Authentication method, terminal and network equipment
Patent Information
- Application Number
- CN202280101567.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-14
- Publication Date
- 2025-06-13
Smart Images

Figure CN120153680A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication, and more particularly, to an authentication method, a terminal, and a network device. Background Art
[0002] In many scenarios, a network device needs to determine whether a terminal is allowed to access the network based on the distance between the network device and the terminal. For example, when a terminal requests to access a bank network, the terminal will be allowed to access the bank network only when the terminal is near the bank. The network device can determine whether the terminal is nearby according to the measurement result, and the measurement result can be obtained by measuring the signal from the terminal. However, this mechanism is not secure because an illegal terminal can access the network by sending a signal to the network device with a high transmission power. Therefore, the technical problem to be solved is how to improve the security of the access network. Summary of the Invention
[0003] This application provides an authentication method, a terminal, and a network device to improve the security of the access network.
[0004] According to a first aspect, an authentication method is provided. The method can be executed by a network device or a chip in the network device. The method includes: the network device measures at least one first signal from the terminal to obtain a first measurement result, where the first measurement result is used to determine the distance between the terminal and the network device; the network device determines that the terminal is not rejected from accessing the network according to the first measurement result; the network device sends at least one second signal to the terminal; the network device receives authentication information from the terminal, where the authentication information is obtained according to a second measurement result of the at least one second signal; the network device determines whether the terminal is allowed to access the network according to the authentication information.
[0005] In this application, the network device determines whether the terminal is allowed to access the network after double verification. The first verification is based on the first measurement result measured by the network device. If the network device determines that the terminal is not rejected from accessing the network, the network device will perform a second verification according to the authentication information, and the authentication information is obtained by the terminal according to the second measurement. In this way, when an illegal terminal sends a signal to the network device with a high power, the network device measures the received signal and gets an incorrect result in the first verification. Since the illegal terminal cannot obtain the correct authentication information, the network device will reject the illegal terminal from accessing the network in the second verification. Therefore, the authentication method proposed in this application can improve the security of the access network.
[0006] In some possible implementation manners, the authentication information is obtained by performing secure sketch processing on the second measurement result. Determining whether the terminal is allowed to access the network according to the authentication information includes: if the recovery processing of the authentication information according to the first measurement result is successful, the terminal is allowed to access the network, where the recovery processing corresponds to the secure sketch processing; or if the recovery processing of the authentication information according to the first measurement result is not successful, the terminal is not allowed to access the network.
[0007] In this application, when determining whether a terminal is allowed to access the network, a network device and the terminal may apply secure sketch processing and recovery processing.
[0008] In some possible implementation manners, the method further includes: the network device receives request information from the terminal, where the request information requests to access the network; the network device sends response information to the terminal, where the response information instructs the terminal to send the at least one first signal and measure the at least one second signal.
[0009] In some possible implementation manners, performing the recovery processing on the authentication information according to the first measurement result includes: performing quantization processing on the first measurement result, and performing the recovery processing on the authentication information according to the quantized first measurement result.
[0010] Optionally, the quantization processing includes at least one of noise reduction processing and coding processing.
[0011] In this application, quantization processing can be used to improve the convenience of recovery processing.
[0012] In some possible implementation manners, the at least one first signal is measured within a period of time, and the at least one second signal is transmitted within the period of time.
[0013] Optionally, the period of time is based on the channel rate.
[0014] Optionally, the network device determines the period of time and sends measurement indication information to the terminal, where the measurement indication information indicates the period of time.
[0015] In this application, the network device and the terminal measure the received signal within a period of time, so that the first measurement result and the second measurement result can be used for secure sketch processing and recovery processing.
[0016] In some possible implementation manners, the first measurement result includes the signal strength of the at least one first signal, and the second measurement result includes the signal strength of the at least one second signal.
[0017] Optionally, the first measurement result includes the received signal strength indicator (RSSI) of the first signal, and the second measurement result includes the RSSI of the second signal.
