A virtual-real fusion space authentication method for 4G networks
By introducing a network authentication method of virtual and real integration into the 4G network, using the 4G network twin mapping module on the base station side and container virtualization technology on the edge cloud, the response speed and risk resistance of the 4G network under massive terminal connections is solved, and efficient terminal device access and personalized services are achieved.
Patent Information
- Application Number
- CN202211075363.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-05
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2042-09-05
AI Technical Summary
When facing the massive terminal connection needs in the future, the existing 4G networks have high processing pressure, slow response speed, lack risk resistance, and are difficult to meet the flexibility of users' personalized business needs.
Using the network authentication method of virtual and real integration, by adding 4G network twin mapping modules to the base station side, using container virtualization technology to build 4G network twin authentication services on the edge cloud, realizing mapping and authentication between terminal devices and network twins, and using docker containerization technology to build a loosely coupled system to improve the network's response speed and risk resistance.
It realizes low-latency and high-performance terminal device access authentication, builds a loosely coupled system that is easy to manage and observe, improves the risk resistance of the network, and meets the flexibility of users' personalized business needs.
Smart Images

Figure CN115567936B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of communication technology, and in particular relates to a network virtual-real fusion space authentication method. Background Art
[0002] Digital twins map real-world physical models, sensor data, and other data into a digital twin in a networked virtual space, reflecting the entire lifecycle of the corresponding physical entity. As the supporting technology for digital twins, network twins map network resources into a virtual space to construct corresponding network twins. This primarily addresses issues at the network and transport layers, providing services for digital twin applications.
[0003] With the rapid development of computer and information technology, a vast number of devices, including humans, machines, and objects, will be connected to the internet in the future, ushering in an era of the Internet of Everything. Furthermore, the demand for real-time services will increase significantly in major network application scenarios, such as the Internet of Vehicles and smart manufacturing. However, the existing 4G network is a centralized processing network structure. Facing the massive demand for future terminal connections, network processing centers will face immense processing pressure, slowing response speeds and severely lacking resilience. Furthermore, the existing 4G network struggles to meet users' personalized service quality requirements and lacks flexibility. Therefore, a redesign of the existing 4G network structure is necessary. Summary of the Invention
[0004] The purpose of the present invention is to provide a virtual-reality fusion space authentication method for 4G networks to improve the response speed of network processing, enhance the network's risk resistance, and meet the flexibility of users' personalized business needs.
[0005] The present invention proposes a virtual-reality fusion space authentication method for 4G networks, which involves the user side and the base station side. The user side includes various 4G terminal devices in the physical world. Each user may include one or more terminal devices, and the user corresponds one-to-one to the network twin in the virtual space; the base station side adds a 4G network twin mapping module on the basis of the existing base station function. The twin mapping module is a set of functional functions provided to the base station side for calling, which is responsible for maintaining and managing the mapping relationship between users and twins. During the initialization of the base station, the mapping information between the user terminal device identity and its network twin authentication service network identity is read into the memory in the configuration file, and this information is managed and maintained through a set of function interface calls. When the user terminal communicates with the network twin, the base station obtains the corresponding network twin authentication service network identity by calling the function interface of the mapping module, and then establishes a connection with it and transmits signaling; the method of the present invention is based on the idea of network twins, uses container virtualization technology to design the access authentication service of the 4G network twin, registers the network twin in the user terminal device; then generates a mapping relationship between the terminal device identity and the 4G network twin authentication service network identity; then the user terminal device communicates with the corresponding 4G network twin authentication service to perform the access authentication process of the terminal device; the specific steps are:
[0006] Step 1: The user registers their own terminal device to the 4G network twin mapping module. After registration is completed, a containerized instance based on the 4G network twin authentication service basic image will run on the network;
[0007] Step 2: The 4G network twin mapping module on the base station side adds the mapping relationship between the user terminal device identity and its network twin authentication service network identity to the memory through the function addition interface, and notifies the base station to establish a connection with this network twin authentication service;
[0008] Step 3: When the terminal requests access, the base station side obtains the attachment request signaling sent by the terminal device and parses the international mobile user identity field of the terminal device. The 4G network twin mapping module obtains the corresponding network twin authentication service network identifier through the function query interface;
[0009] Step 4: The base station side forwards the terminal access request signaling to the corresponding network twin authentication service according to the network twin authentication service network identifier returned by the 4G network twin mapping module;
[0010] Step 5: The base station and the terminal device begin the traditional 4G access authentication signaling process.
