A decentralized trusted access method for cellular base stations

Through the decentralized secure access mechanism of blockchain technology, the single point of failure risk of pseudo-base station attacks and centralized encryption solutions in 5G mobile networks is solved, and the secure broadcast of cellular base station system information is realized and the reliability verification of users is improved, and the system security performance is improved.

CN115038084BActive Publication Date: 2025-08-19BEIJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210631134.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-06
Publication Date
2025-08-19
Estimated Expiration
2042-06-06

AI Technical Summary

Technical Problem

In existing 5G mobile networks, pseudo-base station attack threats and single-point failure risks based on centralized encryption solutions have not been effectively solved, especially in the non-confidential broadcasting stage of cellular base station system information, user terminals face the problems of information tampering and insufficient security.

Method used

The decentralized secure access mechanism adopts blockchain technology, registers and uploads the main information block to the blockchain network through a cellular base station, and uses the network-wide consensus mechanism to generate block identification information, broadcasts to cellular users for verification, ensuring the authenticity and tamper-proofness of system information.

Benefits of technology

It improves the system information security of cellular users in the initial access stage, reduces the threat of pseudo-base station attacks, and realizes reliability verification and tamper-proof protection of system information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115038084B_ABST
    Figure CN115038084B_ABST
Patent Text Reader

Abstract

The present application belongs to the field of communications, and specifically relates to a decentralized trusted access method for cellular base stations; the method includes uploading registration information to a blockchain network to add the cellular base station as a member to the blockchain network; uploading a master information block to the blockchain network, and receiving block identification information from the blockchain network; broadcasting the master information block and the block identification information to cellular users within the coverage area; receiving an access request from a cellular user, and responding to the access request, uplink synchronizing with the cellular user that issued the access request based on a random access process; the present application designs a system information security protection scheme based on the decentralized anti-tampering characteristics of the blockchain network, overcomes the security risks of existing non-confidential broadcasts and the single point failure risks of centralized encryption schemes, reduces the threat of tampering, improves system security performance, and enables cellular users to verify the reliability of the system during the initial access phase.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communications, and specifically to a decentralized trusted access method for cellular base stations. Background Art

[0002] Among the numerous attacks on 5G mobile network communications, fake base station attacks are a typical method. Attackers often disguise themselves as legitimate carriers' base stations and, according to relevant protocols, send signaling to nearby target mobile devices or force users to connect to the base station, thereby achieving online fraud and obtaining private information.

[0003] Furthermore, while methods such as bidirectional network authentication and 5G encryption of the Subscription Permanent Identifier (SUPI) can mitigate the impact of fake base stations to a certain extent, before completing bidirectional authentication and secure mode encryption, information transmitted between users and cellular base stations is directly exposed to the wireless environment. This is particularly problematic due to the unencrypted broadcast of system information, essential for users to access base stations.

[0004] In TR 33.809, 3GPP proposed several solutions based on encryption algorithms to address the existing problem of unencrypted broadcast of system information, including digital signature-based, certificate-based, and identity-based solutions.

[0005] The above three solutions have the following problems:

[0006] 1. For encryption schemes based on digital signatures, facing the rise of multi-party governance and decentralized wireless networks (such as the Internet of Things, edge computing, and the Industrial Internet), key management lacks unified trust transfer, that is, there is a problem of mutual distrust in key management between different suppliers.

[0007] 2. For certificate-based encryption solutions, since the root certificate is written into the user terminal during the production phase, operators are unable to update and recall old root certificates in a timely manner.

[0008] 3. For identity-based encryption schemes, the user terminal must first trust an authorized third party, whose role is to generate and manage user keys. When the third party fails, the system information encryption is at risk of a single point of failure.

[0009] As a revolutionary data recording system, blockchain has shown tremendous potential in the financial and industrial sectors, inspiring us to explore its applicability in the field of system information security. Leveraging its decentralized, tamper-resistant, and scalable nature, blockchain offers a novel distributed security approach for system information. Blockchain-based system information protection solutions do not require the assistance of any authorized third party, yet still incorporate the capabilities and advantages of cryptography, effectively addressing the challenges faced by centralized cryptography-based management solutions. However, while numerous researchers have explored the application of blockchain networks in wireless access networks, most focus on resource allocation and multi-party collaboration. There remains a lack of mechanisms for matching blockchain with wireless access processes for system information security, as well as analytical solutions for improving the energy efficiency of blockchain-based system information security. Summary of the Invention

[0010] In response to the threat of fake base station attacks posed by the unconfidential broadcast of system information in the current 5G R16 version, as well as the single point failure risks and performance limitations of core network-assisted verification in security protection models based on centralized encryption, this application aims to leverage the distributed, decentralized, network-wide consensus, and tamper-proof characteristics of blockchain technology to design a decentralized secure access mechanism based on blockchain, providing a decentralized trusted access method for cellular base stations to achieve the following objectives:

[0011] 1. In an environment lacking decentralized trust, the entire network consensus is used to ensure that the system information broadcast by the base station is authentic and valid, and cannot be tampered with, thereby improving the security of system information;

[0012] 2. Enable cellular users to resist attacks such as tampering and replaying of system information by fake base stations;

[0013] 3. Allows cellular users to verify the authenticity, reliability, and freshness of system information during the initial access phase, eliminating reliance on core network-assisted verification.

[0014] Based on the above technical objectives, in a first aspect of the present application, the present application provides a decentralized trusted access method for a cellular base station, which is applied to a cellular base station, and the method includes:

[0015] Uploading registration information to a blockchain network, the registration information including a public key pair and a certificate of the cellular base station; and adding the cellular base station as a member to the blockchain network based on the public key pair and the certificate;

[0016] Uploading a master information block to the blockchain network, the master information block being used to indicate basic information required for cellular users within the coverage area of the cellular base station to access the cellular base station;

[0017] Receiving block identification information from the blockchain network, the block identification information being information generated by executing a consensus algorithm on a block and, after conditions of the consensus algorithm are met, storing the block on the blockchain; the block being a data block packaged and formed after the blockchain network authenticates the master information block;

[0018] broadcasting the master information block and the block identification information to cellular users within the coverage area;

[0019] receiving an access request from a cellular user, wherein the access request includes a cellular base station to be accessed determined by the cellular user based on the master information block and the block identification information;

[0020] In response to the access request, uplink synchronization is performed with the cellular user that issued the access request based on a random access process.

