An electric power 5G eSIM terminal and a secondary authentication method thereof

By employing a multi-module design and dynamic behavior analysis encryption algorithm in the power 5G eSIM terminal, the issues of data security and communication switching in the power industry have been resolved. This enables flexible multi-carrier switching and real-time security monitoring, thereby improving the security and efficiency of data transmission.

CN119697632BActive Publication Date: 2025-12-26STATE GRID FUJIAN ELECTRIC POWER RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411781599.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-05
Publication Date
2025-12-26
Estimated Expiration
2044-12-05

AI Technical Summary

Technical Problem

The power industry faces challenges in data security and identity authentication. Traditional encryption methods are insufficient, 5G terminal communication designs cannot meet the needs of multi-operator switching, and secondary authentication is difficult to cope with security threats in dynamic environments.

Method used

It adopts a power-based 5G eSIM terminal design, which includes a built-in eSIM, an external eSIM module, and a physical USIM card, enabling free switching between cards from the three major operators; combined with pseudo-tag dynamic behavior analysis algorithm and dynamic encryption algorithm, it provides real-time monitoring and encryption processing.

Benefits of technology

It improves the security and flexibility of power communication terminals, ensures flexibility in multi-operator switching, identifies potential threats in real time, and enhances data transmission security and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119697632B_ABST
    Figure CN119697632B_ABST
Patent Text Reader

Abstract

The application provides a power 5G eSIM terminal and a secondary authentication method thereof, which introduces a dynamic behavior analysis algorithm and a dynamic encryption algorithm based on a pseudo label, thereby significantly improving the security and data transmission efficiency of the power 5G terminal compared with the prior art. The dynamic behavior analysis algorithm monitors the behavior of the power 5G terminal in real time and identifies abnormal activities, thereby enhancing the security of identity verification. The dynamic encryption algorithm dynamically generates an encryption key and selects an encryption algorithm according to context information, thereby improving the security and adaptability of data transmission, especially in the case of data scarcity and complex network environment, thereby providing a more flexible and adaptable security guarantee for the power 5G management and control platform and the State Grid encryption service platform without sacrificing efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of power communication, in particular to a power 5G eSIM terminal and a secondary authentication method thereof. BACKGROUND

[0002] With the rapid development of information technology, the power industry is undergoing digital transformation. The introduction of 5G communication technology provides strong support for the intelligentization and automation of the power system. 5G lightweight communication terminals can achieve higher data transmission rates and lower latency, promoting real-time monitoring, fault diagnosis, and remote control of power equipment. The widespread use of these terminals not only improves the safety and reliability of the power grid, but also provides flexible network solutions for power companies, supporting a variety of application scenarios. However, as the application scenarios of the power special network become increasingly complex, the industry faces multiple security challenges.

[0003] (1) Data security issues: As a critical infrastructure, the power industry faces network attack risks such as data leakage and service interruption. Traditional identity authentication methods have the potential to be exploited by attackers, making it difficult to effectively prevent identity spoofing. In addition, the need for confidentiality and integrity protection during data transmission is also a major challenge. Traditional encryption methods are insufficient in performance when handling large amounts of data, and key management is complex.

[0004] (2) Communication design issues of 5G terminals: In the power communication network, small data packet transmission is commonly required, with medium to high bandwidth demand, extremely strict latency and reliability requirements. Although the flexible deployment of 5G terminals reduces communication construction costs and improves the response speed of grid control and the monitoring intensity of power equipment, in actual applications, the current 5G module has at most 2 7816 interfaces, which cannot simultaneously satisfy the free switching selection of mobile eSIM, China Unicom / eSIM, and USIM cards, posing a challenge to the communication design of 5G eSIM terminals.

[0005] (3) Operator switching issues: Currently, due to the protection of domestic operators' own card number resources, it is impossible to realize the function of switching between multiple operators based on one eSIM card, which poses a challenge to the power industry.

[0006] (4) Issues with secondary authentication: Traditional identity authentication is usually a one-time static authentication, which is difficult to cope with security challenges in dynamic environments and is vulnerable to impersonation or attacks. After single authentication, the system may be affected by undetected vulnerabilities or malicious code, resulting in the risk of terminal exploitation in subsequent operations. Current authentication does not have real-time monitoring and feedback mechanisms, and cannot immediately identify security vulnerabilities or abnormal behavior. SUMMARY

[0007] Therefore, the present application aims to provide a power 5G eSIM terminal and a secondary authentication method, to improve the flexibility, security and reliability of the power special network, and effectively guarantee the security and flexibility of the power communication terminal.

