Terminal authentication method and device of open network, electronic equipment and medium

CN116709320BActive Publication Date: 2026-08-21BEIJING UNIV OF POSTS & TELECOMM
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310644789.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-01
Publication Date
2026-08-21
Estimated Expiration
2043-06-01

AI Technical Summary

Technical Problem

然而,对于开环网络来说,由于其超低时延网络所服务的业务大多采用短包发送,因此完整性校验码的使用会导致短包数据信息的分片成倍增加,不仅浪费资源,同时也恶化了网络时延性能

Benefits of technology

[0035]本申请中,在多个接入点接收到用户终端当前发送的信号时,将用于反映信号状态的当前信号特征发送给锚节点,其中多个接入点中包括用户终端请求接入的待接入点;锚节点通过当前信号特征与历史信号特征集合的匹配度,检测用户终端的合法性,历史特征集合包括用户终端在第一历史时段中发送信号的特征集合;若锚节点检测到用户终端为合法终端,确定用户终端接入到待接入点。通过应用本申请的技术方案,可以由锚节点根据多个接入点各自接收到的用户终端的信号特征与该终端在历史时段发送过的信号特征进行比对,并只有在确定二者较为相似的情况下才会确定该终端合法。从而一方面实现一种通过物理层的认证方式来避免出现添加附加完整性验证码才可实现终端认证而导致的开销较大的弊端。另一方面也可以根据多个接入点接收到的信号特征进行比对的方式来进行终端身份的判决,进而也增加了认证结果的可靠性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116709320B_ABST
    Figure CN116709320B_ABST
Patent Text Reader

Abstract

The application discloses a terminal authentication method and device of an open-loop network, electronic equipment and a medium. By applying the technical solution of the application, the anchor node can compare the signal characteristics of the user terminal received by each of the plurality of access points with the signal characteristics sent by the terminal in the historical period, and only in the case where it is determined that the two are similar, it is determined that the terminal is legal. Thus, on the one hand, a physical layer authentication method is used to avoid the problem of high overhead caused by adding an additional integrity verification code to realize terminal authentication. On the other hand, the terminal identity can also be determined by comparing the signal characteristics received by the plurality of access points, thereby increasing the reliability of the authentication result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to communication technology, and in particular to a terminal authentication method, apparatus, electronic device, and medium for an open-loop network. Background Technology

[0002] Active open-loop networking is a novel network architecture that provides extremely low-latency services. It employs an open-loop transmission mode to minimize the complex control signaling interactions and feedback between user equipment and the network. This mode introduces new technical requirements for continuous authentication of on-network users.

[0003] In related technologies, most current wireless networks employ terminal authentication methods that attach integrity check codes to transmitted data, thereby implicitly authenticating users. However, for open-loop networks, since the services served by their ultra-low latency networks mostly use short packet transmission, the use of integrity check codes leads to a significant increase in the fragmentation of short packet data, wasting resources and degrading network latency performance. Therefore, the authentication method for user terminals in open-loop networks is not sufficiently efficient. Summary of the Invention

[0004] This application provides a terminal authentication method, apparatus, electronic device, and medium for open-loop networks. This solves the problem in related technologies where user terminal authentication in open-loop networks is time-consuming and costly.

[0005] According to one aspect of the embodiments of this application, a terminal authentication method for an open-loop network is provided, comprising:

[0006] When multiple access points receive the signal currently sent by the user terminal, the current signal characteristics reflecting the signal state are sent to the anchor node, wherein the multiple access points include the access point to be accessed by the user terminal.

[0007] The anchor node detects the legitimacy of the user terminal by matching the current signal features with the historical signal feature set. The historical feature set includes the signal feature set sent by each access point in the first historical time period.

[0008] If the anchor node detects that the user terminal is a legitimate terminal, it determines that the user terminal is connected to the access point.

[0009] Optionally, in another embodiment based on the method described above, the step of sending a set of current signal features reflecting the signal state to the anchor node when a signal currently sent by a user terminal is received at multiple access points includes:

[0010] When the access point receives the signal currently sent by the user terminal, it sends a first current signal feature reflecting the signal state to the anchor node; and,

[0011] When an access point receives a signal currently sent by the user terminal, it sends a second current signal feature reflecting the signal status to the anchor node, wherein the access point is an access point that the user terminal has accessed during the second historical time period.

[0012] Optionally, in another embodiment based on the method described above, the step of sending current signal features reflecting the signal state to the anchor node when multiple access points receive the signal currently sent by the user terminal includes:

[0013] When the access point receives the signal currently sent by the user terminal, it extracts the signal strength value, angle of arrival value, channel state information, in-phase / quadrature imbalance value, and carrier frequency offset value from the signal.

