Data transmission system and method

By deploying a WiFi network connection and authentication subsystem in 5G mobile phones, two-way authentication and dynamic data transmission switching between the terminal and the WiFi network are achieved, solving the security and power consumption issues of 5G mobile phones in WiFi network connections, and improving the convenience of connection and battery efficiency.

CN119110283BActive Publication Date: 2026-02-03CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411456818.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-17
Publication Date
2026-02-03
Estimated Expiration
2044-10-17

AI Technical Summary

Technical Problem

Typical mobile terminals such as 5G phones cannot connect to WiFi networks securely, conveniently, and with low power consumption when using WiFi and 5G technologies, resulting in faster power consumption.

Method used

By deploying a WiFi network connection subsystem and an authentication subsystem, two-way authentication between the target terminal and the WiFi network is achieved, connection authentication information is dynamically generated, MAC address authentication and encryption mechanisms are used to ensure security, and data transmission methods are switched according to network performance and location.

Benefits of technology

It improves the security of WiFi networks and the battery efficiency of terminals, reduces energy consumption, and ensures convenient connection and data transmission in different scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119110283B_ABST
    Figure CN119110283B_ABST
Patent Text Reader

Abstract

The application discloses a data transmission system and method. A WiFi network connection subsystem in the system acquires and reports cell information of a cell where a terminal is located; then a WiFi network authentication subsystem verifies whether the cell is covered by a WiFi network based on the cell information, and if yes, performs security check on the terminal, and determines terminal identification information corresponding to a terminal MAC address, and sends encrypted information of the terminal MAC address and indication information for indicating data transmission through the WiFi network to the WiFi network connection subsystem according to the terminal identification information, the WiFi network connection subsystem decrypts the encrypted information, and when the decrypted MAC address is the same as the terminal MAC address, controls the terminal to perform data transmission through the WiFi network according to the indication information. The application solves the technical problem of low safety of the whole system due to lack of security check of the terminal on the WiFi network in related data transmission technologies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of wireless communication technology, and more specifically, to a data transmission system and method. Background Technology

[0002] Currently, typical mobile terminals such as 5G phones have both WiFi and 5G access capabilities. This means that when using WiFi hotspots, they are used in permanent scenarios such as homes and fixed office locations, while in public places such as shopping malls and supermarkets, they often use the data within their mobile phone data plan for data transmission services.

[0003] However, in non-residential WiFi networks, upon arriving at an unfamiliar location, users must first obtain the WiFi network's SSID and access password before using it; or they must use a one-time password or similar method to connect to WiFi normally. Furthermore, to quickly connect to WiFi in trusted locations, users often leave the WiFi switch on for extended periods, or install WiFi auto-connection apps like "WiFi Genie" on their phones. These apps periodically scan for WiFi signals to quickly connect to any WiFi hotspot. This periodic scanning keeps the phone in a high-power consumption state, accelerating battery drain.

[0004] In summary, typical mobile terminals such as 5G smartphones cannot securely, conveniently, and with low power consumption simultaneously use WiFi and 5G technologies. Currently, no effective solution has been proposed to address these issues. Summary of the Invention

[0005] This application provides a data transmission system and method to at least solve the technical problem that the overall system security is low due to the lack of terminal security verification of WiFi networks in related data transmission technologies.

[0006] According to one aspect of the embodiments of this application, a data transmission system is provided, including: a WiFi network connection subsystem deployed on the target terminal side and a WiFi network authentication subsystem deployed on the wireless network side, wherein the WiFi network connection subsystem is used to obtain cell information of the target serving cell where the target terminal is located in the current period, and report the cell information to the WiFi network authentication subsystem; the WiFi network authentication subsystem is used to determine whether the target serving cell is covered by a WiFi network based on the cell information, and when the target serving cell is covered by a target WiFi network, respond to the WiFi network connection subsystem's connection request to the target WiFi network; perform security verification on the target terminal, and when the target terminal passes the security verification, determine the target terminal identification information corresponding to the target MAC address of the target terminal, and send encrypted information obtained by encrypting the target MAC address and the indication information for data transmission through the target WiFi network to the WiFi network connection subsystem according to the target terminal identification information; the WiFi network connection subsystem is further used to decrypt the encrypted information, determine whether the decrypted MAC address is the same as the target MAC address, and when the decrypted MAC address is the same as the target MAC address, control the target terminal to transmit data through the target WiFi network according to the indication information.

[0007] Optionally, the WiFi network connection subsystem includes a serving cell monitoring module, which is used to periodically acquire cell information of the serving cell where the target terminal is located, and report the cell information of the target serving cell where the target terminal is located in the current period to the WiFi network authentication subsystem. The cell information includes at least one of the following: physical cell identifier, base station identifier of the base station where the serving cell is located, and group code of the cell group to which the serving cell belongs.

[0008] Optionally, the data transmission system further includes: a WiFi network connection collaboration subsystem connected to the WiFi network authentication subsystem, and the WiFi network connection collaboration subsystem includes: a connection authentication information generation module; the WiFi network authentication subsystem includes: a terminal air interface connection authentication module; and the WiFi network connection subsystem further includes: a connection authentication information storage module. The connection authentication information generation module is used to periodically generate connection authentication information for each WiFi network according to preset information generation rules, and store the connection authentication information in a preset database. The connection authentication information includes: an SSID name and the corresponding SSID connection password. The terminal air interface connection authentication module is used to connect the cell information with... The system matches the preset wireless indoor distribution system cell group information to obtain the corresponding matching results. The wireless indoor distribution system cell group information includes multiple cell groups and the WiFi network covering each cell group, and each cell group includes multiple cells under the coverage of the same WiFi network. If the matching result is successful, the target WiFi network covered in the target service cell is determined. The target connection authentication information of the target WiFi network is obtained from the connection authentication information generation module and fed back to the connection authentication information storage module. The target connection authentication information is recorded in the historical connection database of the target terminal and the usage priority of the target connection authentication information is set to the highest priority.

[0009] Optionally, the WiFi network connection collaboration subsystem also includes: a WiFi network encoding module and a terminal MAC address authentication module. The WiFi network encoding module is used to obtain the MAC addresses of all access points of the target WiFi network and encode the MAC addresses of all access points using a preset encoding method to obtain the corresponding target network encoding information. The terminal MAC address authentication module is used to perform security verification on the target terminal based on the target MAC address when the connection request of the WiFi network connection subsystem is successfully responded to by the WiFi network authentication subsystem, and send the target network encoding information to the WiFi network authentication subsystem when the verification is successful.