[0008] To achieve the above-mentioned purpose, the present application adopts the following technical solution: a power 5G eSIM terminal, which comprises a 5G module with a built-in eSIM, an external eSIM module and a physical USIM card; wherein the built-in eSIM is responsible for providing a communication number of China Unicom or China Telecom, the external eSIM module is responsible for providing a communication number of China Mobile, and the physical USIM card can communicate with the numbers of China Mobile, China Unicom and China Telecom; when the physical USIM card is inserted, the external eSIM module is disabled, and the built-in eSIM is not affected; and when the physical USIM card is pulled out, the external eSIM module is enabled and powered on, and the built-in eSIM can also take effect, ensuring that the USIM cards and eSIMs of the three major operators can communicate on the 5G terminal.

[0009] The present application also provides a secondary authentication method based on a power 5G eSIM terminal, which adopts the power 5G eSIM terminal, comprising the following steps:

[0010] Step 1: eSIM pre-set certificate; the power 5G management platform generates an eUICC certificate before the eSIM chip is shipped, which is integrated with platform information and loaded into the chip; when the device activates the eSIM service for the first time, the pre-set certificate is automatically verified to ensure the legality of the device identity and network access authority;

[0011] Step 2: code number application; the power 5G management platform obtains code numbers from the operator in batches, and the operator returns the ciphertext information of the code numbers, including ICCID, IMSI, KI, OPC and MSISDN;

[0012] Step 3: secondary authentication and code number download; when the power 5G terminal is connected to the network for the first time, the secure proxy SDK and the eSIM chip encryption application are used to complete the two-way identity authentication with the power 5G management platform and the State Grid service platform; after the authentication is passed, the power 5G terminal will automatically download and configure the network code number with the eSIM chip using the services of the power 5G management platform, to realize fast access; after the power 5G terminal successfully accesses the 5G network, if it needs to access a specific power special network, the terminal must be authenticated again; the secondary authentication is carried out between the terminal and the authentication server, and the authentication server feeds back the related QoS parameters, MAC address, IP address and user charging information according to the terminal information;

[0013] Step 4: After completing the secondary authentication, the power 5G terminal can start uploading the key data; the terminal encrypts the important business data through the embedded security chip and sends the encrypted data to the business system.

[0014] In a preferred embodiment, the step 3 monitors and analyzes the behavior of the power 5G terminal in real time by a pseudo-label dynamic behavior analysis algorithm, constructs a behavior model, and specifically includes the following steps:

[0015] Step 31: data preparation;

[0016] 1) Collect labeled data

[0017] First, collect and organize a well-labeled data and corresponding label to form a labeled data set D labled :

[0018] D labled = {(X i , y i )}, y i is the label (y i = 1 represents normal; y i = 0 represents abnormal);

[0019] X i is the behavior feature vector of the power 5G terminal i (i = 1 ~ k), X i = {x1, x2, ···, x n}, x1 is the first behavior feature of the power 5G terminal i, x2 is the second behavior feature of the power 5G terminal i, and x n is the nth behavior feature of the power 5G terminal i;

[0020] 2) Collect unlabeled data: collect a large number of unlabeled data sets at the same time to form an unlabeled data set D unlabled , extract the feature vector F j of the unlabeled data for subsequent pseudo-label generation;

[0021] D unlabeled = {F j};;

[0022] F j is the behavior feature vector of the unlabeled power 5G terminal j (j = 1 ~ m),

[0023] F j = {x′1, x′2, ···, x′ n}, x′1 is the first behavior feature of the power 5G terminal j, x′2 is the second behavior feature of the power 5G terminal j, and x′ nThe nth behavior feature of the power 5G terminal j;

[0024] Step 32: pre-training model;

[0025] Training initial model: using labeled data set D labeled , training a preliminary power 5G terminal behavior classification model f:

[0026] f * = arg min L(D labeled ,f)

[0027] The loss function adopts an improved binary cross entropy loss function, which is expressed as:

[0028]

