] An embodiment of the present invention further provides a device authentication method, comprising:

[0018] The terminal obtains a second timestamp sent by the LSC device and a first timestamp sent by the target access node AP, where the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event;

[0019] When the first timestamp and the second timestamp are consistent, the terminal determines that the target AP is the access AP of the terminal.

[0020] Optionally, the method of the embodiment of the present invention further includes:

[0021] The terminal sends the second timestamp to the target AP.

[0022] An embodiment of the present invention further provides a device authentication method, comprising:

[0023] The local service center LSC device receives a second AP switching request sent by the source AP, where the second AP switching request is used to request the terminal to perform AP switching;

[0024] The LSC device determines a target AP according to the second AP switching request, where the target AP is the AP to which the terminal is connected after performing the AP switching;

[0025] The LSC device sends a first timestamp to the target AP and sends a second timestamp to the terminal.

[0026] Optionally, determining the target AP includes:

[0027] Determining, according to the AP switching list, a switching AP corresponding to the switching time of the terminal as the target AP;

[0028] The AP switching list stores switching APs corresponding to different switching times.

[0029] Optionally, the LSC device sending a first timestamp to the target AP includes:

[0030] Sending a first AP switching request to the target AP, where the first AP switching request is used to request the terminal to switch from the source AP to the target AP;

[0031] Obtaining verification information sent by the target AP in response to the first AP handover request;

[0032] When it is determined that the target AP is a legitimate AP according to the verification information, a first timestamp is sent to the target AP.

[0033] Optionally, the verification information includes identification information of the target AP and password information corresponding to the identification information;

[0034] The method further comprises:

[0035] Obtaining a hash value corresponding to the password information based on the password information and the random number;

[0036] If the hash value is consistent with the hash value corresponding to the identification information stored in the database, the target AP is determined to be a legitimate AP.

[0037] Optionally, before sending the first AP switching request to the target AP, the method further includes:

[0038] Obtain identification information and public key certificate of the target AP sent by the target AP;

[0039] After verifying the identification information using the public key certificate, generating password information corresponding to the identification information;

[0040] The password information is sent to the target AP, and a hash value corresponding to the identification information is generated based on the password information and a random number and saved.

[0041] An embodiment of the present invention further provides a device authentication apparatus, applied to a target AP, comprising a memory, a transceiver, and a processor;

[0042] A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations:

[0043] Acquire, by a transceiver, a first timestamp sent by a local service center (LSC) device and a second timestamp sent by the terminal, where the second timestamp is sent by the LSC device to the terminal, and the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event;

[0044] When the first timestamp is consistent with the second timestamp, the target AP determines that the terminal is an access terminal of the target AP.

[0045] Optionally, when executing the program, the processor further implements the following steps:

[0046] Acquire, through the transceiver, a first AP switching request sent by the LSC device, where the first AP switching request is used to request the terminal to switch from the source AP to the target AP;

[0047] Sending verification information to the LSC device through the transceiver according to the first AP switching request;

[0048] The first timestamp is sent to the target AP after the LSC determines that the target AP is a legitimate AP based on the verification information.

[0049] Optionally, the verification information includes identification information of the target AP and password information corresponding to the identification information;

[0050] When the processor executes the program, the following steps are further implemented:

[0051] Send identification information and public key certificate to LSC device via transceiver;

[0052] The cryptographic information corresponding to the identification information and sent by the LSC is acquired through a transceiver, wherein the cryptographic information is encrypted using the public key certificate.

[0053] Optionally, when executing the program, the processor further implements the following steps:

[0054] The first timestamp is sent to the terminal through a transceiver.

[0055] An embodiment of the present invention further provides a device authentication apparatus, applied to a terminal, comprising a memory, a transceiver, and a processor;

[0056] A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations:

[0057] Acquire, by a transceiver, a second timestamp sent by an LSC device and a first timestamp sent by a target access node AP, where the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event;

[0058] When the first timestamp and the second timestamp are consistent, the target AP is determined to be the access AP of the terminal.

[0059] Optionally, when executing the program, the processor further implements the following steps:

[0060] The second timestamp is sent to the target AP through a transceiver.

[0061] The embodiment of the present invention also provides a device authentication apparatus, which is applied to a local service center LSC device and includes a memory, a transceiver, and a processor;

[0062] A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations:

[0063] receiving, through the transceiver, a second AP switching request sent by the source AP, where the second AP switching request is used to request the terminal to perform AP switching;

[0064] Determining a target AP according to the second AP switching request, where the target AP is the AP to which the terminal is connected after performing the AP switching;

[0065] A first timestamp is sent to the target AP through a transceiver, and a second timestamp is sent to the terminal.

[0066] Optionally, when executing the program, the processor further implements the following steps:

[0067] Determining, according to the AP switching list, a switching AP corresponding to the switching time of the terminal as the target AP;

[0068] The AP switching list stores switching APs corresponding to different switching times.

[0069] Optionally, when executing the program, the processor further implements the following steps:

[0070] Sending a first AP switching request to the target AP, where the first AP switching request is used to request the terminal to switch from the source AP to the target AP;

[0071] Acquire, by a transceiver, verification information sent by the target AP in response to the first AP handover request;

[0072] When it is determined that the target AP is a legitimate AP according to the verification information, a first timestamp is sent to the target AP via a transceiver.

[0073] Optionally, the verification information includes identification information of the target AP and password information corresponding to the identification information;

[0074] When the processor executes the program, the following steps are further implemented:

[0075] Obtaining a hash value corresponding to the password information based on the password information and the random number;

[0076] If the hash value is consistent with the hash value corresponding to the identification information stored in the database, the target AP is determined to be a legitimate AP.

[0077] Optionally, when executing the program, the processor further implements the following steps:

[0078] Obtaining identification information and a public key certificate of the target AP sent by the target AP through a transceiver;

[0079] After verifying the identification information using the public key certificate, generating password information corresponding to the identification information;

[0080] The password information is sent to the target AP via a transceiver, and a hash value corresponding to the identification information is generated and saved based on the password information and a random number.

[0081] An embodiment of the present invention further provides a device authentication apparatus, which is applied to a target AP and includes:

[0082] A first acquiring unit is configured to acquire a first timestamp sent by a local service center (LSC) device and a second timestamp sent by a terminal, where the second timestamp is sent by the LSC device to the terminal, and the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event;

[0083] The first determining unit is configured to determine, when the first timestamp is consistent with the second timestamp, that the terminal is an access terminal of the target AP.

[0084] An embodiment of the present invention further provides a device authentication apparatus, applied to a terminal, comprising:

[0085] A second acquiring unit, configured to acquire a second timestamp sent by the LSC device and a first timestamp sent by the target access node AP, where the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event;

[0086] A second determining unit is configured to determine, when the first timestamp and the second timestamp are consistent, that the target AP is the access AP of the terminal.