[0014] The signal strength value, angle of arrival value, channel state information, in-phase / quadrature imbalance value, and carrier frequency offset value are used as the current signal characteristics of the signal.

[0015] Optionally, in another embodiment based on the method described above in this application, the anchor node detects the legitimacy of the user terminal by the matching degree between the current signal features and the historical signal feature set, including:

[0016] The anchor node traverses the set of historical signal features to determine whether there is a historical access point that is the same as the access point.

[0017] If they exist, the historical signal features corresponding to the historical access point are compared with the current signal features, and the matching degree between the current signal features and the set of historical signal features is determined based on the result of the similarity comparison.

[0018] If it does not exist, the association between the current signal feature and the corresponding access point is stored in the historical signal feature set.

[0019] Optionally, in another embodiment based on the method described above in this application, determining the matching degree between the current signal feature and the historical signal feature set based on the result of the similarity comparison includes:

[0020] Obtain at least one historical vector value corresponding to the historical signal feature; and obtain at least one current vector value corresponding to the current signal feature;

[0021] Based on the similarity comparison between at least one of the historical vector values ​​and at least one of the current vector values, the matching degree between the current signal feature and the set of historical signal features is determined.

[0022] Optionally, in another embodiment based on the method described above in this application, the step of determining that the user terminal is connected to the access point if the anchor node detects that the user terminal is a legitimate terminal includes:

[0023] If the anchor node detects that the user terminal is a legitimate terminal;

[0024] The first downlink data is sent to the user terminal through the access point to be accessed; or, the second downlink data is sent to the user terminal through other base stations, wherein the second downlink data includes an access success message to inform the user terminal that it has successfully accessed the access point to be accessed.

[0025] Optionally, in another embodiment based on the method described above in this application, after detecting the legitimacy of the user terminal, the method further includes:

[0026] If the anchor node detects that the user terminal is an illegal terminal, it discards the current signal feature.

[0027] According to another aspect of the embodiments of this application, a terminal authentication device for an open-loop network is provided, comprising:

[0028] The receiving module is configured to send current signal characteristics reflecting the signal state to the anchor node when it receives a signal currently sent by the user terminal at multiple access points, wherein the multiple access points include the access point to be accessed by the user terminal.

[0029] The detection module is configured so that the anchor node detects the legitimacy of the user terminal by the matching degree between the current signal features and the historical signal feature set, wherein the historical feature set includes the signal feature set sent by each access point in the first historical time period;

[0030] The determination module is configured to determine that the user terminal is connected to the access point if the anchor node detects that the user terminal is a legitimate terminal.

[0031] According to another aspect of the embodiments of this application, an electronic device is provided, comprising:

[0032] Memory, used to store executable instructions; and

[0033] A display, used in conjunction with the memory to execute the executable instructions to perform the terminal authentication method of any of the above-described open-loop networks.

[0034] According to another aspect of the embodiments of this application, a computer-readable storage medium is provided for storing computer-readable instructions, which, when executed, perform the operation of any of the above-described open-loop network terminal authentication methods.

[0035] In this application, when multiple access points receive signals currently transmitted by a user terminal, they send current signal features reflecting the signal state to an anchor node. Among these access points are pending access points for which the user terminal requests access. The anchor node detects the legitimacy of the user terminal by comparing the current signal features with a set of historical signal features. The historical feature set includes the feature set of signals transmitted by the user terminal in a first historical time period. If the anchor node detects that the user terminal is a legitimate terminal, it determines that the user terminal has accessed the pending access point. By applying the technical solution of this application, the anchor node can compare the signal features of the user terminal received by each of the multiple access points with the signal features transmitted by the terminal in historical time periods, and only determine the terminal as legitimate if the two are found to be similar. This achieves a physical layer authentication method that avoids the drawback of high overhead caused by adding additional integrity verification codes for terminal authentication. Furthermore, it increases the reliability of the authentication result by comparing the signal features received by multiple access points to determine the terminal's identity.

[0036] The technical solution of this application will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0037] The accompanying drawings, which form part of this specification, illustrate embodiments of this application and, together with the description, serve to explain the principles of this application.

[0038] This application can be more clearly understood with reference to the accompanying drawings and the following detailed description, wherein:

[0039] Figure 1 This is a schematic diagram of a terminal authentication method for an open-loop network proposed in this application;

[0040] Figure 2 This is a schematic diagram of the system architecture of the open-loop network proposed in this application;

[0041] Figure 3 This is an overall flowchart of a terminal authentication method for an open-loop network proposed in this application;

[0042] Figure 4 This is a schematic diagram illustrating the steps of a terminal authentication method for an open-loop network proposed in this application.

