A multi-dimensional authentication method and device for fixed migration fusion
By designing a multi-dimensional authentication method and device that supports username/password, user number, and device identifier, the compatibility problem of multiple authentication methods in enterprise-level authentication systems is solved, and unified authentication of enterprise-level authentication systems is realized. This is applicable to MEC services of telecom operators and simplifies the terminal access process.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-20
- Publication Date
- 2026-03-24
AI Technical Summary
Existing technologies are difficult to be compatible with multiple authentication methods of mobile terminals from different manufacturers, especially in enterprise-level authentication systems, where they cannot simultaneously support authentication requirements for username/password, user number, and device identifier.
Design a multi-dimensional authentication method and device for fixed-mobile convergence. By registering APN information and user accounts, it supports three authentication methods: username/password, user number, and device identifier. It also performs fixed-mobile convergence authentication for enterprise-level authentication systems based on the Radius authentication protocol.
It achieves compatibility certification for different terminals, simplifies the access and deployment of enterprise MEC and WiFi terminals, enhances the enterprise's self-control capabilities, and is suitable for MEC services of telecom operators.
Smart Images

Figure CN116321142B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the field of MEC applications, and in particular to a fixed-mobile converged multi-dimensional authentication method and device. BACKGROUND
[0002] MEC provides enterprises with large bandwidth, low latency and security privacy requirements, effectively enabling enterprise digital upgrading. In MEC applications, there are a large number of customer mobile terminal access requirements. When the customer mobile terminal accesses, after obtaining network access permission through a telecom operator, it still needs to be authenticated again in the enterprise's own authentication system, and an IP address is allocated as needed. Different manufacturers' customer mobile terminals provide different authentication methods, which are generally authenticated through a user number or a device identifier. At the same time, the enterprise authentication system often also needs to bear the authentication requirements of internal WiFi users based on a username / password. SUMMARY
[0003] In order to solve the compatibility problem of different terminal authentication methods, the application provides a fixed-mobile converged multi-dimensional authentication method and device, which is compatible with three authentication methods based on a username / password, a user number and a device identifier, and meets the authentication requirements of mobile terminals and fixed network WiFi terminals.
[0004] To achieve the above purpose, the application adopts the following technical scheme:
[0005] In an embodiment of the application, a fixed-mobile converged multi-dimensional authentication method is provided, which comprises the following steps:
[0006] Registering APN information, specifying authentication methods, including three authentication methods based on a username / password, a user number and a device identifier;
[0007] Registering a user account, inputting corresponding username / password, user number and device identifier information according to the authentication method;
[0008] When the customer mobile terminal accesses, calling the authentication service to perform fixed-mobile converged authentication.
[0009] Further, the fixed-mobile converged authentication process is as follows:
[0010] Receiving an authentication request message, obtaining an APN identifier from the message;
[0011] According to the APN identifier, querying the corresponding authentication method in the APN information database of the enterprise-level authentication system;
[0012] According to the authentication method, selecting different branches to verify the username / password, user number and device identifier.
[0013] Furthermore, depending on the authentication method, different branches are selected to verify the username / password, user number, and device identifier, including:
[0014] Distinguish between username / password, user number, and device identifier based on the authentication method;
[0015] If the authentication method is username / password, then verify whether the username / password is correct; if the authentication method is user number, then verify whether the user number is valid; if the authentication method is device identifier, then verify whether the device identifier is valid.
[0016] If authentication is successful, an IP address will be assigned; if authentication fails, authentication will be rejected.
[0017] Furthermore, the enterprise-level authentication system is implemented based on the standard Radius authentication protocol.
[0018] In one embodiment of the present invention, a multi-dimensional authentication device for fixed-mobile fusion is also proposed, the device comprising:
[0019] The APN registration module is used to register APN information and specify authentication methods, including three authentication methods based on username / password, user number, and device identifier.
[0020] The user account registration module is used to register user accounts. Users need to enter the corresponding username / password, user number, and device identification information according to the authentication method.
[0021] The authentication service module is used to call the authentication service to perform fixed-mobile converged authentication when a customer's mobile terminal accesses the network.
[0022] Furthermore, the fixed-mobile convergence certification process is as follows:
[0023] Receive authentication request messages and obtain the APN identifier from the messages;
[0024] Based on the APN identifier, query the corresponding authentication method in the APN information database of the enterprise-level authentication system;
[0025] Select different branches based on the authentication method to verify the username / password, user number, and device identifier respectively.