[0011] Among them, the users correspond to people in the physical world and correspond one-to-one with the network twins in the virtual space. That is, after registration, each user will have a unique 4G network twin corresponding to him. The same user can have multiple 4G terminal devices of the same or different types. The same 4G terminal device cannot belong to multiple users at the same time.
[0012] Furthermore, the 4G network twin can include multiple 4G network services, including a 4G network twin authentication service. The 4G network twin authentication service is composed of a set of microservices and implemented through Docker containerization technology.
[0013] Furthermore, the services included in the 4G network twin are built on the edge cloud, that is, the edge infrastructure close to the user.
[0014] Furthermore, the terminal device identity identifier is the international mobile user identification code field of the 4G terminal device, and the network twin authentication service network identifier is the IP address of its entry docker container engine.
[0015] This invention can well meet the high-performance and low-latency user requirements for large-scale terminal device access authentication in the future Internet of Things scenario. The network twin's design method using Docker is conducive to building and running a loosely coupled system that can be elastically expanded, has good fault tolerance, is easy to manage and observe, improves the network's risk resistance, and provides basic support for future user personalized services based on 4G network twins. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 This is a network structure diagram of the 4G network twin authentication based on network twins described in the present invention.
[0017] Figure 2 It is a diagram of the mapping relationship between the terminal device identity based on 4G network twin and the 4G network twin authentication service network address as described in the present invention.
[0018] Figure 3 It is a flowchart of the 4G user equipment access authentication process based on network twins described in the present invention. DETAILED DESCRIPTION
[0019] The method proposed by the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.
[0020] The 4G network twin authentication network based on network twin provided by the present invention has a structure as shown in Figure 1As shown. The user side includes various 4G terminal devices in the physical world. Each user may include one or more terminal devices, and the user corresponds one-to-one to the network twin in the virtual space. The base station adds a 4G network twin mapping module on the basis of the traditional base station function. After the base station receives the access request from the user terminal, the twin mapping module obtains the mapping relationship between the device identity obtained through the analysis and the IP address of the network twin authentication service to ensure that the terminal device in the physical world can accurately establish a connection with the corresponding 4G network twin; the 4G network twin authentication service is implemented through docker virtualization container technology and deployed on the edge cloud close to the user, responsible for providing access authentication services for terminal devices. The present invention can well meet the high-performance and low-latency user requirements for large-scale terminal device access authentication in the future Internet of Things scenario. The network twin uses a cloud-native design method that is conducive to building and running a loosely coupled system that is elastically scalable, fault-tolerant, easy to manage and easy to observe, improves the network's risk resistance, and provides basic support for future user personalized services based on 4G network twins.
[0021] like Figure 2 As shown in the figure, it is an embodiment of the virtual-real fusion space authentication method for 4G network. Taking the Huawei 4G terminal with IMSI 203920000000003 as an example, the user first registers the 4G terminal to his own twin, and the edge cloud starts a twin authentication service with an IP address of 192.168.61.3. Then, the IMSI and the twin authentication service identifier are written to the base station configuration file. The base station reads the mapping relationship in the configuration file. The IMSI is stored in the data type of uint64_t and the IP is stored in the data type of in_addr. Then, the mapping insertion interface function insert_cybertwin_authentication_IP_by_IMSI provided by the mapping module is called. Add or update to the hash table in memory; when the 4G terminal is turned on, it will actively search for the base station and initiate an access request. The base station receives the access request signaling sent by the 4G terminal and obtains its IMSI (203920000000003) through parsing, and then obtains the IP address of the twin authentication service (192.168.61.3) by calling the mapping lookup interface function get_cybertwin_authentication_IP_by_IMSI provided by the mapping module. The base station establishes a connection with the corresponding 4G twin authentication service through the IP address and forwards the access request signaling to the 4G twin authentication service; after the 4G network twin authentication service receives the access request from the terminal device, it starts the traditional 4G access authentication signaling process.