[0043] Figure 5 This is a schematic diagram illustrating the steps of another open-loop network terminal authentication method proposed in this application;

[0044] Figure 6 A schematic diagram illustrating the steps of another open-loop network terminal authentication method proposed in this application;

[0045] Figure 7 This is a schematic diagram illustrating the steps of another open-loop network terminal authentication method proposed in this application;

[0046] Figure 8 This is a schematic diagram of the structure of an electronic device proposed in this application;

[0047] Figure 9 This is a schematic diagram of the structure of an electronic device proposed in this application. Detailed Implementation

[0048] Various exemplary embodiments of the present application will now be described in detail with reference to the accompanying drawings. It should be noted that, unless otherwise specifically stated, the relative arrangement, numerical expressions, and values ​​of the components and steps set forth in these embodiments do not limit the scope of the present application.

[0049] At the same time, it should be understood that, for ease of description, the dimensions of the various parts shown in the accompanying drawings are not drawn according to actual scale.

[0050] The following description of at least one exemplary embodiment is merely illustrative and is not intended to limit the scope of this application or its application or use.

[0051] Techniques, methods, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, such techniques, methods, and equipment should be considered part of the specification.

[0052] It should be noted that similar labels and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be discussed further in subsequent figures.

[0053] Furthermore, the technical solutions of the various embodiments of this application can be combined with each other, but only if they are based on the ability of those skilled in the art to implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be considered that such combination of technical solutions does not exist and is not within the scope of protection claimed by this application.

[0054] It should be noted that all directional indicators (such as up, down, left, right, front, back, etc.) in the embodiments of this application are only used to explain the relative positional relationship and movement of each component in a certain specific posture (as shown in the figure). If the specific posture changes, the directional indicator will also change accordingly.

[0055] The following is combined with Figures 1-7This application describes a terminal authentication method for open-loop networks according to exemplary embodiments thereof. It should be noted that the following application scenarios are shown only to facilitate understanding of the spirit and principles of this application, and the embodiments of this application are not limited in any way. Rather, the embodiments of this application can be applied to any applicable scenario.

[0056] This application also proposes a terminal authentication method, apparatus, electronic device, and medium for open-loop networks.

[0057] Figure 1 A schematic flowchart illustrating a terminal authentication method for an open-loop network according to an embodiment of this application is shown. Figure 1 As shown, the method includes:

[0058] S101, when multiple access points receive the signal currently sent by the user terminal, the current signal characteristics used to reflect the signal status are sent to the anchor node, where the multiple access points include the access point to be accessed by the user terminal.

[0059] S102, the anchor node detects the legitimacy of the user terminal by matching the current signal features with the historical signal feature set. The historical feature set includes the feature set of signals sent by the user terminal in the first historical period.

[0060] S103, if the anchor node detects that the user terminal is a legitimate terminal, it determines that the user terminal is connected to the access point.

[0061] Currently, most wireless networks implicitly authenticate users by attaching integrity check codes to transmitted data. However, ultra-low latency networks primarily serve services that use short packet transmission. The use of integrity check codes leads to a significant increase in the fragmentation of short packet data, wasting resources and degrading network latency. Physical layer security authentication technology, on the other hand, can verify user data without introducing additional information.

[0062] Furthermore, in existing communication networks, most security authentication schemes using the physical layer are implemented for a single base station, and authentication is required through upper-layer assistance during handover.

[0063] Furthermore, in active open-loop networks, multiple access points (APs) typically form a virtual cell centered on the user terminal (UE) to provide data communication services to that UE. Since APs have a smaller coverage area compared to traditional base stations in other communication networks, AP handover becomes more frequent when the UE moves. Therefore, the authentication methods for user terminals in related technologies not only waste resources but also increase network latency.

[0064] To address the aforementioned problems, this application proposes a terminal authentication method for open-loop networks. The idea is that the anchor node compares the signal characteristics of the user terminal received by multiple access points with the signal characteristics sent by the terminal in historical time periods, and only determines that the terminal is legitimate if the two are found to be similar.

[0065] like Figure 2 As shown, the open-loop network in this embodiment of the application can be a wireless access portion consisting of one or more access nodes (APs) and an anchor node (AN) that manages the APs.

[0066] The AN (Access Controller) has certain computing and storage capabilities to manage the access network and is directly connected to the core network. Each AN manages numerous APs within a certain range. When a user terminal (UE) (such as a mobile phone, computer, robot, or other smart device) is within the network service range, multiple APs form a virtual cell around the user and use CoMP (Cooperative Membership) technology to collaboratively provide services.

[0067] In one approach, the access portion of the active open-loop network mainly consists of a two-layer structure: AN and AP. The AN is primarily responsible for coordinating radio resources, managing data transmitted from the AP, and performing other management functions.