[0026] Furthermore, depending on the authentication method, different branches are selected to verify the username / password, user number, and device identifier, including:
[0027] Distinguish between username / password, user number, and device identifier based on the authentication method;
[0028] If the authentication method is username / password, then verify whether the username / password is correct; if the authentication method is user number, then verify whether the user number is valid; if the authentication method is device identifier, then verify whether the device identifier is valid.
[0029] If authentication is successful, an IP address will be assigned; if authentication fails, authentication will be rejected.
[0030] Furthermore, the enterprise-level authentication system is implemented based on the standard Radius authentication protocol.
[0031] In one embodiment of the present invention, a computer device is also proposed, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the aforementioned multidimensional authentication method of fixed-mobile fusion.
[0032] In one embodiment of the present invention, a computer-readable storage medium is also provided, which stores a computer program for performing a multidimensional authentication method of fixed-mobile fusion.
[0033] Beneficial effects:
[0034] 1. This invention designs a multi-dimensional authentication scheme for fixed-mobile convergence, which has been effectively applied in the MEC service of telecom operators.
[0035] 2. This invention is compatible with access scenarios for both MEC terminals and enterprise WiFi terminals. As MEC services continue to expand, it can gain significant promotional potential among numerous enterprises. Looking to the future, this flexible secondary authentication scheme will enable enterprises to achieve greater autonomy and control. Attached Figure Description
[0036] Figure 1 This is a schematic diagram of the multi-dimensional authentication method for solid-mobile fusion of the present invention;
[0037] Figure 2 This is a schematic diagram of an APN registration page according to an embodiment of the present invention;
[0038] Figure 3 This is a schematic diagram of a user account registration page according to an embodiment of the present invention;
[0039] Figure 4 This is a schematic diagram of a fixed-mobile fusion authentication process according to an embodiment of the present invention;
[0040] Figure 5 This is a schematic diagram of the structure of the multi-dimensional authentication device for solid-mobile fusion of the present invention;
[0041] Figure 6 This is a schematic diagram of the computer device structure of the present invention. Detailed Implementation
[0042] The principles and spirit of the present invention will now be described with reference to several exemplary embodiments. It should be understood that these embodiments are provided merely to enable those skilled in the art to better understand and implement the present invention, and are not intended to limit the scope of the present invention in any way. Rather, these embodiments are provided to make this disclosure more thorough and complete, and to fully convey the scope of this disclosure to those skilled in the art.
[0043] Those skilled in the art will recognize that embodiments of the present invention can be implemented as a system, apparatus, device, method, or computer program product. Therefore, this disclosure can be specifically implemented in the following forms: entirely hardware, entirely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software.
[0044] According to an embodiment of the present invention, a multi-dimensional authentication method and apparatus for fixed-mobile convergence is proposed, which can simultaneously support three authentication methods: username / password, user number, and device identifier, effectively solving the compatibility problem of different terminal authentication methods.
[0045] The principles and spirit of the present invention will be explained in detail below with reference to several representative embodiments.
[0046] Figure 1 This is a schematic diagram of the multi-dimensional authentication method for fixed-mobile fusion according to the present invention. Figure 1 As shown, this method, based on the standard Radius (a remote access authentication protocol) authentication protocol, implements an enterprise-level authentication system, including:
[0047] S1. Register APN (Access Point Name) information and specify the authentication method, including three authentication methods based on username / password, user number, and device identifier;
[0048] S2. Register a user account. Enter the corresponding username / password, user number, and device identification information according to the authentication method.
[0049] S3. When a customer's mobile terminal accesses the network, the authentication service is invoked to perform fixed-mobile converged authentication; details are as follows:
[0050] When a customer's mobile terminal accesses the system, the enterprise-level authentication system obtains the username / password, user number or device identification information, and the corresponding APN identifier contained in the authentication request message. Based on the corresponding APN identifier, the system selects the authentication method and uses the registered user account information to authenticate the user.
[0051] The above solution can effectively address the fixed-mobile convergence certification needs of enterprises for MEC and WiFi.
[0052] It should be noted that although the operation of the method of the present invention has been described in a specific order in the above embodiments and figures, this does not require or imply that the operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.
[0053] To provide a clearer explanation of the above-mentioned multidimensional authentication method for solid-mobile fusion, a specific embodiment will be used for illustration below. However, it is worth noting that this embodiment is only for better illustrating the present invention and does not constitute an improper limitation of the present invention.
