A method and device for a 5G wireless device to access a router

The router configures an image acquisition device to collect and compare the user's physiological characteristics to authenticate the security risks when connecting 5G devices, ensure legal user access, and improve network security.

CN119052890BActive Publication Date: 2025-07-08SHENZHEN KING CHUANG TECH & ELECTRONICS
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410933995.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-12
Publication Date
2025-07-08
Estimated Expiration
2044-07-12

AI Technical Summary

Technical Problem

When a 5G device is connected to a router, if the Wifi password is leaked, unauthorized devices can access the network at will, resulting in a greater security risk to the router.

Method used

The router configures an image acquisition device to determine the authentication result by ingesting the target user's physiological characteristics (such as facial features or iris features) and comparing it with the pre-stored benchmark physiological characteristics, and only control the 5G device to access the network when the authentication is passed.

Benefits of technology

Ensure that only legitimate users can access the network, avoid unauthorized devices at will, and reduce the security risks of the router.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119052890B_ABST
    Figure CN119052890B_ABST
Patent Text Reader

Abstract

The present application discloses a method and device for a 5G wireless device to access a router, relating to the field of network communication technologies. The method and device for a 5G wireless device to access a router in the present application are applied to a router configured with an image acquisition device, and specifically include: receiving an access request sent by a target 5G device, and determining a target authentication object corresponding to the target 5G device based on the access request; capturing a first target image containing the target authentication object through the image acquisition device, and extracting target user physiological features included in the first target image; determining an authentication result corresponding to the target authentication object based on the target user physiological features; and controlling the target 5G device to access a preset target network when it is determined that the authentication result is authentication passed. By adopting the present application, the technical effect of reducing the security risk of the router is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication technologies, and in particular, to a method and device for a 5G wireless device to access a router. Background Art

[0002] With the continuous development of communication devices, 5G devices have become an indispensable tool in the daily lives of more and more users, and routers are important devices for realizing information transmission between these 5G devices.

[0003] In the related art, 5G devices usually need to be connected to the router via Wifi. After the user enters the correct Wifi password, the router can complete the user authentication operation and control the 5G device to access the network.

[0004] However, in the process of accessing the network through the above connection method, once the 5G device leaks the Wifi password, other unauthorized devices can access the network at will, resulting in a large security risk for the router. Summary of the Invention

[0005] The main purpose of this application is to provide a method and device for a 5G wireless device to access a router, aiming to solve the technical problem of large security risks in the related art routers.

[0006] To achieve the above object, this application proposes a method for a 5G wireless device to access a router. The method is applied to a router configured with an image acquisition device, and the method includes:

[0007] Receiving an access request sent by a target 5G device, and determining a target authentication object corresponding to the target 5G device based on the access request;

[0008] Capturing a first target image containing the target authentication object through the image acquisition device, and extracting target user physiological characteristics included in the first target image;

[0009] Determining an authentication result corresponding to the target authentication object based on the target user physiological characteristics, where the authentication result includes authentication passed and authentication failed;

[0010] When it is determined that the authentication result is authentication passed, controlling the target 5G device to access a preset target network.

[0011] In an embodiment, the step of obtaining the authentication result corresponding to the target authentication object based on the target user physiological characteristics includes:

[0012] Obtaining a plurality of preset reference physiological characteristics;

[0013] Compare the target user's physiological characteristics with each of the multiple reference physiological characteristics to obtain multiple first comparison results;

[0014] Based on the multiple first comparison results, determine whether the target reference physiological characteristic is included in the multiple reference physiological characteristics, where the target reference physiological characteristic is the reference physiological characteristic that is consistent with the target user's physiological characteristics;

[0015] If it is determined that the target reference physiological characteristic is included in the multiple reference physiological characteristics, determine that the authentication result corresponding to the target authentication object is the authentication passed;

[0016] If it is determined that the target reference physiological characteristic is not included in the multiple reference physiological characteristics, determine that the authentication result corresponding to the target authentication object is the authentication failed.

[0017] In one embodiment, the step of controlling the target 5G device to access a preset target network includes:

[0018] Read the device identification information included in the access request;

[0019] Based on the device identification information, construct a target communication channel corresponding to the target 5G device, and generate a first address parameter according to the device identification information;

[0020] Send the first address parameter to the target 5G device through the target communication channel to control the target 5G device to access the preset target network according to the first address parameter.

[0021] In one embodiment, the target network includes multiple preset sub-network environments;

[0022] After the step of reading the device identification information included in the access request, the method further includes:

[0023] Determine the access device type corresponding to the target 5G device according to the device identification information;

[0024] Based on the access device type, target a sub-network environment among the multiple preset sub-network environments, and control the target 5G device to access the target sub-network environment.

[0025] In one embodiment, the step of targeting a sub-network environment among the multiple preset sub-network environments based on the access device type includes:

[0026] Determine the device type matching rules corresponding to each of the multiple preset sub-network environments, and determine the reference device types corresponding to the device type matching rules;

[0027] Compare the access device type with the multiple reference device types to determine a target device type among the multiple reference device types;

[0028] Determine the preset sub-network environment corresponding to the target device type as the target sub-network environment.

[0029] In one embodiment, after the step of controlling the target 5G device to access the target sub-network environment, the method further includes:

[0030] Obtain the network access log of the target 5G device, and determine whether there is a security risk for the target 5G device based on the network access log;

[0031] If it is determined that the target 5G device has the security risk, obtain a preset second address parameter;

[0032] Send the second address parameter to the target 5G device to control the target 5G device to switch from the target sub-network environment to a preset isolation network environment.