[0029] Where X i is the feature vector of the ith power 5G terminal, w1 is the weight of the positive class (normal behavior), w0 is the weight of the negative class (abnormal behavior), and f(X i ) is the prediction probability of the model that the ith sample belongs to the positive class; The weights w1 and w0 can be set according to the proportion of positive and negative samples to balance the contribution of two kinds of samples to the loss function;

[0030] Step 33: generate pseudo labels

[0031] Apply pre-trained model: apply the trained model f * to the unlabeled data set D unlabeled to generate a pseudo label set

[0032]

[0033] Step 34: build a new training set

[0034] Merge data set: combine the generated pseudo labels with the labeled data to form a new mixed training set:

[0035]

[0036] Step 35: model retraining

[0037] Train the model on the new data set: use the new mixed data set D new to retrain the model;

[0038] f ** = arg min L(D new ,f)

[0039] Step 36: continuous iteration

[0040] Feedback and update: In actual operation, the performance of the model is continuously monitored; if new labeled samples are obtained, they can be included in the training set to further optimize the model;

[0041] Step 37: Dynamic threshold adjustment

[0042] Adjust the threshold θ according to real-time data:

[0043]

[0044] Where, σ P is the mean and standard deviation of the last N historical prediction probabilities, and k1 is a tunable parameter;

[0045] Step 38: Anomaly detection

[0046] When the power 5G terminal performs secondary authentication, input real-time data X real-time (the feature vector of the power 5G terminal) into the trained model f ** to perform anomaly detection, and the probability P that the current power 5G terminal behavior belongs to normal behavior:

[0047] P(y i =1|X real-time )=f ** (X real-time )

[0048] According to the threshold θ:

[0049] if P(y i =1||X real-time )>θ:y i =1 (normal behavior)

[0050] else:y i =0 (abnormal behavior)

[0051] When abnormal behavior is detected, the system will trigger additional security measures, such as requiring the power 5G terminal to perform additional identity verification to ensure the authenticity of the power 5G terminal when accessing power private network services.

[0052] In a preferred embodiment, the step 4 includes a dynamic encryption algorithm that dynamically generates an encryption key and selects an encryption algorithm according to context information; Specifically, the following steps are included:

[0053] Step 41: Collect context information; Collect context information that affects encryption, including power 5G terminal identity U, network status N, data sensitivity S;

[0054] Step 42: Key generation; Generate a dynamic key K according to the context information:

[0055] K = Hash(U || N || S || timestamp)

[0056] Where || represents concatenation operation, and timestamp is the time stamp;

[0057] Step 43: Selection of encryption algorithm; select encryption algorithm A according to data sensitivity:

[0058]

[0059] For high sensitivity data, a strong encryption algorithm is used to ensure high security of data during transmission;

[0060] For ordinary data, a lightweight encryption algorithm is selected to improve processing speed under the premise of ensuring security;

[0061] Step 44: Data encryption; use the dynamically generated key K and the selected encryption algorithm to encrypt the data Data:

[0062] C = A(K, Data)

[0063] Where C is the ciphertext;

[0064] Step 45: Decryption process; the receiving end uses the same context information to generate the key for decryption:

[0065] Data = A -1 (K, C).

[0066] Compared with the prior art, the present application has the following beneficial effects:

[0067] 1. Based on the pseudo-label dynamic behavior analysis algorithm as a supplementary layer, real-time monitoring and anomaly detection are provided to help identify potential security threats. Combined with dynamic behavior analysis, the flexibility and adaptability of the system can be improved. This algorithm effectively combines labeled data and unlabeled data to improve the training effect and generalization ability of the model.

[0068] 2. The dynamic encryption algorithm dynamically generates encryption keys and selects encryption algorithms according to context information to improve the security of data transmission. BRIEF DESCRIPTION OF DRAWINGS

[0069] Fig. 1 It is a 5G eSIM terminal communication architecture schematic diagram of the preferred embodiment of the present application;

[0070] Fig. 2 It is an eSIM platform schematic diagram of the preferred embodiment of the present application;

[0071] Fig. 3 It is an authentication overall flow schematic diagram of the preferred embodiment of the present application. Detailed Implementation

[0072] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0073] It should be noted that the following detailed descriptions are illustrative and intended to provide further explanation of this application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains.