[0022] In the present invention, the mapping relationship between the user device identity identifier and the network twin authentication service network address based on the 4G network twin is shown in Figure 3 As shown in the figure, each user in the physical world can include one or more 4G terminal devices, each of which has a unique identity, the International Mobile Subscriber Identification (IMSI). Each 4G network twin authentication service has a unique IP address that corresponds to a user.
[0023] According to the description of the above preferred embodiments, the present invention can be carried out by ordinary technicians in this field according to the principles of the present invention to make corresponding replacements, adjustments and improvements to the corresponding parameters and configurations. All these replacements, adjustments and improvements should fall within the scope of protection of the claims attached to the present invention.
Claims
1. A virtual-real fusion space authentication method for 4G networks, characterized in that: It involves the user side and the base station side. The user side includes various 4G terminal devices in the physical world. Each user includes one or more terminal devices, and the user corresponds one-to-one with the network twin in the virtual space. The base station side adds a 4G network twin mapping module based on the existing base station functions. The 4G network twin mapping module is a set of function functions provided to the base station side for call, responsible for maintaining and managing the mapping relationship between users and twins. During the base station initialization process, the mapping information between the user terminal device identity and its network twin authentication service network identity is read into the memory in the configuration file, and this mapping information is called and managed and maintained through a set of function interfaces. When the user terminal communicates with the network twin, the base station obtains the corresponding network twin authentication service network identity by calling the function interface of the mapping module and then establishes a connection with it and transmits signaling; the access authentication service of the 4G network twin is designed using container virtualization technology, and the network twin is registered in the user terminal device; then a mapping relationship between the terminal device identity and the 4G network twin authentication service network identity is generated; then the user terminal device communicates with the corresponding 4G network twin authentication service to perform the terminal device access authentication process; the specific steps are: Step 1: The user registers their own terminal device to the 4G network twin mapping module. After registration is completed, a containerized instance based on the 4G network twin authentication service basic image will run on the network; Step 2: The 4G network twin mapping module on the base station side adds a mapping relationship between the user terminal device identity and its network twin authentication service network identity, and notifies the base station to establish a connection with this network twin authentication service; Step 3: When the terminal requests access, the base station side obtains the attachment request signaling sent by the terminal device, parses the international mobile user identity field of the terminal device, and obtains the corresponding network twin authentication service network identifier through the 4G network twin mapping module; Step 4: The base station side forwards the terminal's attachment request signaling to the corresponding network twin authentication service according to the network twin authentication service network identifier returned by the 4G network twin mapping module; Step 5: The base station and the terminal device start the 4G access authentication signaling process; Among them, the users correspond to people in the physical world and correspond one-to-one to the network twins in the virtual space. That is, each user has a unique 4G network twin corresponding to him after registration. The same user includes multiple 4G terminal devices of the same or different types. The same 4G terminal device cannot belong to multiple users at the same time.
2. The virtual-real fusion space authentication method for 4G network according to claim 1 is characterized in that: The 4G network twin includes multiple 4G network services, including a 4G network twin authentication service; the 4G network twin authentication service is composed of a group of microservices and is implemented through docker containerization technology.
3. The virtual-real fusion space authentication method for 4G network according to claim 2, characterized in that: The services included in the 4G network twin are built on the edge cloud, that is, the edge infrastructure close to the user.
4. The virtual-real fusion space authentication method for 4G network according to claim 1, characterized in that: The terminal device identity identifier is the international mobile user identification code field of the 4G terminal device, and the network twin authentication service network identifier is the IP address of its entry docker container engine.
Citation Information
Patent Citations
Association method and device between communication devices
CN114189848A
Communication system, server, and communication method and apparatus
WO2021227579A1