[0033] In addition, to achieve the above object, the present application further provides a 5G wireless device access router device, the 5G wireless device access router device is applied to a router configured with an image acquisition device, and the device includes:

[0034] A target determination module, configured to receive an access request sent by a target 5G device, and determine a target authentication object corresponding to the target 5G device based on the access request;

[0035] A feature acquisition module, configured to capture a first target image including the target authentication object through the image acquisition device, and extract target user physiological features included in the first target image;

[0036] An authentication execution module, configured to determine an authentication result corresponding to the target authentication object based on the target user physiological features, where the authentication result includes authentication passed and authentication failed;

[0037] A device access module, configured to control the target 5G device to access a preset target network when it is determined that the authentication result is authentication passed.

[0038] In addition, to achieve the above object, the present application further provides a router, the router includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the method for 5G wireless device access router as described above.

[0039] In addition, to achieve the above object, the present application further provides a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the method for a 5G wireless device to access a router as described above are implemented.

[0040] In addition, to achieve the above object, the present application further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps of the method for a 5G wireless device to access a router as described above are implemented.

[0041] The method for a 5G wireless device to access a router provided by an embodiment of the present application is applied to a router configured with an image acquisition device. By receiving an access request sent by a target 5G device and determining a target authentication object corresponding to the target 5G device based on the access request; capturing a first target image including the target authentication object by the image acquisition device and extracting target user physiological features included in the first target image; determining an authentication result corresponding to the target authentication object based on the target user physiological features, where the authentication result includes authentication passed and authentication failed; and controlling the target 5G device to access a preset target network when it is determined that the authentication result is authentication passed.

[0042] In this embodiment, when the router is running, it first receives an access request sent by a target 5G device that needs to access the network, and determines a target authentication object that needs to be authenticated and holds the target 5G device based on the access request. Then, the router calls the image acquisition device configured by itself to take a picture of the target authentication object, so as to capture a first target image including the target authentication object. The router then processes the first target image to extract the target user physiological features included in the first target image. After that, the router performs an identity authentication operation based on the target user physiological features to determine the authentication result of the target authentication object. Finally, when it is determined that the authentication result is authentication passed, the router determines that the target authentication object is a user with access permission, and the router thus controls the target 5G device to access a preset target network.

[0043] In this way, the present application solves the technical problem that there are relatively large security risks in routers in the related art, that is, when the router receives an access request sent by a 5G device, the present application can ensure that the 5G device is controlled to access the network only when the user himself has access permission by collecting the physiological features of the user holding the 5G device and performing an identity authentication operation based on the physiological features, avoiding unauthorized other devices from being able to access the network at will in the case of Wifi password leakage, and achieving the technical effect of reducing the security risk of the router. Brief Description of the Drawings

[0044] The drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.

[0045] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.

[0046] Figure 1 It is a schematic flowchart provided for the first embodiment of the method for a 5G wireless device to access a router according to the present application;

[0047] Figure 2 It is a schematic flowchart of the brief process of the method for a 5G wireless device to access a router according to the present application;

[0048] Figure 3 It is a schematic flowchart provided for the second embodiment of the method for a 5G wireless device to access a router according to the present application;

[0049] Figure 4 It is a schematic diagram of the module structure of the device for a 5G wireless device to access a router according to the embodiment of the present application;

[0050] Figure 5 It is a schematic diagram of the device structure of the hardware operating environment involved in the method for a 5G wireless device to access a router according to the embodiment of the present application.

[0051] The realization of the purpose, functional features and advantages of the present application will be further described with reference to the embodiments and the drawings. Detailed Embodiments

[0052] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.

[0053] To better understand the technical solutions of the present application, the following will be described in detail in combination with the drawings in the specification and the specific embodiments.

[0054] In this embodiment, for the convenience of description, the following will be described with a router internally configured with an image acquisition device, a communication module and a storage module as the execution subject.

[0055] Based on the above router, the overall concept of the method for a 5G wireless device to access a router according to the present application is proposed here.

[0056] With the continuous development of communication devices, 5G devices have become an indispensable tool in the daily lives of more and more users. A router is an important device for enabling information transmission between these 5G devices. In related technologies, 5G devices usually need to be connected to the router via Wifi. Thus, after the user enters the correct Wifi password, the router can complete the user authentication operation and control the 5G device to access the network. However, during the process of accessing the network through the above connection method, once the 5G device leaks the Wifi password, other unauthorized devices can access the network at will, leading to a technical problem that the router has a relatively high security risk.

[0057] In view of the above phenomenon, this application provides a method for a 5G wireless device to access a router. The method is applied to a router configured with an image acquisition device, and the method includes: receiving an access request sent by a target 5G device, and determining a target authentication object corresponding to the target 5G device based on the access request; capturing a first target image containing the target authentication object through the image acquisition device, and extracting target user physiological characteristics included in the first target image; determining an authentication result corresponding to the target authentication object based on the target user physiological characteristics, where the authentication result includes authentication passed and authentication failed; and controlling the target 5G device to access a preset target network when it is determined that the authentication result is authentication passed.

[0058] In this way, this application solves the technical problem that the router has a relatively high security risk in related technologies. That is, when the router receives an access request sent by a 5G device, this application captures the physiological characteristics of the user holding the 5G device and performs an identity authentication operation based on the physiological characteristics to determine whether the user has access rights. In this way, it can be ensured that the 5G device is controlled to access the network only when the user himself has access rights, avoiding the situation that other unauthorized devices can access the network at will when the Wifi password is leaked, achieving the technical effect of reducing the security risk of the router.

