Distributed Access Authentication Method and System for Power 5G Terminals for Access to New Power Systems

By adopting the combination of IPSEC VPN architecture, group shared keys and physical features in the power 5G network, multiple challenges of 5G terminal access authentication are solved, and efficient and secure terminal access and data transmission are achieved.

CN119211930BActive Publication Date: 2025-06-13INNER MONGOLIA ELECTRIC POWER (GRP) CO LTD DIGITAL RES BRANCH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411242251.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-05
Publication Date
2025-06-13
Estimated Expiration
2044-09-05

AI Technical Summary

Technical Problem

Access authentication of 5G terminals in power 5G networks face challenges of edge-side end-to-end identity authentication, large-scale terminal access authentication, and physical layer terminal identity recognition.

Method used

The wide-area distributed authentication method based on the network layer is adopted to realize edge-side end-to-end identity authentication through the IPSEC VPN architecture; the group sharing key method based on the link layer is used for large-scale terminal access authentication; and the device identity identification is used for combined power terminal wireless signal physical characteristics and channel status information.

Benefits of technology

It realizes efficient and secure access to power 5G terminals, reduces signaling load, improves the efficiency and difficulty of identity authentication, and ensures the security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119211930B_ABST
    Figure CN119211930B_ABST
Patent Text Reader

Abstract

Diagram of a distributed access authentication method for power 5G terminals for accessing a new power system, including three types of authentication methods: end-to-end identity authentication on the edge side, link layer identity authentication, and power device identity recognition. Starting from the identity authentication and data transmission of the four components of the power system, namely the terminal group, the edge side, the link layer, and the power device, a more efficient and secure power data interaction strategy is designed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a 5G terminal access authentication method, in particular to a distributed access authentication method for power 5G terminals for access to a new power system and a system for implementing the method, belonging to the field of 5G device connection security. Background Art

[0002] There are three major problems in 5G terminal access authentication: end-to-end identity authentication on the edge side, large-scale terminal access authentication, and physical layer terminal identity recognition.

[0003] For the first problem, under the authentication framework of the power 5G network, terminal identities will be diversified, and different services will be provided according to different industries. This requires diversified certificates and diversified authentication methods. Some terminal devices have strong capabilities and may be equipped with SIM (Subscriber Identity Module) / USIM (Universal Subscriber Identity Module) cards and have certain computing and storage capabilities. Some terminal devices do not have SIM / USIM cards, and some terminal devices with low capabilities do not even have specific hardware to securely store identity identifiers and authentication credentials. Therefore, the power 5G network needs to build a unified identity management system that can support different authentication methods, different identity identifiers, and authentication credentials.

[0004] For the second problem, in a dedicated power network, there are a large number of terminals with the same service connected. As the number of terminals attempting to access the power 5G network at the same time increases, the signaling load on the core network increases, and when it reaches a certain level, signaling congestion occurs. How to efficiently and stably access a large number of terminals is an urgent problem to be solved.

[0005] For the third problem, traditional digital signatures are used. However, in the face of a large number of devices, the security issues of identity recognition digital signatures cannot be ignored. Therefore, the key is to develop an identification method that is difficult to crack. Summary of the Invention

[0006] Based on the above problems, the present invention provides a distributed access authentication method for power 5G terminals for access to a new power system, including an end-to-end identity authentication method on the edge side based on wide-area distributed authentication at the network layer, a large-scale terminal access authentication method based on link layer access authentication, and a device identity recognition method based on the physical characteristics of power terminal wireless signals and combined with channel state information (CSI) fusion recognition. Among them,

[0007] The edge - side end - to - end identity authentication method based on wide - area distributed authentication at the network layer is based on the IPSEC VPN architecture. By monitoring the load of authentication signaling, it specifically includes turning off the NAS signaling authentication of the original power 5G network, only retaining the one - time authentication when the terminal attaches. An IPSEC VPN tunnel is established between the power 5G network access terminal and the distributed authentication gateway. In the IPSEC VPN, the national cryptographic algorithms SM3 and SM4 are used to achieve data encryption and integrity protection.