[0018] According to a second aspect, there is provided an information transmission method, which may be executed by a terminal or a chip in the terminal. The method includes: the terminal sends at least one first signal to a network device, where the at least one first signal is used to determine the distance between the terminal and the network device; the terminal measures at least one second signal from the network device to obtain a second measurement result; the terminal obtains authentication information according to the second measurement result, where the authentication information is used to determine whether the terminal is allowed to access the network; the terminal sends the authentication information to the network device.
[0019] In some possible implementation manners, obtaining the authentication information according to the second measurement result includes: the terminal performs secure sketch processing on the second measurement result to obtain the authentication information.
[0020] In some possible implementation manners, the method further includes: the terminal sends request information to the network device, where the request information requests to access the network; the terminal receives response information from the network device, where the response information instructs the terminal to send the at least one first signal and measure the at least one second signal.
[0021] In some possible implementation manners, performing the secure sketch processing on the second measurement result to obtain the authentication information includes: performing quantization processing on the second measurement result, and performing the secure sketch processing on the quantized second measurement result to obtain the authentication information.
[0022] In some possible implementation manners, the at least one second signal is measured within a period of time, and the at least one first signal is transmitted within the period of time.
[0023] In some possible implementation manners, the first measurement result includes the signal strength of the at least one first signal, and the second measurement result includes the signal strength of the at least one second signal.
[0024] The various implementation manners of the second aspect are terminal methods corresponding to the various implementation manners of the first aspect. The beneficial technical effects of the various implementation manners of the second aspect may refer to the descriptions of the relevant implementation manners of the first aspect, and will not be elaborated herein.
[0025] According to a third aspect, a network device is provided. The network device includes functions or units for performing the method according to any one of the first aspect or possible implementations of the first aspect.
[0026] According to a fourth aspect, a terminal is provided. The terminal includes functions or units for performing the method according to any one of the second aspect or possible implementations of the second aspect.
[0027] According to a fifth aspect, a system is provided. The system includes: the network device according to the third aspect and the terminal according to the fourth aspect.
[0028] According to a sixth aspect, a network device is provided. The network device includes a processor, a memory, and a communication interface. The processor and the memory are connected to the communication interface. The memory is used to store instructions, the processor is used to execute the instructions, and the communication interface is used to communicate with other network elements under the control of the processor. When the processor executes the instructions stored in the memory, the processor is caused to execute the method according to any one of the first aspect or possible implementations of the first aspect.
[0029] According to a seventh aspect, a terminal is provided. The terminal includes a processor, a memory, and a communication interface. The processor and the memory are connected to the communication interface. The memory is used to store instructions, the processor is used to execute the instructions, and the communication interface is used to communicate with other network elements under the control of the processor. When the processor executes the instructions stored in the memory, the processor is caused to execute the method according to any one of the second aspect or possible implementations of the second aspect.
[0030] According to an eighth aspect, a computer storage medium is provided. The computer storage medium stores program code for executing the instructions of the method according to any one of the first aspect or possible implementations of the first aspect.
[0031] According to a ninth aspect, a computer storage medium is provided. The computer storage medium stores program code for executing the instructions of the method according to any one of the second aspect or possible implementations of the second aspect. Description of the Drawings
[0032] Figure 1 is a schematic diagram of an application scenario provided by this application;
[0033] Figure 2 is a schematic flowchart of an information transmission method;
[0034] Figure 3It is a schematic diagram of quantization processing and secure sketch processing on the terminal side;
[0035] Figure 4 It is a schematic diagram of quantization processing and restoration processing on the network device side;
[0036] Figures 5 to 9 It is a schematic block diagram of a possible device provided by an embodiment of the present application. Detailed implementation manners
[0037] The technical solutions of the embodiments of the present application will be described below with reference to the accompanying drawings.
[0038] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as Global System for Mobile Communications (GSM), Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, General Packet Radio Service (GPRS) system, Long Term Evolution (LTE) system, LTE Frequency Division Duplex (FDD) system, LTE Time Division Duplex (TDD) system, Universal Mobile Telecommunications System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) communication system, future fifth generation (5G) system or New Radio (NR) system.