[0059] Based on the overall concept of the method for a 5G wireless device to access a router in this application, an embodiment of this application provides a method for a 5G wireless device to access a router. Refer to Figure 1 , Figure 1 which is a schematic flowchart of the first embodiment of the method for a 5G wireless device to access a router in this application.

[0060] In this embodiment, the method for a 5G wireless device to access a router is applied to a router configured with an image acquisition device. The method for a 5G wireless device to access a router includes steps S10 to S40:

[0061] Step S10: Receive an access request sent by a target 5G device, and determine a target authentication object corresponding to the target 5G device based on the access request;

[0062] In this embodiment, when the router is running, it first receives an access request sent by a target 5G device. The router then reads the access request to determine the location information of the target 5G device based on the access request. At the same time, the router calls an image acquisition device to capture a second target image including multiple users of the target 5G device. The router then determines, among the multiple users, the user holding the target 5G device based on the location information and the second target image, and further determines the user holding the target 5G device as the target authentication object that needs to perform an identity authentication operation.

[0063] Exemplarily, for example, when a user is near the router and controls the held target 5G device to send a network access request to the router, the router first receives the access request sent by the target 5G device and reads the network access request to determine the location information of the target 5G device within the house based on the network access request. The router calls the image acquisition device configured by itself to capture the house, thereby obtaining a second target image including all users in the house. The router then filters the multiple users included in the second target image based on the location information to filter out the user with the target 5G device among the multiple users, and further determines the user holding the target 5G device as the target authentication object that needs to perform an identity authentication operation.

[0064] Step S20: Capture a first target image including the target authentication object through the image acquisition device, and extract target user physiological features included in the first target image;

[0065] It should be noted that the target user physiological features are characteristic parameters that can indicate the identity information of the user, and specifically can be facial features or iris features, etc. It can be understood that the specific type of the target user physiological features is not limited in this application.

[0066] In this embodiment, after determining the target authentication object, the router calls the image acquisition device configured by itself to capture the target authentication object, thereby obtaining a first target image including the target authentication object. The router then processes the first target image to extract target user physiological features included in the first target image that can indicate the identity information of the target authentication object.

[0067] Exemplarily, for example, after the router determines the target authentication object that needs to perform the identity authentication operation, it calls the image acquisition device configured by itself to take a picture of the target authentication object, thereby capturing a first target image including the target authentication object. Then, the router inputs the first target image into the image processing module configured by itself, and the image processing module processes the first target image to extract the target user facial features included in the first target image, which can indicate the identity information of the target authentication object.

[0068] Step S30: Determine the authentication result corresponding to the target authentication object based on the target user physiological characteristics, where the authentication result includes authentication passed and authentication failed;

[0069] In this embodiment, after obtaining the target user physiological characteristics, the router performs an identity authentication operation based on the target user physiological characteristics, so as to determine whether the authentication result corresponding to the target authentication object is authentication passed or authentication failed.

[0070] In a feasible implementation manner, the above step S30 may specifically include steps S301 to S305:

[0071] Step S301: Obtain a plurality of preset reference physiological characteristics;

[0072] Step S302: Compare the target user physiological characteristics with the plurality of reference physiological characteristics respectively to obtain a plurality of first comparison results;

[0073] Step S303: Based on the plurality of first comparison results, determine whether the plurality of reference physiological characteristics include a target reference physiological characteristic, where the target reference physiological characteristic is a reference physiological characteristic that is consistent with the target user physiological characteristics;

[0074] Step S304: If it is determined that the plurality of reference physiological characteristics include the target reference physiological characteristic, determine that the authentication result corresponding to the target authentication object is the authentication passed;

[0075] Step S305: If it is determined that the plurality of reference physiological characteristics do not include the target reference physiological characteristic, determine that the authentication result corresponding to the target authentication object is the authentication failed.

[0076] It should be noted that the reference physiological characteristics are physiological characteristics that are pre-stored in the storage module of the router and are used to indicate the identity information of the users who have obtained access authorization. It can be understood that there are many ways to obtain the reference physiological characteristics, and this application does not limit this.

[0077] In this embodiment, after obtaining the physiological characteristics of the target user, the router first reads the configured storage module of itself to obtain a plurality of preset reference physiological characteristics. Then, the router compares the obtained physiological characteristics of the target user and the plurality of reference physiological characteristics respectively to obtain a plurality of first comparison results. After that, the router determines whether the plurality of reference physiological characteristics include a reference physiological characteristic that is consistent with the physiological characteristics of the target user according to the plurality of first comparison results. Then, if the router determines that the plurality of reference physiological characteristics include the target reference physiological characteristic, it determines that the target authentication object is a user who has registered identity information, and thus determines that the authentication result corresponding to the target authentication object is authentication success. If the router determines that the plurality of reference physiological characteristics do not include the target reference physiological characteristic, it determines that the target authentication object has not registered identity information, and thus determines that the authentication result corresponding to the target authentication object is authentication failure.