[0008] The large - scale terminal access authentication method based on link - layer access authentication adopts the fixed - terminal group access authentication of the power 5G network based on group - shared keys.

[0009] The device identity recognition method includes:

[0010] I. Device recognition based on the physical characteristics of power terminal wireless signals, which includes adding a radio frequency security protection device and a radio frequency security access platform outside the original wireless access point at the hardware layer. The two cooperate to complete the access of legal wireless terminals and block illegal wireless terminals, and at the same time handle the security rules of the third and fourth layers of the network. At the software layer, set the wireless module physical - layer feature extraction method, the device feature extraction method based on the constellation trajectory diagram, and the device feature extraction method based on time - domain and frequency - domain waveforms executed by the radio frequency security protection device.

[0011] II. The device identity recognition combining channel state information (CSI) fusion recognition includes terminal recognition based on channel fingerprints.

[0012] III. Fuse the physical - layer features, constellation trajectory diagram, time - domain and frequency - domain waveforms, and channel fingerprints in I and II to form a cipher map, which is used as the power device identity authentication method before accepting the data decrypted by the national cryptographic algorithms SM3 and SM4, and the formation of the cipher map is realized in the radio frequency security access platform.

[0013] Optionally, the method of group - shared keys includes:

[0014] S1 Establish a heterogeneous graph neural network in the group, with group members as nodes;

[0015] S2 Obtain the historical data transmitted and received within the group members. Select a node in the group. If there are multiple sets of data in the calculated historical data with overlapping time periods above the specified power consumption, then these other nodes are defined as the neighbors of the selected node, and find the neighbors of each node in the group.

[0016] S3 Calculate the neighbor weights of each node: , where is the deep neural network of node attention, They are the vector representations of the node and its neighbors respectively. Select the nodes with the top 5 - 8 digits in terms of the numerical values of the neighbor weights, randomly sort their respective neighbor weights, and form a shared key.

[0017] Optionally, the physical layer feature extraction method of the wireless module processes the baseband of the radio frequency signal emitted by the wireless device at the receiving end to form a stable I / Q trajectory diagram, thereby obtaining the fingerprint features of the device; the device feature extraction method based on the constellation trajectory diagram includes that after the receiving end obtains the received signal with the same frequency and phase as the transmitting end, the signal can be plotted in the constellation trajectory diagram for feature extraction; by plotting the received signal point by point on the time axis in the form of the I channel and the Q channel, a time domain waveform diagram containing three - dimensional information of the time axis, the I axis, and the Q axis can be obtained; after segmenting the received signal according to a specified length and then performing Fourier transform, the spectrum of the Fourier transform can be analyzed, and features can be extracted in the frequency domain.

[0018] Optionally, the ciphertext formation method includes:

[0019] a. Randomly select time points, or randomly select time points during the overlapping period, give the two - dimensional IQ diagram formed by the I axis and the Q axis at this time point, and randomly select the I / Q trajectory diagram, the two - dimensional IQ diagram, the frequency domain waveform, and the channel fingerprint.

[0020] b. Stitch the I / Q trajectory diagram, the two - dimensional IQ diagram, the frequency domain waveform, and the channel fingerprint in the selected order to form a ciphertext.

[0021] Optionally, the method for identifying the authenticity of the ciphertext is:

[0022] c. Establish a convolutional neural network or a generative adversarial network. Obtain multiple fake ciphertexts according to method steps a and b. Form an atlas of the ciphertext and the fake ciphertexts, divide it into a training set and a validation set. Mark the fake ciphertexts with consistent sorting as suspected genuine. Subtract the suspected genuine diagram from the ciphertext. If the sum of the pixel values of the difference is below the specified value, it is defined as approximately genuine. If it is above, it is still suspected genuine. If the sorting is inconsistent, it is fake, divided into three categories. Figure 1 d. Train the above - mentioned network with the training set, verify the accuracy rate with the validation set, optimize the network parameters according to the backpropagation of the loss function for each training. When the loss function continuously decreases and stabilizes, and the verification accuracy rate reaches the highest and is stable, obtain the trained network.

