Large-scale heterogeneous terminal architecture and large-scale heterogeneous terminal architecture access method
By classifying 5G terminal devices and configuring preamble codes to generate access authentication schemes, the problems of high authentication delay and network congestion in the 5G authentication mechanism are solved, heterogeneous integration and interconnection of multiple types of terminals are achieved, and differentiated service needs are met.
Patent Information
- Application Number
- CN202310506453.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-06
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2043-05-06
AI Technical Summary
The existing 5G authentication mechanism is unable to provide differentiated secure access solutions for multiple types of access terminals, resulting in high authentication delays and network signaling congestion. This problem is particularly serious in massive machine-type communication scenarios.
By classifying terminal devices based on communication delay, a group authentication terminal device set and an independent authentication terminal device set are formed, and the preamble code is configured and the access authentication scheme is generated. The terminal device group leader and the reverse hash tree are used to generate personal and group signatures for authentication.
It achieves heterogeneous integration and interconnection of multiple types of access terminals, reduces authentication delays, alleviates network congestion, and meets the differentiated service needs of different terminal devices.
Smart Images

Figure CN116600291B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of wireless communication technology, and more specifically, to a large-scale heterogeneous terminal architecture and a large-scale heterogeneous terminal architecture access method. Background Art
[0002] With the development of technologies such as cloud computing, big data, artificial intelligence (AI), and 5G, various IoT services have also flourished, and the number of access terminals has increased dramatically. However, in 5G application scenarios, different types of access terminals have different computing capabilities, transmission capabilities, and security levels. The existing 5G Authentication Key Agreement Protocol (5G-AKA) and Extensible Authentication Protocol-AKA (EAP-AKA) authentication processes are single and rigid, and cannot provide service-oriented terminal security access solutions. In addition, in the existing authentication mechanism, each user equipment (UE) or terminal device must perform an authentication process when accessing the network or updating its location. This one-to-one authentication method will result in high authentication and re-authentication delays, and in massive machine type communication (mMTC) scenarios, it will also cause severe signaling congestion in the core network.
[0003] Therefore, under the premise of ensuring the basic communication security of users, it is an urgent problem to achieve heterogeneous integration and interconnection of multiple types of access terminals and meet differentiated security protection needs. Summary of the Invention
[0004] Some embodiments of the present application provide a large-scale heterogeneous terminal architecture and a large-scale heterogeneous terminal architecture access method that can at least partially solve the above-mentioned problems existing in the prior art.
[0005] According to one aspect of the present application, an access method for a large-scale heterogeneous terminal architecture is provided, which may include: classifying terminal devices based on communication delay to obtain a group authentication terminal device set and an independent authentication terminal device set; receiving an access authentication request from the terminal device, and dividing the terminal devices in the group authentication terminal device set into groups based on the access authentication request to obtain multiple terminal device groups; configuring a preamble code for the terminal devices in the group authentication terminal device set and the independent authentication terminal device set; and obtaining the access authentication request from the terminal device again, generating an access authentication scheme based on the preamble code, and authenticating the terminal device based on the access authentication scheme.
[0006] In one embodiment of the present application, the group authentication terminal devices are divided into groups based on the access authentication request to obtain multiple terminal device groups, which may include: setting an initial number of the terminal device group and an initial central terminal device; dividing the terminal devices in the group authentication terminal device set into groups based on the initial central terminal device, the initial number and the access authentication request to obtain multiple initial terminal device groups; calculating the similarity of the initial terminal device groups, wherein the similarity includes distance similarity and delay similarity; and comparing the distance similarity and the delay similarity with preset conditions, if the distance similarity and the delay similarity meet the preset conditions, then using the initial terminal device group as the terminal device group, if the distance similarity and the delay similarity do not meet the preset conditions, then re-dividing the terminal device group.
[0007] In one embodiment of the present application, the access authentication request may include geographic location, service requirements, security level, and quality of service (QoS) requirements, wherein the service requirements may also include communication delay, device type, and mobility.
[0008] In one embodiment of the present application, configuring preamble codes for the terminal devices in the group authentication terminal device set and the independent authentication terminal device set may include: obtaining the number of preamble codes in a cell and a number prediction result, wherein the number prediction result includes the number of the terminal devices in the group authentication terminal device set and the number of the terminal devices in the independent authentication terminal device set; and dividing the preamble codes into a first preamble code set and a second preamble code set based on the number prediction result, and allocating the corresponding preamble code in the first preamble code set or the second preamble code set to each terminal device, and allocating a corresponding access prohibition factor.
[0009] In one embodiment of the present application, obtaining the access authentication request of the terminal device again and generating an access authentication scheme based on the preamble code may include: obtaining a preset value of the terminal devices accessing the network, and comparing the quantity prediction result with the preset value to obtain the access authentication scheme, wherein the access authentication scheme includes: in response to the quantity prediction result being less than or equal to the preset value, obtaining the access authentication requests of all the terminal devices and performing authentication; or in response to the quantity prediction result being greater than the preset value, determining the network access order based on the prohibited access factor, wherein determining the network access order based on the prohibited access factor includes: obtaining the access authentication request of the terminal device in the independent authentication terminal device set and performing authentication, and when the independent authentication terminal device set completes authentication, obtaining the access authentication request of the terminal device in the group authentication terminal device set and performing authentication.