[0074] It should be noted that the terminology used herein is for the purpose of describing particular implementations only and is not intended to limit the exemplary implementations according to this application; as used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise; furthermore, it should be understood that when the terms “comprising” and / or “including” are used in this specification, they indicate the presence of features, steps, operations, devices, components and / or combinations thereof.

[0075] refer to Figs. 1-3 In most power distribution automation terminal application scenarios, the flexible deployment of 5G terminals reduces communication construction costs and improves the power grid's control response speed and power equipment monitoring capabilities. However, current 5G modules have a maximum of only two 7816 interfaces, which cannot simultaneously meet the free switching selection of mobile eSIM, China Unicom / China Telecom eSIM, and USIM cards. To solve this problem, an external eSIM module is introduced, using a hardware switch to realize an automatic switching mechanism between USIM and eSIM, ensuring that mobile eSIM and USIM cards can be switched freely. At the same time, China Unicom / China Telecom eSIM is either built into the module or externally placed outside the module through another 7816 port (the built-in eSIM includes a 7816 interface and an SPI interface). Specifically, when a physical USIM card is inserted, the eSIM module is disabled; when the physical USIM card is removed, the eSIM module is enabled and powered on. This design can flexibly meet different communication needs and ensure effective switching of SIM card types in various scenarios. In terms of number management, mobile eSIM can only be written to the external network air interface through the mobile eSIM platform after a pre-set eSIM seed number is configured.

[0076] The China Telecom / China Unicom eSIM supports number writing via the power eSIM management platform. This involves pre-installing a private network seed number on the eSIM and then writing the number through the power intranet platform, or having a 5G terminal communicate with the intranet platform via a USIM card. The eSIM chip performs number writing via the SPI interface. For China Telecom / China Unicom eSIMs, secondary authentication is achieved by embedding a national network security certificate and algorithm within the eSIM chip; China Mobile eSIMs utilize a quantum T-card (SDIO to USB) or a quantum softkey for quantum communication authentication.

[0077] Through this design, the eSIM card can be switched between multiple operators. Through the design of hardware switch and external eSIM module, combined with various interfaces and functions, the ability to flexibly manage and switch different eSIM cards on terminal devices is realized. This switching mode provides users with greater freedom and flexibility, allowing them to choose different operator services according to their needs without the need to replace physical SIM cards, thereby improving user experience and convenience.

[0078] The secondary authentication includes the following steps:

[0079] Step 1: eSIM pre-set certificate

[0080] The power 5G management platform generates an eUICC certificate before the eSIM chip is shipped. This certificate is integrated with platform information and loaded into the chip. When the device first activates the eSIM service, the pre-set certificate is automatically verified to ensure the legality of the device identity and network access rights.

[0081] Arrangement 2: Code number application

[0082] The power 5G management platform obtains code numbers in bulk from the operator, and the operator returns the ciphertext information of the code numbers, including ICCID, IMSI, KI, OPC, and MSISDN, etc. This process ensures the security and privacy protection of the code numbers.

[0083] Step 3: Secondary authentication and code number download

[0084] When the power 5G terminal first connects to the network, it completes the two-way identity authentication with the power 5G management platform and the State Grid security platform through the secure proxy SDK and eSIM chip encryption application. After authentication, the power 5G terminal will automatically download and configure network code numbers using the power 5G management platform service and eSIM chip, realizing fast access.

[0085] Once the power 5G terminal successfully accesses the 5G network, if it needs to access a specific power dedicated network, the terminal must undergo secondary authentication. This process requires the terminal to carry specific user credentials, which are issued by the power dedicated network, not by the operator. Authentication is carried out between the terminal and the authentication server, and the authentication server feeds back relevant QoS parameters, MAC address, IP address, and user billing information, etc. This mechanism ensures the authenticity of the power 5G terminal when accessing the power dedicated network service, and provides necessary security connection information for the 5G network.