[0023] e. Input the diagram to be tested into the trained network. When the probability of being approximately genuine is the largest among the three categories, subtract the diagram to be tested from the ciphertext. If the sum of the pixel values of the difference is less than the preset value, then the identity is recognized. Otherwise, it is judged as an attempted input of a dangerous intrusion. When the probability of being approximately genuine is not the largest among the three categories, it is also an attempted intrusion.

[0024] e. Input the diagram to be tested into the trained network. When the probability of being approximately genuine is the largest among the three categories, subtract the diagram to be tested from the ciphertext. If the sum of the pixel values of the difference is less than the preset value, then the identity is recognized. Otherwise, it is judged as an attempted input of a dangerous intrusion. When the probability of being approximately genuine is not the largest among the three categories, it is also an attempted intrusion.

[0025] Among them, the convolutional neural network, the generative adversarial network, and the output ends are all connected to a fully connected layer and a classification function layer to output the probabilities of predicting three categories. The formation of the channel fingerprint includes feature extraction by the following parameters: the number of multipaths, delay spread, Doppler spread, slow-time direction frequency characteristics, mean received power, amplitude standard deviation, and amplitude derivative standard deviation. Then, these features are pixelated, and these pixelated extracted features are selected according to a random selection method, and then the pixels are spliced in the selected order.

[0026] Preferably, when the frequency of occurrence of near-genuine forged images increases within a predetermined time period during the identity recognition process, steps a and b are re-performed to form a new encrypted image.

[0027] It is easy to understand that by using the above network for the identity recognition of the image to be tested, it can be determined whether the attempt result of the party attempting to decrypt is already relatively close to the encrypted image, so as to give an early warning. Beneficial effects

[0028] Through the identity authentication of the edge side, the link layer, and the power equipment, the efficient and secure transmission of relevant power equipment data is completed, and the early warning mechanism for the intrusion stage of attempting to decrypt and the mechanism for updating the encrypted image can be carried out through intelligent models (convolutional neural network, generative adversarial network). At the same time, a terminal group of heterogeneous graph neural networks is constructed, so as to construct a shared key for identity recognition with the link layer, further improving the efficiency of identity authentication. Description of the drawings

[0029] Figure 1 A comprehensive diagram of a power 5G terminal distributed access authentication method and system for a new power system access of the present invention

[0030] Figure 2 A composition diagram of the encrypted image

[0031] Figure 3 A flowchart of the encrypted image recognition based on a convolutional neural network and the early warning and encrypted image update mechanism in the decryption intrusion stage (attempt stage and danger stage) of the system Specific implementation manners

[0032] Figure 1A diagrammatic illustration of a distributed access authentication method for power 5G terminals for access to a new power system is given, including three types of authentication methods: end-to-end identity on the edge side, link layer identity, and power device identity recognition. The channel on which the method is based is given in the figure from the terminal group - distributed authentication gateway - original AP + radio frequency security protection device - radio frequency secure access platform - switch - device, where the link layer refers to the three of the distributed authentication gateway - original AP + radio frequency security protection device - radio frequency secure access platform. That is, when data is transmitted between the terminal group and the power device in the figure, after completing the end-to-end identity on the edge side, identity authentication also needs to be implemented at the link layer.

[0033] Terminals with the same or similar network data requirements in the figure form a terminal group. Taking one of the groups in the figure as an example, a group composed of terminal A - terminal E and neighbor 1 and neighbor 2 of terminal A is given. Multiple such groups and the distributed authentication gateway, that is, the edge side identity authentication of the network, need to close the traditional NAS signaling authentication (indicated by × in the figure), open the IPSEC VPN tunnel, and implement end-to-end identity authentication on the edge side. Specifically, by monitoring the load of the authentication signaling, only one authentication when the terminal group attaches is finally retained, so as to finally realize the data encryption transmission between the two using the national cryptography algorithms SM3 and SM4.