[0010] Optionally, the terminal MAC address authentication module is further configured to add the target MAC address to a preset connection-state MAC address list; determine whether the target MAC address is in a preset whitelist MAC address list, wherein the whitelist MAC address list stores the MAC addresses of multiple terminals using the target WiFi network for data transmission; if the target MAC address is in the whitelist MAC address list, add the target MAC address to a preset service-state MAC address list, and determine that the target terminal has passed the security verification.

[0011] Optionally, the WiFi network authentication subsystem further includes: a terminal identification module and an encryption module. The terminal identification module is used to determine the target terminal identification information corresponding to the target MAC address from a preset terminal identification set. The terminal identification set stores the correspondence between the MAC addresses of multiple terminals in the whitelist MAC address list of the target WiFi network and the terminal identification information. The terminal identification information includes at least one of the following: a globally unique temporary identifier and an International Mobile Subscriber Identity (IMSI). The encryption module is used to encrypt the target MAC address and the indication information used to indicate data transmission through the target WiFi network according to a preset encryption key to obtain encrypted information. The encrypted information is then sent to the WiFi network connection subsystem via a 5G network message based on the target terminal identification information.

[0012] Optionally, the WiFi network connection subsystem further includes: a decryption module and a data transmission control module. The decryption module is used to decrypt encrypted information using a preset decryption key to obtain the corresponding decryption result; check if the MAC address in the decryption result is the same as the target MAC address; if the MAC address in the decryption result is different from the target MAC address, determine that the target WiFi network has failed the security check; if the MAC address in the decryption result is the same as the target MAC address, determine that the target WiFi network has passed the security check. The data transmission control module is used to prevent data transmission through the target WiFi network when the target WiFi network fails the security check; and to control the target terminal to transmit data through the target WiFi network according to the instruction information when the target WiFi network passes the security check.

[0013] Optionally, the WiFi network connection subsystem further includes: a network performance monitoring module, which is used to periodically monitor the network performance of the target WiFi network, wherein the network performance includes at least one of the following: received signal strength and carrier-to-interference ratio; and a data transmission control module, which is used to continue controlling the target terminal to transmit data through the target WiFi network when the network performance of the target WiFi network is not lower than a preset network performance threshold over multiple periods; and to stop the target terminal from transmitting data through the target WiFi network and control the target terminal to use a cellular data network for data transmission when the network performance of the target WiFi network is lower than the preset network performance threshold over multiple periods.

[0014] Optionally, the serving cell monitoring module is used to monitor whether the target serving cell where the target terminal is located within the current target period belongs to the target cell group of the target WiFi network, wherein the target cell group includes multiple cells within the coverage area of ​​the target WiFi network; the data transmission control module is used to continue controlling the target terminal to transmit data through the target WiFi network when the target serving cell belongs to the target cell group; when the target serving cell does not belong to the target cell group, determine the duration for which the target terminal stays in the target serving cell; if the duration does not exceed a preset duration threshold, continue controlling the target terminal to transmit data through the target WiFi network; if the duration exceeds the preset duration threshold, stop the target terminal from transmitting data through the target WiFi network and control the target terminal to use the cellular data network for data transmission.

[0015] According to another aspect of the embodiments of this application, a data transmission method is also provided. This method is applied to a WiFi network connection subsystem, comprising: obtaining cell information of the target serving cell where the target terminal is located in the current period; reporting the cell information to a WiFi network authentication subsystem and obtaining encrypted information fed back by the WiFi network authentication subsystem, wherein the WiFi network authentication subsystem is used to determine whether the target serving cell is covered by a WiFi network based on the cell information, and when the target serving cell is covered by a target WiFi network, responding to a connection request from the WiFi network connection subsystem to the target WiFi network; performing security verification on the target terminal, and when the target terminal passes the security verification, determining target terminal identification information corresponding to the target MAC address of the target terminal, and sending encrypted information obtained by encrypting the target MAC address and indication information for indicating data transmission through the target WiFi network to the WiFi network connection subsystem according to the target terminal identification information; decrypting the encrypted information and determining whether the decrypted MAC address is the same as the target MAC address, and when the decrypted MAC address is the same as the target MAC address, controlling the target terminal to transmit data through the target WiFi network according to the indication information.

[0016] According to another aspect of the embodiments of this application, a data transmission method is also provided. The method is applied to a WiFi network authentication subsystem, including: obtaining cell information of the target serving cell where the target terminal is located in the current period, reported by the WiFi network connection subsystem; determining whether the target serving cell is covered by a WiFi network based on the cell information, and responding to the WiFi network connection subsystem's connection request to the target WiFi network when the target serving cell is covered by a target WiFi network; performing security verification on the target terminal, and determining the target terminal identification information corresponding to the target MAC address of the target terminal when the target terminal passes the security verification, and sending encrypted information obtained by encrypting the target MAC address and the indication information for data transmission through the target WiFi network to the WiFi network connection subsystem according to the target terminal identification information, wherein the WiFi network connection subsystem is used to decrypt the encrypted information, determine whether the decrypted MAC address is the same as the target MAC address, and when the decrypted MAC address is the same as the target MAC address, controlling the target terminal to transmit data through the target WiFi network according to the indication information.

[0017] According to another aspect of the embodiments of this application, a non-volatile storage medium is also provided, the non-volatile storage medium including a stored computer program, wherein the device where the non-volatile storage medium is located executes the above-described data transmission method by running the computer program.

[0018] According to another aspect of the embodiments of this application, a computer program product is also provided, the computer program product including a stored computer program, wherein the computer program implements the above-described data transmission method when executed by a processor.

[0019] In this embodiment of the application, the WiFi network connection subsystem in the data transmission system performs security verification on the target WiFi network of the target serving cell where the target terminal is located in the current period, and the WiFi network authentication subsystem performs security verification on the target terminal, thereby realizing two-way authentication between the target WiFi network and the target terminal, ensuring the security of the target terminal and the target WiFi network respectively, thus solving the technical problem that the security of the entire system is low due to the lack of terminal security verification of WiFi network in related data transmission technologies. Attached Figure Description

[0020] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0021] Figure 1This is a schematic diagram of an optional data transmission system according to an embodiment of this application;

[0022] Figure 2 This is a schematic diagram of the structure of a computer device (mobile device) for implementing a data transmission method according to an embodiment of this application;

[0023] Figure 3 This is a flowchart illustrating an optional data transmission method according to an embodiment of this application;

[0024] Figure 4 This is a flowchart illustrating another optional data transmission method according to an embodiment of this application. Detailed Implementation

[0025] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0026] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0027] Furthermore, all information and data (including but not limited to user device information, user personal information, etc.) involved in this application are information and data authorized by the user or fully authorized by all parties. For example, this system has an interface with the relevant user or organization. Before obtaining relevant information, it needs to send an acquisition request to the aforementioned user or organization through the interface, and obtain the relevant information after receiving consent from the aforementioned user or organization.