[0068] Specifically, an AN (Application Network) comprises multiple APs (Access Points). Each AP has a relatively small coverage area and is distributed throughout the AN's service area to jointly provide spatial coverage. When providing services to a UE (User Equipment), the multiple APs centered around the UE collaborate to form a virtual cell and jointly provide data services. As an example, multi-point transmission technology is used to ensure transmission reliability when transmitting data.

[0069] In one approach, to minimize latency, the open-loop network allows the UE to take the initiative in transmission during virtual cell establishment and uplink data transmission. This means that the UE can independently and proactively select and access radio resources in one or more APs without waiting for feedback.

[0070] In another approach, the terminal authentication method proposed in this application can be a method of authentication performed at the physical layer. As an example, it could be a security authentication method that utilizes the spatiotemporal uniqueness of the wireless channel characteristics of a UE's transmitted signal to determine the UE's identity.

[0071] For example, the AP can determine the legitimacy of the sender's identity by comparing the similarity of the signal characteristics transmitted by the same UE at different times (i.e., the current time period and the historical time period), thereby achieving the purpose of preventing attackers from tampering or forging.

[0072] Understandably, the inherent randomness and short-term distinctness of the wireless environment in open-loop networks determine the uniqueness of wireless channel characteristics. Therefore, they are mainly used to compare the similarity of continuous signals with short transmission intervals. Compared to complex upper-layer cryptographic algorithms, physical layer security authentication technology is characterized by its speed and efficiency.

[0073] Furthermore, this application incorporates herein... Figure 3 The plan will be explained in detail:

[0074] Step 1a: When the access point receives the signal currently sent by the user terminal, it sends the first current signal feature, which reflects the signal status, to the anchor node.

[0075] Among them, the access point to be accessed is the AP that the UE requests to access (i.e., the AP to be accessed).

[0076] Step 1b: When the access point receives the signal currently sent by the user terminal, it sends the second current signal feature, which reflects the signal status, to the anchor node.

[0077] Among them, the accessed points are the APs that the UE has accessed during the second historical time period (i.e., the APs that have been accessed).

[0078] It should be noted that this application does not specifically limit the first historical period and the second historical period; they may be periods of the same duration or different durations.

[0079] In one approach, such as Figure 4 As shown, before sending uplink data, the user terminal can choose whether to switch APs to send uplink data based on its own situation or the type of data to be transmitted.

[0080] Understandably, if a user chooses to switch APs, they need to select one or more APs to connect to. They also need to send uplink data to both the selected APs and the one or more already connected APs simultaneously.

[0081] In another approach, if the user terminal does not choose to switch access points, it will still use one or more of the original access points for uplink data transmission.

[0082] Step 2: When the access point receives the signal currently sent by the user terminal, extract the signal strength value, angle of arrival value, channel state information, in-phase / quadrature imbalance value and carrier frequency offset value from the signal.

[0083] The AP can use signal strength, angle of arrival, channel state information, in-phase / quadrature imbalance, and carrier frequency offset as the current signal characteristics.

[0084] Step 3: The access point sends the current signal characteristics, which reflect the signal status, to the anchor node.

[0085] In one approach, such as Figure 5 As shown, when multiple APs (i.e., APs to be connected and APs that have already been connected) receive signals (i.e., uplink data sent to them by user terminals), each AP needs to extract the current signal feature vector from the signals it received.

[0086] As an example, the current signal characteristics can be parameterized from various physical layer attributes, including but not limited to Received Signal Strength (RSS), Angle of Arrival (AOA), Channel State Information (CSI), In-Phase / Quadrature Imbalance (IQI), Carrier Frequency Offset (CFO), and so on.

[0087] Furthermore, after multiple APs obtain the current signal characteristics that reflect the signal state, they can forward the current signal characteristics and the received signal to the corresponding AN.

[0088] Depend on Figure 5 It can be seen that after receiving the current signal characteristics, an AP will extract the relevant attributes contained therein. And W... i ={w i1 ,…,w i3 ,…,w iJ} is a collection of multiple extracted attributes.

[0089] Step 4: The anchor node iterates through the historical signal feature set to check if there is a historical access point that is the same as the access point. Then proceed to step 5a or step 6.

[0090] Furthermore, AN can receive and aggregate all current signal features, i.e., C i =(W i1 ,…,W ik ,…,W iM ) T .

[0091] Among them, W ik For AP k The current signal characteristics forwarded to the AN by the kth access point.

[0092] Step 5a: If it exists, compare the similarity between the historical signal features corresponding to the historical access point and the current signal features, and determine the matching degree between the current signal features and the set of historical signal features based on the result of the similarity comparison.