[0034] Next, in order to achieve secure data transmission at the link layer, in the figure, taking the terminal as a node in each terminal group, still taking the above terminal group as an example, a heterogeneous graph neural network composed of terminal A - terminal E and neighbor 1 and neighbor 2 of terminal A is established, and an attention mechanism is constructed therein.

[0035] Taking terminal A as an example, it is selected as a node in the group. By calling the historical data of terminal A, it is found that in the E-t function graph of electricity consumption E and time t in the figure, there are multiple groups of data with overlapping periods exceeding the specified electricity consumption during the green time period, which is the same as the situation of the other two nodes. For example, there are 5 - 10 such overlapping periods where the electricity consumption exceeds the specified electricity consumption (such as the average electricity consumption of the group during this period), and the same exists in neighbor 1 and neighbor 2 of the node. Taking neighbor 1 as an example in the figure, the red excess part and the black excess part are also within the green time period. Then this node neighbor 1 is defined as a neighbor. Similarly, neighbor 2 is also defined in this way. Then within this group, calculate the neighbor weight of this node terminal A: , where is the deep neural network of the node attention, are the vector representations of this node terminal A and its neighbor respectively. Similarly, the neighbor weights of terminal B - terminal E are , , , . Next, in Randomly selected from and arranged in the selected order to form a shared key Use this shared key to complete the group identity authentication at the link layer.

[0036] Finally, as Figure 1 The implementation of the device identity recognition method includes:

[0037] I. Device recognition based on the physical characteristics of the wireless signal of the power terminal, which includes adding a radio frequency security protection device and a radio frequency security access platform outside the original wireless access point at the hardware layer. The two cooperate to complete the admission of legal wireless terminals and block illegal wireless terminals, and at the same time process the security rules of the third and fourth layers of the network.

[0038] The hardware layer includes the original AP, radio frequency security access platform, switch connected in sequence, and multiple power devices such as Device 1 and Device 2 connected to the switch. The radio frequency security protection device is communicatively connected to the radio frequency security access platform.

[0039] At the software layer, set the physical layer feature extraction method of the wireless module executed by the radio frequency security protection device, the device feature extraction method based on the constellation trajectory diagram, and the device feature extraction method based on the time domain and frequency domain waveforms.

[0040] II. The device identity recognition combining channel state information (CSI) fusion recognition includes terminal recognition based on channel fingerprints.

[0041] III. Fuse the physical layer features, constellation trajectory diagram, time domain and frequency domain waveforms, and channel fingerprints in I and II to form a ciphertext map as the power device identity authentication method before decrypting the data by the national secret encryption algorithms SM3 and SM4.

[0042] As Figure 2 shown, where the physical layer feature extraction method of the wireless module processes the baseband of the radio frequency signal emitted by the wireless device at the receiving end to form a stable I / Q trajectory diagram, thereby obtaining the fingerprint features of the device. Two I / Q trajectories in the fingerprint are given in the figure.

[0043] The device feature extraction method based on the constellation trajectory diagram includes that after the receiving end obtains a received signal with the same frequency and phase as the transmitting end, the signal can be plotted in the constellation trajectory diagram for feature extraction. Different from the I / Q trajectory, the constellation trajectory diagram is a time function of the signal with the same frequency and phase, and the I / Q trajectory contains data of each frequency and phase. By plotting the received signal point by point on the time axis in the I-channel and Q-channel manner, a time domain waveform diagram containing three-dimensional information of the time axis, I-axis, and Q-axis can be obtained. Figure 2 The Q-I-t three-dimensional coordinate time domain waveform diagram is given in, and the I direction is perpendicular to the plane facing outwards. In Figure 1Randomly select a time point within the green overlapping period to make a vertical plane on the t-axis, and the formed cross-section is a two-dimensional IQ diagram (taking the cross-section circled in red in the figure as an example).