[0010] In one embodiment of the present application, authenticating the terminal device based on the access authentication scheme may also include: screening the terminal device group leader in each of the terminal device groups in the group authentication terminal device set based on communication capabilities; verifying the communication capabilities of the terminal device group leader to obtain a verification result; and completing the access authentication of the terminal device group leader based on the verification result.
[0011] In one embodiment of the present application, completing the access authentication of the terminal device group leader based on the verification result may include: the terminal device group leader obtaining a group key; constructing a reverse hash tree, and obtaining a personal key of each of the terminal devices based on the reverse hash tree and the group key; generating a corresponding personal signature based on the personal key of the terminal device; aggregating the personal signatures corresponding to the terminal devices in the group authentication terminal device set to generate a group signature; and completing the authentication of the terminal device based on the personal signature and the group signature.
[0012] In one embodiment of the present application, the method may also include a base station accepting the access authentication request of the terminal device and performing data aggregation and forwarding; translating the access authentication request to obtain translation information; selecting an access authentication algorithm and a key management scheme based on the translation information; and feeding back the access authentication algorithm and the key management scheme to the terminal device.
[0013] On the other hand, the present application provides a large-scale heterogeneous terminal architecture, which may include: a terminal side, used to generate an access authentication request; a network side, used to classify terminal devices based on communication delay to obtain a group authentication terminal device set and an independent authentication terminal device set; receiving the access authentication request of the terminal device, and grouping the terminal devices in the group authentication terminal device set based on the access authentication request to obtain multiple terminal device groups; configuring a preamble code for the terminal devices in the group authentication terminal device set and the independent authentication terminal device set; and obtaining the access authentication request of the terminal device again, generating an access authentication scheme based on the preamble code, and authenticating the terminal device based on the access authentication scheme.
[0014] In one embodiment of the present application, the network side can also be used to: set the initial number and the initial central terminal device of the terminal device group; group the terminal devices in the group authentication terminal device set based on the initial central terminal device, the initial number and the access authentication request to obtain multiple initial terminal device groups; calculate the similarity of the initial terminal device group, wherein the similarity includes distance similarity and delay similarity; and compare the distance similarity and the delay similarity with preset conditions. If the distance similarity and the delay similarity meet the preset conditions, the initial terminal device group is used as the terminal device group; if the distance similarity and the delay similarity do not meet the preset conditions, the terminal device group is re-divided.
[0015] In one embodiment of the present application, the access authentication request may include geographic location, service requirements, security level, and quality of service (QoS) requirements, wherein the service requirements may also include communication delay, device type, and mobility.
[0016] In one embodiment of the present application, the network side can also be used to: obtain the number of preamble codes in the cell and the number prediction result, wherein the number prediction result includes the number of terminal devices in the group authentication terminal device set and the number of terminal devices in the independent authentication terminal device set; and divide the preamble codes into a first preamble code set and a second preamble code set based on the number prediction result, and allocate the corresponding preamble code in the first preamble code set or the second preamble code set to each terminal device, and allocate a corresponding access prohibition factor.
[0017] In one embodiment of the present application, the network side can also be used to: obtain a preset value of the terminal devices accessing the network, and compare the quantity prediction result with the preset value to obtain the access authentication scheme, wherein the access authentication scheme includes: in response to the quantity prediction result being less than or equal to the preset value, obtaining the access authentication requests of all the terminal devices and performing authentication; or in response to the quantity prediction result being greater than the preset value, determining the network access order based on the prohibited access factor, wherein determining the network access order based on the prohibited access factor includes: obtaining the access authentication request of the terminal device in the independent authentication terminal device set and performing authentication, and when the independent authentication terminal device set completes authentication, obtaining the access authentication request of the terminal device in the group authentication terminal device set and performing authentication.
[0018] In one embodiment of the present application, the network side can also be used to: screen the terminal device group leader in each terminal device group in the group authentication terminal device set based on communication capabilities; verify the communication capabilities of the terminal device group leader to obtain a verification result; and complete the access authentication of the terminal device group leader based on the verification result.
[0019] In one embodiment of the present application, the network side can also be used for: the terminal device group leader obtains the group key; constructs a reverse hash tree, and obtains the personal key of each terminal device based on the reverse hash tree and the group key; generates a corresponding personal signature based on the personal key of the terminal device; aggregates the personal signatures corresponding to the terminal devices in the group authentication terminal device set to generate a group signature; and completes the authentication of the terminal device based on the personal signature and the group signature.
[0020] In one embodiment of the present application, the network side can also be used for: the base station accepts the access authentication request of the terminal device, and performs data aggregation and forwarding; translates the access authentication request to obtain translation information; selects an access authentication algorithm and a key management scheme based on the translation information; and feeds back the access authentication algorithm and the key management scheme to the terminal device.