[0054] This solution is applied in Sany Heavy Industry's MEC enterprise-level authentication system, providing multiple authentication methods for access to internal enterprise WiFi and 5G terminals, simplifying deployment and control. In this embodiment, 5G terminal access is authenticated using device identifier or user number, distinguished by an APN identifier allocated by China Unicom; internal enterprise WiFi access is authenticated using username / password, with the fixed string "Sanyi" representing the corresponding APN identifier; after receiving an authentication request, the authentication server distinguishes between a 5G terminal and an enterprise WiFi user based on the APN identifier and performs the corresponding authentication operation. Thus, a single authentication system satisfies both authentication needs of the enterprise. The specific implementation is as follows:
[0055] 1. Register APN information and specify the authentication method, such as... Figure 2 As shown;
[0056] Note: Fields marked with "*" are required, others are optional; "Authentication Method" dropdown options: Username / Password, User Number, and Device Identifier.
[0057] 2. Register a user account. Enter the corresponding username / password, user number, and device identifier according to the authentication method, such as... Figure 3 As shown;
[0058] Note: The search term "APN" is selected from the dropdown menu, and intelligent suggestions are provided; fields marked with "*" are required, others are optional; required fields are set according to the authentication method corresponding to the selected APN, and required fields are listed first:
[0059] When the authentication method is "username / password", username and password are required.
[0060] When the authentication method is "user number", the user number is required.
[0061] When the authentication method is "Device Identifier", the Device Identifier is required.
[0062] 3. When a customer's mobile terminal accesses the system, the authentication service is invoked. This service supports three authentication methods, and the processing flow is as follows: Figure 4 As shown;
[0063] Instructions: Upon receiving an authentication request message, the system retrieves the APN identifier from the message. Based on the APN identifier, it queries the corresponding authentication method in the APN information database of the enterprise-level authentication system. If the method does not exist, authentication is rejected. If the method exists, different branches are selected according to the authentication method to verify the username / password, user number, and device identifier, respectively, as follows:
[0064] Distinguish between username / password, user number, and device identifier based on the authentication method;
[0065] If the authentication method is username / password, then verify whether the username / password is correct; if the authentication method is user number, then verify whether the user number is valid; if the authentication method is device identifier, then verify whether the device identifier is valid.
[0066] If authentication is successful, an IP address will be assigned; if authentication fails, authentication will be rejected.
[0067] Based on the same inventive concept, this invention also proposes a multi-dimensional authentication device that integrates fixed and mobile technologies. The implementation of this device can refer to the implementation of the method described above, and repeated details will not be elaborated further. The term "module" used below can refer to a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0068] Figure 5 This is a schematic diagram of the multi-dimensional authentication device for solid-mobile fusion of the present invention. (See diagram below.) Figure 5 As shown, this device implements an enterprise-level authentication system based on the standard Radius authentication protocol, including:
[0069] APN registration module 101 is used to register APN information and specify authentication methods, including three authentication methods based on username / password, user number, and device identifier;
[0070] User account registration module 102 is used to register user accounts. According to the authentication method, the user should enter the corresponding username / password, user number and device identification information.
[0071] Authentication service module 103 is used to call the authentication service to perform fixed-mobile converged authentication when a customer's mobile terminal accesses the network. The specific process is as follows:
[0072] Receive authentication request messages and obtain the APN identifier from the messages;
[0073] Based on the APN identifier, query the corresponding authentication method in the APN information database of the enterprise-level authentication system;
[0074] Select different branches based on the authentication method, and verify the username / password, user number, and device identifier respectively, as follows:
[0075] Distinguish between username / password, user number, and device identifier based on the authentication method;
[0076] If the authentication method is username / password, then verify whether the username / password is correct; if the authentication method is user number, then verify whether the user number is valid; if the authentication method is device identifier, then verify whether the device identifier is valid.
[0077] If authentication is successful, an IP address will be assigned; if authentication fails, authentication will be rejected.
[0078] It should be noted that although several modules of the fixed-mobile fusion multidimensional authentication device are mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of the present invention, the features and functions of two or more modules described above can be embodied in one module. Conversely, the features and functions of one module described above can be further divided and embodied by multiple modules.
[0079] Based on the aforementioned inventive concept, such as Figure 6 As shown, the present invention also proposes a computer device 200, including a memory 210, a processor 220, and a computer program 230 stored in the memory 210 and executable on the processor 220. When the processor 220 executes the computer program 230, it implements the aforementioned fixed-mobile fusion multidimensional authentication method.