[0021] In a second aspect of the present application, the present application further provides a decentralized trusted access method for cellular base stations, which is applied to a blockchain network. The method includes:

[0022] receiving registration information uploaded by a cellular base station, the registration information including a public key pair and a certificate of the cellular base station;

[0023] In response to the public key pair and the certificate, performing a registration process for the cellular base station to add the cellular base station as a member to the blockchain network;

[0024] receiving a master information block uploaded by the cellular base station, where the master information block is used to indicate basic information required for a cellular user within a coverage area of the cellular base station to access the cellular base station;

[0025] In response to the master information block, after authenticating the master information block, the master information block is packaged into a block; a consensus algorithm is executed on the block, and after the consensus algorithm conditions are met, the block is stored on the chain and block identification information is generated;

[0026] The block identification information is returned to the cellular base station so that the cellular base station can broadcast the master information block and the block identification information to cellular users within the coverage area, so that the cellular users within the coverage area can determine the cellular base station to be accessed based on the master information block and the block identification information, and achieve uplink synchronization with the cellular base station to be accessed based on a random access process.

[0027] In a third aspect of the present application, the present application further provides a decentralized trusted access method for a cellular base station, which is applied to a cellular user, and the method includes:

[0028] Obtaining a master information block and block identification information broadcast by a cellular base station, and verifying the block identification information; the master information block is used to indicate basic information required for cellular users within the coverage area of the cellular base station to access the cellular base station; the block identification information is generated by executing a consensus algorithm on the block and storing the block on the chain after the consensus algorithm conditions are met; the block is a data block packaged by the blockchain network after authenticating the master information block;

[0029] If it is verified that the block identification information exists, verifying the block identification information; if the block identification information passes the verification, continuing to verify the block corresponding to the block identification information; if the block verification passes, determining that the cellular base station is the cellular base station to be accessed;

[0030] Uplink synchronization with the cellular base station to be accessed is carried out based on a random access process.

[0031] In a fourth aspect of the present application, the present application further provides a decentralized trusted access method for a cellular base station, which is applied to the first aspect, the second aspect, or / and the third aspect of the present application, and the method further includes:

[0032] The probability that a cellular user determines that a pseudo base station is the cellular base station to be accessed is defined as the access failure probability;

[0033] Calculate the access failure probability of cellular users;

[0034] Comparing the calculated access failure probability with the pre-calculated access failure probability to calculate the security gain of the blockchain network;

[0035] The block threshold of the blockchain network is deployed according to the security gain, and the verification threshold of the block depth in the blockchain network is updated.

[0036] Beneficial effects of this application:

[0037] This application designs a system information security protection scheme based on the decentralized and tamper-proof characteristics of the blockchain network. The blockchain network verifies and stores the main information blocks broadcast by legitimate base stations, overcoming the security risks of existing non-confidential broadcasts and the single point failure risks of centralized encryption schemes, reducing the threat of tampering, improving system security performance, and enabling cellular users to verify the reliability of the system during the initial access phase. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 This is a schematic diagram of the blockchain structure;

[0039] Figure 2 Schematic diagram of a decentralized trusted access architecture for cellular base stations in an embodiment of the present application;

[0040] Figure 3 This is a flow chart of a decentralized trusted access method for a cellular base station in one embodiment of the present application;

[0041] Figure 4 This is a flow chart of a decentralized trusted access method for a cellular base station in another embodiment of the present application;

[0042] Figure 5 This is a flow chart of a decentralized trusted access method for a cellular base station in another embodiment of the present application;

[0043] Figure 6 is a verification flow chart for determining a cellular base station to be accessed in an embodiment of the present application;

[0044] Figure 7 is a verification flow chart for determining a cellular base station to be accessed in an embodiment of the present application;

[0045] Figure 8 This is a flow chart of a decentralized trusted access method for cellular base stations in a preferred embodiment of the present application;

[0046] Figure 9 This is a graph showing the relationship between system security gain and block confirmation threshold under different attack station computing power ratios;

[0047] Figure 10 is different f The relationship between the system security gain and the attacker's computing power ratio in this case;

[0048] Figure 11 is the system security gain as ρ f and ρ u Change relationship diagram. DETAILED DESCRIPTION

[0049] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0050] To facilitate understanding of the method provided in this application, the following terms are explained:

[0051] System Information

[0052] According to the standardized technical specification TS 38.331 released by the Third Generation Partnership Project (3GPP), system information is broadcast information periodically sent by cellular base stations to users. System information is key information for mobile devices to connect to base stations. It essentially provides all the necessary detailed information for accessing the network, such as the system frame number, system bandwidth, cell selection and reselection thresholds, etc. In 5G, users will read system information when turning on the phone to camp on a cell and perform cell selection and reselection in RRC_IDLE mode.

[0053] System information consists of a Master Information Block (MIB) and a series of System Information Blocks (SIBs), which can be divided into minimum system information and other system information. Minimum system information includes the Master Information Block and SIB1, which are usually broadcast regularly by 5G base station nodes. Other system information includes system information blocks SIB2 to SIB9, which are sent or broadcast regularly according to user terminal needs.

[0054] System information broadcast is the first step for user terminals to obtain basic service information. Through the system information broadcast process, user terminals can obtain primary access stratum information and non-access stratum information. This primary and non-access stratum information determines how user terminals reside, reselect, and initiate calls on the cellular network.

[0055] The main access layer information includes common channel information, cell selection / reselection information, domain information, etc., while the non-access layer information includes operator information. The master information block in the minimum system information contains the most basic information for users to access the cell and guidance information for SIB1, which plays an important role in the user's initial access process. Therefore, this application example designs a trusted access method based on blockchain technology to protect the transmission of the master information block in the minimum system information.

[0056] Blockchain

[0057] As a distributed ledger, blockchain has attracted widespread attention in many fields such as industrial manufacturing, information management, and digital asset trading due to its outstanding performance in cryptocurrency. In addition, in recent years, many researchers have been actively exploring the potential of blockchain applications in radio access networks (RAN). In essence, Figure 1As shown, a blockchain consists of a growing set of blocks, authorized by a consensus mechanism and linked together into a chain using cryptographic algorithms. Each block securely records a certain number of transactions. Each block is hashed with metadata containing information about the hash of the previous block. A change to one block causes changes to all subsequent blocks in the chain, making it possible to protect the data contained in the block from being modified.

[0058] Since the essence of blockchain is a distributed system, the security and efficiency of blockchain are maintained through consensus algorithms, which solves the coordination problem of how to reach consensus among multiple nodes. Depending on the type of blockchain, the requirements for using consensus mechanisms are different, and consensus mechanisms have also evolved differently. According to access and management permissions, blockchains can be divided into public chains, private chains, and consortium chains. The PoW (Proof-of-Work) consensus algorithm in the blockchain stipulates that only nodes that have solved the hash puzzle can obtain the right to record transactions in the new block, ensuring that the blockchain cannot be tampered with, and is traceable and secure. Blocks recognized by the consensus mechanism can be added to the blockchain as new blocks, where the blockchain selects the longest chain as the valid chain based on the "longest chain" principle. This application example introduces trusted and secure access to the blockchain based on this principle.