[0093] Furthermore, AN can determine the current signal feature set C. i Each of the W items ik Can we find the historical signal feature set D?i =(X i1 ,…,X ik ,…,X iR ) T Find the corresponding item originating from the same AP.

[0094] Understandably, the existence of a corresponding entry indicates that the same AP received the UE's signal and obtained the corresponding signal characteristics during a historical period. Therefore, the AN can use historical signal characteristics X... ik and current signal characteristics W ik Calculate the similarity between the two. ik .

[0095] Step 5b: Obtain the historical vector value corresponding to at least one historical signal feature; and obtain the current vector value corresponding to at least one current signal feature.

[0096] Step 5c: Based on the similarity comparison between at least one historical vector value and at least one current vector value, determine the matching degree between the current signal feature and the set of historical signal features. Then proceed to step 7.

[0097] In one approach, AN obtains the similarity vector L. i ={l i1 ,…,l ik ,…,l iK}, K≤M. The process of calculating the similarity between two entities can be done based on their corresponding vector values. Various distance measures can be used to calculate the similarity, such as Euclidean distance, Manhattan distance, Chebyshev distance, and cosine distance. One possible approach is to use a feasible distance measure. For example:

[0098]

[0099] Furthermore, AN can be used to obtain the weighted overall similarity L of users. * ,

[0100] L * =f(l i1 ,…,l ik ,…,l iM )=A1*B1*l i1 +…+A k *B k *l ik +…+A M *B M *l iM

[0101] Wherein, weight A k Related to channel quality, weight B kIt is related to the time interval Δτ between the current signal and the previous signal.

[0102] Furthermore, embodiments of this application can compare the overall similarity L of the UE. * The AN determines whether the UE is a legitimate user based on a preset threshold θ.

[0103] Step 6: If the relationship between the current signal feature and the corresponding access point does not exist, store it in the historical signal feature set. Then proceed to Step 7.

[0104] like Figure 6 As shown, if AN compares the overall similarity L of UE... * If the user terminal is determined to be a legitimate user after being compared with a preset threshold θ, the AN updates the historical signal features based on the current signal characteristics. However, if the UE is determined to be an illegitimate user, the AN needs to discard the current signal feature matrix and the received signals.

[0105] Step 7: If the anchor node detects that the user terminal is a legitimate terminal, it determines that the user terminal is connected to the access point.

[0106] The AN determines the UE's access to the AP in the following two ways:

[0107] First scenario:

[0108] The first downlink data is sent to the UE through the AP to be accessed.

[0109] The second scenario:

[0110] The second downlink data is sent to the UE through other APs, and the second downlink data includes an access success message to inform the UE that it has successfully accessed the AP to be accessed.

[0111] In one approach, once the AN determines that the UE is a legitimate user, it can send corresponding downlink data to the UE via the AP based on the received uplink data. In another approach, an access success message (i.e., used to inform the UE that it has successfully accessed the AP) can be appended to the downlink data. In yet another approach, the ID number of the AP to be accessed can also be added to this message.

[0112] Furthermore, such as Figure 7 As shown, after the UE receives downlink data, it can check whether it carries an access success message and the ID number contained in the message. If the received ID number matches the ID number of the AP to be accessed, the AP handover is successful, and the UE can choose to disconnect from the AP in the original AP access set.

[0113] In addition, if no access success message is carried or the ID number does not match, the data transmission failure count of the AP to be accessed is updated. When the updated failure count is greater than a certain preset value, the UE can reselect other APs to be accessed.

[0114] In this application, when multiple access points receive the signal currently sent by the user terminal, they send the current signal features reflecting the signal status to the anchor node. Among the multiple access points is the access point to which the user terminal requests access. The anchor node detects the legitimacy of the user terminal by matching the current signal features with the historical signal feature set. The historical feature set includes the feature set of signals sent by the user terminal in the first historical time period. If the anchor node detects that the user terminal is a legitimate terminal, it determines that the user terminal has accessed the access point.

[0115] By applying the technical solution of this application, the anchor node can compare the signal characteristics of the user terminal received by multiple access points with the signal characteristics sent by the terminal in historical time periods. Only when the two are determined to be highly similar will the terminal be deemed legitimate. This achieves a physical layer authentication method, avoiding the overhead of adding additional integrity verification codes for terminal authentication. Furthermore, comparing the signal characteristics received by multiple access points increases the reliability of the authentication result.

[0116] Optionally, in another embodiment based on the method described above, the step of sending a set of current signal features reflecting the signal state to the anchor node when a signal currently sent by a user terminal is received at multiple access points includes:

[0117] When the access point receives the signal currently sent by the user terminal, it sends a first current signal feature reflecting the signal state to the anchor node; and,

[0118] When an access point receives a signal currently sent by the user terminal, it sends a second current signal feature reflecting the signal status to the anchor node, wherein the access point is an access point that the user terminal has accessed during the second historical time period.