[0021] According to an exemplary embodiment of the present application, by classifying terminal devices based on communication latency, a group authentication terminal device set and an independent authentication terminal device set are obtained. The terminal devices in the group authentication terminal device set are then divided into groups, resulting in multiple terminal device groups and corresponding preamble codes. This allows the network to provide differentiated services to the terminal devices. This can alleviate network congestion during concurrent connections to a certain extent. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Other features, objects and advantages of the present application will become more apparent from the detailed description of non-limiting embodiments made with reference to the following drawings, in which:
[0023] Figure 1 This is a schematic diagram of the 5G-AKA authentication process in the prior art;
[0024] Figure 2 1 is a schematic diagram of a large-scale heterogeneous terminal architecture 1000 according to an embodiment of the present application;
[0025] Figure 3 Flowchart of an access method 2000 based on a large-scale heterogeneous terminal architecture according to an embodiment of the present application;
[0026] Figure 4 This is a flow chart of dividing terminal devices into groups according to an exemplary embodiment of the present application;
[0027] Figure 5 Flowchart of configuring a preamble according to an exemplary embodiment of the present application;
[0028] Figure 6 A schematic diagram of a structure for authenticating a terminal device based on an access authentication scheme according to an exemplary embodiment of the present application;
[0029] Figure 7 A flowchart of authenticating a terminal device based on an access authentication scheme according to an exemplary embodiment of the present application;
[0030] Figure 8 Flowchart of an access authentication process according to an exemplary embodiment of the present application;
[0031] Figure 9 The present invention is a flowchart of heterogeneous integration of a terminal device according to an exemplary embodiment of the present application. DETAILED DESCRIPTION
[0032] For a better understanding of the present application, various aspects of the present application will be described in more detail with reference to the accompanying drawings. It should be understood that these detailed descriptions are merely descriptions of exemplary embodiments of the present application and are not intended to limit the scope of the present application in any way. Throughout the specification, the same reference numerals refer to the same elements. The expression "and / or" includes any and all combinations of one or more of the associated listed items.
[0033] In the accompanying drawings, the size, dimensions, and shapes of the elements have been slightly adjusted for ease of illustration. The accompanying drawings are for illustration only and are not drawn strictly to scale. As used herein, the terms "substantially," "approximately," and similar terms are used to indicate approximations, not degrees, and are intended to illustrate inherent deviations in measurements or calculations that would be recognized by a person of ordinary skill in the art. In addition, in this application, the order in which the steps are described does not necessarily represent the order in which these steps would occur in actual operation, unless otherwise specified or inferred from the context.
[0034] It should also be understood that expressions such as "comprises," "including," "having," "includes," and / or "comprising" are open rather than closed expressions in this specification, indicating the presence of the stated features, elements, and / or components, but do not exclude the presence of one or more other features, elements, components, and / or combinations thereof. In addition, when expressions such as "at least one of..." appear after a list of listed features, they modify the entire list of features rather than just the individual elements in the list. In addition, when describing embodiments of the present application, "may" is used to mean "one or more embodiments of the present application." And, the term "exemplary" is intended to refer to an example or illustration.
[0035] Unless otherwise defined, all words used herein (including engineering terms and scientific and technological terms) have the same meaning as commonly understood by those skilled in the art to which this application belongs. It should also be understood that, unless otherwise specified in this application, words defined in commonly used dictionaries should be interpreted as having the same meaning as they do in the context of the relevant technology, and should not be interpreted in an idealized or overly formal sense.
[0036] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in this application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0037] With its outstanding performance of high speed, large capacity and low latency, 5G is gradually supporting three typical application scenarios: enhanced mobile bandwidth, ultra-reliable low-latency communication (uRLLC) and massive machine type communication (mMTC). It is promoting the rapid development of new fields such as augmented reality (AR), virtual reality (VR), autonomous driving, industrial Internet, and telemedicine. However, it has also caused problems in network security and data privacy protection.
[0038] Among the three application scenarios of 5G network, the large-scale machine communication scenario is mainly used to solve the communication problem of a large number of Internet of Things devices, and 5G network needs to meet higher traffic density, energy density and connection number density. As the main form of Internet of Things, a large number of machine type communication devices need to be deployed in the future mobile cellular network, and the number of access terminal devices also increases sharply. Among a large number of terminal devices, there are the following problems:
[0039] 1. The terminal device types are various and the functions are different. For example, part of the access terminal device has strong ability and has certain computing and storage ability; part of the access terminal device has no SIM card or USIM card for identity identification, and the identity can be IP address, MAC or digital certificate; some low-function terminal devices even have no specific hardware to securely store identity and authentication credentials.
[0040] 2. The 5G authentication process is single and the access delay is high. For example, the existing access authentication algorithm is relatively single, and the traditional AKA authentication process of ordinary user equipment is used to realize mutual authentication with the 5G core network, which will cause high authentication and re-authentication delay, and also cause serious signaling congestion of the core network. And when facing the increasing types of business, it is impossible to avoid the decline of access success rate and the super high access delay.
[0041] 3. There are security problems and privacy protection problems in 5G access authentication. For example, the current 5G access authentication mechanism transmits the authentication response message in plaintext, which has security problems such as linkability attack and location tracking threat. Specifically: the identity authentication response message fed back by the terminal device to the network is transmitted in plaintext form on the air interface, if the attacker eavesdrops the message on the air interface through certain technical means, it can analyze the current state of the terminal based on the authentication result information and failure reason information, and use this vulnerability to determine whether the target user is in a specific location.
[0042] Existing network communications are based on the new 5G network architecture, which consists of four main components: user equipment (UE), radio access network (RAN), 5G core network (5GC), and data network (DN). UEs can include mobile phones, smart terminals, multimedia devices, and streaming media devices; RAN enables user equipment to wirelessly access base stations; 5GC manages data; and DN stores data.