[0087] The embodiment of the present invention further provides a device authentication apparatus, which is applied to a local service center (LSC) device, comprising:

[0088] A first receiving unit is configured to receive a second AP switching request sent by a source AP, where the second AP switching request is used to request the terminal to perform AP switching;

[0089] a third determining unit, configured to determine a target AP according to the second AP switching request, where the target AP is the AP to which the terminal is connected after performing AP switching;

[0090] The first transceiver unit is configured to send a first timestamp to the target AP and a second timestamp to the terminal.

[0091] An embodiment of the present invention further provides a processor-readable storage medium, wherein the processor-readable storage medium stores program instructions, and the program instructions are used to enable the processor to execute the steps of the device authentication method described above.

[0092] The above technical solution of the present invention has at least the following beneficial effects:

[0093] In an embodiment of the present invention, when a terminal needs to switch APs, the LSC sends a first timestamp and a second timestamp to the target AP and the terminal respectively. The target AP compares the first timestamp with the second timestamp received from the terminal. If the two are consistent, the terminal is determined to be the terminal that is about to access. In this way, by comparing the timestamps, the access device can be quickly authenticated, thereby improving the authentication efficiency between the terminal and the AP. BRIEF DESCRIPTION OF THE DRAWINGS

[0094] Figure 1 A structural diagram showing a network system to which an embodiment of the present invention can be applied;

[0095] Figure 2 A schematic diagram of the UUDN network architecture is shown;

[0096] Figure 3 A schematic diagram showing a flow chart of a device authentication method according to an embodiment of the present invention;

[0097] Figure 4A second flowchart illustrating a device authentication method according to an embodiment of the present invention;

[0098] Figure 5 A third flowchart of a device authentication method according to an embodiment of the present invention is shown;

[0099] Figure 6 A schematic diagram showing the dynamic changes of the APG in an embodiment of the present invention;

[0100] Figure 7 A schematic diagram showing segmented authentication according to an embodiment of the present invention;

[0101] Figure 8 A schematic diagram illustrating an interaction method for device authentication according to an embodiment of the present invention;

[0102] Figure 9 One of the structural block diagrams of the device authentication apparatus according to an embodiment of the present invention;

[0103] Figure 10 A second structural block diagram showing the device authentication apparatus according to an embodiment of the present invention;

[0104] Figure 11 A schematic diagram showing a module of a device authentication apparatus according to an embodiment of the present invention;

[0105] Figure 12 A second schematic diagram showing a module of a device authentication apparatus according to an embodiment of the present invention;

[0106] Figure 13 A third schematic diagram of a module of a device authentication apparatus according to an embodiment of the present invention. DETAILED DESCRIPTION

[0107] The technical solution provided in the embodiment of the present invention can be applicable to a variety of systems, especially 5G systems. For example, applicable systems may be Global System of Mobile communication (GSM) systems, Code Division Multiple Access (CDMA) systems, Wideband Code Division Multiple Access (WCDMA) systems, Time Division Synchronous Code Division Multiple Access (TD-SCDMA) systems, General Packet Radio Service (GPRS) systems, Long Term Evolution (LTE) systems (including TD-LTE and FDDLTE), Long Term Evolution Advanced (LTE-A) systems, Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability For Microwave Access (WiMAX) systems, 5G New Radio (NR) systems, etc. These various systems include terminal devices and network devices. The system can also include core network parts, such as the Evolved Packet System (EPS), 5G system (5GS / 5GC), etc.

[0108] Figure 1A block diagram of a wireless communication system applicable to an embodiment of the present application is shown. The wireless communication system includes a terminal 11 and a network device 12. Among them, the terminal 11 can also be referred to as a terminal device or a user terminal (User Equipment, UE). The terminal 11 can be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer) or a notebook computer, a personal digital assistant (Personal Digital Assistant, PDA), a handheld computer, a netbook, an ultra-mobile personal computer (Ultra-Mobile Personal Computer, UMPC), a mobile Internet device (Mobile Internet Device, MID), a wearable device (Wearable Device) or a vehicle-mounted device (VUE), a pedestrian terminal (PUE) and other terminal-side devices. Wearable devices include: bracelets, headphones, glasses, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application. The network device 12 can be a base station or a core network, where the base station can be referred to as a node B, an evolved node B, an access point, a base transceiver station (Base Transceiver Station, BTS), a radio base station, a radio transceiver, a basic service set (Basic Service Set, BSS), an extended service set (Extended Service Set, ESS), a B node, an evolved B node (eNB), a home B node, a home evolved B node, a WLAN access point, a WiFi node, a transmitting and receiving point (Transmitting Receiving Point, TRP) or other appropriate terms in the field. As long as the same technical effect is achieved, the base station is not limited to a specific technical vocabulary. It should be noted that in the embodiment of the present application, only the base station in the NR system is taken as an example, but the specific type of the base station is not limited.

[0109] In order to enable those skilled in the art to better understand the embodiments of the present invention, the following description is first given.

[0110] Future networks will have no specific cell boundaries. Instead, they will be user-centric, with the coverage of base stations and their antenna units adaptively adjusted based on user service needs and interference distribution. In user-centric ultra-dense networks (UUDNs), the physical and logical concepts of "cells" in traditional cellular networks are eliminated. Instead, access nodes (APs) of different network types form a cluster at the control plane. APs dynamically collaborate with each other, providing flexibility and a superior user experience.

[0111] UUDN is a user-centric ultra-dense network that organizes a dynamic access point group (APG) to provide services for each user. Figure 2 As shown in the figure, in the UUDN network architecture, access nodes are not directly connected to the 5G core network. Instead, they are organized through numerous access nodes APs to form a "user-centric" access node group APG, which is connected to the network service center NSC, i.e. the 5G core network, through the local service center LSC. The APG members will dynamically change with the user's movement to provide users with seamless network services.

[0112] LSC is the control service center that organizes dynamic APG service users and provides localized control and management functions, including access control, multi-RAT collaboration, local mobility management, local QoS management, local data routing, and centralized user data processing.

[0113] As the network service center, NSC is responsible for providing control functions related to user policy control, authentication, authorization and accounting (Authentication, Authorization and Accounting) and high-level mobility management.

[0114] UUDN mainly faces the following two security issues:

[0115] In ultra-dense network environments, only performing traditional AKA on user UEs can lead to the possibility of fake access points (APs). This poses a significant threat to the security of ultra-dense networks, and user UEs face security threats such as being hijacked by illegal or malicious APs.

[0116] In the UUDN network architecture, the high density of AP deployments of various network types leads to frequent and complex handoffs and authentication processes. When user UEs and each network access point (AP) undergo access authentication, the constant mobility of UEs leads to frequent handoffs between UEs and APs, which in turn leads to inefficient security authentication and reduces the user experience.