[0119] Optionally, in another embodiment based on the method described above, the step of sending current signal features reflecting the signal state to the anchor node when multiple access points receive the signal currently sent by the user terminal includes:

[0120] When the access point receives the signal currently sent by the user terminal, it extracts the signal strength value, angle of arrival value, channel state information, in-phase / quadrature imbalance value, and carrier frequency offset value from the signal.

[0121] The signal strength value, angle of arrival value, channel state information, in-phase / quadrature imbalance value, and carrier frequency offset value are used as the current signal characteristics of the signal.

[0122] Optionally, in another embodiment based on the method described above in this application, the anchor node detects the legitimacy of the user terminal by the matching degree between the current signal features and the historical signal feature set, including:

[0123] The anchor node traverses the set of historical signal features to determine whether there is a historical access point that is the same as the access point.

[0124] If they exist, the historical signal features corresponding to the historical access point are compared with the current signal features, and the matching degree between the current signal features and the set of historical signal features is determined based on the result of the similarity comparison.

[0125] If it does not exist, the association between the current signal feature and the corresponding access point is stored in the historical signal feature set.

[0126] Optionally, in another embodiment based on the method described above in this application, determining the matching degree between the current signal feature and the historical signal feature set based on the result of the similarity comparison includes:

[0127] Obtain at least one historical vector value corresponding to the historical signal feature; and obtain at least one current vector value corresponding to the current signal feature;

[0128] Based on the similarity comparison between at least one of the historical vector values ​​and at least one of the current vector values, the matching degree between the current signal feature and the set of historical signal features is determined.

[0129] Optionally, in another embodiment based on the method described above in this application, the step of determining that the user terminal is connected to the access point if the anchor node detects that the user terminal is a legitimate terminal includes:

[0130] If the anchor node detects that the user terminal is a legitimate terminal;

[0131] The first downlink data is sent to the user terminal through the access point to be accessed; or, the second downlink data is sent to the user terminal through other base stations, wherein the second downlink data includes an access success message to inform the user terminal that it has successfully accessed the access point to be accessed.

[0132] Optionally, in another embodiment based on the method described above in this application, after detecting the legitimacy of the user terminal, the method further includes:

[0133] If the anchor node detects that the user terminal is an illegal terminal, it discards the current signal feature.

[0134] In this embodiment, after the initial authentication of the user terminal (i.e., the user terminal has been authenticated in the historical time period) is successful, the AN can verify the identity of the signal sender by comparing the physical layer state characteristics of the historical signals sent by a user terminal with the physical layer state characteristics of the current signal, thus avoiding receiving forged or tampered information from attackers. Furthermore, it considers the characteristic of mobile devices frequently switching access points in active networks, ensuring continuous, non-interactive authentication of mobile users during AP switching.

[0135] Furthermore, during open-loop network communication, the AN can extract relevant channel state features based on the received uplink data, and use the channel state features corresponding to uplink data transmissions obtained in previous time periods as historical reference signal features; and use the channel state features corresponding to the current uplink data transmission as the current signal features. It can be understood that these historical signal features correspond to legitimate users. Authentication is performed by comparing the historical signal features and the current signal features, and the authentication result indicates whether the user corresponding to the current signal features is a legitimate user or an illegitimate user.

[0136] By applying the technical solution of this application, the anchor node can compare the signal characteristics of the user terminal received by multiple access points with the signal characteristics sent by the terminal in historical time periods. Only when the two are determined to be highly similar will the terminal be deemed legitimate. This achieves a physical layer authentication method, avoiding the overhead of adding additional integrity verification codes for terminal authentication. Furthermore, comparing the signal characteristics received by multiple access points increases the reliability of the authentication result.

[0137] Optionally, in another embodiment of this application, such as Figure 7 As shown, this application also provides a terminal authentication device for an open-loop network. It includes:

[0138] The receiving module 201 is configured to send current signal characteristics reflecting the signal state to the anchor node when it receives a signal currently sent by the user terminal at multiple access points, wherein the multiple access points include the access point to be accessed by the user terminal.

[0139] The detection module 202 is configured to detect the legitimacy of the user terminal by the anchor node through the matching degree between the current signal features and the historical signal feature set, wherein the historical feature set includes the signal feature set sent by each access point in the first historical time period;

[0140] The determination module 203 is configured to determine that the user terminal is connected to the access point if the anchor node detects that the user terminal is a legitimate terminal.