[0028] Example 1

[0029] According to the embodiments of this application, the following are provided: Figure 1The data transmission system 10 shown is as follows: Figure 1 As shown, the system 10 includes: a WiFi network connection subsystem 11 deployed on the target terminal side and a WiFi network authentication subsystem 12 deployed on the wireless network side. The WiFi network connection subsystem 11 and the WiFi network authentication subsystem 12 can achieve data transmission according to the following interaction process:

[0030] First, the WiFi network connection subsystem 11 can obtain the cell information of the target serving cell where the target terminal is located in the current period, and report the cell information to the WiFi network authentication subsystem 12;

[0031] Next, the WiFi network authentication subsystem 12 can determine whether the target serving cell is covered by a WiFi network based on the cell information, and when the target serving cell is covered by the target WiFi network, it responds to the WiFi network connection subsystem's connection request to the target WiFi network.

[0032] Then, the WiFi network authentication subsystem 12 can perform security verification on the target terminal, and when the target terminal passes the security verification, determine the target terminal identification information corresponding to the target MAC address of the target terminal, and send the encrypted information obtained by encrypting the target MAC address and the indication information used to indicate data transmission through the target WiFi network to the WiFi network connection subsystem 11 according to the target terminal identification information.

[0033] Finally, the WiFi network connection subsystem 11 can decrypt the encrypted information and determine whether the decrypted MAC address is the same as the target MAC address. If the decrypted MAC address is the same as the target MAC address, it controls the target terminal to transmit data through the target WiFi network according to the instruction information.

[0034] During the above interaction, the WiFi network authentication subsystem 12 can authenticate the target terminal, and the WiFi network connection subsystem 11 can also authenticate the target WiFi network, thereby realizing two-way authentication between the target terminal and the target WiFi network and ensuring the security of the target WiFi network and the target terminal.

[0035] Specifically, the data transmission system 10 in this embodiment of the application performs bidirectional authentication between the target terminal and the target WiFi network, mainly in the following three steps:

[0036] Step S1: The target WiFi network authenticates the legitimacy of the target terminal's air interface connection.

[0037] The relevant structures within the aforementioned data transmission system 10 involved in step S1 will be described below.

[0038] The WiFi network connection subsystem 11 includes a serving cell monitoring module 111. Specifically, the serving cell monitoring module 111 can periodically acquire the cell information of the serving cell where the target terminal is located, and report the cell information of the target serving cell where the target terminal is located in the current period to the WiFi network authentication subsystem 12. The cell information includes, but is not limited to: Physical Cell Identity (PCI), base station identifier (i.e., gNodeB ID) of the base station where the serving cell is located, and group code (Cell ID) of the cell group to which the serving cell belongs.

[0039] In addition, the data transmission system 10 also includes a WiFi network connection collaboration subsystem 13 connected to the WiFi network authentication subsystem 12, and the WiFi network connection collaboration subsystem 13 includes a connection authentication information generation module 131. The WiFi network authentication subsystem 12 includes a terminal air interface connection authentication module 121. The WiFi network connection subsystem 11 also includes a connection authentication information storage module 112.

[0040] The connection authentication information generation module 131 can periodically generate connection authentication information for each WiFi network according to preset information generation rules, and store the connection authentication information in a preset database. The connection authentication information includes: SSID name and corresponding SSID connection password.

[0041] The reason why the connection authentication information generation module 131 adopts a scheme of periodically and dynamically generating connection authentication information for each WiFi network is that the SSID names of existing WiFi networks are all in plaintext and remain unchanged for a long time, making them easy targets for wireless air interface cracking. Dynamically generating connection authentication information in this way can effectively improve the wireless air interface security of WiFi networks.

[0042] The terminal air interface connection authentication module 121 can match the cell information with the preset wireless indoor distribution system cell group information to obtain the corresponding matching result. The wireless indoor distribution system cell group information includes multiple cell groups and the WiFi network covering each cell group, and each cell group includes multiple cells under the coverage of the same WiFi network. If the matching result is successful, it is determined that the target serving cell is covered by a WiFi network and the target WiFi network covered by the target serving cell is determined. The target connection authentication information of the target WiFi network is obtained from the connection authentication information generation module 131 and fed back to the connection authentication information storage module 112.

[0043] In addition, the connection authentication information storage module 112 can record the target connection authentication information in the target terminal's historical connection database and set the usage priority of the target connection authentication information to the highest priority.

[0044] Therefore, step S1 above can be implemented through the interaction between the various modules described above, and can be broken down into the following steps:

[0045] Step S11: When the target terminal reselects / switches from the outdoor area to the 5G indoor distribution sector, the serving cell monitoring module 111 can report the cell information of the target serving cell where the target terminal is currently located to the terminal air interface connection authentication module 121 in the WiFi network authentication subsystem 12.

[0046] In step S12, the terminal air interface connection authentication module 121 can match the cell information with the wireless indoor distribution system cell group information to obtain the corresponding matching result. The wireless indoor distribution system cell group information includes multiple cells and the WiFi network covering each cell.

[0047] Step S13: If the matching result is a failure, the terminal air interface connection authentication module 121 determines that there is no target WiFi network covering the target serving cell.

[0048] Step S14: If the matching result is successful, the terminal air interface connection authentication module determines the target WiFi network covered within the target serving cell.

[0049] Step S15: The terminal air interface connection authentication module 121 obtains the target connection authentication information of the target WiFi network from the connection authentication information generation module 131, and feeds back the target connection authentication information to the connection authentication information storage module 112.

[0050] In step S16, the connection authentication information storage module 112 can record the target connection authentication information in the historical connection database of the target terminal and set the usage priority of the target connection authentication information to the highest priority.