[0117] The following will be combined with the accompanying drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0118] like Figure 3 As shown, an embodiment of the present invention provides a device authentication method, including:

[0119] Step 301: The target access node AP obtains a first timestamp sent by a local service center LSC device and a second timestamp sent by a terminal, where the second timestamp is sent by the LSC device to the terminal. The first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event or an AP switching request.

[0120] For example, the AP switching event may be that the LSC receives a switching request from the source AP, or the LSC determines a switching strategy, or the LSC determines a target AP, or the LSC determines that the target AP is a legitimate AP, etc.;

[0121] In this embodiment of the present invention, a terminal reports measurements, and the source AP decides whether to perform AP handover based on the measurement information reported by the terminal. If AP handover is determined, the source AP sends a handover request to the LSC device, requesting the LSC device to determine the AP to handover to. In other words, the LSC device determines the target AP. After determining the target AP, the LSC device generates a timestamp and sends it to the target AP and the terminal, respectively. Here, the timestamp sent by the LSC device to the target AP is referred to as the first timestamp, and the timestamp sent by the LSC device to the terminal is referred to as the second timestamp. The first and second timestamps are identical.

[0122] Optionally, the first timestamp or the second timestamp may be a specific moment of switching, or other time information.

[0123] Step 302: When the first timestamp is consistent with the second timestamp, the target AP determines that the terminal is an access terminal of the target AP.

[0124] In this step, the target AP compares the first timestamp received from the LSC device with the second timestamp sent by the terminal. If the two are consistent, the terminal is determined to be a legitimate terminal, that is, the terminal is determined to be the access terminal of the target AP, and then handover preparation is performed.

[0125] In the device authentication method of an embodiment of the present invention, when a terminal needs to switch APs, the LSC sends a first timestamp and a second timestamp to the target AP and the terminal respectively. The target AP compares the first timestamp with the second timestamp received from the terminal. If the two are consistent, the terminal is determined to be the terminal that is about to access. In this way, by comparing the timestamps, the access device can be quickly authenticated, thereby improving the authentication efficiency between the terminal and the AP.

[0126] Optionally, before the target access node AP obtains the first timestamp sent by the local service center LSC device, the method further includes:

[0127] The target AP obtains a first AP switching request sent by the LSC device, where the first AP switching request is used to request the terminal to switch from the source AP to the target AP;

[0128] The target AP sends verification information to the LSC device according to the first AP switching request;

[0129] The first timestamp is sent to the target AP by the LSC after determining that the target AP is a legitimate AP according to the verification information.

[0130] In an embodiment of the present invention, after the LSC device determines the target AP, it sends the first AP switching request to the target AP to request the terminal to switch from the source AP to the target AP. The target AP responds to the request and sends verification information to the LSC device. After the LSC device determines that the target AP is a legitimate AP based on the verification information, it generates a timestamp and sends it to the target AP and the terminal. In this way, the LSC device authenticates the AP.

[0131] Optionally, the verification information includes identification information of the target AP and password information corresponding to the identification information;

[0132] Before the target AP obtains the first AP switching request sent by the LSC device, the method further includes:

[0133] Send identification information and public key certificate to LSC device;

[0134] Acquire cryptographic information corresponding to the identification information and sent by the LSC, wherein the cryptographic information is encrypted using the public key certificate.

[0135] Here, the identification information is the identity identification information of the target AP, which may be, but is not limited to, AP-ID. Other identifiers that can uniquely identify the target AP may also be used here.

[0136] In an embodiment of the present invention, in a UUDN scenario, a large number of densely deployed APs form an AP group - APG with the user UE as the center to provide services for the UE. After the AP enters the network, it needs to be authenticated at the LSC first. The AP first sends a digital signature and a public key certificate to the LSC. The content of the digital signature is the AP-ID (the digital signature is encrypted with a private key). The AP-ID can also be other identifiers representing the AP identity, which determines the uniqueness of the AP identity. After the LSC device verifies the identification information of the AP based on the above public key certificate (the public key certificate and the above private key match), it searches its own authentication information database. If the authentication information corresponding to the AP-ID does not exist, authentication information is created for the AP. The authentication information database entries may include the following:

[0137] Username AP-ID;

[0138] Random number rand, which is generated by the LSC device. The embodiment of the present invention does not impose any specific restrictions on the generation algorithm and length of the random number. This random number is used to store cryptographic information, making the storage of cryptographic information in the LSC device more confidential.

[0139] Hash value: This hash value is based on the password information and a random number. The password information is generated by the LSC device and corresponds one-to-one with the AP_ID or other identity identifier that represents the uniqueness of the AP. There are no requirements for its generation algorithm or length. The hash value is obtained by performing a hash operation on the password information and random number on the LSC device and is stored in the LSC device to prevent the password from being stored in plain text.

[0140] After the target AP sends the verification information to the LSC, the LSC device obtains the password information corresponding to the identification information of the target AP, encrypts the password information using the public key certificate, and then sends it to the target AP.

[0141] Optionally, the method of the embodiment of the present invention further includes:

[0142] The first timestamp is sent to the terminal.

[0143] Here, the first timestamp is sent to the terminal so that the terminal compares the first timestamp with the second timestamp sent by the LSC device to the terminal, thereby achieving authentication of the target AP.

[0144] According to the method of the embodiment of the present invention, when a terminal needs to switch APs, the LSC sends a first timestamp and a second timestamp to the target AP and the terminal respectively. The target AP compares the first timestamp with the second timestamp received from the terminal. If the two are consistent, the terminal is determined to be the terminal that is about to access. In this way, by comparing the timestamps, the access device can be quickly authenticated, thereby improving the authentication efficiency between the terminal and the AP.

[0145] like Figure 4 As shown, an embodiment of the present invention also provides a device authentication method, including:

[0146] Step 401: The terminal obtains a second timestamp sent by a local service center LSC device and a first timestamp sent by a target access point AP. The first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event or an AP switching request.

[0147] In this embodiment of the present invention, a terminal reports measurements, and the source AP decides whether to perform AP handover based on the measurement information reported by the terminal. If AP handover is determined, the source AP sends a handover request to the LSC device, requesting the LSC device to determine the AP to handover to. In other words, the LSC device determines the target AP. After determining the target AP, the LSC device generates a timestamp and sends it to the target AP and the terminal, respectively. Here, the timestamp sent by the LSC device to the target AP is referred to as the first timestamp, and the timestamp sent by the LSC device to the terminal is referred to as the second timestamp. The first and second timestamps are identical.

[0148] Optionally, the first timestamp or the second timestamp may be a specific moment of switching, or other time information.

[0149] Step 402: When the first timestamp and the second timestamp are consistent, the terminal determines that the target AP is the access AP of the terminal.