[0059] Merkle Tree

[0060] Blockchains use Merkle trees for data storage. A Merkle tree is a tree structure in which leaf nodes store transaction data, while non-leaf nodes store the hash values of their children. This tree is then computed layer by layer to generate new hash nodes, ultimately creating a Merkle root that is stored in the block header. Therefore, any changes to the underlying data will cause the Merkle root to change. This allows the integrity of the entire block to be determined by comparing the Merkle root in the block header, allowing for rapid location based on the hash path.

[0061] Figure 2 Schematic diagram of a decentralized trusted access architecture for cellular base stations in an embodiment of the present application. Figure 2As shown, the present application mainly includes two types of entities, including cellular base stations and cellular users. The cellular base stations and the cellular users are connected through a wireless network, and the cellular base stations interact with the blockchain network as blockchain members; in the process of cellular users accessing the cellular base stations, the cellular base stations will upload the master information block to the blockchain network, and the blockchain network will process the master information block as transaction information, generate a new block, and after consensus, this new block will be stored on the chain and block identification information will be generated, and the block identification information corresponds to the block; the cellular base station will broadcast the master information block and block identification information to all cellular users within its coverage area; the cellular user will verify the obtained master information block and block identification information. After the verification is passed, the cellular user can obtain specific system information from the block corresponding to the block identification information and make an initial connection with the cellular base station.

[0062] Figure 3 This is a flow chart of a decentralized trusted access method for a cellular base station in the first embodiment of the present application. Figure 3 As shown, the method is applied to a cellular base station, comprising:

[0063] 101. Upload registration information to a blockchain network, the registration information including a public key pair and a certificate of the cellular base station; and add the cellular base station as a member to the blockchain network based on the public key pair and the certificate.

[0064] In an embodiment of the present application, the cellular base station will initiate a registration request to the blockchain network, requesting that the cellular base station be added to the blockchain network as a member node; by uploading registration information to the blockchain network, the blockchain network will complete the registration of the cellular base station based on the registration information; the registration information includes the public key pair and certificate of the cellular base station, and the public key pair and certificate can be provided in advance by the equipment manufacturer, and the public key certificate signed by the equipment manufacturer is pre-installed.

[0065] For example, a cellular base station uploads its public key pair and certificate to a blockchain network for registration. The blockchain network verifies the base station's registration request based on the root certificate. The certificate authentication mechanism can utilize a certification authority certificate mechanism based on 3GPP 33.310 (R17) to address the issue of trust in the identity of blockchain nodes. The base station initiates a registration request to the blockchain network. The blockchain network verifies the base station's identity based on the vendor's root certificate and the vendor's signature certificate. If verification succeeds, the blockchain network issues a registration certificate to the base station and returns a certificate response. The base station then replaces its pre-registration certificate with the registration certificate, completing base station registration.

[0066] It can be understood that the cellular base station joins the blockchain network as a member node, and the member node may include a client node and a computing node; that is, the cellular base station can serve as a client node or a computing node of the blockchain network. When the cellular base station serves as a computing node, it jointly maintains the blockchain network; that is, it can complete traditional computing functions, including but not limited to block packaging and verification; when the cellular base station serves as a client node, these client nodes send the main information block to the blockchain network in the form of a transaction; in the blockchain network, at the same time, some cellular base stations serve as computing nodes, and other cellular base stations serve as client nodes, jointly maintaining the operation of the entire blockchain network to achieve the purpose of cellular user access.

[0067] 102. Upload a master information block to the blockchain network, where the master information block indicates basic information required for cellular users within the coverage area of the cellular base station to access the cellular base station;

[0068] In an embodiment of the present application, a cellular base station is eligible to verify the master information block uploaded to the blockchain network as a blockchain member only after registering with the blockchain network. The master information block MIB includes decoding information of SIB1, and SIB1 contains scheduling information of other system information (OSI, Other system information). Therefore, the master information block can be used to indicate the basic information required for cellular users within the coverage area of the cellular base station to access the cellular base station.

[0069] In an embodiment of the present application, in order to reduce the overhead of requesting authentication, the cellular base station is not allowed to send requests repeatedly within a certain period of time. The request transaction information may include the following parts {MIB, Cell_ID, Dowlink_Frequency, Time_Counter}, where the transaction information can be changed according to the actual scenario and system security evolution requirements.

[0070] 103. Receive block identification information from the blockchain network, where the block identification information is generated by executing a consensus algorithm on the block and storing the block on the blockchain after the consensus algorithm conditions are met; the block is a data block packaged by the blockchain network after authenticating the master information block;

[0071] In an embodiment of the present application, the cellular base station will receive block identification information corresponding to the main information block uploaded by the cellular base station. The block identification information corresponds one-to-one to the block in the blockchain network, that is, the block identification information can identify the corresponding block in the blockchain network. For example, assuming that the block identification information is 000000000019d6689c, then the block identification information 000000000019d6689c can identify a unique block in the blockchain network; therefore, the cellular base station only needs to obtain the corresponding block according to the block identification information, thereby ensuring the information security of each cellular base station and its corresponding cellular users.

[0072] In this embodiment of the present application, the base station publishes transaction information containing system information to the blockchain network for consensus verification. When the blockchain network reaches a consensus, a new block containing the system information block will be added to the blockchain network. The consensus mechanism is optional, and this embodiment uses PoW as an example for illustration:

[0073] The base station publishes transaction information containing system information to the blockchain transaction pool, and the consensus node verifies its validity and integrity.

[0074] Afterwards, the consensus node will select transactions to be packaged into blocks according to the order of publication, and use the Merkle tree to summarize all transactions and obtain the Merkle root.

[0075] Then continue to modify the random number and calculate the hash value of the block header information until a random value that meets the conditions is found.

[0076] When a node successfully finds a solution, it enters the solution into the random number field of the block header information. The block is then added to the local ledger and broadcast to peers. Once other blockchain nodes verify that it is a valid block, they will also execute the operation.

[0077] Afterwards, the base station broadcasts the block header information of the new block and the Merkle verification path containing the main information block transactions to form the block identification information.

[0078] Due to the limitation of physical channel coding, the new block certificate of the system can be placed in new_SIB and broadcast together with SIB1. In addition, new_SIB guide information is also stored in SIB1.

[0079] 104. Broadcast the master information block and the block identification information to cellular users within the coverage area;

[0080] In an embodiment of the present application, a cellular base station broadcasts the master information block and block identification information received from the blockchain network to cellular users within its coverage area. The broadcasting can be performed at a certain period. The purpose of the broadcasting is to enable cellular users to obtain basic business information. The master information block contained in the block corresponding to the block identification information is based on the tamper-proof nature of the blockchain, which can prevent malicious modification, thereby improving the system security performance and enabling cellular users to verify the reliability of the system during the initial access phase.

