An efficient authentication method and system applied to a mobile communication system

By introducing user identification information feature user list and authentication vector stock pool in the mobile communication system, the authentication process is optimized, and the authentication time-consuming problem in traditional systems is solved, and efficient authentication response is achieved.

CN116208957BActive Publication Date: 2025-07-29CHENGDU SANLING RUITONG MOBILE COMM CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310197725.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-03
Publication Date
2025-07-29
Estimated Expiration
2043-03-03

AI Technical Summary

Technical Problem

In traditional mobile communication systems, when the authentication system faces a large number of registered mobile communication terminal users, there are problems such as the global retrieval time and the authentication response time is extended.

Method used

The user identification information feature user list and the authentication vector stock pool are designed, and the authentication vector is directly extracted from the authentication vector stock pool through weighted calculation and multi-level retrieval optimization authentication process, thereby reducing the waiting time for authentication operations.

Benefits of technology

It improves the search efficiency and authentication response speed of mobile communication terminal user authentication, shortens authentication time, and improves the overall efficiency of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116208957B_ABST
    Figure CN116208957B_ABST
Patent Text Reader

Abstract

The present invention provides an efficient authentication method and system for a mobile communication system. The method comprises: a mobile communication terminal on the terminal side initiates an authentication request to an authentication device on the network side; the authentication request carries user identification information of the mobile communication terminal; after receiving the authentication request from the mobile communication terminal, the authentication device searches a user list of user identification information characteristics according to the user identification information carried in the authentication request, and extracts an authentication vector from an authentication vector stock pool based on the search result; the authentication vector is sent to the mobile communication terminal as an authentication response; the mobile communication terminal receives the authentication response and then completes two-way identity authentication on the terminal side and the network side. The present invention eliminates the waiting time for authentication operations, improves the efficiency of retrieval and acquisition of authentication vectors during mobile communication terminal user authentication, shortens the authentication response time, and effectively improves the efficiency of mobile communication terminal user authentication responses in the mobile communication system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of mobile communications, and more particularly, to an efficient authentication method and system applied to a mobile communication system. Background Art

[0002] With the development of mobile communication technology, network security issues have become increasingly prominent. How to protect the security of the communication network while providing high-quality communication services has become an important issue in the field of mobile communications. In this scenario, mutual authentication between the user and the network is an important means for the user and the network to determine the legitimacy of each other. However, since the authentication system usually faces a large number of registered mobile communication terminal users, the traditional authentication system has the following problems:

[0003] 1. For authentication requests initiated by different users, it is usually necessary to perform a global search in the information database of mobile communication terminal user identification information. When the number of registered mobile communication terminal users is large, the search takes a long time;

[0004] 2. After the authentication system receives the authentication request sent by the terminal, it temporarily performs authentication operations to generate an authentication vector. The waiting time for the authentication operation is long, resulting in an extended authentication response time and reducing the overall efficiency of the system. Summary of the Invention

[0005] The present invention aims to provide an efficient authentication method and system applied to a mobile communication system to solve the problems existing in the above-mentioned traditional authentication system.

[0006] An efficient authentication method applied to a mobile communication system provided by the present invention includes the following steps:

[0007] S100. The mobile communication terminal on the terminal side sends an authentication request to the authentication device on the network side; the authentication request carries the mobile communication terminal user identification information, and the user identification information is used to uniquely identify the user identity information in the mobile communication network;

[0008] S200. The authentication device receives the authentication request sent by the mobile communication terminal:

[0009] S210. According to the user identification information carried in the authentication request, perform a search in the user list of user identification information features, and extract the authentication vector from the authentication vector inventory pool according to the search result;

[0010] S220. Send the authentication vector as an authentication response to the mobile communication terminal;

[0011] S300. The mobile communication terminal receives the authentication response, and then completes the two-way identity authentication between the terminal side and the network side.

[0012] Furthermore, the user identification information characteristic user list is maintained based on the following four dimensions:

[0013] The frequency of recent authentication of mobile communication terminal users;

[0014] The time interval of the last authentication of mobile communication terminal users;

[0015] The identity priority of mobile communication terminal users;

[0016] And the priority of the region to which the registered location of the mobile communication terminal user belongs.