[0150] In this step, the terminal compares the second timestamp received from the LSC device with the second timestamp sent by the target AP. If the two are consistent, the target AP is determined to be a legitimate AP, that is, the target AP is determined to be the AP that the terminal needs to access, and then prepares for switching.

[0151] In the device authentication method of an embodiment of the present invention, when a terminal needs to switch APs, the LSC sends a first timestamp and a second timestamp to the target AP and the terminal respectively. The terminal compares the second timestamp with the first timestamp received from the target AP. If the two are consistent, the target AP is determined to be the AP to be accessed. In this way, by comparing the timestamps, the access device can be quickly authenticated, thereby improving the authentication efficiency between the terminal and the AP.

[0152] Optionally, the method of the embodiment of the present invention further includes:

[0153] The terminal sends the second timestamp to the target AP.

[0154] Here, the second timestamp is sent to the target AP so that the target AP compares the second timestamp with the first timestamp sent by the LSC device to the target AP, thereby achieving authentication of the terminal.

[0155] According to the method of the embodiment of the present invention, when a terminal needs to switch APs, the LSC sends a first timestamp and a second timestamp to the target AP and the terminal respectively. The terminal compares the second timestamp with the first timestamp received from the target AP. If the two timestamps are consistent, the target AP is determined to be the AP to be accessed. In this way, by comparing the timestamps, the access device can be quickly authenticated, thereby improving the authentication efficiency between the terminal and the AP.

[0156] like Figure 5 As shown, an embodiment of the present invention also provides a device authentication method, including:

[0157] Step 501: The local service center LSC device receives a second access node AP switching request sent by a source AP. The second AP switching request is used to request a terminal to perform AP switching.

[0158] In this embodiment of the present invention, the terminal performs measurement reporting, and the source AP determines whether to perform AP switching based on the measurement information reported by the terminal. If AP switching is determined, the source AP sends a switching request (a second AP switching request) to the LSC device, requesting the LSC device to determine which AP to switch to. In other words, the LSC device determines the target AP.

[0159] Step 502: The LSC device determines a target AP according to the second AP switching request. The target AP is the AP to which the terminal is connected after performing AP switching.

[0160] After the LSC device determines the target AP, it determines the target AP based on the AP switching list or other switching algorithms.

[0161] Step 503: The LSC device sends a first timestamp to the target AP and sends a second timestamp to the terminal.

[0162] In this step, after the LSC device determines the target AP, it generates a timestamp and sends the timestamp to the target AP and the terminal respectively. Here, the timestamp sent by the LSC device to the target AP is called the first timestamp, and the timestamp sent by the LSC device to the terminal is described as the second timestamp. The first timestamp and the second timestamp are the same.

[0163] According to the method of the embodiment of the present invention, when a terminal needs to switch APs, the LSC sends a first timestamp and a second timestamp to the target AP and the terminal respectively. The terminal compares the second timestamp with the first timestamp received from the target AP. If the two timestamps are consistent, the target AP is determined to be the AP to be accessed. In this way, by comparing the timestamps, the access device can be quickly authenticated, thereby improving the authentication efficiency between the terminal and the AP.

[0164] Optionally, determining the target AP includes:

[0165] According to the AP switching list, the switching AP corresponding to the switching time of the terminal is determined as the target AP;

[0166] The AP switching list stores switching APs corresponding to different switching times.

[0167] For example, the AP switching list is: t1: AP2; t2: AP4, which means that the AP switches to AP2 at time t1 and switches to AP4 at time t2.

[0168] The above AP switching list is obtained based on the channel conditions of other UEs connected to the LSC device. The channel conditions are the channel conditions measured by other UEs before the target time, and the target time is the switching time of the current UE.

[0169] Here, the LSC device determines the AP switching list based on the above channel conditions. Based on this AP switching list, it can predict the UE's switching route. That is, only the LSC knows the base station to which the UE will switch next. Each time a switch occurs, the LSC notifies the UE and the AP that the UE is about to access. Security is reflected in the fact that only the AP and the UE know the switching moment, and the UE only needs to check the timestamp with the AP to confirm the other party's identity.

[0170] In the embodiment of the present invention, after the APG is established, its members can change dynamically according to the user's mobile location or wireless environment, such as a new node joining the APG or an existing node leaving the APG. In the embodiment of the present invention, the method of a new node joining the APG, i.e., the UE switching to a new AP, adopts a switching list. Figure 6 As shown, the LSC stores a handover list for the current UE, representing the UE's handover routes after the current moment. When the UE moves, the LSC notifies the UE of the corresponding access base station node at time t2: AP4, based on the handover list. It also sends the corresponding timestamp t2 to the UE and AP4, preparing for the UE to disconnect from AP2 and handover to AP4. If the UE and AP4 mutually confirm that the timestamp is t2, the UE hands over to AP4. The membership of APG1 changes from AP1, AP2, AP3 to AP1, AP3, AP4 based on the LSC's handover list, and the handover is complete.

[0171] Optionally, the LSC device sends a first timestamp to the target AP, including:

[0172] Sending a first AP switching request to the target AP, where the first AP switching request is used to request the terminal to switch from the source AP to the target AP;

[0173] Obtaining verification information sent by the target AP in response to the first AP handover request;

[0174] When it is determined that the target AP is a legitimate AP according to the verification information, a first timestamp is sent to the target AP.

[0175] In an embodiment of the present invention, after the LSC device determines the target AP, it sends the first AP switching request to the target AP to request the terminal to switch from the source AP to the target AP. The target AP responds to the request and sends verification information to the LSC device. After the LSC device determines that the target AP is a legitimate AP based on the verification information, it generates a timestamp and sends it to the target AP and the terminal. In this way, the LSC device authenticates the AP.

[0176] In order to ensure the legitimacy of the AP, the LSC authenticates the AP to avoid occupying too many UE resources and consuming the UE's power. Figure 7 As shown, the embodiment of the present invention adopts segmented authentication, that is, after the AP and the LSC are successfully authenticated, the AP and the UE are authenticated again, which can avoid security threats posed by some illegal APs.

[0177] Optionally, the verification information includes identification information of the target AP and password information corresponding to the identification information;

[0178] The method further includes:

[0179] Obtain a hash value corresponding to the password information based on the password information and the random number;

[0180] If the hash value is consistent with the hash value corresponding to the identification information stored in the database, the target AP is determined to be a legitimate AP.

[0181] Optionally, before sending the first AP switching request to the target AP, the method further includes:

[0182] Obtain the target AP's identification information and public key certificate sent by the target AP;

[0183] After verifying the identification information using the public key certificate, generating password information corresponding to the identification information;

[0184] The password information is sent to the target AP, and a hash value corresponding to the identification information is generated based on the password information and the random number and saved.