[0086] In particular, while the national encryption algorithm provides high-level security protection, the pseudo-label dynamic behavior analysis algorithm can serve as a complementary layer, providing real-time monitoring and anomaly detection to help identify potential security threats. Combined with dynamic behavior analysis, the system's flexibility and adaptability can be improved. For example, when the behavior of a power 5G terminal changes, the system can automatically adjust security measures, rather than relying solely on static identity verification mechanisms. Therefore, before the two-way identity authentication with the power 5G management platform and the national encryption service platform, a dynamic behavior analysis algorithm based on pseudo-labels is introduced to enhance the security of the authentication process, aiming to monitor power 5G terminals in real-time and identify abnormal activities to enhance identity verification and system security. Through self-supervised learning methods, this algorithm effectively combines labeled data and unlabeled data, improving the training effect and generalization ability of the model, especially in data-scarce situations. The algorithm mainly includes the following steps:

[0087] (1) Data preparation

[0088] 1) Collect labeled data

[0089] First, collect and organize a well-labeled dataset and corresponding labels. For example:

[0090] D labled ={(X i ,y i )} where y i labels (y i = 1 indicates normal; y i = 0 indicates abnormal);

[0091] where X i is the feature vector of power 5G terminal i (i = 1 ~ k), X i = {x1, x2, ···, x n} is the behavior feature of power 5G terminal i (including login time, device type, IP address, geographic location, operation type, network delay, device power, etc.);

[0092] 2) Collect unlabeled data: Collect a large number of unlabeled data sets to form an unlabeled data set D unlabled , extract the feature vector F j of the unlabeled data for subsequent pseudo-label generation;

[0093] D unlabeled ={F j};;

[0094] where F j is the feature vector of unlabeled power 5G terminal j (j = 1 ~ m),

[0095] Fj = {x'1, x'2, ···, x'N} n} is the behavior characteristics of the power 5G terminal j (including login time, device type, IP address, geographic location, operation type, network delay, device power, etc.);

[0096] (2) Pre-training model

[0097] 1) Training the initial model: using the labeled data set D labeled , training a preliminary power 5G terminal behavior classification model f:

[0098] f * = arg min L(D labeled , f)

[0099] 2) The loss function uses an improved binary cross-entropy loss function, denoted as:

[0100]

[0101] where X i is the feature vector of the i-th power 5G terminal, w1 is the weight of the positive class (normal behavior), w0 is the weight of the negative class (abnormal behavior), and f(X i ) is the prediction probability of the model that the i-th sample belongs to the positive class. The weights w1 and w0 can be set according to the proportion of positive and negative samples to balance the contribution of the two types of samples to the loss function;

[0102] (3) Generate pseudo labels

[0103] Apply the pre-trained model: apply the trained model f * to the unlabeled data set D unlabeled to generate a pseudo label set

[0104]

[0105] (4) Build a new training set

[0106] Merge the data set: combine the generated pseudo labels with the labeled data to form a new hybrid training set:

[0107]

[0108] (5) Model retraining

[0109] Train the model on the new data set: use the new hybrid data set D new to retrain the model;

[0110] f ** = arg min L(D newf)

[0111] (6) Continuous iteration

[0112] Feedback and update: In actual operation, the performance of the model is continuously monitored; if new labeled samples are obtained, they can be included in the training set to further optimize the model;

[0113] (7) Dynamic threshold adjustment

[0114] According to real-time data, dynamically adjust the threshold θ:

[0115]

[0116] Where, σ P is the mean and standard deviation of the last N historical prediction probabilities, and k1 is a tunable parameter;

[0117] (8) Anomaly detection

[0118] When the power 5G terminal performs secondary authentication, input real-time data X real-time (the feature vector of the power 5G terminal) into the trained model f ** , perform anomaly detection, and the probability P that the current terminal behavior belongs to normal behavior:

[0119] P(y i =1|X real-time ) = f ** (X real-time )

[0120] According to the threshold θ, judge:

[0121] if P(y i =1||X real-time ) > θ: y i =1 (normal behavior)

[0122] else: y i =0 (abnormal behavior)

[0123] When abnormal behavior is detected, the system will trigger additional security measures, such as requiring the power 5G terminal to perform additional identity verification to ensure the identity authenticity of the power 5G terminal when accessing power private network services.

[0124] After authentication, the power 5G terminal will automatically download and configure network codes with the eSIM chip using the services of the power 5G management platform, realizing fast access.

[0125] Step 4: Key data encryption upload and delivery

[0126] After completing the secondary authentication, the power 5G terminal can start uploading key data. The terminal encrypts important business data through the embedded security chip and sends the encrypted data to the business system. After receiving the ciphertext, the business system calls the unified password service platform for decryption processing and returns the plaintext data. Similarly, when the business system needs to issue key data, it first calls the unified password service platform to encrypt the plaintext data, and then sends the encrypted data to the power 5G communication terminal. The terminal receives the data and decrypts it through the embedded security chip to obtain the required plaintext data.