[0043] 5G networks support multiple authentication methods, such as 5G KA and EAPAKA. However, the authentication process in all of them involves deriving the key information required for establishing a secure connection between the user and the network. This article will use the 5G KA authentication process as an example. Figure 1 This is a schematic diagram of the 5G-AKA authentication process in the prior art. Figure 1 As shown, the 5G-AKA authentication process may include the following steps:
[0044] Step S10: The user equipment sends an access request;
[0045] Step S20: After receiving the access request, the access and mobility management function module obtains the user hidden identifier and user equipment parameters of the user equipment and performs an authorization verification request;
[0046] Step S30: The authentication server function module determines the information sending authority of the access and mobility management function module based on the service network parameters. If the access and mobility management function module does not have the information sending authority, the user equipment sends an access request again.
[0047] Step S40: If the access and mobility management function module has the information sending authority, the authentication server function module obtains the authority verification request and sends an authentication request to the unified data management function module, wherein the authentication request carries the user permanent identifier and the user hidden identifier;
[0048] Step S50: The unified data management function module calculates the environment authentication vector and the user equipment information parameters, and sends the user equipment information parameters to the authentication server function module;
[0049] Step S60: The authentication server function module, the access and mobility management function module and the user equipment complete mutual authentication.
[0050] In the prior art, a user device sends an access request to start establishing a connection with the network. The Access and Mobility Management Function (AMF) module can obtain the user hidden identifier and user device parameters of the user device and send a permission verification request to the Authentication Server Function (AUSF) module. When the AUSF module receives the permission verification request, it can determine whether the AMF module can send information. If the AMF module cannot send information, steps S10 and S20 are repeated; if the AMF module can send information, the AUSF obtains the permission verification request and sends an authentication request to the Unified Data Management (UDM) module, wherein the authentication request carries the Subscription Permanent Identifier (SUPI) and the Subscription Concealed Identifier (SUCI). The UDM module calculates the environment authentication vector (5GHEAV) and uses an algorithm to derive user equipment information parameters, which may include MAC, expected user response (ExpectedUserResponse, referred to as XRES), encryption algorithm key (CK), integrity protection algorithm key (IK) and AK key information, and sends them to the AUSF module. The AUSF module, AMF module and UE complete mutual authentication, perform authentication and key negotiation with the UE, and obtain the encryption algorithm key CK and integrity protection algorithm key IK for subsequent secure communication.
[0051] The above authentication process is rigid and single-minded, making it impossible to design effective congestion-mitigating access strategies to meet the differentiated service needs of different services. Each device that accesses the network or updates its location requires an authentication process. In mMTC scenarios, the traditional one-to-one authentication method increases network signaling, leading to network congestion.
[0052] Figure 2 Schematic diagram of a large-scale heterogeneous terminal architecture 1000 according to an embodiment of the present application. Figure 2As shown, a large-scale heterogeneous terminal architecture 1000 may include a terminal side and a network side, wherein the network side may include an access network, a service network, and a home network. The terminal side is configured to generate an access authentication request, while the network is configured to classify terminal devices based on communication latency to obtain a group authentication terminal device set and an independent authentication terminal device set; receive an access authentication request from a terminal device, and group the terminal devices in the group authentication terminal device set based on the access authentication request to obtain multiple terminal device groups; configure preambles for the terminal devices in the group authentication terminal device set and the independent authentication terminal device set; and again obtain an access authentication request from the terminal device, generate an access authentication scheme based on the preamble, and authenticate the terminal device based on the access authentication scheme.
[0053] Figure 3 FIG. 2 is a flow chart of an access method 2000 based on a large-scale heterogeneous terminal architecture according to an embodiment of the present application. Figure 3 As shown, the access method 2000 based on a large-scale heterogeneous terminal architecture may include:
[0054] Step S100: Classify the terminal devices based on the communication delay to obtain a group authentication terminal device set and an independent authentication terminal device set;
[0055] Step S200: receiving an access authentication request from a terminal device, and dividing the terminal devices in the group authentication terminal device set into groups based on the access authentication request to obtain multiple terminal device groups;
[0056] Step S300: configuring a preamble code for the terminal devices in the group authentication terminal device set and the independent authentication terminal device set; and
[0057] Step S400: obtaining the terminal device access authentication request again, generating an access authentication scheme based on the preamble, and authenticating the terminal device based on the access authentication scheme.
[0058] The following will be combined Figure 2 and Figure 3 The specific contents of each step of the above-mentioned large-scale heterogeneous terminal architecture access method 2000 are described in detail.