[0017] Furthermore, the method for maintaining the user identification information characteristic user list includes:

[0018] Extract feature codes from the four dimensions of the frequency of recent authentication of mobile communication terminal users, the time interval of the last authentication of mobile communication terminal users, the identity priority of mobile communication terminal users, and the priority of the region to which the registered location of the mobile communication terminal user belongs. Calculate the weighted sum of the feature codes of each dimension according to their dimension weights, and the weighted calculation result is the current feature value of each mobile communication terminal user;

[0019] According to the current feature value of the user, adjust its sorting position in the preset full database of mobile communication terminal user identification information, and extract the top N user identification information to form the user identification information characteristic user list.

[0020] Furthermore, the user identification information characteristic user list is set as a multi-level characteristic user name.

[0021] Furthermore, when performing the retrieval in step S210, retrieve each level of the characteristic user list in turn. If the retrieval is successful, extract the corresponding authentication vector from the authentication vector stock pool; otherwise, extract the corresponding authentication vector from the authentication vector stock pool. Otherwise, according to the user identification information carried in the authentication request, perform a retrieval in the full database of mobile communication terminal user identification information. If the retrieval is successful, extract the corresponding authentication vector from the authentication vector stock pool; otherwise, return an authentication response indicating retrieval failure to the mobile communication terminal.

[0022] Furthermore, when extracting the corresponding authentication vector from the authentication vector stock pool, it is necessary to determine whether the extraction is successful:

[0023] If the extraction is successful, in step S220, the extracted authentication vector is sent as the authentication response to the mobile communication terminal;

[0024] If the extraction fails, perform an authentication operation according to the user identification information carried in the received authentication request to generate an authentication vector, and in step S220, send the generated authentication vector as the authentication response to the mobile communication terminal.

[0025] Further, if the mobile communication terminal on the terminal side initiates an authentication request to the authentication device on the network side for the first time, the authentication device generates M groups of authentication vectors at one time according to the user identification information carried in the authentication request, and stores the M groups of authentication vectors in the authentication vector stock pool; when the mobile communication terminal on the terminal side initiates an authentication request to the authentication device on the network side again, the authentication device retrieves in the user list of characteristic users according to the user identification information carried in the authentication request, and extracts a group of authentication vectors from the authentication vector stock pool according to the retrieval result and sends it to the mobile communication terminal as an authentication response.

[0026] Further, M groups of authentication vectors are generated only for the mobile communication terminal that has been authenticated at least once.

[0027] Further, an independent daemon process maintains the task of ensuring an adequate number of authentication vectors in the authentication vector stock pool in real time, and this task is performed when the system is idle.

[0028] The present invention also provides an efficient authentication system applied to a mobile communication system, including a mobile communication terminal on the terminal side and an authentication device on the network side; the mobile communication terminal on the terminal side and the authentication device on the network side are used to execute the above-mentioned efficient authentication method applied to the mobile communication system.

[0029] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are as follows:

[0030] Compared with the traditional authentication system, the present invention eliminates the waiting time for authentication operations, improves the efficiency of retrieval and the efficiency of obtaining authentication vectors during the authentication of mobile communication terminal users, shortens the authentication response time, and effectively improves the authentication response efficiency of mobile communication terminal users in the mobile communication system. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0032] Figure 1 It is a schematic network connection diagram of the efficient authentication system applied to the mobile communication system in the embodiment of the present invention.

[0033] Figure 2 It is the overall flowchart of the efficient authentication method applied to the mobile communication system in the embodiment of the present invention.

[0034] Figure 3This is the flowchart for maintaining the list of characteristic users of the user identification information in the embodiments of the present invention.

[0035] Figure 4 This is the detailed flowchart of the efficient authentication method applied to the mobile communication system in the embodiments of the present invention.

[0036] Figure 5 This is the structural schematic diagram of the authentication vector inventory pool in the embodiments of the present invention.