[0051] It should be noted that while the connection authentication information storage module 112 sets the priority of the target connection authentication information to the highest priority, it is necessary to reduce the priority of the connection authentication information previously used to connect to the WiFi network.

[0052] Step S2: The target WiFi network authenticates the legitimacy of the target terminal's MAC address.

[0053] The relevant structures within the aforementioned data transmission system 10 involved in step S2 will be described below.

[0054] The WiFi network connection collaboration subsystem 13 also includes: a WiFi network encoding module 132 and a terminal MAC address authentication module 133, wherein...

[0055] The WiFi network encoding module 132 can obtain the MAC addresses of all access points of the target WiFi network and encode the MAC addresses of all access points using a preset encoding method to obtain the corresponding target network encoding information.

[0056] In other words, the WiFi network encoding module 132 encodes the MAC addresses of all APs in the access point AP address list. The encoding methods include, but are not limited to, string encoding, compressed encoding, hexadecimal encoding, decimal encoding, and binary encoding. This application does not impose specific restrictions on the encoding methods.

[0057] The terminal MAC address authentication module 133 can perform security verification on the target terminal based on the target MAC address when the connection request of the WiFi network connection subsystem is successfully responded to by the WiFi network authentication subsystem, and send the target network encoding information to the WiFi network authentication subsystem 12 when the verification is successful.

[0058] Therefore, step S2 above can be implemented through the interactions between the various modules described above, and can be broken down into the following steps:

[0059] In step S21, the terminal MAC address authentication module 133 responds to the WiFi network connection subsystem 11's connection request to the target WiFi network.

[0060] This can be understood as follows: the WiFi network connection subsystem 11 turns on the WiFi switch of the target terminal, connects to the network with the corresponding SSID name according to the target WiFi network's target connection authentication information, and automatically enters the SSID connection password. However, at this time, the target terminal is not allowed to start data transmission.

[0061] Step S22: When the WiFi network connection subsystem successfully responds to the WiFi network authentication subsystem's connection request, the terminal MAC address authentication module 133 performs security verification on the target terminal based on the target MAC address and through the following steps:

[0062] Step S221: Add the target MAC address to the preset connected MAC address list, wherein the connected MAC address list includes multiple MAC addresses that have already established a connection with the target WiFi network;

[0063] Step S222: Determine whether the target MAC address is in the whitelist MAC address list, wherein the whitelist MAC address list stores the MAC addresses of multiple terminals that use the target WiFi network for data transmission;

[0064] Step S223: If the target MAC address is in the whitelisted MAC address list, add the target MAC address to the preset service-mode MAC address list, and confirm that the target terminal passes the security verification. The service-mode MAC address list includes the MAC addresses of multiple terminals that have undergone security verification through the target WiFi network.

[0065] In steps S221-S223 above, considering that after the initial two-way authentication between the target terminal and the target WiFi network is completed, the target connection authentication information of the target WiFi network is constantly being dynamically updated, if a normal authentication process is used, a new two-way authentication needs to be performed between the target terminal and the target WiFi network after each dynamic update of the target connection authentication information. This greatly increases the load on the data transmission system, and two-way authentication takes a certain amount of time, thus seriously affecting the user's service experience. Therefore, in order to balance security, system load, and user experience, this application embodiment proposes to keep the service-mode MAC address list unchanged in the subsequent two-way authentication stages between the target terminal and the target WiFi network. In this way, when the target WiFi network performs subsequent authentication of the target terminal, it can directly query the service-mode MAC address list, which greatly simplifies the two-way authentication process.

[0066] It should be noted that although the terminal MAC address authentication module 133 adds the target MAC address to the service MAC address list, data transmission is still not possible through the target WiFi network because the WiFi network connection subsystem 11 has not authenticated the target WiFi network.

[0067] In step S23, the terminal MAC address authentication module 133 obtains the target network encoding information from the WiFi network encoding module 132.

[0068] In step S24, the terminal MAC address authentication module 133 sends the target network encoding information to the WiFi network authentication subsystem 12.

[0069] It should be noted that the terminal MAC address authentication module 133 can also send the target MAC address to the WiFi network authentication subsystem 12, which belongs to the "network side," to facilitate network authentication of the terminal; and the WiFi network authentication subsystem 12 can also send the MAC addresses of all connection points of the target WiFi network to the WiFi network connection subsystem 11, which belongs to the "terminal side," to facilitate terminal network authentication. Thus, when the target terminal connects to the target WiFi network subsequently, rapid two-way authentication between the target terminal and the target WiFi network can be achieved.

[0070] Step S3: The target terminal authenticates the legitimacy of the target WiFi network.

[0071] The relevant structures within the data transmission system 10 mentioned above, which involve step S3, will be described below.

[0072] The aforementioned WiFi network authentication subsystem 12 also includes: a terminal identification module 122 and an encryption module 123, wherein,

[0073] The terminal identification module 122 can determine the target terminal identification information corresponding to the target MAC address from a preset terminal identification set. The terminal identification set stores the correspondence between the MAC addresses of multiple terminals in the whitelist MAC address list of the target WiFi network and the terminal identification information. The terminal identification information includes, but is not limited to, (4G / 5G) Globally Unique Temporary Identifier (GUTI), International Mobile Subscriber Identity (IMSI), Temporary Mobile Subscriber Identity (TMSI), etc.

[0074] The encryption module 123 can encrypt the target MAC address and the indication information used to indicate data transmission through the target WiFi network according to the preset encryption key to obtain encrypted information; and send the encrypted information to the WiFi network connection subsystem 11 through the 5G network message according to the target terminal identification information.

[0075] The WiFi network connection subsystem 11 also includes: a decryption module 113 and a data transmission control module 114, wherein...

[0076] The decryption module 113 can use a preset decryption key to decrypt the encrypted information and obtain the corresponding decryption result; check whether the MAC address in the decryption result is the same as the target MAC address; if the MAC address in the decryption result is different from the target MAC address, determine that the target WiFi network has failed the security check; if the MAC address in the decryption result is the same as the target MAC address, determine that the target WiFi network has passed the security check.

[0077] Furthermore, the data transmission control module 114 can prevent the target WiFi network from transmitting data when the target WiFi network fails the security verification; and when the target WiFi network passes the security verification, it can control the target terminal to transmit data through the target WiFi network according to the instruction information.