[0141] By applying the technical solution of this application, the anchor node can compare the signal characteristics of the user terminal received by multiple access points with the signal characteristics sent by the terminal in historical time periods. Only when the two are determined to be highly similar will the terminal be deemed legitimate. This achieves a physical layer authentication method, avoiding the overhead of adding additional integrity verification codes for terminal authentication. Furthermore, comparing the signal characteristics received by multiple access points increases the reliability of the authentication result.

[0142] In another embodiment of this application, the determining module 203 is configured to:

[0143] When the access point receives the signal currently sent by the user terminal, it sends a first current signal feature reflecting the signal state to the anchor node; and,

[0144] When an access point receives a signal currently sent by the user terminal, it sends a second current signal feature reflecting the signal status to the anchor node, wherein the access point is an access point that the user terminal has accessed during the second historical time period.

[0145] In another embodiment of this application, the determining module 203 is configured to:

[0146] When the access point receives the signal currently sent by the user terminal, it extracts the signal strength value, angle of arrival value, channel state information, in-phase / quadrature imbalance value, and carrier frequency offset value from the signal.

[0147] The signal strength value, angle of arrival value, channel state information, in-phase / quadrature imbalance value, and carrier frequency offset value are used as the current signal characteristics of the signal.

[0148] In another embodiment of this application, the determining module 203 is configured to:

[0149] The anchor node traverses the set of historical signal features to determine whether there is a historical access point that is the same as the access point.

[0150] If they exist, the historical signal features corresponding to the historical access point are compared with the current signal features, and the matching degree between the current signal features and the set of historical signal features is determined based on the result of the similarity comparison.

[0151] If it does not exist, the association between the current signal feature and the corresponding access point is stored in the historical signal feature set.

[0152] In another embodiment of this application, the determining module 203 is configured to:

[0153] Obtain at least one historical vector value corresponding to the historical signal feature; and obtain at least one current vector value corresponding to the current signal feature;

[0154] Based on the similarity comparison between at least one of the historical vector values ​​and at least one of the current vector values, the matching degree between the current signal feature and the set of historical signal features is determined.

[0155] In another embodiment of this application, the determining module 203 is configured to:

[0156] If the anchor node detects that the user terminal is a legitimate terminal;

[0157] The first downlink data is sent to the user terminal through the access point to be accessed; or, the second downlink data is sent to the user terminal through other base stations, wherein the second downlink data includes an access success message to inform the user terminal that it has successfully accessed the access point to be accessed.

[0158] In another embodiment of this application, the determining module 203 is configured to:

[0159] If the anchor node detects that the user terminal is an illegal terminal, it discards the current signal feature.

[0160] Figure 7 This is a logical structure block diagram of an electronic device according to an exemplary embodiment. For example, electronic device 300 may be an electronic device.

[0161] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions, such as a memory including instructions, is also provided. These instructions can be executed by an electronic device processor to complete the terminal authentication method for the open-loop network described above. The method includes: when multiple access points receive a signal currently transmitted by a user terminal, sending current signal features reflecting the signal state to an anchor node, wherein the multiple access points include a pending access point requested by the user terminal; the anchor node detects the legitimacy of the user terminal by matching the current signal features with a historical signal feature set, the historical feature set including a set of signal features transmitted by each access point in a first historical time period; if the anchor node detects that the user terminal is a legitimate terminal, it determines that the user terminal has accessed the pending access point.

[0162] Optionally, the above instructions can also be executed by the processor of the electronic device to complete other steps involved in the exemplary embodiments described above. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

[0163] In an exemplary embodiment, an application / computer program product is also provided, including one or more instructions that can be executed by a processor of an electronic device to complete the aforementioned open-loop network terminal authentication method. The method includes: when multiple access points receive a signal currently sent by a user terminal, sending current signal features reflecting the signal state to an anchor node, wherein the multiple access points include a pending access point requested by the user terminal; the anchor node detects the legitimacy of the user terminal by matching the current signal features with a historical signal feature set, wherein the historical feature set includes a set of signal features sent by each access point in a first historical time period; if the anchor node detects that the user terminal is a legitimate terminal, it determines that the user terminal has accessed the pending access point.

[0164] Alternatively, the above instructions may also be executed by the processor of the electronic device to complete other steps involved in the above exemplary embodiments.

[0165] Figure 7 This is an example diagram of an electronic device 300. Those skilled in the art will understand that it is illustrative. Figure 7 This is merely an example of electronic device 300 and does not constitute a limitation on electronic device 300. It may include more or fewer components than shown, or combine certain components, or different components. For example, electronic device 300 may also include input / output devices, network access devices, buses, etc.

[0166] The processor 302 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor, or processor 302 can be any conventional processor. Processor 302 is the control center of electronic device 300, connecting all parts of electronic device 300 via various interfaces and lines.