[0078] Exemplarily, for example, after obtaining the facial characteristics of the target user corresponding to the target authentication object, the router first reads the configured storage module of itself to obtain the reference facial characteristics corresponding to a plurality of users who have pre-registered identity information and obtained access rights. Then, the router compares the obtained facial characteristics of the target user and the plurality of reference facial characteristics respectively to obtain a plurality of first comparison results. After that, when the router determines that a certain comparison result among the plurality of first comparison results is that the facial characteristics of the target user and the reference facial characteristics match, it determines that there is a target reference facial characteristic among the reference facial characteristics that is consistent with the facial characteristics of the target user. The router thus determines that the user holding the target 5G device is a user who has obtained access rights, and determines that the target 5G device can access the preset target network, and further determines that the authentication result corresponding to the target authentication object is authentication passed. Similarly, when the router determines that all the plurality of first comparison results are that the facial characteristics of the target user and the reference facial characteristics do not match, it determines that there is no target reference facial characteristic among the plurality of reference facial characteristics. The router thus determines that the user holding the target 5G device is a user who has not obtained access rights, and determines that the target 5G device cannot access the target network, and further determines that the authentication result corresponding to the target authentication object is authentication failure.

[0079] In addition, in this embodiment and another embodiment, after the router determines the authentication result corresponding to the target authentication object according to the first target image, it can further obtain the user fingerprint feature of the target authentication object through the fingerprint acquisition device configured by itself, and compare the user fingerprint feature with a plurality of preset reference fingerprint features respectively to obtain a plurality of second comparison results. Then, when the router determines that any one of the first comparison results among the plurality of first comparison results is that the target user face feature matches the reference face feature, and any one of the second comparison results among the plurality of second comparison results is that the user fingerprint feature matches the reference fingerprint feature, it determines that the user holding the target 5G device is the user who has obtained the access permission, and determines that the authentication result corresponding to the target authentication object is authentication passed. When it is determined that all of the first comparison results are that the target user face feature does not match the reference face feature, and / or all of the second comparison results are that the user fingerprint feature does not match the reference fingerprint feature, it determines that the user holding the target 5G device is the user who has not obtained the access permission, and determines that the authentication result corresponding to the target authentication object is authentication failed.

[0080] Step S40: When it is determined that the authentication result is authentication passed, control the target 5G device to access a preset target network;

[0081] In this embodiment, when the router determines that the authentication result corresponding to the target authentication object is authentication passed, it constructs a target communication channel with the target 5G device, and controls the target 5G device to access the preset target network through the target communication channel.

[0082] Exemplarily, for example, when the router determines that the authentication result corresponding to the target authentication object is authentication passed, it first constructs a shared encryption key with the target 5G device through a preset key exchange protocol, and performs a key certificate exchange operation with the target 5G device to exchange the encryption key and digital certificate respectively. Then, after the router determines that the target 5G device has completed the verification operation of the encryption key and digital certificate, it determines the encryption communication parameters corresponding to the target 5G device, and constructs a target communication channel corresponding to the target 5G device based on the encryption communication parameters. Then, the router allocates the first IP address parameter to the target 5G device through the target communication channel, so that the target 5G device accesses the preset target network based on the first IP address parameter.

[0083] It should be noted that the encryption communication parameter is an encryption algorithm matching the target 5G device. The encryption communication parameter can be pre-stored in the storage module by technical personnel for the router to obtain by accessing the storage module when needed. It can be understood that this application does not limit the acquisition method and specific content of the encryption algorithm. In addition, the specific processing process of the router constructing the target communication channel based on the encryption algorithm is a prior art, so it will not be elaborated here.

[0084] In a feasible implementation manner, the step of "controlling the target 5G device to access a preset target network" in the above step S40 may specifically include steps S401 to S403:

[0085] Step S401: Read the device identification information included in the access request;

[0086] Step S402: Based on the device identification information, construct a target communication channel corresponding to the target 5G device, and generate a first address parameter according to the device identification information;

[0087] Step S403: Send the first address parameter to the target 5G device through the target communication channel, so as to control the target 5G device to access the preset target network according to the first address parameter.

[0088] In this embodiment, when the router determines that the authentication result corresponding to the target authentication object is authentication passed, the router first reads the access request sent by the target 5G device to determine the device identification information included in the access request. Then, the router determines the encryption communication parameters corresponding to the target 5G device based on the device identification information, and constructs a target communication channel between the router and the target 5G device based on the encryption communication parameters. At the same time, the router generates a first address parameter corresponding to the target 5G device based on the device identification information. Finally, the router sends the first address parameter to the target 5G device through the target communication channel, so that the target 5G device accesses the preset target network based on the first address parameter.

[0089] Exemplarily, for example, when the router determines that the authentication result corresponding to the target authentication object is authentication passed, the router first reads the above access request to obtain the device identification information corresponding to the target 5G device carried in the access request. Then, the router determines the key exchange protocol corresponding to the target 5G device based on the device identification information. The router thus constructs an encryption key and a digital certificate based on the key exchange protocol, and sends the encryption key and the digital certificate to the target 5G device for the target 5G device to verify the encryption key and the digital certificate. After receiving the verification result returned by the target 5G device, the router determines the encryption communication parameters such as the encryption algorithm corresponding to the target 5G device based on the device identification information, and constructs a target communication channel between itself and the target 5G device based on the encryption communication parameters. At the same time, the router generates a first IP address matching the device identification information based on the preset DHCP (Dynamic Host Configuration Protocol), and finally, the router sends the first IP address to the target 5G device through the target communication channel, so that the target 5G device accesses the preset target network by following the first IP address.