[0127] The terminal encrypts important business data through the embedded security chip and sends the encrypted data to the business system. To improve data security and transmission efficiency, the system introduces a dynamic encryption algorithm that dynamically generates encryption keys and selects encryption algorithms based on context information. To improve the security of data transmission.

[0128] Specific implementation steps:

[0129] (1) Context information collection

[0130] Collect context information that affects encryption, including power 5G terminal identity U, network status N, and data sensitivity S.

[0131] (2) Key generation

[0132] Generate dynamic key K based on context information:

[0133] K = Hash(U || N || S || timestamp)

[0134] Where || represents concatenation operation, and timestamp is the time stamp.

[0135] (3) Encryption selection

[0136] Select encryption algorithm based on data sensitivity:

[0137]

[0138] For high sensitivity data (such as control instructions), use strong encryption algorithm (such as AES-256) to ensure high security of data during transmission.

[0139] For ordinary data (such as state monitoring information), you can choose lightweight encryption algorithm (such as AES-128) to improve processing speed while ensuring security.

[0140] (4) Data encryption

[0141] Encrypt data Data using dynamically generated key K and selected encryption algorithm:

[0142] C = A(K, Data)

[0143] Where C is the ciphertext.

[0144] (5) Decryption process

[0145] The receiving end uses the same context information to generate a key for decryption:

[0146] Data = A -1 (K, C)

[0147] Through the proposed dynamic encryption algorithm, the power 5G terminal can effectively improve the security and transmission efficiency of data during the uploading and downloading process of critical data. This mechanism not only ensures the confidentiality and integrity of data, but also adapts to changing network environments, enhancing the flexibility and responsiveness of the system.

[0148] By introducing the dynamic behavior analysis algorithm based on pseudo labels and the dynamic encryption algorithm, compared with the prior art, the security and data transmission efficiency of the power 5G terminal are significantly improved. The dynamic behavior analysis algorithm monitors the behavior of the power 5G terminal in real time and identifies abnormal activities, enhancing the security of identity verification. The dynamic encryption algorithm dynamically generates encryption keys and selects encryption algorithms based on context information, improving the security and adaptability of data transmission, especially in the case of data scarcity and complex network environments, thus providing a more flexible and adaptable security guarantee for the power 5G control platform and the State Grid security service platform without sacrificing efficiency.