[0167] The memory 301 can be used to store computer-readable instructions 303. The processor 302 implements various functions of the electronic device 300 by running or executing the computer-readable instructions or modules stored in the memory 301 and calling the data stored in the memory 301. The memory 301 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, application programs required for at least one function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the electronic device 300, etc. In addition, the memory 301 may include a hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, read-only memory (ROM), random access memory (RAM), or other non-volatile / volatile storage devices.

[0168] If the modules integrated in the electronic device 300 are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by instructing related hardware through computer-readable instructions. The computer-readable instructions can be stored in a computer-readable storage medium, and when executed by a processor, they can implement the steps of the various method embodiments described above.

[0169] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.

[0170] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A terminal authentication method for an open-loop network, characterized in that, include: When multiple access points receive the signal currently sent by the user terminal, they send the current signal characteristics reflecting the signal state to the anchor node. The multiple access points include the access point to be accessed by the user terminal. The current signal characteristics include the signal strength value, angle of arrival value, channel state information, in-phase / quadrature imbalance value, and carrier frequency offset value of the signal. The anchor node detects the legitimacy of the user terminal by matching the current signal features with the historical signal feature set. The historical signal feature set includes the signal feature set sent by each access point in the first historical time period. If the anchor node detects that the user terminal is a legitimate terminal, it determines that the user terminal is connected to the access point.

2. The method as described in claim 1, characterized in that, When a signal currently sent by a user terminal is received at multiple access points, the step of sending a set of current signal features reflecting the signal state to the anchor node includes: When the access point receives the signal currently sent by the user terminal, it sends a first current signal feature reflecting the signal state to the anchor node; and, When an access point receives a signal currently sent by the user terminal, it sends a second current signal feature reflecting the signal status to the anchor node, wherein the access point is an access point that the user terminal has accessed during the second historical time period.

3. The method as described in claim 1, characterized in that, The anchor node detects the legitimacy of the user terminal by matching the current signal features with the historical signal feature set, including: The anchor node traverses the set of historical signal features to determine whether there is a historical access point that is the same as the access point. If they exist, the historical signal features corresponding to the historical access point are compared with the current signal features, and the matching degree between the current signal features and the set of historical signal features is determined based on the result of the similarity comparison. If it does not exist, the association between the current signal feature and the corresponding access point is stored in the historical signal feature set.

4. The method as described in claim 3, characterized in that, Determining the matching degree between the current signal feature and the historical signal feature set based on the similarity comparison result includes: Obtain at least one historical vector value corresponding to the historical signal feature; and obtain at least one current vector value corresponding to the current signal feature; Based on the similarity comparison between at least one of the historical vector values ​​and at least one of the current vector values, the matching degree between the current signal feature and the set of historical signal features is determined.

5. The method as described in claim 1, characterized in that, If the anchor node detects that the user terminal is a legitimate terminal, determining that the user terminal is connected to the access point includes: If the anchor node detects that the user terminal is a legitimate terminal; The first downlink data is sent to the user terminal through the access point to be accessed; or, the second downlink data is sent to the user terminal through other base stations, wherein the second downlink data includes an access success message to inform the user terminal that it has successfully accessed the access point to be accessed.

6. The method as described in claim 1, characterized in that, After verifying the legitimacy of the user terminal, the method further includes: If the anchor node detects that the user terminal is an illegal terminal, it discards the current signal feature.

7. A terminal authentication device for an open-loop network, characterized in that, include: The receiving module is configured to send current signal characteristics reflecting the signal state to the anchor node when it receives a signal currently transmitted by a user terminal at multiple access points, wherein the multiple access points include the access point to be accessed by the user terminal; the current signal characteristics include the signal strength value, angle of arrival value, channel state information, in-phase / quadrature imbalance value, and carrier frequency offset value of the signal. The detection module is configured so that the anchor node detects the legitimacy of the user terminal by the matching degree between the current signal features and the historical signal feature set, wherein the historical signal feature set includes the signal feature set sent by each access point in the first historical time period; The determination module is configured to determine that the user terminal is connected to the access point if the anchor node detects that the user terminal is a legitimate terminal.

8. An electronic device, characterized in that, include: Memory, used to store executable instructions; as well as, A processor, configured to execute the executable instructions with the memory to perform the operation of the terminal authentication method for any of the open-loop networks described in claims 1-7.

9. A computer-readable storage medium for storing computer-readable instructions, characterized in that, When the instruction is executed, it performs the operation of the terminal authentication method for any of the open-loop networks described in claims 1-7.

Citation Information

Patent Citations

  • 5G-based physical layer cooperative authentication method and system and electronic equipment

    CN113840285A