[0081] 105. Receive an access request from a cellular user, where the access request includes a cellular base station to be accessed determined by the cellular user based on the master information block and the block identification information;

[0082] In an embodiment of the present application, the cellular user will send an access request to the cellular base station to be accessed that it has determined. Since the access request is specific, the access request determines the object initiated by the cellular user. Therefore, once the cellular base station receives the access request, it indicates that the cellular base station that receives the access request is the cellular base station to be accessed that the cellular user has determined.

[0083] The cellular base station to be accessed determined by the cellular user based on the master information block and the block identification information specifically includes:

[0084] The cellular user verifies the block identification information received and broadcasted from the cellular base station. If the block identification information exists, the user continues to verify the block identification information received and broadcasted from the cellular base station. If the block identification information passes the verification, the user continues to verify the block corresponding to the block identification information. If the following conditions are simultaneously met, the user determines that the cellular base station broadcasting the block is the cellular base station to be accessed.

[0085] The conditions are as follows:

[0086] The timestamp in the block identification information is legal or the timestamp of the block is legal;

[0087] The Merkle tree root calculated using the block identification information is consistent with the Merkle tree root stored in the blockchain network;

[0088] The block depth of the block corresponding to the block identification information is not less than a verification threshold.

[0089] Among them, among the above three conditions, only one of the timestamp of the block identification information or the timestamp of the block is legal needs to be met, and the Merkle root calculated based on the block identification information must be consistent with the Merkle root stored in the blockchain network, and the block depth of the block must be no less than the verification threshold. Once these conditions are met, it means that the block identification information is verified and the block verification is passed. Then the cellular base station corresponding to the verified block / and block identification information is the cellular base station to be accessed.

[0090] Based on the above judgment factors, the validity, existence and security of the main information block corresponding to the block identification information can be guaranteed.

[0091] 106. In response to the access request, perform uplink synchronization with the cellular user that issued the access request based on a random access procedure.

[0092] In an embodiment of the present application, after the cellular user obtains the corresponding physical cell identifier, master information block and corresponding block identifier information, it detects the physical downlink shared channel according to the information in the master information block MIB to obtain SIB1, and further obtains other system information and random access information required by the terminal.

[0093] Therefore, in this application, the cellular base station that receives the access request sent by the cellular user is also the cellular base station to be accessed by the cellular user. In response to the access request, the cellular base station performs uplink synchronization on the cellular user that issued the access request based on the random access process. The trusted access process in this application includes:

[0094] Cellular users obtain the cell identity, master information block and verify the blockchain identity information.

[0095] The cellular user verifies the master information block based on the blockchain identification information.

[0096] Cellular users perform downlink synchronization.

[0097] The cellular user obtains the time-frequency domain position of SIB1.

[0098] Cellular users obtain the required random access information from SIB1.

[0099] The random access procedure is performed by cellular users over the uplink.

[0100] The cellular user performs a subsequent initial access process with the cellular base station.

[0101] In a preferred embodiment of the present application, a cellular user that issues an access request can obtain random access process information (such as uplink frequency and physical random channel configuration) through SIB1, and perform uplink synchronization through the random access process. Then, the initial registration procedure is started. Among them, for the current R16 version of the protocol, in connection with the independent networking scenario targeted by this embodiment, random access can adopt a two-step random access scheme. The first step includes uplink MSGA transmission, which includes preamble and payload, and it is necessary to send MsgApreamble first, and then send MsgApayload. The second step of the two-step random access is the downlink MSGB transmission (sent by the base station to the user), which includes MsgB PDCCH and MsgB PDSCH. If MsgB is not received within the MsgB Response Window, MsgA is retransmitted.

[0102] Figure 4 This is a flow chart of a decentralized trusted access method for a cellular base station in another embodiment of the present application. Figure 4 As shown, the method is applied to a blockchain network, comprising:

[0103] 201. Receive registration information uploaded by a cellular base station, where the registration information includes a public key pair and a certificate of the cellular base station;

[0104] In an embodiment of the present application, the cellular base station will initiate a registration request to the blockchain network, requesting that the cellular base station be added to the blockchain network as a member node; the cellular base station uploads registration information to the blockchain network, and after the blockchain network receives the registration information, it will complete the registration of the cellular base station based on the registration information; the registration information includes the public key pair and certificate of the cellular base station, and the public key pair and certificate can be provided in advance by the equipment manufacturer, and the public key certificate signed by the equipment manufacturer is pre-installed.

[0105] 202. In response to the public key pair and the certificate, perform a registration process for the cellular base station to add the cellular base station as a member to the blockchain network;

[0106] In an embodiment of the present application, the blockchain network responds to the registration information uploaded from the cellular base station and registers the cellular base station in the blockchain network according to the registration information; the registration information of the cellular base station can be verified according to the root certificate, and if the verification is successful, the cellular base station is added to the blockchain network as a member; otherwise, the cellular base station is denied admission to the blockchain network as a member.

[0107] The base station is pre-provisioned with a public key pair by the vendor and pre-installed with a public key certificate signed by the vendor. The base station uploads its public key pair and certificate to the blockchain network for registration. The blockchain network verifies the base station's registration request based on the root certificate. The certificate authentication mechanism can adopt a certification authority certificate mechanism based on 3GPP 33.310 (R17 version) to address the issue of trust in the principal identity of blockchain nodes. The base station initiates a registration request to the blockchain network, which verifies the base station's identity based on the vendor's root certificate and the vendor's signed certificate. If verification is successful, the blockchain network issues a registration certificate to the base station and returns a certificate response. The base station certificate is replaced with the registration certificate, completing the base station registration.

[0108] 203. Receive a master information block uploaded by the cellular base station, where the master information block is used to indicate basic information required for cellular users within the coverage area of the cellular base station to access the cellular base station;

[0109] In an embodiment of the present application, the blockchain network can receive the master information block uploaded from the cellular base station periodically or in real time. The master information block MIB includes decoding information of SIB1, and SIB1 contains scheduling information of other system information. Therefore, the master information block can be used to indicate the basic information required for cellular users within the coverage area of the cellular base station to access the cellular base station.

[0110] 204. In response to the master information block, authenticate the master information block and package it into a block; execute a consensus algorithm on the block, and after the consensus algorithm conditions are met, store the block on the chain and generate block identification information;

[0111] In an embodiment of the present application, the blockchain network responds to the master information block received from the cellular base station and authenticates the master information block. If the authentication is successful, the master information block is packaged into a block; otherwise, it is discarded. A consensus algorithm, such as PoW or DAG, is executed on the block containing the authenticated master information block. When the nodes in the blockchain network reach a consensus, the block is stored on the chain and block identification information is generated for the block.

[0112] It can be understood that the consensus algorithm executed on the blocks of the main information block in the embodiment of the present application can be any consensus algorithm existing in the prior art, as long as it can achieve consensus on the blocks. This application does not make any specific restrictions on this.