[0078] Furthermore, when the target WiFi network passes the security verification, the WiFi network connection subsystem 11 can also store the MAC addresses of all access points within the target WiFi network on the terminal side, i.e., store relevant information about the target WiFi network. In the subsequent two-way authentication phase between the target terminal and the target WiFi network, the target terminal can directly compare the MAC address of its connected access point with the pre-stored MAC addresses of all access points within the target WiFi network. If they match, the target WiFi network has passed the security verification, greatly simplifying the two-way authentication process and improving user experience.

[0079] It should be noted that the encryption key used in the encryption module 123 and the decryption key used in the decryption module 113 are obtained through prior negotiation. This application does not impose specific restrictions on the encryption and decryption algorithms used to generate the encryption and decryption keys.

[0080] Therefore, step S3 above can be implemented through the interactions between the various modules described above, and can be broken down into the following steps:

[0081] Step S31, the terminal identification module 122 determines the target terminal identification information corresponding to the target MAC address from the preset terminal identification set;

[0082] In step S32, the encryption module 123 encrypts the target MAC address and the indication information used to indicate data transmission through the target WiFi network (i.e., opening the data transmission channel of the target WiFi network) according to the preset encryption key to obtain encrypted information.

[0083] In step S33, the encryption module 123 sends the encrypted information to the decryption module 113 of the WiFi network connection subsystem 11 according to the target terminal identification information;

[0084] In step S34, the decryption module 113 uses a preset decryption key to decrypt the encrypted information and obtain the corresponding decryption result.

[0085] Step S35: Check if the MAC address in the decryption result is the same as the target MAC address;

[0086] Step S36: If the MAC address in the decryption result is different from the target MAC address, it is determined that the target WiFi network has failed the security check. In this case, the data transmission control module 114 does not use the target WiFi network for data transmission.

[0087] Step S37: When the MAC address in the decryption result is the same as the target MAC address, it is determined that the target WiFi network has passed the security verification. In this case, the data transmission control module 114 controls the target terminal to transmit data through the target WiFi network according to the instruction information.

[0088] After the target terminal and the target WiFi network complete two-way authentication through steps S1-S3, the target terminal can then transmit data via the target WiFi network. The target terminal can choose the frequency band of the target WiFi network it uses based on actual conditions, but 5GHz is generally preferred.

[0089] Furthermore, when the target terminal transmits data through the target WiFi network, there may be situations where the signal quality of the 5G wireless indoor distribution system or the target WiFi network itself deviates in certain local areas. To ensure that the target terminal can process services normally, corresponding data transmission switching mechanisms can be set up for the following two situations.

[0090] Scenario 1: The target terminal is currently located in a target service cell that belongs to the target cell group of the target WiFi network, but the network quality of the target WiFi network does not meet the requirements in a short period of time.

[0091] The above situation can be understood as follows: within a 5G wireless indoor distribution system, if the target serving cell (PCI) where the target terminal is currently located belongs to the target cell group (PCI of multiple cells) of the target WiFi network, it means that the target terminal is still within the coverage area of ​​the target WiFi network. However, in reality, the coverage area of ​​the target WiFi network may be smaller than the coverage area of ​​the 5G wireless indoor distribution system, causing the target terminal to be located outside the coverage area of ​​the target WiFi network.

[0092] In this scenario, the data transmission control module 114 and the network performance monitoring module 115 within the WiFi network connection subsystem 11 can interact in the following manner to ensure that the target terminal can utilize the wireless network to process services normally:

[0093] First, the network performance monitoring module 115 can periodically monitor the network performance of the target WiFi network, including but not limited to: Received Signal Strength (RSSI), Carrier-to-Interference Ratio (C / 1), etc.

[0094] Then, the data transmission control module 114 can continue to control the target terminal to transmit data through the target WiFi network when the network performance of the target WiFi network is not lower than the preset network performance threshold within multiple cycles; and when the network performance of the target WiFi network is lower than the preset network performance threshold within multiple cycles, it can stop the target terminal from transmitting data through the target WiFi network and control the target terminal to use the cellular data network for data transmission.

[0095] The specific duration of each cycle can be set by the user, such as monitoring once every two minutes. Furthermore, the data transmission control system can monitor network performance for multiple consecutive cycles.

[0096] For example, if the target service currently being served by the target terminal belongs to the target cell group of the target WiFi network, but the network signal quality of the target service cell does not meet the requirements in a short period of time, the WiFi network connection subsystem 11 can measure the network quality of the target WiFi network every 2 seconds through the network performance monitoring module 115, and obtain the corresponding measurement data after 10 consecutive measurements. If the 10 sets of measurement data are not lower than the specified network performance threshold, the data transmission control module 114 will continue to control the target terminal to transmit data through the target WiFi network. If all 10 sets of measurement data are lower than the specified network performance threshold, the target terminal will be controlled to stop transmitting data through the target WiFi network and will be controlled to use the cellular data network for data transmission (i.e., the data transmission channel of the target WiFi network will be closed and the data transmission channel of the cellular data network will be opened).

[0097] Scenario 2: The network quality of the target WiFi network meets the requirements for a short period of time, but the target terminal is currently located in a target serving cell that does not belong to the target cell group of the target WiFi network.

[0098] The above situation can be understood as follows: within the target WiFi network, when the target terminal moves to a certain area, the target serving cell (PCI) where the target terminal is currently located may not belong to the target cell group (PCI of multiple cells) of the target WiFi network. However, after a short period of time, the target serving cell (PCI) where the target terminal is currently located may again belong to the target cell group (PCI of multiple cells) of the target WiFi network. For example, the target terminal may be located near a window on a high floor.

[0099] In this scenario, the serving cell monitoring module 111 and the data transmission control module 114 within the WiFi network connection subsystem 11 can interact in the following manner to ensure that the target terminal can utilize the wireless network to process services normally:

[0100] First, the serving cell monitoring module 111 monitors whether the target serving cell where the target terminal is located in the current period belongs to the target cell group of the target WiFi network. The target cell group includes multiple cells within the coverage area of ​​the target WiFi network.

[0101] If the target serving cell belongs to the target cell group, the data transmission control module 114 continues to control the target terminal to transmit data through the target WiFi network;

[0102] If the target serving cell does not belong to the target cell group, the data transmission control module 114 determines the duration for which the target terminal stays in the target serving cell;

[0103] If the duration does not exceed the preset duration threshold, the data transmission control module 114 continues to control the target terminal to transmit data through the target WiFi network;

[0104] When the duration exceeds the preset duration threshold, the data transmission control module 114 stops the target terminal from transmitting data through the target WiFi network and controls the target terminal to use the cellular data network for data transmission.