[0090] In this embodiment, when the router is running, it first receives an access request sent by a target 5G device. The router then reads the access request to determine the location information of the target 5G device based on the access request. At the same time, the router calls an image acquisition device to capture the target 5G device to obtain a second target image containing multiple users. The router then determines the user holding the target 5G device among the multiple users based on the location information and the second target image, and further determines the user holding the target 5G device as the target authentication object that needs to perform an identity authentication operation. After that, the router calls the image acquisition device configured by itself to capture the target authentication object, thereby obtaining a first target image containing the target authentication object. The router then processes the first target image to extract the target user physiological characteristics contained in the first target image that can indicate the identity information of the target authentication object. After that, the router performs an identity authentication operation based on the target user physiological characteristics to determine whether the authentication result corresponding to the target authentication object is authentication passed or authentication failed. Finally, when the router determines that the authentication result corresponding to the target authentication object is authentication passed, it constructs a target communication channel with the target 5G device and controls the target 5G device to access a preset target network through the target communication channel.

[0091] In this way, this application solves the technical problem that there are relatively large security risks in routers in the related art, that is, this application, when the router receives an access request sent by a 5G device, collects the physiological characteristics of the user holding the 5G device and performs an identity authentication operation based on the physiological characteristics to determine whether the user has access rights. This can ensure that only when the user himself has access rights, the 5G device will be controlled to access the network, avoiding unauthorized other devices from being able to access the network at will in the case of Wifi password leakage, achieving the technical effect of reducing the security risk of the router.

[0092] Based on the first embodiment of this application, the second embodiment of this application is proposed here. In the second embodiment of this application, the same or similar content as in the above-mentioned first embodiment can be referred to the above introduction and will not be elaborated later. On this basis, the target network contains multiple preset sub-network environments. Please refer to Figure 3 , Figure 3 which is the flowchart provided for the second method embodiment of the 5G wireless device accessing the router in this application. As Figure 3 shown, after the above step S401, the method for the 5G wireless device to access the router in this application may further include steps A10 to A20:

[0093] Step A10: Determine the access device type corresponding to the target 5G device according to the device identification information;

[0094] Step A20: Based on the access device type, determine a target sub-network environment among multiple preset sub-network environments, and control the target 5G device to access the target sub-network environment.

[0095] In this embodiment, after the router determines the device identification information corresponding to the target 5G device, it may first determine the access device type corresponding to the target 5G device according to the device identification information. Then, among the multiple preset sub-network environments included in the target network, the router determines a target sub-network environment that matches the access device type, and constructs a second communication channel between the target sub-network environment and the target 5G device. Furthermore, the router controls the target 5G device to access the target sub-network environment through the second communication channel, so that the target 5G device can access the Internet in the target sub-network environment.

[0096] Exemplarily, for example, after the router determines the device identification information corresponding to the target 5G device, it further determines that the device access type corresponding to the target 5G device is a guest device according to the device identification information. Then, the router filters multiple preset sub-network environments such as the guest network environment, office network environment, and home network environment included in the target network based on the device access type, so as to determine that the guest network environment is the target sub-network environment that matches the device access type among the preset multiple sub-network environments. The router determines the encryption algorithms corresponding to the target 5G device and the guest network environment based on the device identification information, and constructs a second communication channel between the target 5G device and the guest network environment based on the encryption algorithm. At the same time, the router generates a third IP address that matches the device identification information based on the preset DHCP, and sends the third IP address to the target 5G device through the second communication channel, and applies ACL to the guest network environment, so that the target 5G device can access the guest network environment and restricts the resources and network services that the target 5G device can access in the guest network environment.

[0097] In this way, the router can determine the device access type of the 5G device, so as to allocate the 5G device to different environments according to different device access types, further improving the security of the router.

[0098] In a feasible implementation manner, the step of "determine a target sub-network environment among multiple preset sub-network environments based on the access device type" in the above step A20 may specifically include steps A201 to A203:

[0099] Step A201: Determine the device type matching rules corresponding to each of the multiple preset sub-network environments, and determine the reference device type corresponding to each of the device type matching rules;

[0100] Step A202: Compare the access device type with the multiple reference device types to determine the target device type among the multiple reference device types;

[0101] Step A203: Determine the preset sub-network environment corresponding to the target device type as the target sub-network environment.

[0102] In this embodiment, after the router determines the access device type corresponding to the target 5G device, it first determines the device type matching rules corresponding to each of the multiple preset sub-network environments included in the target network, and determines the reference device types included in the multiple device type matching rules. Then, the router compares the obtained access device type with the multiple reference device types respectively, so as to determine the target device type that is consistent with the access device type among the multiple reference device types. Finally, the router determines the preset sub-network environment corresponding to this target device type as the target sub-network environment.

[0103] Exemplarily, for example, after the router determines that the access device type corresponding to the target 5G device is the visitor device type, it first determines the device type matching rules corresponding to each of the multiple preset sub-network environments such as the visitor network environment, the home network environment, and the office network environment included in the target network. Thus, based on the device type matching rules, it determines that the reference device type corresponding to the visitor network environment is the visitor device type, the reference device type corresponding to the home network environment is the home device type, and the reference device type corresponding to the office network environment is the office device type. Then, the router compares the obtained access device type with the multiple reference device types respectively, so as to determine the target device type that is consistent with the access device type among the visitor device type, the home device type, and the office device type. Finally, when the router determines that the target device type is the visitor device type, it determines the visitor network environment corresponding to the visitor device type as the target sub-network environment.

