An access authentication method for a communication terminal

By adopting a channel authentication method in the wireless communication access platform and using a fully connected neural network classifier model for three-stage authentication, the problem of user accounts and passwords being easily stolen is solved, which improves information security and reduces the cost of equipment requirements.

CN118870359BActive Publication Date: 2025-06-17GUANGZHOU CHENSI COMM TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202411028675.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-30
Publication Date
2025-06-17
Estimated Expiration
2044-07-30

AI Technical Summary

Technical Problem

In existing wireless communication technologies, user accounts and passwords are easily stolen, resulting in information leakage. Existing solutions such as intranet access, electromagnetic shielding or control of communication distances have limitations and high costs.

Method used

The channel authentication method is adopted. By pre-saving the identity authentication information and pilot sequence of the communication terminal in the access platform, the channel characteristics of the communication terminal to the access platform are extracted, a fully connected neural network classifier model is constructed, and the communication terminal is authenticated in three stages to ensure that it only accesses within the allowed geographical range.

Benefits of technology

It effectively avoids illegal login with theft of account passwords, improves information security, and filters out communication devices outside the geographical range through channel authentication, reducing the cost of accessing platform equipment requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118870359B_ABST
    Figure CN118870359B_ABST
Patent Text Reader

Abstract

The present invention discloses an access authentication method for a communication terminal, comprising the following steps: S1. Pre-save original data in an access platform; S2. Extract the channel characteristics from the communication terminal to the access platform when the communication terminal is inside or outside the allowed access geographical range; S3. Label the channel characteristics, construct training samples, and form a sample set; S4. The access platform constructs a classifier model based on a fully connected neural network and trains to obtain a trained classifier model; S5. Perform a first-stage authentication on the communication terminal using the first identity authentication information; S6. Perform a second-stage authentication on the communication terminal through the second identity authentication information; S7. The communication terminal sends an original pilot sequence to the access platform, and the access platform extracts the actual channel characteristics from the communication terminal to the access platform based on the received signal; S8. Perform a third-stage authentication on the communication terminal. The present invention can screen out communication devices outside the allowed geographical range and reject access, which is beneficial to improving information security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of wireless communication, and particularly to an access authentication method for a communication terminal. Background Art

[0002] With the development of wireless communication technology, more and more enterprises or institutions begin to use wireless access platforms for users within the enterprise or institution to access through communication terminals. However, the wireless access method makes it possible for user accounts and passwords to be stolen, which is not conducive to the confidentiality of enterprise or institutional information.

[0003] In some units or enterprises with relatively strict confidentiality requirements, generally only access and login are allowed within a certain geographical range (such as the park where the enterprise is located). If access is made outside the geographical range, information leakage may occur. For most current units, the methods adopted generally include intranet access, electromagnetic shielding, or strict control of the communication distance, etc. However, intranet access has certain limitations. For example, it often requires the establishment of an independent local area network or the use of proprietary equipment for login, which brings great inconvenience. Electromagnetic shielding or strict control of the communication distance will increase a large amount of costs and have high requirements for the devices accessing the platform, bringing many inconveniences to the access of communication terminals within the enterprise. Summary of the Invention

[0004] The purpose of the present invention is to overcome the deficiencies of the prior art and provide an access authentication method for a communication terminal. Through channel authentication, communication devices outside the allowed geographical range can be screened out and access can be refused, which is conducive to improving information security.