[0113] 205. Send the block identification information to the cellular base station, so that the cellular base station broadcasts the master information block and the block identification information to cellular users within the coverage area, so that the cellular users within the coverage area determine the cellular base station to be accessed based on the master information block and the block identification information, and achieve uplink synchronization with the cellular base station to be accessed based on a random access process.

[0114] In an embodiment of the present application, the blockchain network will send corresponding block identification information to the cellular base station, and the cellular base station will also broadcast the master information block and the block identification information to the cellular users within its coverage area; the cellular user will calculate the cellular base station to be accessed based on the received master information block and the block identification information. After determining the cellular base station to be accessed, the cellular user will send an access request to the cellular base station to be accessed. The cellular base station to be accessed will respond to the access request and synchronize with the uplink of the cellular base station to be accessed based on a random access process.

[0115] Figure 5 FIG. 1 is a flow chart of a decentralized trusted access method for a cellular base station in another embodiment of the present application; FIG. Figure 5 As shown, the method is applied to a cellular user, comprising:

[0116] 301. Obtain a master information block and block identification information broadcast by a cellular base station, and verify the block identification information;

[0117] In an embodiment of the present application, the master information block is used to indicate the basic information required for a cellular user within the coverage area of the cellular base station to access the cellular base station; the block identification information broadcast by the cellular base station is sent by the cellular base station with which the blockchain network is registered, and the block identification information is generated by executing a consensus algorithm on the block and storing the block on the chain after the consensus algorithm conditions are met; the block is a data block packaged by the blockchain network after authenticating the master information block;

[0118] 302. If the block identification information is verified successfully, continue to verify the block. If the block is verified successfully, determine that the cellular base station is the cellular base station to be accessed.

[0119] In the embodiment of the present application, the cellular user first verifies the block identification information. If the block identification information exists, the user continues to verify the block identification information. If the verification succeeds, the user continues to verify the block. If the following conditions are simultaneously met, the user determines that the cellular base station included in the block corresponding to the broadcasted block identification information is the cellular base station to be accessed;

[0120] The block identification information is verified. If the block identification information passes the verification, the block corresponding to the block identification information is further verified. The verification conditions used include:

[0121] Verifying whether a first Merkle tree root calculated using the block identification information is consistent with a second Merkle tree root in the block stored in the blockchain network;

[0122] Verifying whether the timestamp of the block identification information is legal, or whether the timestamp of the block corresponding to the block identification information is legal;

[0123] Verify whether the block depth of the block corresponding to the block identification information is not less than a verification threshold.

[0124] In an embodiment of the present application, verifying whether the first Merkle root calculated using the block identification information is consistent with the second Merkle root in the block stored in the blockchain network includes:

[0125] Obtaining the Merkle path and block header information from the block identification information;

[0126] Calculating a hash value of the main information block, and calculating a first Merkle tree root according to the hash value of the main information block and the Merkle path;

[0127] Synchronize the main chain block header information, and search the synchronized main chain block header information for the block header information corresponding to the block identification information;

[0128] Get the second Merkle tree root through the saved main chain block header information;

[0129] The first Merkle tree root is compared with the second Merkle tree root. If the comparison is inconsistent, the cellular base station that broadcasts the block identification information is marked as a malicious cellular base station.

[0130] It can be understood that in the embodiment of the present application, it is only necessary to determine whether the timestamp of the block identification information or the timestamp of the block is legal, and there is no need to determine whether the timestamp of the block identification information and the timestamp of the block are legal at the same time; when only determining whether the timestamp of the block identification information is legal, it is necessary to verify whether the timestamp of the block identification information is legal before the block depth of the block corresponding to the block identification information is not less than the verification threshold, that is, the order of determining the legality of the timestamp of the block identification information and the determination of the Merkle tree root of the block identification information can be exchanged. When both are verified at the same time, it means that the verification of the block identification information is passed. At this time, the block identification information is verified again. When only the timestamp of a block is determined to be legitimate, it is necessary to verify the legitimacy of the timestamp of the block after verifying whether the first Merkle root calculated using the block identification information is consistent with the second Merkle root of the block stored in the blockchain network. That is, the order of determining the legitimacy of the timestamp of the block and the block depth of the block can be swapped. When the first Merkle root calculated using the block identification information is consistent with the second Merkle root of the block stored in the blockchain network, it indicates that the block identification information has been verified. At this time, the block corresponding to the block identification information is verified. This verification method can be flexibly applied to different scenarios. In particular, if either the block identification information or the timestamp of the block is invalid, it indicates that the cellular base station broadcasting the block identification information is invalid.

[0131] In the embodiment of the present application, verifying whether the block depth of the block corresponding to the block identification information is not less than a verification threshold includes:

[0132] If the block depth of the block is less than the verification threshold, marking the cellular base station broadcasting the block identification information as a malicious invalid base station;

[0133] If the block depth of the block is not less than the verification threshold, the cellular base station broadcasting the block identification information is marked as a cellular base station to be accessed.

[0134] In some embodiments, for the verification process used to verify whether the following conditions are met simultaneously, the embodiments of the present application may adopt the following process:

[0135] Verify whether the timestamp of the block identification information is legal;

[0136] If the timestamp of the block identification information is valid, continue to verify whether the first Merkle tree root calculated based on the block identification information is consistent with the second Merkle tree root in the block stored in the blockchain network;

[0137] If the timestamp of the block identification information is illegal, the block identification information verification fails, it is determined that the cellular base station corresponding to the block identification information that fails the verification is not the cellular base station to be accessed, and the verification ends;

[0138] If the first Merkle tree root and the second Merkle tree root are consistent, the block identification information verification is passed, and further verification is continued to determine whether the block depth of the block corresponding to the verified block identification information is not less than the verification threshold;

[0139] If the first Merkle tree root and the second Merkle tree root are inconsistent, the block identification information verification fails, it is determined that the cellular base station corresponding to the block identification information that fails the verification is not the cellular base station to be accessed, and the verification ends;

[0140] If the block depth of the block is not less than the verification threshold, the block verification is passed, and the cellular base station corresponding to the block that has passed the verification is determined to be the cellular base station to be accessed;

[0141] If the block depth of the block is less than the verification threshold, the block verification fails, it is determined that the cellular base station corresponding to the block that fails the verification is not the cellular base station to be accessed, and the verification ends;

[0142] Among them, in other embodiments, for the verification process used to verify whether the following conditions are met at the same time, the embodiments of the present application may adopt the following process:

[0143] Verifying whether a first Merkle tree root calculated using the block identification information is consistent with a second Merkle tree root in the block stored in the blockchain network;

[0144] If the first Merkle tree root and the second Merkle tree root are consistent, then continue to verify whether the timestamp of the block identification information is legal;

[0145] If the first Merkle tree root and the second Merkle tree root are inconsistent, the block identification information verification fails, it is determined that the cellular base station corresponding to the block identification information that fails the verification is not the cellular base station to be accessed, and the verification ends;

[0146] If the timestamp of the block identification information is legal, the block identification information is verified to be passed, and the block depth of the block corresponding to the verified block identification information is further verified to be not less than the verification threshold;

[0147] If the timestamp of the block identification information is illegal, the block identification information verification fails, it is determined that the cellular base station corresponding to the block identification information that fails the verification is not the cellular base station to be accessed, and the verification ends;

[0148] If the block depth of the block is not less than the verification threshold, the block verification is passed, and the cellular base station corresponding to the block that has passed the verification is determined to be the cellular base station to be accessed;

[0149] If the block depth of the block is less than the verification threshold, the block verification fails, and it is determined that the cellular base station corresponding to the block that fails the verification is not the cellular base station to be accessed, and the verification ends.