[0059] Step S100
[0060] In an exemplary embodiment of the present application, the access network first classifies terminal devices based on communication latency to obtain a set of group-authenticated terminal devices and a set of independently authenticated terminal devices. 5G primarily encompasses three application scenarios: enhanced mobile broadband (eMBB), ultra-reliable and low-latency connectivity (uRLLC), and massive machine-type communications (mMTC). eMBB is a user-device-centric application scenario with ultra-high transmission data rates. uRLLC requires a connection latency of 1ms and supports high-reliability connections under high-speed mobility, primarily targeting specialized applications such as the Internet of Vehicles, industrial control, and telemedicine. mMTC primarily enables deep integration across various vertical industries, such as smart cities, smart homes, and environmental monitoring. The Internet of Everything (IoE) offers low data rates and is latency-insensitive. Different application scenarios can correspond to different communication latencies. For example, the uRLLC scenario has a latency requirement of 0-1ms, the eMBB scenario has a latency requirement of 1-10ms, and the mMTC scenario has a service requirement of 10-1000ms. Because uRLLC and eMBB have higher communication latency requirements, while mMTC has lower communication latency requirements, user devices can be categorized into two types based on communication latency: a group-authenticated terminal device set and an independently authenticated terminal device set. The communication latency of user devices in the group-authenticated terminal device set is greater than that of user devices in the independently authenticated terminal device set. For example, the terminal devices in the group-authenticated terminal device set use one-to-many authentication, which may include terminal devices used in the mMTC application scenario. The terminal devices in the independently authenticated terminal device set use one-to-one authentication, which may include terminal devices used in the uRLLC and eMBB application scenarios.
[0061] According to an exemplary embodiment of the present application, by classifying terminal devices based on communication delay to obtain a group authentication terminal device set and an independent authentication terminal device set, the access authentication of user devices can be reasonably arranged in the subsequent communication process, which can meet the communication delay of user devices and reduce signaling congestion to a certain extent.
[0062] Step S200
[0063] In an exemplary embodiment of the present application, after obtaining a group authentication terminal device set and an independent authentication terminal device set, when the access network receives a terminal device access authentication request, the terminal devices in the group authentication terminal device set are divided into groups based on the access authentication request to obtain multiple terminal device groups. Exemplarily, when a user device first accesses the network, a conventional contention-based random access method can be used to establish a connection with a base station. The user device can send an access authentication request to the base station, wherein the access authentication request may include a geographic location, service requirements, security level, and quality of service (QoS) requirements. The service requirements may also include communication latency, device type, mobility, etc.
[0064] Figure 4 The flowchart of dividing terminal devices into groups according to an exemplary embodiment of the present application is shown in FIG.
[0065] like Figure 4 As shown, dividing the terminal device groups may include the following steps:
[0066] Step S210: setting the initial number of terminal device groups and the initial central terminal device;
[0067] Step S220: Dividing the terminal devices in the group authentication terminal device set into groups based on the initial central terminal device, the initial number, and the access authentication request to obtain multiple initial terminal device groups;
[0068] Step S230: Calculating the similarity of the initial terminal device group, wherein the similarity includes distance delay similarity and delay similarity;
[0069] Step S240: Compare the distance similarity and the delay similarity with the preset conditions. If the distance similarity and the delay similarity meet the preset conditions, the initial terminal device group is used as the terminal device group. If the distance similarity and the delay similarity do not meet the preset conditions, the terminal device group is re-divided.
[0070] Exemplarily, the access network can set the initial number of terminal device groups and the initial central terminal device based on the sum of squared errors (SSE) of the terminal devices in the group authentication terminal device set. The terminal devices in the group authentication terminal device set are grouped based on the initial central terminal device, the initial number, and the access authentication request, and divided into multiple initial terminal device groups. Then, the distance delay similarity and delay similarity of the initial terminal device groups are calculated, and the similarity is determined. The preset condition can be a similarity threshold. If the similarity of the initial terminal device group is greater than or equal to the similarity threshold, the division result of the initial terminal device group is used as the final division result to obtain the terminal device group; if the similarity of the initial terminal device group is less than the similarity threshold, steps S210 to S230 are repeated until the similarity of the initial terminal device group is greater than or equal to the similarity threshold, and the group division of the terminal devices is completed.
[0071] According to an exemplary embodiment of the present application, by dividing the terminal devices in the group authentication terminal device set into groups based on the access authentication request, multiple terminal device groups are obtained, and each terminal device group can have the same or similar communication delay requirements to facilitate the subsequent selection of the same authentication service and authentication scheme.
[0072] Step S300
[0073] In an exemplary embodiment of the present application, after completing the division of terminal devices into groups, the access network may configure preamble codes for terminal devices in the group authentication terminal device set and the independent authentication terminal device set. Figure 5 FIG. 1 is a flow chart of configuring a preamble according to an exemplary embodiment of the present application. Figure 5 As shown, configuring the preamble may include the following steps:
[0074] Step S310: obtaining the number of preambles in the cell and a number prediction result, wherein the number prediction result includes the number of terminal devices in the group authentication terminal device set and the number of terminal devices in the independent authentication terminal device set; and
[0075] Step S320: Divide the preambles into a first preamble set and a second preamble set based on the quantity prediction result, and allocate a corresponding preamble in the first preamble set or the second preamble set to each terminal device, and allocate a corresponding access prohibition factor.
[0076] Exemplarily, the access network can provide different numbers of preambles for terminal devices with different communication delay requirements in multiple business scenarios, send them to the terminal side, and provide them with differentiated access services. Specifically, first obtain the number M of preambles in the cell and the prediction results of the number of terminal devices, wherein the number prediction results include the number X of terminal devices in the group authentication terminal device set and the number Y of terminal devices in the independent authentication terminal device set. Then, based on the number prediction results, the preambles are divided into a first preamble set M1 and a second preamble set M2, and a corresponding preamble is allocated to each terminal device in the first preamble set or the second preamble set and a corresponding access prohibition factor is allocated. The preambles in the first preamble set M1 are allocated to the terminal devices in the group authentication terminal device set, and the preambles in the second preamble set M2 are allocated to the terminal devices in the independent authentication terminal device set, wherein M2≥Y.