[0005] The purpose of the present invention is achieved through the following technical solutions: An access authentication method for a communication terminal includes the following steps:

[0006] S1. Pre-save the first identity authentication information, the second identity authentication information, and the original pilot sequence for the access of the communication terminal in the access platform;

[0007] S2. When the communication terminal is inside and outside the allowed geographical range for access, send the original pilot sequence to the access platform multiple times respectively. The access platform extracts the channel characteristics from the communication terminal to the access platform according to the received signal;

[0008] S3. Tag the channel characteristics, construct training samples, and form a sample set;

[0009] S4. The access platform constructs a classifier model based on a fully connected neural network, and uses the training samples in the sample set to train the classifier model to obtain a trained classifier model;

[0010] S5. When the communication terminal requests access, perform the first-stage authentication on the communication terminal using the first identity authentication information;

[0011] S6. After the first-stage authentication is passed, perform the second-stage authentication on the communication terminal using the second identity authentication information;

[0012] S7. After the second-stage authentication is passed, enter the pre-access stage. The communication terminal sends the original pilot sequence to the access platform, and the access platform extracts the actual channel characteristics from the communication terminal to the access platform based on the received signal;

[0013] S8. The access platform performs the third-stage authentication on the communication terminal based on the trained classifier model. After the authentication is successful, the communication terminal accesses successfully.

[0014] The beneficial effects of the present invention are as follows: Through the second-stage authentication of the present invention, it is possible to avoid the illegal login of the communication terminal when the account password is stolen, improving the security of information; The channel authentication method of the present invention can screen out communication devices outside the permitted geographical range and reject access, further improving the security of information, and there is no need to create an additional local area network or additional electromagnetic shielding equipment, which can effectively reduce the equipment requirements for the access platform. Brief Description of the Drawings

[0015] Figure 1 The flowchart of the method of the present invention. Detailed Embodiments

[0016] The technical solution of the present invention will be further described in detail below with reference to the drawings, but the protection scope of the present invention is not limited to the following.

[0017] As Figure 1 shown, an access authentication method for a communication terminal, characterized in that it includes the following steps:

[0018] S1. Pre-save the first identity authentication information, the second identity authentication information, and the original pilot sequence for the access of the communication terminal in the access platform;

[0019] S2. When the communication terminal is inside and outside the permitted geographical range for access, send the original pilot sequence to the access platform multiple times respectively, and the access platform extracts the channel characteristics from the communication terminal to the access platform based on the received signal;

[0020] The step S2 includes:

[0021] S201. When the communication terminal is inside the permitted geographical range for access, the communication terminal sends the original pilot sequence to the access platform, and the access platform extracts the channel characteristic matrix based on the pre-saved original pilot sequence and the received signal;

[0022] Suppose there are M frames in the original pilot sequence, then the access platform can extract M channel feature matrices in total, which are used as the channel features from the communication terminal to the access platform within the geographical range allowed for access.

[0023] When the communication terminal is at multiple different positions within the geographical range allowed for access, step S201 is repeatedly executed. Suppose a total of N1 different positions are considered, then within the geographical range allowed for access, a total of M * N1 channel features from the communication terminal to the access platform are obtained.

[0024] When the communication terminal is outside the geographical range allowed for access, the communication terminal sends the original pilot sequence to the access platform, and the access platform extracts the channel feature matrix based on the pre - saved original pilot sequence and the received signal.

[0025] Since there are M frames in the original pilot sequence, the access platform can extract M channel feature matrices in total, which are used as the channel features from the communication terminal to the access platform outside the geographical range allowed for access.

[0026] When the communication terminal is at multiple different positions outside the geographical range allowed for access, step S203 is repeatedly executed. Suppose a total of N2 different positions are considered, then outside the geographical range allowed for access, a total of M * N2 channel features from the communication terminal to the access platform are obtained.

[0027] S3. Label the channel features, construct training samples, and form a sample set.

[0028] The said step S3 includes:

[0029] For the M * N1 channel features from the communication terminal to the access platform obtained within the geographical range allowed for access, add the label 0 to obtain M * N1 training samples.

[0030] For the M * N2 channel features from the communication terminal to the access platform obtained outside the geographical range allowed for access, add the label 1 to obtain M * N2 training samples.

[0031] Add all the training samples into the same set to obtain the sample set.

[0032] S4. The access platform constructs a classifier model based on a fully - connected neural network, and uses the training samples in the sample set to train the classifier model to obtain a trained classifier model.