[0104] In this way, the router can determine the device access type of the 5G device, and thus allocate the 5G device to different environments according to the different device access types, further improving the security of the router.

[0105] Based on the first embodiment and / or the second embodiment of the present application, the third embodiment of the present application is hereby proposed. In the third embodiment of the present application, for the same or similar content as in the above embodiments, reference can be made to the above introduction and will not be repeated hereinafter. On this basis, after the above step A20, the method for a 5G wireless device to access a router according to the present application may further include steps B10 to B30:

[0106] Step B10: Obtain the network access log of the target 5G device, and determine whether there is a security risk for the target 5G device based on the network access log;

[0107] Step B20: If it is determined that the target 5G device has the security risk, obtain a preset second address parameter;

[0108] Step B30: Send the second address parameter to the target 5G device to control the target 5G device to switch from the target sub-network environment to a preset isolated network environment.

[0109] In this embodiment, after the router controls the target 5G device to access the target sub-network environment, it further detects the target 5G device to obtain the network access logs generated when the target 5G device sends and receives data. Then, the router determines whether the target 5G device has a security risk based on the network access logs. After that, if the router determines that the target 5G device has a security risk, it obtains the second address parameter corresponding to the preset isolated network environment. Finally, the router sends the second address parameter to the target 5G device through the above-mentioned second communication channel, so that the target 5G device accesses the isolated network environment based on the second address parameter.

[0110] Exemplarily, for example, after the router controls the target 5G device to access the guest network environment, it further detects the target 5G device to obtain the network access logs generated by the target 5G device in the guest network environment. Then, the router compares the network access logs with a preset plurality of abnormal network logs. Thus, when it is determined that there is an abnormal network log in the plurality of abnormal network logs that matches the network access logs, it is determined that the target 5G device has a security risk. After that, the router obtains the second IP address corresponding to the preset isolated network environment and sends the second IP address to the target 5G device through the above-mentioned second communication channel, so that the target 5G device accesses the separately operating isolated network environment. At the same time, the router adds an ACL to the isolated network environment to restrict the resources and network services that the target 5G device can access in the isolated network environment.

[0111] In this way, when the router detects that the target 5G device has a security risk, it can immediately switch the target 5G device to a separately operating isolated network environment, thereby avoiding risks in the main network and further improving the security of the router.

[0112] Exemplarily, to help understand the implementation process of the method for a 5G wireless device to access a router after combining this embodiment with the above embodiment, please refer to Figure 2 , Figure 2 A brief flowchart of the method for a 5G wireless device to access a router is provided. Specifically:

[0113] In this embodiment, the router first receives an access request sent by a target 5G device, reads the access request to determine the location information of the target 5G device, and then controls the image acquisition device configured thereon to capture a second target image including multiple users. Based on the location information, the router filters the multiple users included in the second target image to determine the target user who holds the target 5G device, and determines the target user as the target authentication object that needs to perform an identity authentication operation. After that, the router calls the image acquisition device to photograph the target authentication object to obtain a first target image including the target authentication object, and extracts the facial features of the target user included in the first target image. Then, the router compares the facial features of the target user with a plurality of preset reference facial features to obtain a plurality of first comparison results, and determines the authentication result corresponding to the target authentication object based on the plurality of first comparison results. After that, when the router determines that the authentication result is authentication passed, it reads the device identification information included in the access request, and determines the access device type corresponding to the target 5G device based on the device identification information. Then, the router determines a target sub-network environment that matches the access device type among the plurality of sub-network environments included in the target network, and constructs a communication channel between the target sub-network environment and the target 5G device. At the same time, the router assigns a corresponding IP address to the target 5G device and sends the IP address to the target 5G device through the communication channel to enable the target 5G device to access the target sub-network environment. Finally, the router collects the network access logs generated by the target 5G device in the target sub-network environment, and determines whether the target 5G device has a security risk based on the network access logs. When the router determines that the target 5G device has a security risk, it controls the target 5G device to switch from the target sub-network environment to an isolated network environment so that the target 5G device operates in the isolated network environment.

[0114] It should be noted that the above examples are only for understanding the present application and do not constitute a limitation on the method for a 5G wireless device to access a router in the present application. Based on this technical concept, more forms of simple transformations are within the protection scope of the present application.

[0115] The present application also provides a 5G wireless device access router device. Please refer to Figure 4 , the 5G wireless device access router device is applied to a router configured with an image acquisition device, and includes:

[0116] A target determination module 10, configured to receive an access request sent by a target 5G device, and determine a target authentication object corresponding to the target 5G device based on the access request;

[0117] The feature acquisition module 20 is configured to capture a first target image including the target authentication object through the image acquisition device and extract the target user physiological features included in the first target image;

[0118] The authentication execution module 30 is configured to determine the authentication result corresponding to the target authentication object based on the target user physiological features, where the authentication result includes authentication passed and authentication failed;

[0119] The device access module 40 is configured to control the target 5G device to access a preset target network when it is determined that the authentication result is authentication passed.

[0120] In a feasible implementation manner, the authentication execution module 30 is further configured to:

[0121] Obtain a plurality of preset reference physiological features;

[0122] Compare the target user physiological features with the plurality of reference physiological features respectively to obtain a plurality of first comparison results;

[0123] Judge whether the target reference physiological feature is included in the plurality of reference physiological features based on the plurality of first comparison results, where the target reference physiological feature is the reference physiological feature that is consistent with the target user physiological feature;

[0124] If it is judged that the target reference physiological feature is included in the plurality of reference physiological features, determine that the authentication result corresponding to the target authentication object is authentication passed;

[0125] If it is judged that the target reference physiological feature is not included in the plurality of reference physiological features, determine that the authentication result corresponding to the target authentication object is authentication failed.