[0037] Figure 6 This is the maintenance schematic diagram of the authentication vector inventory pool in the embodiments of the present invention. Detailed implementation manners

[0038] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. Generally, the components of the embodiments of the present invention described and illustrated herein can be arranged and designed in various different configurations.

[0039] Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed present invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0040] Embodiment

[0041] As Figure 1 shown, an efficient authentication system applied to a mobile communication system includes a mobile communication terminal on the terminal side and an authentication device on the network side; wherein, the mobile communication terminal refers to a computer device that can be used while moving and has the ability to access a mobile communication network, including mobile phones, tablet computers, POS machines, satellite terminals, etc. The mobile communication terminal on the terminal side and the authentication device on the network side implement an efficient authentication method applied to a mobile communication system. As Figure 2 shown, the efficient authentication method applied to a mobile communication system includes the following steps:

[0042] S100, the mobile communication terminal on the terminal side sends an authentication request to the authentication device on the network side; the authentication request carries the user identification information of the mobile communication terminal, and this user identification information is used to uniquely identify the user identity information in the mobile communication network;

[0043] S200, the authentication device receives the authentication request sent by the mobile communication terminal:

[0044] S210, retrieve in the user identification information characteristic user list according to the user identification information carried in the authentication request, and extract the authentication vector from the authentication vector stock pool according to the retrieval result;

[0045] S220, send the authentication vector as an authentication response to the mobile communication terminal;

[0046] S300, the mobile communication terminal receives the authentication response, and then completes the two-way identity authentication between the terminal side and the network side.

[0047] In this embodiment, the user identification information characteristic user list is maintained based on the following four dimensions:

[0048] The frequency of recent authentication of the mobile communication terminal user;

[0049] The time interval of the last authentication of the mobile communication terminal user;

[0050] The identity priority of the mobile communication terminal user;

[0051] And the priority of the region to which the registered place of the mobile communication terminal user belongs.

[0052] As Figure 3 shown, the method for maintaining the user identification information characteristic user list includes:

[0053] Extract feature codes from the four dimensions of the frequency of recent authentication of the mobile communication terminal user, the time interval of the last authentication of the mobile communication terminal user, the identity priority of the mobile communication terminal user, and the priority of the region to which the registered place of the mobile communication terminal user belongs. Weight the feature codes of each dimension according to their dimension weights, and the weighted calculation result is the current feature value of each mobile communication terminal user; among them, the weights of each dimension can be adjusted according to the actual situation and requirements of the system to achieve the optimal sorting effect;

[0054] According to the current feature value of the user, adjust its sorting position in the preset full amount library of mobile communication terminal user identification information, and extract the top N user identification information to form the user identification information characteristic user list. Thus, when the authentication device retrieves the mobile communication terminal user identification information, it first retrieves from this user identification information characteristic user list. If not found, it then retrieves in the full amount library of mobile communication terminal user identification information, so as to improve the retrieval efficiency. Among them, the value of N can be adjusted according to the actual situation and specific requirements of the system to achieve the best effect when most terminals are retrieved.

[0055] Furthermore, the system can, as needed, configure the user identification information feature user list as a multi-level feature user list to achieve a system-wide effect of varying search speeds for users at different levels. During the search in step S210, each level of the feature user list is searched sequentially. If the search is successful, the corresponding authentication vector is extracted from the existing authentication vector pool. Otherwise, a search is performed within the entire mobile communication terminal user identification information database based on the user identification information carried in the authentication request. If the search is successful, the corresponding authentication vector is extracted from the existing authentication vector pool. Otherwise, an authentication response indicating a search failure is returned to the mobile communication terminal.