[0033] In step S4, when training the classifier model: the channel features in the training samples are used as inputs, the classifier model obtains the actual output results, the loss function is calculated between the actual output results and the labels in the training samples, and then the classifier model is updated through backpropagation based on the loss function; the mean squared error (MSE) loss function is used as the loss function.

[0034] When all training samples are trained, or when the value of the loss function is less than the set threshold, it is considered that a trained classifier model has been obtained.

[0035] S5. When the communication terminal requests access, the communication terminal is authenticated in the first stage using the first authentication information.

[0036] The first identity information is the account number and password, and the account numbers and passwords of all registered users are stored in the access platform; in step S5, when the communication terminal requests access, it sends its first identity information to the access platform, and the access platform authenticates the communication terminal using the first identity information. If the first identity information sent by the communication terminal is stored in the access platform, the first-stage authentication is passed; otherwise, the first-stage authentication fails.

[0037] S6. After the first-stage authentication is passed, the communication terminal is authenticated in the second stage using the second authentication information.

[0038] The second identity information is the user's mobile communication number. After the first-stage authentication is passed, the access platform sends a short message to the user using the second authentication information. If the user returns a confirmation message within the specified time, the second-stage authentication is passed; otherwise, the second-stage authentication fails.

[0039] S7. After the second-stage authentication is passed, a pre-access stage is performed. The communication terminal sends the original pilot sequence to the access platform, and the access platform extracts the actual channel features from the communication terminal to the access platform based on the received signal.

[0040] S8. The access platform authenticates the communication terminal in the third stage based on the trained classifier model. After successful authentication, the communication terminal accesses successfully.

[0041] The actual channel features from the communication terminal to the access platform are input into the trained classifier model. If the classifier model outputs 0, it is considered that the communication terminal is within the allowed access geographical range and the third-stage authentication is passed; if the classifier model outputs 0, it is considered that the communication terminal is outside the allowed access geographical range and the third-stage authentication fails.

[0042] In the embodiments of the present application, in any of the first-stage authentication, second-stage authentication, and third-stage authentication, when any stage authentication fails, the access platform rejects the communication terminal from accessing.

[0043] The above are the preferred embodiments of the present invention. It should be understood that the present invention is not limited to the forms disclosed herein, should not be regarded as excluding other embodiments, but can be used in other combinations, modifications and environments, and can be changed within the scope of the concept described herein through the above teachings or the technology or knowledge in related fields. Any changes and modifications made by those skilled in the art without departing from the spirit and scope of the present invention shall fall within the protection scope of the appended claims of the present invention.

Claims

1. A communication terminal access authentication method, characterized in that: The following steps are involved: S1. The first identity authentication information, the second identity authentication information and the original pilot sequence of the communication terminal access are pre-stored in the access platform; S2. When the communication terminal is within or outside the geographical range allowed for access, the original pilot sequence is sent to the access platform multiple times, and the access platform extracts the channel characteristics from the communication terminal to the access platform based on the received signal; The step S2 comprises: S201. When the communication terminal is within the geographical range where access is allowed, the communication terminal sends the original pilot sequence to the access platform, and the access platform extracts the channel feature matrix based on the pre-stored original pilot sequence and the received signal; Assuming that there are M frames in the original pilot sequence, the access platform can extract M channel feature matrices as the channel features from the communication terminal to the access platform within the geographical range where access is allowed; S202. When the communication terminal is in multiple different locations within the geographical range allowed for access, step S201 is repeated. If a total of N1 different locations are considered, a total of M*N1 channel characteristics from the communication terminal to the access platform are obtained within the geographical range allowed for access; S203. When the communication terminal is outside the geographical range where access is allowed, the communication terminal sends the original pilot sequence to the access platform, and the access platform extracts the channel characteristic matrix based on the pre-stored original pilot sequence and the received signal; Since the original pilot sequence has a total of M frames, the access platform can extract a total of M channel feature matrices as channel features from the communication terminal to the access platform outside the geographical range where access is allowed; S204. When the communication terminal is at multiple different locations outside the geographical range allowed for access, step S203 is repeated. Assuming that a total of N2 different locations are considered, a total of M*N2 channel characteristics of communication terminals to the access platform are obtained outside the geographical range allowed for access; S3. Label the channel features, construct training samples, and form a sample set; S4. The access platform constructs a classifier model based on a fully connected neural network, and trains the classifier model using training samples in the sample set to obtain a trained classifier model; S5. When the communication terminal requests access, the first stage of authentication of the communication terminal is performed using the first identity authentication information; S6. After the first stage authentication is passed, the communication terminal is authenticated in the second stage through the second identity authentication information; S7. After the second stage authentication is passed, the pre-access stage is carried out, the communication terminal sends the original pilot sequence to the access platform, and the access platform extracts the actual channel characteristics from the communication terminal to the access platform based on the accessed signal; S8. The access platform performs the third stage authentication on the communication terminal based on the trained classifier model. After the authentication is successful, the communication terminal is successfully accessed.