[0105] The above control process can be understood as follows: when the target terminal is within the coverage area of ​​the target WiFi network and the target terminal has WiFi enabled, the serving cell monitoring module 111 can periodically monitor whether the serving cell where the target terminal is located belongs to the target cell group of the target WiFi network. If the target serving cell where the target terminal is located is detected to belong to the target cell group of the target WiFi network, the data transmission control module 114 continues to control the target terminal to transmit data through the target WiFi network. Conversely, if the target serving cell where the target terminal is located is detected not to belong to the target cell group of the target WiFi network, a preset timer can be started, and the timer can be used to detect and determine the cumulative duration of the target terminal in the target serving cell. If the cumulative duration exceeds a preset duration threshold (e.g., 5 minutes), it indicates that the target terminal has left the coverage area of ​​the target WiFi network. Therefore, the data transmission control module 114 can stop the target terminal from transmitting data through the target WiFi network and control the target terminal to use the cellular data network for data transmission. If the cumulative duration does not exceed the preset duration threshold (e.g., 5 minutes), it indicates that the target terminal is still within the coverage area of ​​the target WiFi network. Therefore, the data transmission control module 114 continues to control the target terminal to transmit data through the target WiFi network.

[0106] In addition, if the serving cell of the target terminal is not in the cell group of the target WiFi network during the current period, the target terminal connects to the target WiFi network, but stops transmitting data through the target WiFi network.

[0107] In this situation, the data transmission control module 114 can still perform network switching in the following manner to ensure that the target terminal can use the wireless network to process services normally:

[0108] First, the data transmission control module 114 can periodically monitor the network performance of the target WiFi network;

[0109] When the network performance of the target WiFi network is lower than the preset network performance threshold for multiple periods, stop the target terminal from transmitting data through the target WiFi network and control the target terminal to use the cellular data network for data transmission.

[0110] If the network performance of the target WiFi network is higher than the preset network performance threshold for multiple periods, the target terminal will continue to transmit data through the target WiFi network.

[0111] Specifically, to reduce terminal power consumption, this embodiment of the application may add an indicator module to the WiFi network connection subsystem 11. This indicator module can use a first notification message to indicate that the target terminal is within the coverage area of ​​the target WiFi network, but is not connected to it; a second notification message to indicate that the target terminal is transmitting data through the target WiFi network after completing bidirectional authentication; and a third notification message to indicate that the target terminal has now left the coverage area of ​​the target WiFi network.

[0112] For example, the aforementioned indicator module can be a function light, and the corresponding first prompt message can be the function light flashing slowly and continuously, the second prompt message can be the function light remaining on, and the third prompt message can be the function light turning off.

[0113] In the aforementioned data transmission system 10, the security of the air interface connection of the target WiFi network can be ensured by dynamically generating target authentication connection information of the target WiFi network; bidirectional authentication between the target terminal and the target WiFi network enhances the security of both the target terminal and the target WiFi network; furthermore, the data transmission method is adaptively adjusted according to the target terminal's access to the target WiFi network, and the data transmission channel of the target WiFi network is promptly shut down or the WiFi switch of the terminal is turned off when data transmission is not using the target WiFi network. This not only ensures that the target terminal's business processing can be continuously handled under any circumstances, but also avoids the terminal from being in a high-power consumption state for a long time, thus preventing accelerated battery drain.

[0114] Example 2

[0115] According to an embodiment of this application, a method embodiment for data transmission is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system (i.e., a WiFi network connection subsystem) such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0116] The method embodiments provided in this application can be executed on a mobile terminal, computer terminal, or similar computing device. Figure 2 A structural block diagram of a computer device (mobile terminal) for implementing a data transmission method is shown. For example... Figure 2As shown, the computer terminal 20 (or mobile device 20) may include one or more processors 202 (shown as 202a, 202b, ..., 202n in the figure) 202 (processor 202 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 204 for storing data, and a transmission device 206 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 2 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 20 may also include... Figure 2 The more or fewer components shown, or having the same Figure 2 The different configurations shown.

[0117] It should be noted that the aforementioned one or more processors 202 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 20 (or mobile device). As involved in the embodiments of this application, the data processing circuits serve as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).

[0118] The memory 204 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the data transmission method in this embodiment. The processor 202 executes various functional applications and data processing by running the software programs and modules stored in the memory 204, thereby implementing the aforementioned data transmission method of the application. The memory 204 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 204 may further include memory remotely located relative to the processor 202, and these remote memories can be connected to the computer terminal 20 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0119] The transmission device 206 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 20. In one example, the transmission device 206 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 206 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0120] The display may be, for example, a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 20 (or mobile device).

[0121] Under the above operating environment, Figure 3 This is a flowchart illustrating an optional data transmission method according to an embodiment of this application, as shown below. Figure 3 As shown, the method includes at least steps S302-S306, wherein:

[0122] Step S302: Obtain the cell information of the target serving cell where the target terminal is located in the current period.

[0123] Step S304: Report the cell information to the WiFi network authentication subsystem and obtain the encrypted information fed back by the WiFi network authentication subsystem.

[0124] The WiFi network authentication subsystem can determine whether the target serving cell is covered by a WiFi network based on cell information. If the target serving cell is covered by a target WiFi network, it will respond to the WiFi network connection subsystem's connection request to the target WiFi network. It will also perform security verification on the target terminal. When the target terminal passes the security verification, it will determine the target terminal identification information corresponding to the target MAC address of the target terminal. Based on the target terminal identification information, it will send the encrypted information, which is obtained by encrypting the target MAC address and the indication information used to indicate data transmission through the target WiFi network, to the WiFi network connection subsystem.

[0125] Step S306: Decrypt the encrypted information and determine whether the decrypted MAC address is the same as the target MAC address. If the decrypted MAC address is the same as the target MAC address, control the target terminal to transmit data through the target WiFi network according to the instruction information.

[0126] It should be noted that the interaction process between the WiFi network connection subsystem and the WiFi network authentication subsystem through the above steps S302-S306 has been specifically described in the embodiments, and will not be repeated here.

[0127] Example 3

[0128] According to an embodiment of this application, a method embodiment for data transmission is provided. It should be noted that the steps shown in the flowcharts in the accompanying drawings can be executed in a WiFi network authentication subsystem, such as a set of computer-executable instructions, and the WiFi network authentication subsystem can be specifically referred to... Figure 2 Furthermore, although the logical order is shown in the flowchart, in some cases the steps shown or described may be performed in a different order than that shown here.