[0077] According to an exemplary embodiment of the present application, by allocating different numbers of preamble codes to a group authentication terminal device set and an independent authentication terminal device set, and allocating corresponding access factors, the network side can provide differentiated services for the terminal devices.
[0078] Step S400
[0079] In an exemplary embodiment of the present application, after preamble allocation is completed, the terminal device may regenerate an access authentication request, the access network may reacquire the terminal device's access authentication request, generate an access authentication scheme based on the preamble, and authenticate the terminal device based on the access authentication scheme. Generating the access authentication scheme based on the preamble may include: acquiring a preset number of terminal devices accessing the network, and comparing a quantity prediction result with the preset value to obtain the access authentication scheme, wherein the preset value may be the maximum number of terminal devices allowed to connect to the network. The access authentication scheme includes: when the quantity prediction result is less than or equal to the preset value, acquiring access authentication requests from all terminal devices and performing authentication, i.e., the total number of terminal devices accessing the network is less than the number of terminal devices that can connect to the network, and all terminal devices can access the network simultaneously. When the quantity prediction result is greater than the preset value, determining a network access order based on a prohibited access factor, wherein determining the network access order based on the prohibited access factor includes: acquiring access authentication requests from terminal devices in a set of independently authenticated terminal devices and performing authentication; after the independently authenticated terminal device set completes authentication, acquiring access authentication requests from terminal devices in a set of group authenticated terminal devices and performing authentication.
[0080] According to the exemplary embodiments of this application, by generating an access authentication scheme based on the preamble and the access barring factor, it is possible to ensure that terminal devices sensitive to communication latency obtain the preamble and receive preferential access to the network, thereby meeting the terminal devices' requirements for communication latency. Furthermore, the access authentication scheme can further ensure the maximum number of terminal devices connected to the network, thereby reducing terminal device authentication time to a certain extent.
[0081] In an exemplary embodiment of the present application, after obtaining the access authentication scheme, the terminal device may be authenticated based on the access authentication scheme. Figure 6 The figure is a schematic diagram of a structure for authenticating a terminal device based on an access authentication scheme according to an exemplary embodiment of the present application. Figure 7 FIG. 1 is a flow chart of authenticating a terminal device based on an access authentication scheme according to an exemplary embodiment of the present application. Figure 7 As shown, authenticating a terminal device based on an access authentication scheme may include the following steps:
[0082] Step S410: screening a terminal device group leader in each terminal device group in the group authentication terminal device set based on communication capabilities;
[0083] Step S420: Verify the communication capability of the terminal device group leader and obtain a verification result;
[0084] Step S430: Complete access authentication of the terminal device group leader based on the verification result.
[0085] For example, in combination Figure 6 and Figure 7 In each terminal device group within the group authentication terminal device set, the terminal devices can be sorted based on their communication capabilities, and the terminal device with the highest priority communication capability can be selected as the terminal device group leader. The terminal device group leader can then be verified and a verification result obtained. For example, the terminal device group leader can send a message to other terminal devices in the group. If all other terminal devices receive the message, it indicates that the terminal device group leader's communication capability is normal. If any terminal device cannot receive the terminal device group leader's message, the terminal device with the second highest priority communication capability can be selected as the terminal device group leader, and verification can be performed again.
[0086] According to the exemplary implementation of the present application, by screening the terminal device group leader in each terminal device group and verifying the communication capabilities of the terminal device group leader, it can be ensured that other terminal devices in the group can receive the information sent by the communication group leader, thereby providing a guarantee for subsequent access authentication in a group manner.
[0087] Figure 8 FIG. 1 is a flow chart of an access authentication process according to an exemplary embodiment of the present application. Figure 8 As shown, the access authentication process may include the following steps:
[0088] Step S431: The terminal device group leader obtains the group key;
[0089] Step S432: construct a reverse hash tree, and obtain the personal key of each terminal device based on the reverse hash tree and the group key;
[0090] Step S433: Generate a corresponding personal signature based on the personal key of the terminal device;
[0091] Step S434: Aggregate the individual signatures corresponding to the terminal devices in the group authentication terminal device set to generate a group signature; and
[0092] Step S435: Complete the authentication of the terminal device based on the personal signature and the group signature.
[0093] For example, the terminal device group leader obtains the group key and then constructs a reverse hash tree. Each node of the reverse hash tree corresponds to a terminal device in the group. Using the group key and hash functions on the left and right branches, each terminal device's individual group key is derived. A corresponding personal signature is generated based on the terminal device's personal key. For terminal devices in the set of independently authenticated terminal devices, the personal key can be directly obtained and a corresponding personal signature generated. Furthermore, the personal signatures corresponding to the terminal devices in the group authentication terminal device set are aggregated to generate a group signature. Terminal device authentication is then completed based on the personal signature and the group signature.