[0150] It can be understood that, in the embodiment of the present application, the core of verifying whether the following conditions are met at the same time is to first determine whether the block identification information can be verified. If the block identification information can be verified, the block corresponding to the verified block identification information will be verified. Since the block identification information and the block are uniquely corresponding, the unique corresponding block can be determined based on the block identification information. If the block uniquely corresponding to the block identification information is also verified, since each cellular base station will only obtain the block identification information corresponding to the main information block of the cellular base station from the blockchain network, one block identification information can only correspond to one cellular base station, indicating that the cellular base station broadcasting the block identification information is the cellular base station to be accessed.

[0151] In the preferred embodiment of this application, Figure 6 As shown, the process of the cellular user verifying the block identification information may include:

[0152] After obtaining the main information block, first determine whether the block identification information exists;

[0153] If the block identification information does not exist, marking the cellular base station broadcasting the block identification information as an unprotected cellular base station;

[0154] If the block identification information exists, continue to verify the block identification information;

[0155] checking a timestamp corresponding to the block identification information; if the timestamp is invalid, marking the cellular base station broadcasting the block identification information as an invalid cellular base station; and if the timestamp is valid, obtaining a Merkle path and block header information from the block identification information;

[0156] Calculating a hash value of the main information block, and calculating a first Merkle tree root according to the hash value of the main information block and the Merkle path;

[0157] Synchronize the main chain block header information and search the synchronized main chain block header information for the block header information corresponding to the block identification information;

[0158] If the calculated first Merkle tree root is inconsistent with the second Merkle tree root in the saved main chain block header information, then mark the cellular base station that broadcasts the block identification information as a malicious cellular base station;

[0159] If the calculated first Merkle tree root is consistent with the saved second Merkle tree root, then continue to verify the block corresponding to the block identification information to determine whether the depth of the block is not less than the verification threshold;

[0160] If the depth of the block is not greater than the verification threshold, marking the cellular base station broadcasting the block identification information as a malicious invalid base station;

[0161] If the depth of the block is not less than the verification threshold, the block of the master information block is deemed available, and the cellular base station broadcasting the block identification information is determined to be the cellular base station to be accessed. At the same time, the physical downlink shared channel can also be detected to obtain SIB1.

[0162] In the preferred embodiment of this application, Figure 7 As shown, the cellular user still verifies the block identification information:

[0163] After obtaining the main information block, first determine whether the block identification information exists; check the main information block and the block identification information to determine whether the block identification information exists;

[0164] If the block identification information does not exist, marking the cellular base station broadcasting the master information block as an unprotected cellular base station;

[0165] If the block identification information exists, obtaining the Merkle path and block header information from the block identification information;

[0166] Calculating a hash value of the main information block, and calculating a first Merkle tree root according to the hash value of the main information block and the Merkle path;

[0167] Synchronize the main chain block header information and search the synchronized main chain block header information for the block header information corresponding to the block identification information;

[0168] If the calculated first Merkle tree root is inconsistent with the second Merkle tree root in the saved main chain block header information, then mark the cellular base station that broadcasts the block identification information as a malicious cellular base station;

[0169] If the calculated first Merkle root is consistent with the second Merkle root in the saved main chain block header information, then continue to verify the timestamp of the block identification information to determine whether the timestamp is legal;

[0170] If the timestamp is illegal, the cellular base station that broadcasts the block identification information is marked as an invalid cellular base station.

[0171] If the timestamp is valid, continue to verify the block corresponding to the block identification information to determine whether the depth of the block is not less than a verification threshold;

[0172] If the depth of the block is less than the verification threshold, marking the cellular base station broadcasting the block identification information as a malicious invalid base station;

[0173] If the depth of the block is not less than the verification threshold, the block is deemed available, and the cellular base station broadcasting the block identification information is determined to be the cellular base station to be accessed.

[0174] It is understandable that after receiving the master information block and block identification information broadcast by the cellular base station, the cellular user can obtain the scheduling information of the main chain block header information from the master information block, and then synchronize the main chain block header information to prepare for the subsequent verification of the block depth information, Merkle tree root and timestamp corresponding to the block identification information; at the same time, the block identification information is parsed to obtain the timestamp, block header information and the Merkle path containing the master information block.

[0175] 303. Perform uplink synchronization with the cellular base station to be accessed based on a random access process.

[0176] In an embodiment of the present application, the cellular base station that receives the access request from the cellular user is also the cellular base station to be accessed by the cellular user. In response to the access request, the cellular base station performs uplink synchronization on the cellular user that issued the access request based on a random access process. The trusted access process in the embodiment of the present application includes:

[0177] The cellular user obtains the cell identification, the master information block, and verifies the block identification information.

[0178] The cellular user verifies the master information block based on the block identification information.

[0179] Cellular users perform downlink synchronization.

[0180] The cellular user obtains the time-frequency domain position of SIB1.

[0181] Cellular users obtain the required random access information from SIB1.

[0182] The random access procedure is performed by cellular users over the uplink.

[0183] The cellular user performs a subsequent initial access process with the cellular base station.

[0184] In a preferred embodiment of the present application, a cellular user that issues an access request can obtain random access process information (such as uplink frequency and physical random channel configuration) through SIB1, and perform uplink synchronization through the random access process. Then, the initial registration procedure is started. Among them, for the current R16 version of the protocol, in connection with the independent networking scenario targeted by this embodiment, the random access process can adopt a two-step random access scheme. The first step includes uplink MSGA transmission, which includes preamble and payload, and it is necessary to send MsgApreamble first, and then send MsgA payload. The second step of the two-step random access is the downlink MSGB transmission (sent by the base station to the user), which includes MsgB PDCCH and MsgB PDSCH. If MsgB is not received within the MsgB ResponseWindow, MsgA is retransmitted.