[0056] For example, the top N1 user identification information is extracted to form a first-level feature user list of mobile communication terminal user identification information, and the top N1+1 to N2 user identification information is extracted to form a second-level feature user list of mobile communication terminal user identification information; wherein, N1 <N2且N1+N2=N。由此,所述用户标识信息特征用户名单包括移动通信终端用户标识信息一级特征用户名单和移动通信终端用户标识信息二级特征用户名单。那么如 Figure 4 As shown, after a mobile communication terminal in a mobile communication system initiates an authentication request, the authentication device, when searching for the mobile communication terminal user identification information, first searches the list of first-level characteristic users of the mobile communication terminal user identification information. If no information is found, it searches the list of second-level characteristic users of the mobile communication terminal user identification information. If no information is found, it searches the entire library of mobile communication terminal user identification information, thereby improving the efficiency of the search. Specifically, step S210 includes the following sub-steps:

[0057] S211, according to the user identification information carried in the authentication request, search the mobile communication terminal user identification information first-level feature user list, if the search is successful, extract the corresponding authentication vector from the authentication vector stock pool, otherwise execute step S212;

[0058] S212, according to the user identification information carried in the authentication request, search the secondary feature user list of the mobile communication terminal user identification information. If the search is successful, extract the corresponding authentication vector from the authentication vector stock pool; otherwise, execute step S213;

[0059] S213: Search the entire database of mobile communication terminal user identification information according to the user identification information carried in the authentication request. If the search is successful, extract the corresponding authentication vector from the authentication vector stock pool. Otherwise, return an authentication response indicating that the search failed and send it to the mobile communication terminal.

[0060] Furthermore, when extracting the corresponding authentication vector from the authentication vector stock pool, it is necessary to determine whether the extraction is successful:

[0061] If the extraction is successful, the extracted authentication vector is sent as an authentication response to the mobile communication terminal in step S220;

[0062] If the extraction fails, authentication operation is performed according to the user identification information carried in the received authentication request to generate an authentication vector, and the generated authentication vector is sent as an authentication response to the mobile communication terminal in step S220.

[0063] As Figure 5 、 Figure 6 shown, if the mobile communication terminal on the terminal side sends an authentication request to the authentication device on the network side for the first time, the authentication device generates M groups of authentication vectors at one time according to the user identification information carried in the authentication request. For example, the M groups of authentication vectors (a 11 -a 1M ) of the mobile communication terminal a1 are stored in the authentication vector stock pool; when the mobile communication terminal on the terminal side sends an authentication request to the authentication device on the network side again, the authentication device retrieves in the user list of user identification information features according to the user identification information carried in the authentication request, and extracts a group of authentication vectors from the authentication vector stock pool according to the retrieval result to send as an authentication response to the mobile communication terminal. It can be seen that the traditional authentication device, after receiving the authentication request sent by the mobile communication terminal, performs authentication operation temporarily, generates a group of authentication vectors, sends them as an authentication response to the mobile communication terminal, and the waiting time for authentication operation is long, resulting in an increase in the authentication response time and a reduction in the overall system efficiency. However, in the efficient authentication method of this embodiment, the waiting time for authentication operation is omitted, which can improve the efficiency of the mobile communication terminal user to obtain the authentication vector. The following optimizations can also be made:

[0064] (1) Considering the system storage pressure, M groups of authentication vectors are generated only for the mobile communication terminals that have been authenticated at least once, rather than all registered users.

[0065] (2) Executing "generating M groups of authentication vectors" can be dynamically configured and adjusted according to the system resource allocation situation to achieve a win-win effect of optimal overall system resource allocation and good authentication response efficiency.

[0066] (3) An independent daemon process maintains the task of ensuring that the number of authentication vectors in the authentication vector stock pool is sufficient in real time, and this task is performed when the system is idle without adding additional load to the system.

[0067] In summary, the efficient authentication method and system of the present invention have the following advantages:

[0068] 1. For the authentication requests initiated by active users and high-priority users, only retrieval in the user list of the user identification information features of the mobile communication terminal is required, which greatly shortens the duration of retrieval and improves the efficiency of retrieval during the authentication of mobile communication terminal users;

[0069] 2. After the authentication system receives the authentication request initiated by the user terminal, it does not need to perform authentication operations, but directly extracts a set of authentication vectors from the authentication vector inventory pool as a response and sends it to the terminal, reducing the authentication response time and increasing the overall efficiency of the system.