2. The access authentication method of a communication terminal according to claim 1, characterized in that: When any of the first-stage authentication, the second-stage authentication and the third-stage authentication fails, the access platform denies access to the communication terminal.

3. The access authentication method of a communication terminal according to claim 1, characterized in that: The step S2 includes: the step S3 includes: For the channel characteristics of M*N1 communication terminals to the access platform obtained within the geographical range where access is allowed, add label 0 to obtain M*N1 training samples; For the channel characteristics of M*N2 communication terminals to the access platform obtained outside the geographical range where access is allowed, label 1 is added to obtain M*N2 training samples; Add all training samples into the same set to obtain a sample set.

4. The access authentication method of a communication terminal according to claim 1, characterized in that: The step S2 includes: in the step S4, when training the classifier model: taking the channel features in the training sample as input, obtaining the actual output result by the classifier model, calculating the loss function between the actual output result and the label in the training sample, and then back-propagating and updating the classifier model based on the loss function; wherein the loss function adopts the MSE loss function; When all training samples are trained, or the loss function value is less than the set threshold, it is considered that the trained classifier model is obtained.

5. The access authentication method of a communication terminal according to claim 1, characterized in that: The step S2 includes: the first identity information is an account number and a password, and the access platform stores the account numbers and passwords of all registered users; in the step S5, when the communication terminal requests access, it sends its first identity information to the access platform, and the access platform performs a first-stage authentication on the communication terminal using the first identity information. If the access platform stores the first identity information sent by the communication terminal, the first-stage authentication passes, otherwise the first-stage authentication fails.

6. The access authentication method of a communication terminal according to claim 1, characterized in that: The step S2 includes: the second identity information is the user's mobile communication number. After the first stage authentication is passed, the access platform sends a text message to the user with the second identity authentication information. If the user returns a confirmation message within the specified time, the second stage authentication is passed, otherwise the second stage authentication fails.

7. The access authentication method of a communication terminal according to claim 1, characterized in that: The step S8 includes: inputting the actual channel characteristics from the communication terminal to the access platform into the trained classifier model; if the classifier model outputs 0, it is considered that the communication terminal is within the geographical scope allowed for access and the third stage authentication is passed; if the classifier model outputs 0, it is considered that the communication terminal is outside the geographical scope allowed for access and the third stage authentication fails.

Citation Information

Patent Citations

  • Method, server and system for user authentication

    CN106603472A

  • Edge-side physical layer channel authentication method based on deep neural network

    CN108924836A

  • Physical layer authentication method based on principal component analysis and residual network

    CN111541632A

  • Dual authentication method based on password and frequency offset

    CN114025350A

  • Terminal access authentication method, system and device and storage medium

    CN114339751A