[0185] It is understandable that uplink synchronization with the cellular base station to be accessed based on the random access process is a conventional technical means adopted by those skilled in the art. This application does not make any specific limitations on this. The above embodiment is only a reference and is not a limitation of this application. Those skilled in the art can perform the above random access process and uplink synchronization process according to actual conditions.

[0186] Figure 8 This is a flow chart of a decentralized trusted access method for a cellular base station in a preferred embodiment of the present application; Figure 8 As shown, the trusted access method in the above embodiment can be optimized, and the optimization process includes:

[0187] Clarify the channel model; in terms of blockchain improving system information security validity proof and corresponding implementation, the channel model is optional. In this embodiment, the Rayleigh channel is used as an example for implementation.

[0188] Based on the channel model, the signal-to-noise ratio distribution expression of the receiving end is obtained, which can be obtained as the signal-to-noise ratio γ of the legitimate base station signal received at the cellular user equipment (UE) u , the signal-to-noise ratio γ of the legitimate base station signal received at the false base station (FBS) e and the signal-to-noise ratio γ of the FBS signal received at the UE f The cumulative probability distribution functions are:

[0189]

[0190] Among them, p f and p s The distribution represents the transmission power of FBS and legal cellular base stations, N represents the number of transmitting antennas of the cellular base station, It represents the noise power when the UE receives the cellular base station signal, the noise power when the FBS receives the base station signal, and the noise power when the UE receives the FBS signal.

[0191] Calculate the interruption probability; In the interruption probability calculation step, the interruption probability is calculated based on the Wyner eavesdropping model in this embodiment. The interruption probability in the blockchain scenario and the non-blockchain scenario are respectively expressed as:

[0192]

[0193] in, With R e They represent the confidentiality redundancy rates in scenarios with and without blockchain respectively.

[0194] Therefore, in the case of blockchain, the probability of UE accessing a fake base station, that is, the access failure probability obtained by the access method of this application, is: in, Indicates the probability that the signal quality of a fake base station is higher than that of a legitimate cellular base station. P is the transmission power of the pseudo base station sending signals to the UE; d The success probability of a double-spending attack launched by FBS based on the latest block of the main chain is expressed as:

[0195]

[0196] Where z is the block depth confirmation threshold, that is, a block is considered valid when it is confirmed by z subsequent blocks; q and p represent the probability of FBS and gNB creating a new block, that is, the proportion of their respective computing power to the total computing power, p + q = 1; is the expected number of blocks produced by FBS, and M is the maximum number of blocks that FBS can accept that lags behind the main chain.

[0197] In the absence of blockchain, the probability of UE accessing a fake base station is the access failure probability obtained by precalculation using the traditional access method: P f =P so ×P e ;in, Indicates the probability that the signal quality of a fake base station is higher than that of a legitimate cellular base station.

[0198] The safety gain is:

[0199]

[0200] The block threshold of the blockchain network is deployed according to the security gain, and the applicable block threshold can be determined according to the security requirements of different application scenarios, wherein the block threshold and its updated data can be placed in the main information block for user access; then the verification threshold is updated according to the block threshold, that is, in step 302, the verification threshold of the cellular user for the depth of the block to which it belongs is updated. If the depth of the block is less than the verification threshold, the cellular base station corresponding to the block is marked as a malicious invalid base station; if the depth of the block is not less than the verification threshold, the block is deemed available, and the cellular base station that broadcasts the block identification information corresponding to the block is determined to be the cellular base station to be accessed.

[0201] In the preferred embodiment of the present application, in addition, this embodiment also supports systematic security analysis in the case of multiple base stations. Next, this embodiment calculates the system security gain improved by using the blockchain network when the base station and FBS location distribution satisfies the Poisson Point Process (PPP). In the PPP scenario, for the convenience of formula expression, the symbol u is used to represent the UE, the cellular base station closest to u is represented as g0, and the pseudo base station closest to u is represented as f0. Based on the above SG analysis framework, it is necessary to obtain the signal-to-noise ratio of the legitimate base station signal received at the UE in the PPP scenario. The signal-to-noise ratio of the legitimate base station signal received at the FBS and the signal-to-noise ratio of the FBS signal received at the UE The cumulative probability distribution function of . Therefore, in the PPP scenario, we can get:

[0202]

[0203] The functions involved are defined as:

[0204]

[0205] in, represents the distance between user u and its nearest cellular base station g0, represents the mathematical expectation of X, p s is the transmission power of the cellular base station g0, is the channel gain between u and g0, represents the Gaussian white noise variance at u, represents the interference received from other cellular base stations at u, f X (.) represents the probability density function of X, Γ(.) represents the gamma function, λ g represents the distribution density of cellular base stations, λ f represents the pseudo base station distribution density, 2F1(.) represents the Gaussian hypergeometric function, τ represents the path loss exponent, ν irepresents the channel gain between the i-th interfering cellular base station and u.

[0206] It is understood that in this embodiment, the probability that a user identifies an FBS as the base station to be accessed is defined as the access failure probability. In this embodiment, the security gain SG of the blockchain network in this embodiment is calculated by comparing the access failure probability calculated in this embodiment with the access failure probability in conventional technology that does not utilize a blockchain network. The block threshold for deploying the blockchain network is updated according to the security gain, and the verification threshold is updated based on the block threshold, thereby achieving a more efficient decentralized trusted method based on cellular base stations.

[0207] Figure 9 This is a graph showing the relationship between the system security gain and the block confirmation threshold under different attack station computing power ratios. In this embodiment, the ratio of the probability of a user safely accessing a legitimate base station in the absence of blockchain to the probability of a user safely accessing a legitimate base station in the presence of blockchain is defined as the system security gain. Figure 9 As shown in the figure, it can be seen that this embodiment can effectively improve the system security gain in both low and high computing power situations. Moreover, the system security gain increases with the increase of block threshold, and the improvement effect is more obvious when the attacker has high computing power.

[0208] In this embodiment, the FBS transmission power p f Noise at UE The ratio is defined as ρ f ,Right now Figure 10 For different ρ f The relationship between the system security gain and the attacker’s computing power ratio in this case. Figure 10 It can be seen that in this embodiment, under different ρ f Under such circumstances, it can still maintain good resistance to pseudo base station attacks, especially high p f In this case, the effect is more obvious.

[0209] In this embodiment, the transmission power of the legal base station p u Noise at UE The ratio is defined as ρ u ,Right now Figure 11 is the system security gain with ρ f and ρ u Change relationship diagram. Figure 11 As shown, in this embodiment, at high ρ f With low ρ u In all cases, the system shows good resistance to fake base station attacks.

[0210] Although the embodiments of the present application have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and variations may be made to these embodiments without departing from the principles and spirit of the present application, and the scope of the present application is defined by the appended claims and their equivalents.