[0185] After the target AP sends the verification information to the LSC, the LSC device obtains the password information corresponding to the identification information of the target AP, encrypts the password information using the public key certificate, and then sends it to the target AP.

[0186] The device authentication method of the present invention is described below with reference to specific embodiments.

[0187] like Figure 8 As shown, the device authentication method of the present invention includes:

[0188] Step 801: UE reports measurement conditions.

[0189] Step 802: The source AP requests the LSC to make a handover decision.

[0190] Step 803: The LSC obtains the target AP for handover according to the AP handover list or other handover algorithms.

[0191] Step 804: Notify the target AP to be handed over.

[0192] Step 805: The target AP sends a response request and sends AP-ID and password information.

[0193] Step 806: If the AP-ID exists in the database, the LSC calculates a hash value based on the password information and the random number. If the calculated hash value is consistent with the hash value corresponding to the AP-ID stored in the database, it is determined to be a legitimate AP.

[0194] Step 807: Send the timestamp to the target AP, and send the timestamp to the terminal through the source AP.

[0195] Step 808: The terminal sends a timestamp to the target AP for identity confirmation.

[0196] Step 809: The target AP compares the timestamps to confirm the UE identity.

[0197] Step 810: The target AP sends a timestamp to the UE to confirm its identity.

[0198] Step 811: The terminal compares the timestamp to confirm whether it is the target AP.

[0199] In the method of the embodiment of the present invention, the UE and AP mutually confirm whether the other party is the UE / AP about to access through timestamps. If the timestamps are consistent, rapid authentication can be achieved, thereby improving the efficiency of authentication between the UE and AP. To ensure the legitimacy of the AP, the LSC authenticates the AP to avoid occupying excessive UE resources and consuming its power. Because ultra-dense networks often deploy a large number of heterogeneous APs that support plug-and-play, the segmented authentication of the present invention, i.e., after the AP successfully authenticates with the LSC, the AP then authenticates with the UE, can prevent some illegal APs from posing security threats.

[0200] like Figure 9 As shown, an embodiment of the present invention provides a device authentication apparatus, including a memory 920, a transceiver 900, and a processor 910;

[0201] The memory 920 is used to store computer programs; the transceiver 900 is used to send and receive data under the control of the processor;

[0202] In one embodiment of the present invention, the processor 910 is configured to read the computer program in the memory and perform the following operations:

[0203] Acquire, through the transceiver 900, a first timestamp sent by a local service center (LSC) device and a second timestamp sent by the terminal, where the second timestamp is sent by the LSC device to the terminal, and the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event or an AP switching request;

[0204] When the first timestamp is consistent with the second timestamp, the target AP determines that the terminal is an access terminal of the target AP.

[0205] Optionally, when executing the program, the processor 910 further implements the following steps:

[0206] Acquire, through the transceiver 900, a first AP switching request sent by the LSC device, where the first AP switching request is used to request the terminal to switch from the source AP to the target AP;

[0207] Sending verification information to the LSC device through the transceiver 900 according to the first AP switching request;

[0208] The first timestamp is sent to the target AP by the LSC after determining that the target AP is a legitimate AP according to the verification information.

[0209] Optionally, the verification information includes identification information of the target AP and password information corresponding to the identification information;

[0210] When the processor 910 executes the program, it also implements the following steps:

[0211] Send identification information and public key certificate to LSC device via transceiver 900;

[0212] The cryptographic information corresponding to the identification information and sent by the LSC is obtained through the transceiver 900, wherein the cryptographic information is encrypted using the public key certificate.

[0213] Optionally, when executing the program, the processor 910 further implements the following steps:

[0214] The first timestamp is sent to the terminal through the transceiver 900 .

[0215] In another embodiment of the present invention, the processor 910 is configured to read the computer program in the memory and perform the following operations:

[0216] Receiving, through the transceiver 900, a second AP switching request sent by the source AP, where the second AP switching request is used to request the terminal to perform AP switching;

[0217] Determining a target AP according to the second AP switching request, where the target AP is the AP to which the terminal is connected after performing the AP switching;

[0218] The transceiver 900 sends a first timestamp to the target AP and sends a second timestamp to the terminal.

[0219] Optionally, when executing the program, the processor 910 further implements the following steps:

[0220] According to the AP switching list, the switching AP corresponding to the switching time of the terminal is determined as the target AP;

[0221] The AP switching list stores switching APs corresponding to different switching times.

[0222] Optionally, when executing the program, the processor 910 further implements the following steps:

[0223] Sending a first AP switching request to the target AP, where the first AP switching request is used to request the terminal to switch from the source AP to the target AP;

[0224] Acquiring, through the transceiver 900, verification information sent by the target AP in response to the first AP handover request;

[0225] When it is determined that the target AP is a legitimate AP according to the verification information, a first timestamp is sent to the target AP via a transceiver.

[0226] Optionally, the verification information includes identification information of the target AP and password information corresponding to the identification information;

[0227] When the processor 910 executes the program, it also implements the following steps:

[0228] Obtain a hash value corresponding to the password information based on the password information and the random number;

[0229] If the hash value is consistent with the hash value corresponding to the identification information stored in the database, the target AP is determined to be a legitimate AP.

[0230] Optionally, when executing the program, the processor 910 further implements the following steps:

[0231] Obtaining identification information and public key certificate of the target AP sent by the target AP through the transceiver 900;

[0232] After verifying the identification information using the public key certificate, generating password information corresponding to the identification information;

[0233] The password information is sent to the target AP via the transceiver 900 , and a hash value corresponding to the identification information is generated and saved based on the password information and the random number.

[0234] Among them, Figure 9 In the embodiment, the bus architecture may include any number of interconnected buses and bridges, specifically various circuits linked together by one or more processors represented by processor 910 and memory represented by memory 920. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are all well known in the art and, therefore, will not be described further herein. The bus interface provides an interface. The transceiver 900 may be a plurality of components, i.e., a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium, such as a wireless channel, a wired channel, an optical cable, and the like. The processor 910 is responsible for managing the bus architecture and general processing, and the memory 920 may store data used by the processor 910 when performing operations.

[0235] The processor 910 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor may also adopt a multi-core architecture.

[0236] It should be noted here that the above-mentioned device provided in the embodiment of the present invention can implement all the method steps implemented in the above-mentioned device authentication method embodiment, and can achieve the same technical effect. The parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.

[0237] like Figure 10 As shown, an embodiment of the present invention further provides a device authentication apparatus, applied to a terminal, comprising a memory 1020, a transceiver 1000, and a processor 1010;

[0238] The memory 1020 is used to store computer programs; the transceiver 1000 is used to send and receive data under the control of the processor; and the processor 1010 is used to read the computer program in the memory and perform the following operations:

[0239] Acquire, by the transceiver 1000, a second timestamp sent by the LSC device and a first timestamp sent by the target access node AP, where the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event or an AP switching request;

[0240] When the first timestamp and the second timestamp are consistent, the target AP is determined to be the access AP of the terminal.