[0039] The terminal in the embodiments of the present application may be a user equipment, an access terminal, a user unit, a user station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal device, a wireless communication device, a user agent or a user device. Alternatively, the terminal may be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication function, a computing device, other processing devices connected to a wireless modem, a vehicle-mounted device, a wearable device, a terminal in a future 5G network or a terminal in a future evolved public land mobile communication network (PLMN). The embodiments of the present application do not limit this.
[0040] The network device in the embodiments of the present application may be a device for communicating with a terminal. The network device may be a base transceiver station (BTS) in a global system for mobile communications (GSM) or a code division multiple access (CDMA) system, may also be a Node B (NB) in a wideband code division multiple access (WCDMA) system, may also be an evolved Node B (eNB or eNodeB) in an LTE system, and may also be a radio controller in a cloud radio access network (CRAN) scenario. Alternatively, the network device may be a relay station, an access point, a vehicle-mounted device, a wearable device, a network device in a future 5G network, a network device in a future evolved PLMN, or one or a group of antenna panels (including multiple antenna panels) of a base station in a 5G system, and may also be a network node constituting a gNB or a transmission point, such as a baseband unit (BBU) or a distributed unit (DU). The embodiments of the present application do not limit this.
[0041] In some deployments, the gNB may include a centralized unit (CU) and a DU. The gNB may also include an active antenna unit (AAU). The CU implements some functions of the gNB, and the DU implements some functions of the gNB. For example, the CU is responsible for processing non-real-time protocols and services and implementing the functions of the radio resource control (RRC) layer and the packet data convergence protocol (PDCP) layer. The DU is responsible for processing physical layer protocols and real-time services and implementing the functions of the radio link control (RLC) layer, the media access control (MAC) layer, and the physical (PHY) layer. The AAU implements some physical layer processing functions, radio frequency processing, and functions related to active antennas. The information of the RRC layer is finally converted into the information of the PHY layer or is converted from the information of the PHY layer. Therefore, in this architecture, high-layer signaling such as RRC layer signaling can also be considered to be sent by the DU, or sent by the DU and the AAU. It can be understood that the network device may be a device including one or more of the CU node, the DU node, and the AAU node. In addition, the CU may be classified as a network device in the access network (AN), or the CU may be classified as a network device in the core network (CN). This application does not make a limitation in this regard.
[0042] In the embodiments of this application, a terminal or a network device includes a hardware layer, an operating system layer running on top of the hardware layer, and an application layer running on top of the operating system layer. The hardware layer includes hardware such as a central processing unit (CPU), a memory management unit (MMU), and a memory (also referred to as the main memory). The operating system may be any one or more computer operating systems that implement service processing through processes, such as the Linux operating system, the Unix operating system, the Android operating system, the iOS operating system, or the Windows operating system. The application layer includes applications such as a browser, an address book, a word processing software, and an instant messaging software. In addition, the specific structure of the execution subject of the method provided in the embodiments of this application is not specifically limited in the embodiments of this application, as long as it can run a program recording the method code provided in the embodiments of this application and communicate according to the method provided in the embodiments of this application. For example, the execution subject of the method provided in the embodiments of this application may be a terminal or a network device, or may be a functional module in the terminal or the network device that can call and execute the program.
[0043] In addition, aspects or features of the present application can be implemented as methods, apparatuses, or products using standard programming and / or engineering techniques. The term "product" as used in the present application encompasses computer programs that can be accessed from any computer-readable component, carrier, or medium. For example, computer-readable media can include, but are not limited to: magnetic storage components (e.g., hard disks, floppy disks, or magnetic tapes), optical discs (e.g., compact discs (CDs) or digital versatile discs (DVDs)), smart cards, flash memory components (e.g., erasable programmable read-only memories (EPROMs), memory cards, memory sticks, or key drives). In addition, the various storage media described in this specification can represent one or more devices and / or other machine-readable media for storing information. The term "machine-readable media" can include, but is not limited to: wireless channels and various other media that can store, include, and / or carry instructions and / or data.