[0044] Segment the received signal according to a specified length (i.e., a longer time period spanning the Figure 1 overlapping period in the middle, which can be 3 - 5 overlapping time periods), and then perform Fourier transform. The spectrum of the Fourier transform can be analyzed, and features can be extracted in the frequency domain.

[0045] The method for forming channel fingerprints includes: extracting seven types of features from the RF data received by the terminal group, namely the number of multipaths, delay spread, Doppler spread, slow-time direction frequency characteristics, average received power, amplitude standard deviation, and amplitude derivative standard deviation, and then pixelating them according to the feature values, and randomly selecting seven pixels and arranging them in the selected order to form.

[0046] Thus, the method for forming a secret diagram can be described, including:

[0047] a. Randomly select a time point in the overlapping period (as Figure 2 shown), give the two-dimensional IQ diagram formed by the I-axis and Q-axis at this time point, and randomly select the I / Q trajectory diagram, two-dimensional IQ diagram, frequency domain waveform, and channel fingerprint.

[0048] b. Stitch the I / Q trajectory diagram, two-dimensional IQ diagram, frequency domain waveform, and channel fingerprint in the selected order to form a secret diagram ( Figure 2 ) Therefore, from Figure 2 it can be seen that the randomly selected arrangement order is channel fingerprint, I / Q trajectory diagram, two-dimensional IQ diagram, and frequency domain waveform.

[0049] As a method for identifying the group identity, it relies on the authenticity identification of the secret diagram. The specific method is:

[0050] c. Establish a convolutional neural network, obtain multiple fake secret diagrams according to method steps a and b, form an atlas of the secret diagram and the fake secret diagrams, divide it into a training set and a validation set, mark the fake secret diagrams with the same order as the secret diagram as suspected genuine, subtract the suspected genuine diagram from the secret diagram. If the sum of the pixel values of the difference is below the specified value, it is defined as approximately genuine, and those above are still suspected genuine, and those with inconsistent orders are fake, divided into three categories; Figure 1 d. Train the above network with the training set, verify the accuracy with the validation set, optimize the network parameters according to the backpropagation of the loss function for each training. When the loss function continuously decreases and stabilizes, and the validation accuracy reaches the highest and stable, the trained network is obtained;

[0051] d. Train the above network with the training set, verify the accuracy with the validation set, optimize the network parameters according to the backpropagation of the loss function for each training. When the loss function continuously decreases and stabilizes, and the validation accuracy reaches the highest and stable, the trained network is obtained;

[0052] e. Input the test image into the trained network. When the probability of approximate truth is the largest among the three categories, subtract the test image from the encrypted image. If the sum of the pixel values of the difference is less than the preset value, then the identity is recognized; otherwise, it is judged as an attempted dangerous intrusion. When the probability of approximate truth is not the largest among the three categories, it is also an attempted intrusion.

[0053] The fact that the predicted probability of approximate truth is not the largest indicates that the attempted intruder is still in the initial stage of decryption. Therefore, it belongs to the stage of attempted intrusion. When the predicted probability is the largest, it means that a closer attempt to the real encrypted image has been made. At this time, after inputting the test image into the trained convolutional neural network, the difference from the encrypted image is obtained. If the sum of the total pixel values of the difference is less than the preset value (such as grayscale value 5 - 10) at this time, then the identity is recognized. Otherwise, it means that the intruder's attempt is already very close to the encrypted image. At this time, preparations for updating the encrypted image must be made. If it is found that the frequency increases within a predetermined time period (such as within the length of the overlapping time period), then steps a and b are re - executed to form a new encrypted image.

[0054] Through the above - mentioned method, it is possible to ensure the efficient and accurate identity authentication among the terminal, the edge side, the link layer, the switch, and multiple devices, as well as more secure data transmission.