Claims

1.A secondary authentication method based on a power 5G eSIM terminal, characterized in that, Comprising the following steps: Step 1: eSIM pre-set certificate; The power 5G management platform generates an eUICC certificate before the eSIM chip is shipped, which is integrated with platform information and loaded into the chip; when the device activates the eSIM service for the first time, the pre-set certificate is automatically verified to ensure the legality of the device identity and network access rights; Step 2: Code number application; The power 5G management platform obtains code numbers from the operator in batches, and the operator returns the ciphertext information of the code number, including ICCID, IMSI, KI, OPC and MSISDN; Step 3: Secondary authentication and code number download; when the power 5G terminal first connects to the network, it completes the two-way identity authentication with the power 5G management platform and the State Grid service platform through the secure proxy SDK and eSIM chip encryption application; after the authentication is passed, the power 5G terminal will automatically download and configure the network code number with the power 5G management platform service and eSIM chip to realize fast access; after the power 5G terminal successfully accesses the 5G network, if it needs to access a specific power special network, the terminal must perform secondary authentication; secondary authentication is performed between the terminal and the authentication server, and the authentication server feeds back the related QoS parameters, MAC address, IP address and user charging information according to the terminal information; Step 4: After completing the secondary authentication, the power 5G terminal can start uploading key data; the terminal encrypts important business data through the embedded security chip and sends the encrypted data to the business system. 2.The secondary authentication method based on the power 5G eSIM terminal of claim 1, wherein, The step 3 monitors and analyzes the behavior of the power 5G terminal in real time based on the pseudo-label dynamic behavior analysis algorithm, constructs its behavior model, and specifically includes the following steps: Step 31: Data preparation; 1) Collect labeled data First, a well-labeled data and corresponding labels are collected and organized to form a labeled dataset : ; wherein, is a behavior feature vector of a power 5G terminal , , , is a 1st behavior feature of a power 5G terminal , is a 2nd behavior feature of a power 5G terminal , is an n-th behavior feature of a power 5G terminal , 2) Collect unlabeled data: Collect a large number of unlabeled data sets at the same time to form an unlabeled data set , extract the feature vector of the unlabeled data , for subsequent pseudo-label generation; ; wherein, is a behavior feature vector of a power 5G terminal that is not labeled , , is a first behavior feature of a power 5G terminal , is a second behavior feature of a power 5G terminal , is an nth behavior feature of a power 5G terminal ; Step 32: Pre-training model; Training an initial model: using a labeled dataset , training a preliminary power 5G terminal behavior classification model : The loss function uses an improved binary cross-entropy loss function, which is expressed as: in, For the first Feature vectors of 5G power terminals The positive class, i.e., the weight of normal behavior, This is the negative class, representing the weight of abnormal behavior. The model is for the first The predicted probability that a sample belongs to the positive class; weights and The ratio of positive to negative samples can be set to balance the contribution of the two types of samples to the loss function; Step 33: Generate pseudo-label Apply pre-trained model: Apply the trained model to the unlabeled dataset , generating a pseudo-label set : Step 34: Build a new training set Merge the data set: combine the generated pseudo-label with the labeled data to form a new hybrid training set: Step 35: Model retraining Train the model on new data set: Use new mixed data set Retrain the model; Step 36: Continuous iteration Feedback and update: in actual operation, continuously monitor the performance of the model; if new labeled samples are obtained, they can be included in the training set to further optimize the model; Step 37: Dynamic threshold adjustment Adjusting threshold values dynamically based on real-time data : wherein, , is the mean and standard deviation of the last N historical prediction probabilities, a tunable parameter; Step 38: Abnormality detection When the secondary authentication is performed on the power 5G terminal, the feature vector of the real-time data power 5G terminal is input to the trained model to perform the anomaly detection, and the probability that the current power 5G terminal behavior belongs to the normal behavior : According to the threshold A determination is made: When abnormal behavior is detected, the system will trigger additional security measures, such as requiring the power 5G terminal to perform additional identity verification, to ensure the authenticity of the power 5G terminal when accessing power special network services. 3.The secondary authentication method based on the power 5G eSIM terminal of claim 1, wherein, The step 4 includes a dynamic encryption algorithm that dynamically generates encryption keys and selects encryption algorithms based on context information; Specifically includes the following steps: Step 41: Context information collection; collect context information that affects encryption, including power 5G terminal identity , network status , data sensitivity ; Step 42: Key generation; generation of dynamic key based on context information : Wherein, || represents the splicing operation, and timestamp is the timestamp; Step 43: Selection of encryption algorithm; selection of encryption algorithm based on data sensitivity : For high-sensitivity data, use strong encryption algorithms to ensure high security of data during transmission; For ordinary data, select lightweight encryption algorithms to improve processing speed while ensuring security; Step 44: Data encryption; use of dynamically generated key and the selected encryption algorithm to encrypt the data : wherein is a ciphertext; Step 45: Decryption process; the receiving end generates a key using the same context information for decryption: 。 4. An electric power 5G eSIM terminal, characterized by, The method for secondary authentication based on the power 5G eSIM terminal according to any one of claims 1-3; the power 5G eSIM terminal includes a 5G module with a built-in eSIM, an external eSIM module and a physical USIM card; wherein the built-in eSIM is responsible for providing a communication number of China Unicom or China Telecom, the external eSIM module is responsible for providing a communication number of China Mobile, and the physical USIM card can communicate with the numbers of China Mobile, China Unicom and China Telecom; when the physical USIM card is inserted, the external eSIM module is disabled, and the built-in eSIM is not affected; and when the physical USIM card is pulled out, the external eSIM module is enabled and powered on, and the built-in eSIM can also take effect, ensuring that the USIM cards and eSIMs of the three major operators can communicate on the 5G terminal.

Citation Information

Patent Citations

  • Wireless communication terminal distribution network secondary authentication method and system and storage medium

    CN117651274A

  • Communication method for accessing eSIM 5G power terminal to power private network

    CN117956464A