[0044] Figure 1 is a schematic diagram of the communication system provided by the present application. Figure 1 The communication system in can include at least one terminal (e.g., terminal 10, terminal 20, terminal 30, terminal 40, terminal 50, and terminal 60) and a network device 70. The network device 70 is used to provide communication services for the terminal and access the core network. The terminal can access the network by searching for synchronization signals or broadcast signals sent by the network device 70 to communicate with the network. Figure 1 The terminals 10, 20, 30, 40, and 60 in can perform uplink and downlink transmissions with the network device 70. For example, the network device 70 can send downlink signals to the terminals 10, 20, 30, 40, and 60, and can also receive uplink signals sent by the terminals 10, 20, 30, 40, and 60.
[0045] In addition, the terminals 40, 50, and 60 can also be regarded as communication systems. The terminal 60 can send downlink signals to the terminals 40 and 50, and can also receive uplink signals sent by the terminals 40 and 50.
[0046] It should be noted that the embodiments of the present application can be applied to communication systems including one or more network devices, and can also be applied to communication systems including one or more terminals. The present application does not make any limitations in this regard.
[0047] It should be understood that a communication system may include one or more network devices. A network device may send data or control signaling to one or more terminals. Multiple network devices may simultaneously send data or control signaling to one or more terminals.
[0048] This application provides an authentication method, a terminal, and a network device. The terminal sends at least one first signal to the network device, and the network device measures the at least one first signal to obtain a first measurement result. The network device sends at least one second signal to the terminal, and the terminal measures the at least one second signal to obtain a second measurement result. The terminal obtains authentication information based on the second measurement result and sends the authentication information to the network device. The network device determines whether the terminal is denied access to the network based on the first measurement result. If the network device determines that the terminal is not denied access to the network, the network device determines whether the terminal is allowed access to the network based on the authentication information. In this way, even if an illegal terminal sends a signal to the network device using high power, the network device will measure the received signal and obtain an incorrect result during the first verification. Since the illegal terminal cannot obtain the correct authentication information, the network device will deny the illegal terminal access to the network during the second verification. Therefore, the authentication method proposed in this application can improve the security of the access network. The following will describe this method in detail in combination with Figures 2 to 4 to describe this method in detail.
[0049] Figure 2 is a schematic flowchart of the information transmission method provided by an embodiment of this application. Figure 2 The network device in Figure 1 may correspond to the network device 70 in Figure 2 The terminal in Figure 1 may correspond to any one of the terminals 10 to 60 in
[0050] 210: The terminal sends at least one first signal to the network device. Correspondingly, the network device measures the at least one first signal to obtain a first measurement result.
[0051] 220: The network device sends at least one second signal to the terminal. Correspondingly, the terminal measures the at least one second signal to obtain a second measurement result.
[0052] The network device that measures the first signal and the terminal that measures the second signal can be referred to as being synchronized.
[0053] Optionally, at least one first signal is measured over a period of time, and at least one second signal is measured over the same period of time, that is, the network device and the terminal exchange a series of signals over a period of time. For example, the network device sends one or more request messages (the one or more request messages are the second signals) to the terminal, and the terminal sends one or more corresponding response messages (the one or more corresponding response messages are the first signals) to the network device.
[0054] It should be noted that for ease of description, this period of time is sometimes denoted by the symbol T.
[0055] Optionally, the period of time T is based on the channel rate, that is, the period of time T can be determined according to the measured channel rate. For example, if the channel rate is greater than or equal to a certain threshold, then T = T1; if the channel rate is lower than the threshold, then T = T2, and T1 < T2.
[0056] It should be noted that the period of time T can be preset, or determined by the network device or by the terminal. This application does not make specific limitations in this regard.
[0057] Optionally, the first measurement result includes the signal strength of the first signal. The second measurement result includes the signal strength of the second signal.
[0058] For example, the first measurement result includes the received signal strength indicator (RSSI) of the first signal, and the second measurement result includes the RSSI of the second signal. For the relevant information about RSSI, reference can be made to existing protocols and will not be elaborated here.