[0126] In a feasible implementation manner, the device access module 40 is further configured to:

[0127] Read the device identification information included in the access request;

[0128] Construct a target communication channel corresponding to the target 5G device based on the device identification information and generate a first address parameter according to the device identification information;

[0129] Send the first address parameter to the target 5G device through the target communication channel to control the target 5G device to access the preset target network according to the first address parameter.

[0130] In a feasible implementation manner, the device access module 40 is further configured to:

[0131] After the step of reading the device identification information included in the access request, the method further includes:

[0132] Determine the access device type corresponding to the target 5G device according to the device identification information;

[0133] Based on the access device type, determine a target sub-network environment among a plurality of the preset sub-network environments, and control the target 5G device to access the target sub-network environment.

[0134] In a feasible implementation manner, the device access module 40 is further configured to:

[0135] Determine the device type matching rules corresponding to the respective preset sub-network environments, and determine the reference device types corresponding to the respective device type matching rules;

[0136] Compare the access device type with the plurality of reference device types to target a device type among the plurality of reference device types;

[0137] Determine the preset sub-network environment corresponding to the target device type as the target sub-network environment.

[0138] In a feasible implementation manner, the device access module 40 is further configured to:

[0139] Obtain the network access log of the target 5G device, and determine whether there is a security risk for the target 5G device based on the network access log;

[0140] If it is determined that the target 5G device has the security risk, obtain a preset second address parameter;

[0141] Send the second address parameter to the target 5G device to control the target 5G device to switch from the target sub-network environment to a preset isolation network environment.

[0142] The 5G wireless device access router device provided by the present application adopts the method of the 5G wireless device access router in the above embodiment, and can solve the technical problem that there are relatively large security risks in the related art routers. Compared with the prior art, the beneficial effects of the 5G wireless device access router device provided by the present application are the same as the beneficial effects of the method of the 5G wireless device access router provided by the above embodiment, and other technical features in the 5G wireless device access router device are the same as the features disclosed in the method of the above embodiment, and will not be elaborated here.

[0143] This application provides a router, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method for a 5G wireless device to access the router in the first embodiment above.

[0144] The following refers to Figure 5 , which shows a schematic structural diagram of a router suitable for implementing the embodiments of the present application. The router in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 5 The router shown is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present application.

[0145] As Figure 5 shown, the router may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM: Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of the router are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the router to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows a router with various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems may be alternatively implemented or had.

[0146] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product that includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by a processing device 1001, the above-mentioned functions defined in the methods of the embodiments disclosed in the present application are executed.

[0147] The router provided by the present application adopts the method for a 5G wireless device to access a router in the above embodiments, and can solve the technical problem of a relatively large security risk existing in the router in the related art. Compared with the prior art, the beneficial effects of the router provided by the present application are the same as those of the method for a 5G wireless device to access a router provided in the above embodiments, and other technical features in the router are the same as those disclosed in the method of the previous embodiment, and will not be elaborated herein.

[0148] It should be understood that the various parts disclosed in the present application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.

[0149] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application, and all of them should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0150] The present application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the method for a 5G wireless device to access a router in the above embodiments.

[0151] The computer-readable storage medium provided by the present application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. The program code contained on the computer-readable storage medium can be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0152] The above computer-readable storage medium can be included in a router; or it can exist independently and not be assembled into the router.

[0153] The above computer-readable storage medium carries one or more programs. When the one or more programs are executed by the router, the router receives an access request sent by a target 5G device, and determines a target authentication object corresponding to the target 5G device based on the access request; captures a first target image containing the target authentication object through the image acquisition device, and extracts target user physiological features included in the first target image; determines an authentication result corresponding to the target authentication object based on the target user physiological features, where the authentication result includes authentication passed and authentication failed; and controls the target 5G device to access a preset target network when it is determined that the authentication result is authentication passed.

[0154] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The above-mentioned programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0155] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of the code, and this module, program segment, or part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0156] The modules described in the embodiments of this application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation on the unit itself in some cases.

[0157] The readable storage medium provided by this application is a computer-readable storage medium, and the computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for performing the method of the above-mentioned 5G wireless device accessing the router, which can solve the technical problem of the large security risk existing in the router in the related art. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by this application are the same as those of the method of the 5G wireless device accessing the router provided in the above embodiments, and will not be elaborated here.

[0158] The present application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the method for a 5G wireless device to access a router as described above are implemented.

[0159] The computer program product provided by the present application can solve the technical problem that there are relatively large security risks in routers in related technologies. Compared with the prior art, the beneficial effects of the computer program product provided by the present application are the same as those of the method for a 5G wireless device to access a router provided in the above embodiments, and will not be elaborated here.

[0160] The foregoing are only partial embodiments of the present application, and thus do not limit the patent scope of the present application. Any equivalent structural transformation made under the technical concept of the present application by using the content of the specification and drawings of the present application, or any direct / indirect application in other related technical fields, is included in the patent protection scope of the present application.