[0241] Among them, Figure 10 In the embodiment, the bus architecture may include any number of interconnected buses and bridges, specifically linking together various circuits of one or more processors represented by processor 1010 and memory represented by memory 1020. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are all well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 1000 may be a plurality of components, namely, a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium, such as a wireless channel, a wired channel, an optical cable, and the like. For different user devices, the user interface 1030 may also be an interface capable of connecting external or internal devices as required, and the connected devices include but are not limited to a keypad, a display, a speaker, a microphone, a joystick, and the like.

[0242] The processor 1010 is responsible for managing the bus architecture and general processing, and the memory 1020 can store data used by the processor 1010 when performing operations.

[0243] Optionally, the processor 1010 may be a CPU (central processing unit), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array) or a CPLD (Complex Programmable Logic Device), and the processor may also adopt a multi-core architecture.

[0244] The processor calls the computer program stored in the memory to execute any of the methods provided in the embodiments of the present application according to the obtained executable instructions. The processor and the memory can also be arranged physically separately.

[0245] Optionally, when executing the program, the processor 1010 further implements the following steps:

[0246] The second timestamp is sent to the target AP via the transceiver 1000 .

[0247] It should be noted here that the above-mentioned device provided by the embodiment of the present invention can implement all the method steps implemented by the above-mentioned device authentication method embodiment applied to the terminal, and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as the method embodiment will not be described in detail here.

[0248] like Figure 11 As shown, an embodiment of the present invention further provides a device authentication apparatus, which is applied to a target AP, including:

[0249] A first acquiring unit 1101 is configured to acquire a first timestamp sent by a local service center (LSC) device and a second timestamp sent by a terminal, where the second timestamp is sent by the LSC device to the terminal, and the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event or an AP switching request;

[0250] The first determining unit 1102 is configured to determine, when the first timestamp is consistent with the second timestamp, that the terminal is an access terminal of the target AP.

[0251] Optionally, the device according to the embodiment of the present invention further includes:

[0252] The third acquiring unit is configured to acquire a first AP switching request sent by the local service center LSC device before the first acquiring unit acquires the first timestamp sent by the LSC device, where the first AP switching request is used to request the terminal to switch from the source AP to the target AP;

[0253] A second transceiver unit is configured to send verification information to the LSC device according to the first AP switching request;

[0254] The first timestamp is sent to the target AP by the LSC after determining that the target AP is a legitimate AP according to the verification information.

[0255] Optionally, the verification information includes identification information of the target AP and password information corresponding to the identification information;

[0256] The device also includes:

[0257] a third transceiver unit, configured to send identification information and a public key certificate to the LSC device before the second transceiver unit sends verification information to the LSC device according to the handover request;

[0258] The fourth acquiring unit is configured to acquire cryptographic information corresponding to the identification information and sent by the LSC, wherein the cryptographic information is encrypted using the public key certificate.

[0259] Optionally, the apparatus according to the embodiment of the present invention further includes:

[0260] The fourth transceiver unit is configured to send the first timestamp to the terminal.

[0261] It should be noted here that the above-mentioned device provided in the embodiment of the present invention can implement all the method steps implemented in the above-mentioned device authentication method embodiment, and can achieve the same technical effect. The parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.

[0262] like Figure 12 As shown, an embodiment of the present invention further provides a device authentication apparatus, applied to a terminal, comprising:

[0263] The second acquiring unit 1201 is configured to acquire a second timestamp sent by the LSC device and a first timestamp sent by the target access node AP, where the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event or an AP switching request;

[0264] The second determining unit 1202 is configured to determine, when the first timestamp and the second timestamp are consistent, that the target AP is the access AP of the terminal.

[0265] Optionally, the device according to the embodiment of the present invention further includes:

[0266] The fifth transceiver unit is configured to send the second timestamp to the target AP.

[0267] It should be noted here that the above-mentioned device provided in the embodiment of the present invention can implement all the method steps implemented in the above-mentioned device authentication method embodiment, and can achieve the same technical effect. The parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.

[0268] like Figure 13 As shown, an embodiment of the present invention further provides a device authentication apparatus, which is applied to a local service center LSC device, comprising:

[0269] The first receiving unit 1301 is configured to receive a second AP switching request sent by a source AP, where the second AP switching request is used to request the terminal to perform AP switching;

[0270] The third determining unit 1302 is configured to determine a target AP according to the second AP switching request, where the target AP is the AP to which the terminal is connected after performing the AP switching;

[0271] The first transceiver unit 1303 is configured to send a first timestamp to the target AP and a second timestamp to the terminal.

[0272] Optionally, the third determining unit is configured to determine, according to the AP switching list, a switching AP corresponding to the switching time of the terminal as the target AP;

[0273] The AP switching list stores switching APs corresponding to different switching times.

[0274] Optionally, the first transceiver unit includes:

[0275] A first transceiver subunit is configured to send a first AP switching request to the target AP, where the first AP switching request is used to request the terminal to switch from the source AP to the target AP;

[0276] A first obtaining subunit is configured to obtain verification information sent by the target AP according to the first AP switching request;

[0277] The second transceiver subunit is configured to send a first timestamp to the target AP when it is determined that the target AP is a legitimate AP according to the verification information.

[0278] Optionally, the verification information includes identification information of the target AP and password information corresponding to the identification information;

[0279] The device according to the embodiment of the present invention further includes:

[0280] a fifth obtaining unit, configured to obtain a hash value corresponding to the password information based on the password information and the random number;

[0281] The fourth determining unit is configured to determine that the target AP is a legitimate AP if the hash value is consistent with the hash value corresponding to the identification information stored in the database.

[0282] Optionally, the device according to the embodiment of the present invention further includes:

[0283] a sixth acquiring unit, configured to acquire identification information and a public key certificate of the target AP sent by the target AP before sending the first AP switching request to the target AP;

[0284] A first generating unit is configured to generate password information corresponding to the identification information after verifying the identification information using the public key certificate;

[0285] The sixth transceiver unit is configured to send the password information to the target AP, and generate a hash value corresponding to the identification information based on the password information and the random number, and save the hash value.

[0286] It should be noted here that the above-mentioned device provided in the embodiment of the present invention can implement all the method steps implemented in the above-mentioned device authentication method embodiment, and can achieve the same technical effect. The parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.