[0059] For example, the terminal captures N RSSI samples as X = {x1, x2,..., xN}, where xi represents the RSSI value of the i-th received signal, N ≥ 1, i ∈ [1, N], and the network device captures M RSSI samples as Y = {y1, y2,..., yM}, where yj represents the RSSI value of the j-th received signal, M ≥ 1, j ∈ [1, M].
[0060] 230: The network device determines whether the terminal is rejected from accessing the network according to the first measurement result.
[0061] Whether the terminal is allowed to access the network depends on the distance between the terminal and the network device. When the distance between the network and the terminal is within a certain range, the terminal will be allowed to access the network; when the distance is not within the certain range, the terminal will be refused access to the network. Alternatively, when the distance is less than or equal to a preset value, the terminal will be allowed to access the network; when the distance is greater than the preset value, the terminal will be refused access to the network. For example, only when the terminal is inside the bank will the terminal be allowed to access the bank network. Another example is that only when the terminal is near the network device will the terminal be allowed to share files.
[0062] The first measurement result can be used to determine the distance between the terminal and the network device. For example, the signal strength of the signal can be used to determine the distance. The higher the signal strength, the closer the distance between the terminal and the network device.
[0063] Optionally, the network device can perform data processing on the first measurement result. For example, the data processing can include but is not limited to: taking the absolute value, taking the average value, removing extreme values, etc.
[0064] For example, when the terminal is in a preset area, where the distance d between the terminal and the network device satisfies d1 ≤ d ≤ d2, d1 is the minimum distance from the network device in the preset area, and d2 is the maximum distance from the network device in the preset area. The preset range can be set as v1 ≤ v ≤ v2, where v is the average value of the absolute values of the first signal strength values (for example, v = average value((y 1 , y 2 , …, y N ))), v1 is the minimum signal strength value within the preset range, and v2 is the maximum signal strength value within the preset range. If v is not within the preset range, the network device can determine to refuse the terminal to access the network.
[0065] The above determination process can refer to proximity-based access or authentication, which can be considered as one of the authentication mechanisms that require the location of the terminal. For example, only when the terminal is inside or outside the first area can the access to services be provided to the terminal. This method can also be applied to multi-factor authentication, thus forming an additional layer of authentication mechanism. Since multi-factor authentication can confirm whether the terminal is a legitimate request to access the network even if any attacker steals the credentials, multi-factor authentication can improve the security of the access network.
[0066] The first measurement result is used to preliminarily determine whether to reject the terminal. Even if the first measurement result is within the preset range, the network will not determine that the terminal is allowed to access the network. For example, an illegal terminal far from the network device sends a signal to the network device with high power, causing the network device to misjudge that the illegal terminal is very close. In the embodiments of the present application, the network device will not allow the terminal to access the network only based on the first measurement result. If the network device determines according to the first measurement result that the terminal is not rejected from accessing the network, the network device will further confirm according to the following authentication information.
[0067] 240: The terminal obtains authentication information according to the second measurement result.
[0068] The authentication information is used to determine whether the terminal is allowed to access the network. For example, the terminal performs the following steps 241 and 242 to obtain the authentication information.
[0069] Optionally, 241: The terminal performs quantization processing on the second measurement result.
[0070] The quantization processing may include noise reduction processing, and the noise reduction processing can be used to reduce the noise component in the measurement result. Therefore, the quantization processing can be used to improve the accuracy of the measurement result. For another example, the quantization processing may further include coding processing such as Gray coding or binary coding, and the coding processing can be used to improve the convenience of information processing and transmission. Figure 3 A more detailed description has been made and will not be repeated here.
[0071] Optionally, 242: The terminal performs secure sketch processing on the quantized second measurement result to obtain the authentication information.
[0072] The authentication information obtained by performing secure sketch processing on the second measurement result can be used to verify the credibility of the first measurement result. The secure sketch processing can verify the correlation between the first measurement result and the second measurement result. If the first measurement result is correlated with the second measurement result, the first measurement result can be considered credible. For the convenience of understanding the embodiments of the present application, the following will be combined with Figure 3 A more detailed description of the secure sketch processing has been made and will not be repeated here.