[0055] For this reason, the embodiment also provides a system for implementing the above - mentioned method. As Figure 1 shown, the system includes at least one group of terminal groups composed of multiple terminals forming a heterogeneous graph neural network, a distributed authentication gateway, and at least one group of the terminal groups communicate wirelessly with the hardware layer via the distributed authentication gateway; where

[0056] The hardware layer includes a original AP, a radio frequency security access platform, a switch connected in sequence, and at least one power device connected to the switch. The radio frequency security protection device is communicatively connected to the radio frequency security access platform;

[0057] The identity of at least one group of the terminal groups and the distributed authentication gateway is authenticated through an IPSEC VPN tunnel, and SM3 and SM4 encrypted data are transmitted. The original AP and the radio frequency security access platform communicate wirelessly with the distributed authentication gateway; in the software layer, a method for extracting physical layer features of a wireless module executed by the radio frequency security protection device, a method for extracting device features based on a constellation trajectory diagram, and a method for extracting device features based on time - domain and frequency - domain waveforms are set; the encrypted image is formed in the radio frequency security access platform.

Claims

1. A distributed access authentication method for power 5G terminals for access to new power systems, characterized in that: The method includes an edge-side end-to-end identity authentication method based on network layer wide-area distributed authentication, a large-scale power 5G terminal access authentication method based on link layer access authentication, and a device identity identification method based on the physical characteristics of the wireless signal of the power 5G terminal and combined with channel state information (CSI) fusion identification, wherein: The edge-side end-to-end identity authentication method based on network-layer wide-area distributed authentication is based on the IPSECVPN architecture. By monitoring the authentication signaling load, it specifically includes shutting down the NAS signaling authentication of the original power 5G network, retaining only one authentication when the power 5G terminal is attached, and establishing an IPSECVPN tunnel between the power 5G network access power 5G terminal and the distributed authentication gateway. The national encryption algorithms SM3 and SM4 are used in IPSECVPN to realize data encryption and integrity protection; The large-scale power 5G terminal access authentication method based on link layer access authentication adopts the power 5G network fixed terminal group access authentication based on group shared key; Device identification methods include:

1. Device identification based on the physical characteristics of wireless signals of power 5G terminals, which includes adding RF security protection equipment and RF security access platform to the original wireless access points at the hardware layer, and the two cooperate to complete the access of legal power 5G terminals and block illegal power 5G terminals, while processing security rules; at the software layer, a wireless module physical layer feature extraction method executed by RF security protection equipment, a device feature extraction method based on constellation trajectory diagram, and a device feature extraction method based on time domain and frequency domain waveforms are set; Second, device identification combined with channel state information (CSI) fusion identification includes power 5G terminal identification based on channel fingerprint; 3. The physical layer features, constellation trajectory diagram, time domain and frequency domain waveforms, and channel fingerprints in 1 and 2 are integrated to form a secret map, which is used as an identity authentication method for power equipment before receiving the decrypted data of the national secret encryption algorithm SM3 and SM4, and the secret map is formed in the radio frequency security access platform; The method for group shared keys includes: S1 establishing a heterogeneous graph neural network in the group, with group members as nodes; S2 obtains the historical data sent and received by the group members, selects a node in the group, and if there are multiple sets of data in the historical data that overlap the time period with the specified power consumption, then these other nodes are defined as the neighbors of the selected node, and the neighbors of all nodes in the group are found; S3 calculates the neighbor weight of each node: ,in is a deep neural network with node attention, The vector representations of the node and its neighbors are respectively selected, the nodes with the top 5-8 neighbor weight values ​​are selected, and the respective neighbor weights are randomly sorted to form a shared key.

2. The method according to claim 1, characterized in that The method for extracting the physical layer features of the wireless module is to process the baseband of the RF signal emitted by the device at the receiving end to form a stable I / Q trajectory diagram, thereby obtaining the fingerprint features of the device; The device feature extraction method based on the constellation trajectory diagram includes that after the receiving end obtains the received signal with the same frequency and phase as the transmitting end, the signal can be drawn in the constellation trajectory diagram to extract the feature; By plotting the received signal point by point on the time axis in the form of I-path and Q-path, a time domain waveform diagram containing three-dimensional information on the time axis, I axis and Q axis can be obtained; the received signal is segmented according to the specified length and then Fourier transformed, the spectrum of the Fourier transform can be analyzed to extract features in the frequency domain.