[0129] In the above Figure 2 In the WiFi network authentication subsystem structure shown, Figure 4 This is a flowchart illustrating an optional data transmission method according to an embodiment of this application, as shown below. Figure 4 As shown, the method includes at least steps S402-S406, wherein:

[0130] Step S402: Obtain the cell information of the target serving cell where the target terminal is located in the current period, as reported by the WiFi network connection subsystem.

[0131] Step S404: Determine whether the target serving cell is covered by a WiFi network based on the cell information, and if the target serving cell is covered by a target WiFi network, respond to the WiFi network connection subsystem's connection request to the target WiFi network.

[0132] Step S406: Perform security verification on the target terminal. When the target terminal passes the security verification, determine the target terminal identification information corresponding to the target MAC address of the target terminal. Then, based on the target terminal identification information, send the encrypted information obtained by encrypting the target MAC address and the indication information used to indicate data transmission through the target WiFi network to the WiFi network connection subsystem.

[0133] The aforementioned WiFi network connection subsystem is used to decrypt encrypted information, determine whether the decrypted MAC address is the same as the target MAC address, and control the target terminal to transmit data through the target WiFi network according to the instruction information when the decrypted MAC address is the same as the target MAC address.

[0134] It should be noted that the interaction process between the WiFi network authentication subsystem and the WiFi network connection subsystem through the above steps S402-S406 has been specifically described in the embodiments, and will not be repeated here.

[0135] Example 4

[0136] According to an embodiment of this application, a computer program product is also provided, which includes a stored computer program, wherein the computer program, when executed by a processor, implements the data transmission methods in embodiments 2 and 3.

[0137] Optionally, the computer program performs the following steps: obtaining cell information of the target serving cell where the target terminal is located in the current period; reporting the cell information to the WiFi network authentication subsystem and obtaining encrypted information fed back by the WiFi network authentication subsystem, wherein the WiFi network authentication subsystem is used to determine whether the target serving cell is covered by a WiFi network based on the cell information, and when the target serving cell is covered by a target WiFi network, responding to the WiFi network connection subsystem's connection request to the target WiFi network; performing security verification on the target terminal, and when the target terminal passes the security verification, determining the target terminal identification information corresponding to the target MAC address of the target terminal, and sending encrypted information obtained by encrypting the target MAC address and the indication information used to indicate data transmission through the target WiFi network to the WiFi network connection subsystem according to the target terminal identification information; decrypting the encrypted information and determining whether the decrypted MAC address is the same as the target MAC address, and when the decrypted MAC address is the same as the target MAC address, controlling the target terminal to transmit data through the target WiFi network according to the indication information.

[0138] Optionally, the computer program performs the following steps: obtaining cell information of the target serving cell where the target terminal is located in the current period, reported by the WiFi network connection subsystem; determining whether the target serving cell is covered by a WiFi network based on the cell information, and responding to the WiFi network connection subsystem's connection request to the target WiFi network when the target serving cell is covered by a target WiFi network; performing security verification on the target terminal, and determining the target terminal identification information corresponding to the target MAC address of the target terminal when the target terminal passes the security verification, and sending encrypted information, which is obtained by encrypting the target MAC address and the indication information used to indicate data transmission through the target WiFi network, to the WiFi network connection subsystem according to the target terminal identification information, wherein the WiFi network connection subsystem is used to decrypt the encrypted information and determine whether the decrypted MAC address is the same as the target MAC address, and when the decrypted MAC address is the same as the target MAC address, controlling the target terminal to transmit data through the target WiFi network according to the indication information.

[0139] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0140] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0141] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between units or modules may be electrical or other forms.

[0142] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0143] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0144] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to related technologies, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0145] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. A data transmission system, characterized in that, include: The WiFi network connection subsystem is deployed on the target terminal side, and the WiFi network authentication subsystem is deployed on the wireless network side. The WiFi network connection subsystem is used to obtain the cell information of the target serving cell where the target terminal is located in the current period, and report the cell information to the WiFi network authentication subsystem; The WiFi network authentication subsystem is used to determine whether the target serving cell is covered by a WiFi network based on the cell information, and when the target serving cell is covered by a target WiFi network, to respond to the WiFi network connection subsystem's connection request to the target WiFi network; to perform security verification on the target terminal, and when the target terminal passes the security verification, to determine the target terminal identification information corresponding to the target MAC address of the target terminal, and to send encrypted information obtained by encrypting the target MAC address and the indication information for indicating data transmission through the target WiFi network to the WiFi network connection subsystem according to the target terminal identification information; The WiFi network connection subsystem is also used to decrypt the encrypted information, determine whether the decrypted MAC address is the same as the target MAC address, and when the decrypted MAC address is the same as the target MAC address, control the target terminal to transmit data through the target WiFi network according to the instruction information.

2. The system according to claim 1, characterized in that, The WiFi network connection subsystem includes: a serving cell monitoring module, wherein... The serving cell monitoring module is used to periodically acquire cell information of the serving cell where the target terminal is located, and report the cell information of the target serving cell where the target terminal is located in the current period to the WiFi network authentication subsystem. The cell information includes at least one of the following: physical cell identifier, base station identifier of the base station where the serving cell is located, and group code of the cell group to which the serving cell belongs.

3. The system according to claim 1, characterized in that, The data transmission system further includes: a WiFi network connection collaboration subsystem connected to the WiFi network authentication subsystem, and the WiFi network connection collaboration subsystem includes: a connection authentication information generation module; the WiFi network authentication subsystem includes: a terminal air interface connection authentication module; and the WiFi network connection subsystem further includes: a connection authentication information storage module. The connection authentication information generation module is used to periodically generate connection authentication information for each WiFi network according to a preset information generation rule, and store the connection authentication information in a preset database. The connection authentication information includes: Service Set Identifier (SSID) name and corresponding SSID connection password. The terminal air interface connection authentication module is used to match the cell information with preset wireless indoor distribution system cell group information to obtain a corresponding matching result. The wireless indoor distribution system cell group information includes multiple cell groups and a WiFi network covering each cell group, and each cell group includes multiple cells under the coverage of the same WiFi network. If the matching result is successful, the target WiFi network covered by the target serving cell is determined. The target connection authentication information of the target WiFi network is obtained from the connection authentication information generation module, and the target connection authentication information is fed back to the connection authentication information storage module. The connection authentication information storage module is used to record the target connection authentication information in the historical connection database of the target terminal, and set the usage priority of the target connection authentication information to the highest priority.