[0094] According to an exemplary embodiment of the present application, the terminal device group leader uses the group key and a reverse hash tree to obtain the personal key and corresponding personal signature of each terminal device. The personal signatures are then aggregated to obtain a group signature. The personal signatures of the terminal devices in the independently authenticated terminal device set and the group signature corresponding to the terminal device group in the group authenticated terminal device set are verified. While ensuring that all terminal devices can be authenticated, using the group signature for verification allows all terminal devices in the group to be authenticated at once, which can alleviate network congestion when concurrent connections occur.
[0095] In the exemplary implementation of the present application, heterogeneous integration and interconnection of different types of terminal devices can be further achieved. Figure 9 FIG. 1 is a flow chart of heterogeneous integration of a terminal device according to an exemplary embodiment of the present application. Figure 9 As shown, the heterogeneous integration of terminal devices may include the following steps:
[0096] Step S500: The base station accepts the access authentication request from the terminal device and performs data aggregation and forwarding;
[0097] Step S600: translating the access authentication request to obtain translation information;
[0098] Step S700: Selecting an access authentication algorithm and a key management scheme based on the translated information;
[0099] Step S800: Feedback the access authentication algorithm and key management solution to the terminal device.
[0100] Exemplarily, the base station accepts the access authentication request from the terminal device, which may include a personal signature and a group signature. The base station may aggregate and forward the access authentication request. The AMF located in the service network aggregates the user request information in the access authentication request, extracts the pre-distributed training model based on QoS requirements, security level, etc. through the demand translation module, obtains the translation information, and forwards the translation information to the home network. The AUSF located in the home network provides differentiated authentication and authorization services. For example, the access authentication algorithm and key management scheme are selected based on the translated information, and the KGC allocates the key and feeds it back to the user through the selected access point.
[0101] According to the exemplary implementation of the present application, a demand translation module is added to the service network, and the home network integrates different access authentication methods. The access authentication algorithm and key management scheme are selected according to the information translated by the service network to achieve heterogeneous integration and interconnection of different types of terminals.
[0102] The above-described specific embodiments further illustrate the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the above description is merely a specific embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A method for accessing a large-scale heterogeneous terminal architecture, characterized in that: The method comprises: Classify the terminal devices based on the communication delay to obtain a group authentication terminal device set and an independent authentication terminal device set; receiving an access authentication request from the terminal device, and dividing the terminal devices in the group authentication terminal device set into groups based on the access authentication request to obtain a plurality of terminal device groups; configuring a preamble for the terminal devices in the group authentication terminal device set and the independent authentication terminal device set; and The access authentication request of the terminal device is obtained again, an access authentication scheme is generated based on the preamble, and the terminal device is authenticated based on the access authentication scheme.
2. The access method for large-scale heterogeneous terminal architecture according to claim 1, characterized in that: Dividing the group authentication terminal devices into groups based on the access authentication request to obtain a plurality of terminal device groups, including: Setting the initial number of the terminal device group and the initial central terminal device; Dividing the terminal devices in the group authentication terminal device set into groups based on the initial central terminal device, the initial number, and the access authentication request to obtain a plurality of initial terminal device groups; Calculating similarity of the initial terminal device group, wherein the similarity includes distance similarity and delay similarity; and The distance similarity and the delay similarity are compared with preset conditions. If the distance similarity and the delay similarity meet the preset conditions, the initial terminal device group is used as the terminal device group. If the distance similarity and the delay similarity do not meet the preset conditions, the terminal device group is re-divided.
3. The access method for large-scale heterogeneous terminal architecture according to claim 1, characterized in that: The access authentication request includes geographic location, service requirements, security level, and quality of service (QoS) requirements, wherein the service requirements include communication delay, device type, and mobility.
4. The access method for large-scale heterogeneous terminal architecture according to claim 1, characterized in that: Configuring a preamble for the terminal devices in the group authentication terminal device set and the independent authentication terminal device set includes: Acquire the number of preambles in a cell and a number prediction result, wherein the number prediction result includes the number of the terminal devices in the group authentication terminal device set and the number of the terminal devices in the independent authentication terminal device set; and The preamble codes are divided into a first preamble code set and a second preamble code set based on the quantity prediction result, and the corresponding preamble code is allocated to each terminal device in the first preamble code set or the second preamble code set, and a corresponding access prohibition factor is allocated.
5. The access method for large-scale heterogeneous terminal architecture according to claim 4, characterized in that: Re-acquiring the access authentication request from the terminal device, and generating an access authentication scheme based on the preamble, including: Obtaining a preset value of the terminal devices accessing the network, and comparing the quantity prediction result with the preset value to obtain the access authentication scheme, wherein the access authentication scheme includes: In response to the quantity prediction result being less than or equal to the preset value, obtaining the access authentication requests of all the terminal devices and performing authentication; or In response to the quantity prediction result being greater than the preset value, the network access order is determined based on the access prohibition factor, wherein the network access order is determined based on the access prohibition factor, including: obtaining the access authentication request of the terminal device in the independent authentication terminal device set and performing authentication; when the independent authentication terminal device set completes authentication, obtaining the access authentication request of the terminal device in the group authentication terminal device set and performing authentication.
6. The access method for large-scale heterogeneous terminal architecture according to claim 1, characterized in that: Authenticating the terminal device based on the access authentication scheme further includes: screening a terminal device group leader in each terminal device group in the group authentication terminal device set based on communication capabilities; Verifying the communication capability of the terminal device group leader to obtain a verification result; and Complete the access authentication of the terminal device group leader based on the verification result.