Claims

1. A decentralized trusted access method for cellular base stations, applied to cellular base stations, characterized in that: The method comprises: Uploading registration information to a blockchain network, the registration information including a public key pair and a certificate of the cellular base station; and adding the cellular base station as a member to the blockchain network based on the public key pair and the certificate; Uploading a master information block to the blockchain network, the master information block being used to indicate basic information required for cellular users within the coverage area of the cellular base station to access the cellular base station; Receiving block identification information from the blockchain network, the block identification information being information generated by executing a consensus algorithm on a block and, after conditions of the consensus algorithm are met, storing the block on the blockchain; the block being a data block packaged and formed after the blockchain network authenticates the master information block; broadcasting the master information block and the block identification information to cellular users within the coverage area; receiving an access request from a cellular user, wherein the access request includes a cellular base station to be accessed determined by the cellular user based on the master information block and the block identification information; In response to the access request, uplink synchronization is performed with the cellular user that issued the access request based on a random access process.

2. A decentralized trusted access method for cellular base stations, characterized in that: Applied to a blockchain network, the method includes: receiving registration information uploaded by a cellular base station, the registration information including a public key pair and a certificate of the cellular base station; In response to the public key pair and the certificate, performing a registration process for the cellular base station to add the cellular base station as a member to the blockchain network; receiving a master information block uploaded by the cellular base station, where the master information block is used to indicate basic information required for a cellular user within a coverage area of the cellular base station to access the cellular base station; In response to the master information block, after authenticating the master information block, the master information block is packaged into a block; a consensus algorithm is executed on the block, and after the consensus algorithm conditions are met, the block is stored on the chain and block identification information is generated; The block identification information is returned to the cellular base station so that the cellular base station can broadcast the master information block and the block identification information to cellular users within the coverage area, so that the cellular users within the coverage area can determine the cellular base station to be accessed based on the master information block and the block identification information, and achieve uplink synchronization with the cellular base station to be accessed based on a random access process.

3. A decentralized trusted access method for cellular base stations according to claim 2, characterized in that: The performing registration processing on the cellular base station to add the cellular base station as a member to the blockchain network includes: The registration information of the cellular base station is parsed to obtain the identity information of the cellular base station; the identity information of the cellular base station is verified according to the equipment manufacturer's root certificate and the equipment manufacturer's signature certificate. If the verification is successful, a registration certificate is issued to the cellular base station and a certificate response is returned to the cellular base station, and the cellular base station is added as a member to the blockchain network; otherwise, the cellular base station is denied admission to the blockchain network as a member.

4. A decentralized trusted access method for cellular base stations according to claim 2, characterized in that: After verifying the master information block, it is packaged to form a block; Executing a consensus algorithm on the block, and after the consensus algorithm conditions are met, storing the block on the chain and generating block identification information includes: In response to the master information block, verify the master information block, and if the authentication passes, pack it into a block, otherwise discard it; A consensus algorithm is executed on the block. When the nodes in the blockchain network reach a consensus, the block is stored on the chain and block identification information is generated for the block. The block identification information includes block header information of the block where the main information block is located and a Merkle path containing the main information block.

5. A decentralized trusted access method for cellular base stations, characterized in that: Applied to cellular users, the method includes: Obtaining a master information block and block identification information broadcast by a cellular base station, and verifying the block identification information; the master information block is used to indicate basic information required for cellular users within the coverage area of the cellular base station to access the cellular base station; the block identification information is generated by executing a consensus algorithm on the block and storing the block on the chain after the consensus algorithm conditions are met; the block is a data block packaged by the blockchain network after authenticating the master information block; If it is verified that the block identification information exists, verifying the block identification information; if the block identification information passes the verification, continuing to verify the block corresponding to the block identification information; if the block verification passes, determining that the cellular base station is the cellular base station to be accessed; Uplink synchronization with the cellular base station to be accessed is carried out based on a random access process.

6. A decentralized trusted access method for cellular base stations according to claim 5, characterized in that: The block identification information is verified. If the block identification information passes the verification, the block corresponding to the block identification information is further verified. The verification conditions used include: Verify whether the first Merkle tree root calculated using the block identification information is consistent with the second Merkle tree root in the block stored in the blockchain network; verify whether the timestamp of the block identification information is legal, or whether the timestamp of the block corresponding to the block identification information is legal; verify whether the block depth of the block corresponding to the block identification information is not less than a verification threshold.

7. A decentralized trusted access method for cellular base stations according to claim 6, characterized in that: The verifying whether the first Merkle tree root calculated by using the block identification information is consistent with the second Merkle tree root in the block stored in the blockchain network includes: Obtaining a Merkle path and block header information from the block identification information; calculating a hash value of the main information block, and calculating a first Merkle root based on the hash value of the main information block and the Merkle path; synchronizing the main chain block header information, and searching for the block header information corresponding to the block identification information in the synchronized main chain block header information; obtaining a second Merkle root through the saved main chain block header information; comparing the first Merkle root with the second Merkle root, and if the comparison is inconsistent, marking the cellular base station that broadcasts the block identification information as a malicious cellular base station.

8. The decentralized trusted access method for cellular base stations according to claim 7, characterized in that: Verifying whether the timestamp of the block identification information is legal, or whether the timestamp of the block corresponding to the block identification information is legal, includes: Before verifying whether the block depth of the block corresponding to the block identification information is not less than a verification threshold, verifying whether the timestamp of the block identification information is legal; if the timestamp of the block identification information is illegal, marking the cellular base station broadcasting the block identification information as an invalid cellular base station; after verifying whether the first Merkle tree root calculated based on the block identification information is consistent with the second Merkle tree root in the block stored in the blockchain network, verifying whether the timestamp of the block corresponding to the block identification information is legal; if the timestamp of the block is illegal, marking the cellular base station broadcasting the block identification information as an invalid cellular base station.

9. The decentralized trusted access method for cellular base stations according to claim 7, characterized in that: Verifying whether the block depth of the block corresponding to the block identification information is not less than a verification threshold includes: If the block depth of the block is less than the verification threshold, the cellular base station broadcasting the block identification information is marked as a malicious invalid base station; if the block depth of the block is not less than the verification threshold, the cellular base station broadcasting the block identification information is marked as a cellular base station to be accessed.

10. A decentralized trusted access method for cellular base stations according to any one of claims 1 to 9, characterized in that: The method further comprises: The probability that a cellular user determines that a pseudo base station is a cellular base station to be accessed is defined as the access failure probability; the access failure probability of the cellular user is calculated; the calculated access failure probability is compared with the pre-calculated access failure probability to calculate the security gain of the blockchain network; the block threshold of the blockchain network is deployed according to the security gain, and the verification threshold of the block depth in the blockchain network is updated.

Citation Information

Patent Citations

  • Communication method, device, terminal and system based on blockchain network

    CN110730488A

  • Blockchain based roaming

    EP3579494A1