[0287] It should be noted that the division of units in the embodiments of the present application is schematic and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0288] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) or a processor to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0289] In some embodiments of the present invention, a processor-readable storage medium is further provided, wherein the processor-readable storage medium stores program instructions, and the program instructions are used to cause the processor to execute the following steps:

[0290] Obtaining a first timestamp sent by a local service center (LSC) device and a second timestamp sent by the terminal, where the second timestamp is sent by the LSC device to the terminal, and the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event or an AP switching request; and determining that the terminal is an access terminal of the target AP if the first timestamp is consistent with the second timestamp;

[0291] Alternatively, obtain a second timestamp sent by the LSC device and a first timestamp sent by the target access node AP, where the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event or an AP switching request; when the first timestamp and the second timestamp are consistent, determine that the target AP is the access AP of the terminal.

[0292] Alternatively, a second AP switching request is received from the source AP, where the second AP switching request is used to request the terminal to perform AP switching; based on the second AP switching request, a target AP is determined, where the target AP is the AP to which the terminal is connected after performing AP switching; a first timestamp is sent to the target AP, and a second timestamp is sent to the terminal.

[0293] The terminal device involved in the embodiments of the present application may be a device that provides voice and / or data connectivity to a user, a handheld device with wireless connection function, or other processing devices connected to a wireless modem. In different systems, the name of the terminal device may also be different. For example, in a 5G system, the terminal device may be called a user equipment (UE). A wireless terminal device can communicate with one or more core networks (CN) via a radio access network (RAN). The wireless terminal device can be a mobile terminal device, such as a mobile phone (or "cellular" phone) and a computer with a mobile terminal device. For example, it can be a portable, pocket-sized, handheld, computer-built-in or vehicle-mounted mobile device that exchanges language and / or data with a radio access network. For example, personal communication service (PCS) phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), and other devices. The wireless terminal device may also be referred to as a system, a subscriber unit, a subscriber station, a mobile station, a mobile station, a remote station, an access point, a remote terminal device, an access terminal device, a user terminal device, a user agent, or a user device, but is not limited in the embodiments of the present application.

[0294] The network device involved in the embodiments of the present application may be a base station, which may include multiple cells providing services to terminals. Depending on the specific application scenario, the base station may also be called an access point, or may be a device in an access network that communicates with a wireless terminal device through one or more sectors on an air interface, or may be named otherwise. The network device may be used to interchange received air frames with Internet Protocol (IP) packets, acting as a router between the wireless terminal device and the rest of the access network, wherein the rest of the access network may include an Internet Protocol (IP) communication network. The network device may also coordinate attribute management of the air interface. For example, the network device involved in the embodiments of the present application may be a network device (Base Transceiver Station, BTS) in the Global System for Mobile communications (GSM) or Code Division Multiple Access (CDMA), or a network device (NodeB) in Wide-band Code Division Multiple Access (WCDMA), or an evolutionary network device (eNB or e-NodeB) in the Long Term Evolution (LTE) system, a 5G base station (gNB) in the 5G network architecture (next generation system), or a home evolved Node B (HeNB), a relay node, a femto, a pico, etc., which is not limited in the embodiments of the present application. In some network structures, the network device may include a centralized unit (CU) node and a distributed unit (DU) node, and the centralized unit and the distributed unit may also be geographically separated.

[0295] Network devices and terminal devices can each use one or more antennas for Multiple Input Multiple Output (MIMO) transmission. MIMO transmission can be either Single User MIMO (SU-MIMO) or Multi User MIMO (MU-MIMO). Depending on the configuration and number of antenna combinations, MIMO transmission can be 2D-MIMO, 3D-MIMO, FD-MIMO, or Massive-MIMO. It can also use diversity transmission, precoding, or beamforming.

[0296] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage and optical storage, etc.) that contain computer-usable program code.

[0297] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0298] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the processor-readable memory produce an article of manufacture comprising an instruction device that implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0299] These processor-executable instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0300] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A device authentication method, characterized in that: include: The target access node AP obtains a first timestamp sent by a local service center (LSC) device and a second timestamp sent by the terminal, and sends the first timestamp to the terminal. The second timestamp is sent by the LSC device to the terminal. The first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event. The first timestamp sent by the target AP to the terminal is used by the terminal to determine that the target AP is the access AP of the terminal. When the first timestamp is consistent with the second timestamp, the target AP determines that the terminal is an access terminal of the target AP.

2. The method according to claim 1, characterized in that Before the target access node AP obtains the first timestamp sent by the local service center LSC device, the method further includes: The target AP obtains a first AP switching request sent by the LSC device, where the first AP switching request is used to request the terminal to switch from the source AP to the target AP; The target AP sends verification information to the LSC device according to the first AP switching request; The first timestamp is sent to the target AP after the LSC determines that the target AP is a legitimate AP based on the verification information.

3. The method according to claim 2, characterized in that The verification information includes identification information of the target AP and password information corresponding to the identification information; Before the target AP obtains the first AP switching request sent by the LSC device, the method further includes: Sending the identification information and public key certificate to the LSC device; Acquire cryptographic information corresponding to the identification information and sent by the LSC, wherein the cryptographic information is encrypted using the public key certificate.

4. A device authentication method, characterized in that: include: The terminal obtains a second timestamp sent by a local service center (LSC) device and a first timestamp sent by a target access point (AP), and sends the second timestamp to the target AP, where the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event; wherein the second timestamp sent by the terminal to the target AP is used by the target AP to determine that the terminal is an access terminal of the target AP; When the first timestamp and the second timestamp are consistent, the terminal determines that the target AP is the access AP of the terminal.

5. A device authentication method, characterized in that: include: The local service center LSC device receives the second access node AP switching request sent by the source AP, where the second AP switching request is used to request the terminal to perform AP switching; The LSC device determines a target AP according to the second AP switching request, where the target AP is the AP to which the terminal is connected after performing the AP switching; The LSC device sends a first timestamp to the target AP and sends a second timestamp to the terminal, wherein the first timestamp sent by the LSC device to the target AP is used by the target AP to determine that the terminal is an access terminal of the target AP, and the second timestamp sent by the LSC device to the terminal is used by the terminal to determine that the target AP is an access AP of the terminal.

6. The method according to claim 5, characterized in that The determining of the target AP includes: Determining, according to the AP switching list, a switching AP corresponding to the switching time of the terminal as the target AP; The AP switching list stores switching APs corresponding to different switching times.

7. The method according to claim 5, characterized in that The LSC device sending a first timestamp to the target AP includes: Sending a first AP switching request to the target AP, where the first AP switching request is used to request the terminal to switch from the source AP to the target AP; Obtaining verification information sent by the target AP in response to the first AP handover request; When it is determined that the target AP is a legitimate AP according to the verification information, a first timestamp is sent to the target AP.

8. The method according to claim 7, characterized in that The verification information includes identification information of the target AP and password information corresponding to the identification information; The method further comprises: Obtaining a hash value corresponding to the password information based on the password information and the random number; If the hash value is consistent with the hash value corresponding to the identification information stored in the database, the target AP is determined to be a legitimate AP.