7. The access method for large-scale heterogeneous terminal architecture according to claim 6, characterized in that: Completing access authentication of the terminal device group leader based on the verification result includes: The terminal device group leader obtains the group key; Constructing a reverse hash tree, and obtaining a personal key of each terminal device based on the reverse hash tree and the group key; generating a corresponding personal signature based on the personal key of the terminal device; Aggregating the individual signatures corresponding to the terminal devices in the group authentication terminal device set to generate a group signature; and The authentication of the terminal device is completed based on the personal signature and the group signature.
8. The access method for a large-scale heterogeneous terminal architecture according to any one of claims 1 to 7, characterized in that: The method further comprises: The base station accepts the access authentication request of the terminal device and performs data aggregation and forwarding; Translating the access authentication request to obtain translation information; selecting an access authentication algorithm and a key management scheme based on the translated information; and Feedback the access authentication algorithm and the key management scheme to the terminal device.
9. A large-scale heterogeneous terminal architecture, characterized in that: The terminal architecture includes: On the terminal side, it is used to generate an access authentication request; On the network side, it is used to classify terminal devices based on communication delay and obtain a group authentication terminal device set and an independent authentication terminal device set; receiving an access authentication request from the terminal device, and dividing the terminal devices in the group authentication terminal device set into groups based on the access authentication request to obtain a plurality of terminal device groups; configuring a preamble for the terminal devices in the group authentication terminal device set and the independent authentication terminal device set; and The access authentication request of the terminal device is obtained again, an access authentication scheme is generated based on the preamble, and the terminal device is authenticated based on the access authentication scheme.
10. The large-scale heterogeneous terminal architecture according to claim 9, characterized in that: The network side is further used for: Setting the initial number of the terminal device group and the initial central terminal device; Dividing the terminal devices in the group authentication terminal device set into groups based on the initial central terminal device, the initial number, and the access authentication request to obtain a plurality of initial terminal device groups; Calculating the similarity of the initial terminal device group, wherein the similarity includes distance similarity and delay similarity; as well as The distance similarity and the delay similarity are compared with preset conditions. If the distance similarity and the delay similarity meet the preset conditions, the initial terminal device group is used as the terminal device group. If the distance similarity and the delay similarity do not meet the preset conditions, the terminal device group is re-divided.
11. The large-scale heterogeneous terminal architecture according to claim 9, characterized in that: The access authentication request includes geographic location, service requirements, security level, and quality of service (QoS) requirements, wherein the service requirements include communication delay, device type, and mobility.
12. The large-scale heterogeneous terminal architecture according to claim 9, characterized in that: The network side is further used for: Acquire the number of preambles in a cell and a number prediction result, wherein the number prediction result includes the number of the terminal devices in the group authentication terminal device set and the number of the terminal devices in the independent authentication terminal device set; and The preamble codes are divided into a first preamble code set and a second preamble code set based on the quantity prediction result, and the corresponding preamble code is allocated to each terminal device in the first preamble code set or the second preamble code set, and a corresponding access prohibition factor is allocated.
13. The large-scale heterogeneous terminal architecture according to claim 12, characterized in that: The network side is further used for: Obtaining a preset value of the terminal devices accessing the network, and comparing the quantity prediction result with the preset value to obtain the access authentication scheme, wherein the access authentication scheme includes: In response to the quantity prediction result being less than or equal to the preset value, obtaining the access authentication requests of all the terminal devices and performing authentication; or In response to the quantity prediction result being greater than the preset value, the network access order is determined based on the access prohibition factor, wherein the network access order is determined based on the access prohibition factor, including: obtaining the access authentication request of the terminal device in the independent authentication terminal device set and performing authentication; when the independent authentication terminal device set completes authentication, obtaining the access authentication request of the terminal device in the group authentication terminal device set and performing authentication.
14. The large-scale heterogeneous terminal architecture according to claim 9, characterized in that: The network side is further used for: screening a terminal device group leader in each terminal device group in the group authentication terminal device set based on communication capabilities; Verifying the communication capability of the terminal device group leader to obtain a verification result; as well as Complete the access authentication of the terminal device group leader based on the verification result.
15. The large-scale heterogeneous terminal architecture according to claim 14, characterized in that: The network side is further used for: The terminal device group leader obtains a group key; constructs a reverse hash tree, and obtains a personal key for each terminal device based on the reverse hash tree and the group key; generating a corresponding personal signature based on the personal key of the terminal device; Aggregating the individual signatures corresponding to the terminal devices in the group authentication terminal device set to generate a group signature; as well as The authentication of the terminal device is completed based on the personal signature and the group signature.
16. The large-scale heterogeneous terminal architecture according to any one of claims 9 to 15, characterized in that: The network side is further used for: The base station accepts the access authentication request of the terminal device and performs data aggregation and forwarding; Translating the access authentication request to obtain translation information; selecting an access authentication algorithm and a key management scheme based on the translated information; And feeding back the access authentication algorithm and the key management scheme to the terminal device.
Citation Information
Patent Citations
Group authentication method based on terminal equipment characteristics
CN114666788A
Access control device and authentication control method
IN201634029597A