3. The method according to claim 2, characterized in that The method of forming a dense image includes: a. randomly select a time point, or randomly select a time point in the overlapping period, give a two-dimensional IQ graph formed by the I axis and the Q axis at the time point, and randomly select the I / Q trajectory graph, the two-dimensional IQ graph, the frequency domain waveform, and the channel fingerprint, b. Concatenate the I / Q trajectory diagram, the two-dimensional IQ diagram, the frequency domain waveform, and the channel fingerprint in the selected order to form a dense map.

4. The method according to claim 3, characterized in that The authenticity identification method of the secret image is: c. Establish a convolutional neural network or a generative adversarial network, obtain multiple pseudo-dense images according to steps a and b of the method, form a set of images of dense images and pseudo-dense images, and divide them into a training set and a verification set, mark the pseudo-dense images whose order is consistent with the dense images as suspected true, make a difference between the suspected true images and the dense images, and define the images as approximately true if the sum of the pixel values ​​of the difference is below a specified value, those above the specified value are still suspected true, and those with inconsistent order are false, and they are divided into three categories; d. Use the training set to train the above network, use the verification set to verify the accuracy, and optimize the network parameters according to the back propagation of the loss function of each training. When the loss function continues to decrease and stabilizes, the verification accuracy reaches the highest and stable level, and the trained network is obtained; e. Input the image to be tested into the trained network. When the probability of the approximate truth is the largest among the three categories, the image to be tested is subtracted from the secret image. If the sum of the pixel values ​​of the difference is less than the preset value, the identity is recognized. Otherwise, it is judged as an input attempt of dangerous intrusion. When the probability of the approximate truth is not the largest among the three categories, it is also an attempted intrusion.

5. The method according to claim 4, characterized in that The output ends of the convolutional neural network and the generative adversarial network are connected to the fully connected layer and the classification function layer, and the output predicts the probabilities of three categories. The channel fingerprint formation includes feature extraction based on the following parameters: multipath number, delay spread, Doppler spread, slow time direction frequency characteristics, received power mean, amplitude standard deviation, amplitude derivative standard deviation, and then these features are pixelated, and these pixelated extracted features are selected according to a random selection method, and then the pixels are spliced ​​in the selected order.

6. The method according to claim 5, characterized in that When the frequency of occurrence of the pseudo-cryptographic image that is close to the real one increases within a predetermined time period during the identity recognition process, steps a and b are repeated to form a new cryptographic image.

7. A distributed access authentication system for power 5G terminals for access to a new power system, which implements the method as described in any one of claims 1 to 6, characterized in that: The system includes at least one terminal group consisting of multiple terminals forming a heterogeneous graph neural network, a distributed authentication gateway, and at least one terminal group wirelessly communicates with the hardware layer via the distributed authentication gateway; wherein, The hardware layer includes the original AP, the radio frequency security access platform, the switch, and at least one power device connected to the switch, and the radio frequency security protection device is communicatively connected to the radio frequency security access platform; At least one of the terminal groups authenticates the identity with the distributed authentication gateway through an IPSECVPN tunnel, and transmits SM3 and SM4 encrypted data. The original AP and the radio frequency security access platform communicate wirelessly with the distributed authentication gateway. A wireless module physical layer feature extraction method executed by the radio frequency security protection device, a device feature extraction method based on a constellation trajectory diagram, and a device feature extraction method based on time domain and frequency domain waveforms are set at the software layer. The secret map is formed in the radio frequency security access platform.

Citation Information

Patent Citations

  • IFF signal identification method and device based on radio frequency fingerprint, and medium

    CN113905383A

  • Low-voltage power line carrier communication credible safety access method

    CN113949414A

  • Electric power 5G network electromagnetic space security situation awareness and evaluation method for novel electric power system access

    CN119211987A