4. The system according to claim 3, characterized in that, The WiFi network connection collaboration subsystem also includes: a WiFi network encoding module and a terminal MAC address authentication module, wherein... The WiFi network encoding module is used to obtain the MAC addresses of all access points of the target WiFi network and encode the MAC addresses of all access points using a preset encoding method to obtain the corresponding target network encoding information. The terminal MAC address authentication module is used to perform security verification on the target terminal based on the target MAC address when the connection request of the WiFi network connection subsystem is successfully responded to by the WiFi network authentication subsystem, and send the target network encoding information to the WiFi network authentication subsystem when the verification is successful.

5. The system according to claim 4, characterized in that, The terminal MAC address authentication module is further configured to add the target MAC address to a preset connection-state MAC address list; determine whether the target MAC address is in a preset whitelist MAC address list, wherein the whitelist MAC address list stores the MAC addresses of multiple terminals using the target WiFi network for data transmission; if the target MAC address is in the whitelist MAC address list, add the target MAC address to a preset service-state MAC address list, and determine that the target terminal has passed the security verification.

6. The system according to claim 1, characterized in that, The WiFi network authentication subsystem also includes: a terminal identification module and an encryption module, wherein... The terminal identification module is used to determine the target terminal identification information corresponding to the target MAC address from a preset terminal identification set. The terminal identification set stores the correspondence between the MAC addresses of multiple terminals in the whitelist MAC address list of the target WiFi network and the terminal identification information. The terminal identification information includes at least one of the following: a globally unique temporary identifier or an International Mobile Subscriber Identity (IMSI). The encryption module is used to encrypt the target MAC address and the indication information for data transmission through the target WiFi network according to a preset encryption key to obtain the encrypted information; and to send the encrypted information to the WiFi network connection subsystem via a 5G network message according to the target terminal identification information.

7. The system according to claim 2, characterized in that, The WiFi network connection subsystem also includes: a decryption module and a data transmission control module, wherein... The decryption module is used to decrypt the encrypted information using a preset decryption key to obtain the corresponding decryption result; to check whether the MAC address in the decryption result is the same as the target MAC address; if the MAC address in the decryption result is different from the target MAC address, it is determined that the target WiFi network has failed the security check; if the MAC address in the decryption result is the same as the target MAC address, it is determined that the target WiFi network has passed the security check. The serving cell monitoring module is used to monitor whether the target serving cell where the target terminal is located in the current target period belongs to the target cell group of the target WiFi network, wherein the target cell group includes multiple cells within the coverage area of ​​the target WiFi network; The data transmission control module is configured to prevent data transmission using the target WiFi network when the target WiFi network fails the security verification, and to control the target terminal to transmit data through the target WiFi network according to the indication information when the target WiFi network passes the security verification. The data transmission control module is further configured to: continue controlling the target terminal to transmit data through the target WiFi network when the target serving cell belongs to the target cell group; determine the duration the target terminal stays in the target serving cell when the target serving cell does not belong to the target cell group; continue controlling the target terminal to transmit data through the target WiFi network when the duration does not exceed a preset duration threshold; and stop the target terminal from transmitting data through the target WiFi network and control the target terminal to use a cellular data network when the duration exceeds the preset duration threshold.

8. The system according to claim 7, characterized in that, The WiFi network connection subsystem also includes a network performance monitoring module, wherein... The network performance monitoring module is used to periodically monitor the network performance of the target WiFi network, wherein the network performance includes at least one of the following: received signal strength and carrier-to-interference ratio; The data transmission control module is configured to continue controlling the target terminal to transmit data through the target WiFi network when the network performance of the target WiFi network is not lower than a preset network performance threshold over multiple periods; and to stop the target terminal from transmitting data through the target WiFi network and control the target terminal to use a cellular data network when the network performance of the target WiFi network is lower than the preset network performance threshold over multiple periods.

9. A data transmission method, characterized in that, include: The method is applied to a WiFi network connectivity subsystem, including: Obtain the cell information of the target serving cell where the target terminal is located in the current period; The cell information is reported to the WiFi network authentication subsystem, and encrypted information fed back by the WiFi network authentication subsystem is obtained. The WiFi network authentication subsystem is used to determine whether the target serving cell is covered by a WiFi network based on the cell information, and when the target serving cell is covered by a target WiFi network, it responds to the WiFi network connection subsystem's connection request to the target WiFi network. It performs security verification on the target terminal, and when the target terminal passes the security verification, it determines the target terminal identification information corresponding to the target MAC address of the target terminal, and sends encrypted information, obtained by encrypting the target MAC address and indication information for data transmission through the target WiFi network, to the WiFi network connection subsystem based on the target terminal identification information. The encrypted information is decrypted, and it is determined whether the decrypted MAC address is the same as the target MAC address. If the decrypted MAC address is the same as the target MAC address, the target terminal is controlled to transmit data through the target WiFi network according to the instruction information.

10. A data transmission method, characterized in that, include: The method is applied to a WiFi network authentication subsystem, including: Obtain the cell information of the target serving cell where the target terminal is located in the current period, as reported by the WiFi network connection subsystem; Based on the cell information, verify whether the target serving cell is covered by a WiFi network, and when the target serving cell is covered by a target WiFi network, respond to the WiFi network connection subsystem's connection request to the target WiFi network. The system performs a security verification on the target terminal. When the target terminal passes the security verification, it determines the target terminal identification information corresponding to the target MAC address of the target terminal. Based on the target terminal identification information, it sends encrypted information, which is obtained by encrypting the target MAC address and the indication information for data transmission through the target WiFi network, to the WiFi network connection subsystem. The WiFi network connection subsystem decrypts the encrypted information and determines whether the decrypted MAC address is the same as the target MAC address. If the decrypted MAC address is the same as the target MAC address, it controls the target terminal to transmit data through the target WiFi network according to the indication information.

11. A computer program product, characterized in that, include: A computer program, wherein when executed by a processor, the computer program implements the data transmission method according to any one of claims 9 to 10.

Citation Information

Patent Citations

  • Safe networking method and device

    CN106211163A

  • Method, system and device for helping multi-mode terminal discover communications opportunities

    US20160183174A1