[0080] Based on the aforementioned inventive concept, the present invention also proposes a computer-readable storage medium storing a computer program that performs the aforementioned fixed-mobile fusion multidimensional authentication method.
[0081] To meet the secondary authentication needs of customer mobile terminals in MEC (Mobile Edge Computing) application scenarios, as well as the needs of enterprise Wi-Fi (Wireless Fidelity) authentication, this invention proposes a multi-dimensional authentication method and device for fixed-mobile convergence, which has been effectively applied in the MEC services of telecom operators. It is compatible with the access scenarios of MEC terminals and enterprise Wi-Fi terminals, and with the continuous expansion of MEC services, it can gain significant promotion potential among many enterprises. Looking to the future, based on this flexible secondary authentication scheme, enterprises will be able to achieve greater autonomy and control.
[0082] While the spirit and principles of the invention have been described with reference to several specific embodiments, it should be understood that the invention is not limited to the disclosed specific embodiments, and the division of aspects does not imply that features in these aspects cannot be combined for benefit; such division is merely for ease of description. The invention is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.
[0083] Regarding the limitation of the scope of protection of this invention, those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art without creative effort based on the technical solution of this invention are still within the scope of protection of this invention.
Claims
1. A multi-dimensional authentication method integrating fixed and mobile technologies, characterized in that, The method includes: Register APN information and specify the authentication method, including three authentication methods based on username / password, user number, and device identifier; Register a user account by entering the corresponding username / password, user number, and device identification information according to the authentication method; When a customer's mobile terminal accesses the network, the authentication service is invoked to perform fixed-mobile converged authentication. The fixed-mobile convergence certification process is as follows: Receive authentication request messages and obtain the APN identifier from the messages; Based on the APN identifier, query the corresponding authentication method in the APN information database of the enterprise-level authentication system; Select different branches based on the authentication method to verify the username / password, user number, and device identifier respectively.
2. The multi-dimensional authentication method for fixed-mobile fusion according to claim 1, characterized in that, Select different branches based on the authentication method to verify the username / password, user number, and device identifier, including: Distinguish between username / password, user number, and device identifier based on the authentication method; If the authentication method is username / password, then verify whether the username / password is correct; if the authentication method is user number, then verify whether the user number is valid; if the authentication method is device identifier, then verify whether the device identifier is valid. If authentication is successful, an IP address will be assigned; if authentication fails, authentication will be rejected.
3. The multi-dimensional authentication method for fixed-mobile fusion according to claim 1, characterized in that, The enterprise-level authentication system is implemented based on the standard Radius authentication protocol.
4. A multi-dimensional authentication device integrating fixed and mobile technologies, characterized in that, The device includes: The APN registration module is used to register APN information and specify authentication methods, including three authentication methods based on username / password, user number, and device identifier. The user account registration module is used to register user accounts. Users need to enter the corresponding username / password, user number, and device identification information according to the authentication method. The authentication service module is used to invoke the authentication service to perform fixed-mobile converged authentication when a customer's mobile terminal accesses the network. The fixed-mobile converged authentication process is as follows: Receive authentication request messages and obtain the APN identifier from the messages; Based on the APN identifier, query the corresponding authentication method in the APN information database of the enterprise-level authentication system; Select different branches based on the authentication method to verify the username / password, user number, and device identifier respectively.
5. The multi-dimensional authentication device for fixed-mobile fusion according to claim 4, characterized in that, Select different branches based on the authentication method to verify the username / password, user number, and device identifier, including: Distinguish between username / password, user number, and device identifier based on the authentication method; If the authentication method is username / password, then verify whether the username / password is correct; if the authentication method is user number, then verify whether the user number is valid; if the authentication method is device identifier, then verify whether the device identifier is valid. If authentication is successful, an IP address will be assigned; if authentication fails, authentication will be rejected.
6. The multi-dimensional authentication device for fixed-mobile fusion according to claim 4, characterized in that, The enterprise-level authentication system is implemented based on the standard Radius authentication protocol.
7. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method according to any one of claims 1-3.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that performs the method according to any one of claims 1-3.
Citation Information
Patent Citations
Authentication method, device and system based on space-ground integrated network
CN111885604A
Wireless network user identification method, device and equipment and storage medium
CN113556722A