9. The method according to claim 8, characterized in that Before sending the first AP switching request to the target AP, the method further includes: Obtaining identification information and a public key certificate of the target AP sent by the target AP; After verifying the identification information using the public key certificate, generating password information corresponding to the identification information; The password information is sent to the target AP, and a hash value corresponding to the identification information is generated based on the password information and a random number and saved.

10. A device authentication device, applied to a target AP, characterized in that: Including memory, transceiver, processor; A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations: Obtaining, by a transceiver, a first timestamp sent by a local service center (LSC) device and a second timestamp sent by a terminal, and sending the first timestamp to the terminal, wherein the second timestamp is sent by the LSC device to the terminal, and the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event; wherein the first timestamp sent by the target AP to the terminal is used by the terminal to determine that the target AP is the access AP of the terminal; When the first timestamp is consistent with the second timestamp, the target AP determines that the terminal is an access terminal of the target AP.

11. The device according to claim 10, characterized in that When the processor executes the program, the following steps are further implemented: Acquire, through a transceiver, a first AP switching request sent by an LSC device, where the first AP switching request is used to request the terminal to switch from a source AP to a target AP; Sending verification information to the LSC device through the transceiver according to the first AP switching request; The first timestamp is sent to the target AP after the LSC determines that the target AP is a legitimate AP based on the verification information.

12. The device according to claim 11, characterized in that The verification information includes identification information of the target AP and password information corresponding to the identification information; When the processor executes the program, the following steps are further implemented: Sending the identification information and public key certificate to the LSC device via a transceiver; The cryptographic information corresponding to the identification information and sent by the LSC is acquired through a transceiver, wherein the cryptographic information is encrypted using the public key certificate.

13. A device authentication device, applied to a terminal, characterized in that: Including memory, transceiver, processor; A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations: Obtaining, by a transceiver, a second timestamp sent by a local service center (LSC) device and a first timestamp sent by a target access node (AP), and sending the second timestamp to the target AP, where the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP handover event; wherein the second timestamp sent by the terminal to the target AP is used by the target AP to determine that the terminal is an access terminal of the target AP; When the first timestamp and the second timestamp are consistent, the target AP is determined to be the access AP of the terminal.

14. A device authentication device, applied to a local service center (LSC) device, characterized in that: Including memory, transceiver, processor; a memory for storing computer programs; a transceiver for transmitting and receiving data under the control of the processor; A processor is configured to read the computer program in the memory and perform the following operations: Receiving, through a transceiver, a second access node AP switching request sent by a source AP, where the second AP switching request is used to request the terminal to perform AP switching; Determining a target AP according to the second AP switching request, where the target AP is the AP to which the terminal is connected after performing the AP switching; A first timestamp is sent to the target AP through a transceiver, and a second timestamp is sent to the terminal, wherein the first timestamp sent by the LSC device to the target AP is used by the target AP to determine that the terminal is an access terminal of the target AP, and the second timestamp sent by the LSC device to the terminal is used by the terminal to determine that the target AP is an access AP of the terminal.

15. The device according to claim 14, characterized in that When the processor executes the program, the following steps are further implemented: Determining, according to the AP switching list, a switching AP corresponding to the switching time of the terminal as the target AP; The AP switching list stores switching APs corresponding to different switching times.

16. The device according to claim 14, characterized in that When the processor executes the program, the following steps are further implemented: Sending a first AP switching request to the target AP, where the first AP switching request is used to request the terminal to switch from the source AP to the target AP; Acquire, by a transceiver, verification information sent by the target AP in response to the first AP handover request; When it is determined that the target AP is a legitimate AP according to the verification information, a first timestamp is sent to the target AP via a transceiver.

17. The device according to claim 16, characterized in that The verification information includes identification information of the target AP and password information corresponding to the identification information; When the processor executes the program, the following steps are further implemented: Obtaining a hash value corresponding to the password information based on the password information and the random number; If the hash value is consistent with the hash value corresponding to the identification information stored in the database, the target AP is determined to be a legitimate AP.

18. The device according to claim 17, characterized in that When the processor executes the program, the following steps are further implemented: Obtaining, through a transceiver, identification information and a public key certificate of the target AP sent by the target AP; After verifying the identification information using the public key certificate, generating password information corresponding to the identification information; The password information is sent to the target AP via a transceiver, and a hash value corresponding to the identification information is generated and saved based on the password information and a random number.

19. A device authentication device, applied to a target AP, characterized in that: include: a first acquiring unit, configured to acquire a first timestamp sent by a local service center (LSC) device and a second timestamp sent by a terminal, and send the first timestamp to the terminal, wherein the second timestamp is sent by the LSC device to the terminal, and the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event; wherein the first timestamp sent by the target AP to the terminal is used by the terminal to determine that the target AP is the access AP of the terminal; The first determining unit is configured to determine, when the first timestamp is consistent with the second timestamp, that the terminal is an access terminal of the target AP.

20. A device authentication device, applied to a terminal, characterized in that: include: a second acquiring unit, configured to acquire a second timestamp sent by a local service center (LSC) device and a first timestamp sent by a target access node (AP), and send the second timestamp to the target AP, where the first timestamp and the second timestamp are timestamps sent by the LSC device based on an AP switching event; wherein the second timestamp sent by the terminal to the target AP is used by the target AP to determine that the terminal is an access terminal of the target AP; A second determining unit is configured to determine, when the first timestamp and the second timestamp are consistent, that the target AP is the access AP of the terminal.

21. A device authentication device, applied to a local service center (LSC) device, characterized in that: include: The first receiving unit is configured to receive a second access node AP switching request sent by a source AP, where the second AP switching request is used to request the terminal to perform AP switching; a third determining unit, configured to determine a target AP according to the second AP switching request, where the target AP is the AP to which the terminal is connected after performing AP switching; The first transceiver unit is used to send a first timestamp to the target AP and send a second timestamp to the terminal, wherein the first timestamp sent by the LSC device to the target AP is used by the target AP to determine that the terminal is an access terminal of the target AP, and the second timestamp sent by the LSC device to the terminal is used by the terminal to determine that the target AP is an access AP of the terminal.

22. A processor-readable storage medium, characterized in that: The processor-readable storage medium stores program instructions, and the program instructions are used to cause the processor to execute the steps of the device authentication method according to any one of claims 1 to 3, or execute the steps of the device authentication method according to claim 4, or execute the steps of the device authentication method according to any one of claims 5 to 9.

Citation Information

Patent Citations

  • Handover control method, mobile communication system, and mobile communication terminal

    CN102415153A

  • Mobility management method and device

    CN106937342A

  • Method and device for joining access node group

    US20190334893A1

  • Method for secure handover

    US6370380B1