Claims

1. A method for a 5G wireless device to access a router, characterized in that, The method is applied to a router configured with an image acquisition device. The method includes: Receiving an access request sent by a target 5G device, and determining a target authentication object corresponding to the target 5G device based on the access request. Among them, the step of determining the target authentication object corresponding to the target 5G device based on the access request includes parsing the access request to obtain the location information of the target 5G device; capturing a multi-target image containing at least one authentication object through the image acquisition device; identifying and determining the target authentication object holding the target 5G device in the multi-target image based on the location information and the multi-target image; Capturing a first target image containing the target authentication object through the image acquisition device, and extracting target user physiological features included in the first target image; Determining an authentication result corresponding to the target authentication object based on the target user physiological features, where the authentication result includes authentication passed and authentication failed; When it is determined that the authentication result is authentication passed, controlling the target 5G device to access a preset target network. Among them, the step of controlling the target 5G device to access the preset target network includes: Reading device identification information included in the access request; Constructing a target communication channel corresponding to the target 5G device based on the device identification information, and generating a first address parameter according to the device identification information. Among them, the step of constructing the target communication channel corresponding to the target 5G device based on the device identification information includes calling a preset key exchange protocol according to the device identification information to generate an encryption key and a digital certificate that are uniquely matched with the target 5G device; sending the encryption key and the digital certificate to the target 5G device; when receiving a verification success result returned by the target 5G device, determining encryption communication parameters matching the target 5G device based on the device identification information, and constructing a target communication channel corresponding to the target 5G device based on the encryption communication parameters; Sending the first address parameter to the target 5G device through the target communication channel to control the target 5G device to access the preset target network according to the first address parameter.

2. The method according to claim 1, wherein The step of obtaining the authentication result corresponding to the target authentication object based on the target user physiological features includes: Obtaining a preset plurality of reference physiological features; Respectively comparing the target user physiological features with the plurality of reference physiological features to obtain a plurality of first comparison results; Judging whether the plurality of reference physiological features include a target reference physiological feature based on the plurality of first comparison results, where the target reference physiological feature is a reference physiological feature that is consistent with the target user physiological features; If it is judged that the plurality of reference physiological features include the target reference physiological feature, determining that the authentication result corresponding to the target authentication object is authentication passed; If it is judged that the plurality of reference physiological features do not include the target reference physiological feature, determining that the authentication result corresponding to the target authentication object is authentication failed.

3. The method according to claim 2, characterized in that, The target network contains multiple preset sub-network environments; After the step of reading the device identification information included in the access request, the method further includes: Determining the access device type corresponding to the target 5G device according to the device identification information; Based on the access device type, determining a target sub-network environment among multiple preset sub-network environments, and controlling the target 5G device to access the target sub-network environment.

4. The method according to claim 3, wherein The step of determining a target sub-network environment among multiple preset sub-network environments based on the access device type includes: Determining the device type matching rules corresponding to each of the multiple preset sub-network environments, and determining the reference device types corresponding to the device type matching rules; Comparing the access device type with the multiple reference device types to determine a target device type among the multiple reference device types; Determining the preset sub-network environment corresponding to the target device type as the target sub-network environment.

5. The method according to claim 3, wherein After the step of controlling the target 5G device to access the target sub-network environment, the method further includes: Obtaining the network access log of the target 5G device, and determining whether there is a security risk for the target 5G device based on the network access log; If it is determined that the target 5G device has the security risk, obtaining a preset second address parameter; Sending the second address parameter to the target 5G device to control the target 5G device to switch from the target sub-network environment to a preset isolation network environment.

6. A 5G wireless device access router device, characterized in that, The 5G wireless device access router device is applied to a router configured with an image acquisition device, and the device includes: A target determination module, configured to receive an access request sent by a target 5G device, and determine a target authentication object corresponding to the target 5G device based on the access request. Among them, determining the target authentication object corresponding to the target 5G device based on the access request includes parsing the access request to obtain the location information of the target 5G device; capturing a multi-target image containing at least one authentication object through the image acquisition device; based on the location information and the multi-target image, identifying and determining the target authentication object holding the target 5G device in the multi-target image; A feature collection module, configured to capture a first target image containing the target authentication object through the image acquisition device, and extract the target user physiological features included in the first target image; An authentication execution module, configured to determine an authentication result corresponding to the target authentication object based on the target user physiological features, where the authentication result includes authentication passed and authentication failed; A device access module, configured to control the target 5G device to access a preset target network when it is determined that the authentication result is authentication passed. Among them, controlling the target 5G device to access a preset target network includes: Reading the device identification information included in the access request; Construct a target communication channel corresponding to the target 5G device based on the device identification information, and generate a first address parameter according to the device identification information. Among them, the step of constructing a target communication channel corresponding to the target 5G device based on the device identification information includes: according to the device identification information, call a preset key exchange protocol to generate an encryption key and a digital certificate that uniquely match the target 5G device; send the encryption key and the digital certificate to the target 5G device; upon receiving the verification success result returned by the target 5G device, determine the encryption communication parameters that match the target 5G device based on the device identification information, and construct a target communication channel corresponding to the target 5G device based on the encryption communication parameters; Send the first address parameter to the target 5G device through the target communication channel to control the target 5G device to access a preset target network according to the first address parameter.

7. A router, characterized in that, The router includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the method for a 5G wireless device to access a router according to any one of claims 1 to 5.

8. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the method for a 5G wireless device to access a router according to any one of claims 1 to 5 are implemented.

9. A computer program product, characterized in that, The computer program product includes a computer program. When the computer program is executed by a processor, the steps of the method for a 5G wireless device to access a router according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Routing device, network access method and device of communication terminal

    CN105791139A

  • Face identification router

    CN204392290U