[0070] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. An efficient authentication method applied to a mobile communication system, characterized in that, It includes the following steps: S100, the mobile communication terminal on the terminal side sends an authentication request to the authentication device on the network side; the authentication request carries the user identification information of the mobile communication terminal, and this user identification information is used to uniquely identify the user identity information in the mobile communication network; S200, the authentication device receives the authentication request sent by the mobile communication terminal: S210, according to the user identification information carried in the authentication request, retrieve in the user identification information characteristic user list, and extract the authentication vector from the authentication vector inventory pool according to the retrieval result; S220, send the authentication vector as an authentication response to the mobile communication terminal; S300, the mobile communication terminal receives the authentication response, and then completes the two-way identity authentication between the terminal side and the network side; The user identification information characteristic user list is maintained based on the following four dimensions: The frequency of recent authentication of the mobile communication terminal user; The time interval of the last authentication of the mobile communication terminal user; The identity priority of the mobile communication terminal user; And the priority of the region to which the registration place of the mobile communication terminal user belongs; The maintenance method of the user identification information characteristic user list includes: Extract feature codes from the four dimensions of the frequency of recent authentication of the mobile communication terminal user, the time interval of the last authentication of the mobile communication terminal user, the identity priority of the mobile communication terminal user, and the priority of the region to which the registration place of the mobile communication terminal user belongs. Weight the feature codes of each dimension according to their dimension weights, and the weighted calculation result is the current feature value of each mobile communication terminal user; According to the current feature value of the user, adjust its sorting position in the preset full amount library of mobile communication terminal user identification information, and extract the top N user identification information to form the user identification information characteristic user list; the user identification information characteristic user list is set as a multi-level characteristic user name; When retrieving in step S210, retrieve each level of the characteristic user list in turn. If the retrieval is successful, extract the corresponding authentication vector from the authentication vector inventory pool. Otherwise, according to the user identification information carried in the authentication request, retrieve in the full amount library of mobile communication terminal user identification information. If the retrieval is successful, extract the corresponding authentication vector from the authentication vector inventory pool. Otherwise, return an authentication response indicating retrieval failure to the mobile communication terminal.

2. The efficient authentication method applied to a mobile communication system according to claim 1, characterized in that, When extracting the corresponding authentication vector from the authentication vector inventory pool, it is necessary to determine whether the extraction is successful: If the extraction is successful, then in step S220, send the extracted authentication vector as an authentication response to the mobile communication terminal; If the extraction fails, then perform an authentication operation according to the user identification information carried in the received authentication request to generate an authentication vector, and in step S220, send the generated authentication vector as an authentication response to the mobile communication terminal.

3. The efficient authentication method applied to a mobile communication system according to claim 1, characterized in that If the mobile communication terminal on the terminal side initiates an authentication request to the authentication device on the network side for the first time, the authentication device generates M groups of authentication vectors at one time based on the user identification information carried in the authentication request, and stores the M groups of authentication vectors in the authentication vector stock pool; when the mobile communication terminal on the terminal side initiates an authentication request to the authentication device on the network side again, the authentication device searches the user identification information feature user list according to the user identification information carried in the authentication request, and extracts a group of authentication vectors from the authentication vector stock pool according to the search result and sends it as an authentication response to the mobile communication terminal.

4. The efficient authentication method applied to a mobile communication system according to claim 3, wherein M groups of authentication vectors are generated only for mobile communication terminals that have been authenticated at least once.

5. The efficient authentication method applied to a mobile communication system according to claim 3, wherein An independent daemon process is used to maintain in real time the sufficient number of authentication vectors in the authentication vector stock pool, and this task is performed when the system is idle.

6. An efficient authentication system applied to a mobile communication system, characterized in that, It comprises a mobile communication terminal on the terminal side and an authentication device on the network side; the mobile communication terminal on the terminal side and the authentication device on the network side are used to execute the efficient authentication method applied to the mobile communication system as described in any one of claims 1-5.

Citation Information

Patent Citations

  • Authentication method and device, equipment and storage medium

    CN114125836A