[0073] 250: The terminal sends the authentication information to the network device.
[0074] Optionally, the authentication information can be carried in the authentication message. For example, the authentication message includes the authentication information and may further include at least one of the following: encryption information and the identity information of the terminal, where the encryption information can be used to encrypt the authentication message, and the identity information indicates the terminal.
[0075] For example, the authentication information can be carried in the message Enc k {ID UE||S||Nonce}||MAC k {ID UE ||S||Nonce}, where Enc k represents encryption, ID UE represents the identity of the terminal, Nonce is a random number, which can be a timestamp, and MAC k represents the message authentication code (MAC) function. In addition, the subscript k represents the shared symmetric key between the terminal and the network device, and the symbol || represents the concatenation function in the present invention, which will not be elaborated hereinafter.
[0076] In some implementation manners, the verification process requires not only authentication information but also auxiliary information shared by the terminal and the network device. This method may further include 207.
[0077] Optionally, 260: The terminal sends the auxiliary information to the network device.
[0078] The auxiliary information can be used to assist the network device in performing the recovery process corresponding to the secure sketch process. The auxiliary information can be determined according to the secure sketch process. For example, but not limited to the following cases, the auxiliary information can be auxiliary data called a sketch. Figure 3 A more detailed description has been made.
[0079] It should be noted that the auxiliary information can be carried in the message carrying the authentication information. Alternatively, the auxiliary information can be carried in a separate message, such as Enc k {ID UE ||P||Nonce}||MAC k {ID UE ||P||Nonce}, where P represents the auxiliary information. The embodiments of the present application do not make any limitations in this regard.
[0080] 270: The network device determines whether the terminal is allowed to access the network according to the authentication information.
[0081] If in step 230, the network device determines according to the first measurement result that the terminal is not rejected from accessing the network, the network device will further verify the reliability of the first measurement result. For example, the authentication information is obtained by performing quantization processing (241) and secure sketch processing (242). The network device can execute steps 271 and 272 to determine whether the terminal is allowed to access the network.
[0082] Optionally, 271: The network device performs quantization processing on the first measurement result.
[0083] The quantization methods respectively executed by the terminal and the network device can be similar. Steps 240 and Figure 4is described in more detail in
[0084] Optionally, 272: The network device performs a recovery process on the authentication information.
[0085] The network device performs a recovery process corresponding to the security sketch process on the authentication information according to the quantified first measurement result. If the network device successfully performs the recovery process, the terminal is allowed to access the network. If the network device fails to successfully perform the recovery process, the terminal is denied access to the network device.
[0086] It should be noted that the recovery process can only be successfully performed when the first measurement result is related to the second measurement result. Then, if the first measurement result is related to the second measurement result, the network device determines that the first measurement result is credible and allows the terminal to access the network. Therefore, if an illegal terminal sends a signal to the network device with high power and the network device obtains a measurement result, since the network device cannot successfully perform a recovery process on the authentication information based on this measurement result, the network device will deny the terminal access to the network.
[0087] It should also be noted that whether the recovery process is successfully performed depends on the algorithm setting of the recovery process, and the embodiments of the present application do not make specific limitations in this regard. For the convenience of understanding the embodiments of the present application, the following will be combined with Figure 4 to describe the recovery process in more detail, which will not be elaborated here.
[0088] In some embodiments, the network device and the terminal can start measuring when the terminal requests to access the network, and this method may further include steps 280 and 290 before step 210.
[0089] Optionally, 280: The terminal sends a request message to the network device.
[0090] The request message requests access to the network. Alternatively, the request message requests access to a service, and the provision of the service is based on the distance between the network device and the terminal.
[0091] Optionally, the request message can be carried in an access request message. For example, the access request message includes the request message and may further include at least one of the following: encryption information and the identity information of the terminal, where the encryption information can be used to encrypt the access request message, and the identity information indicates that the terminal requests to access the network.
[0092] For example, the access request message can be: Enc k {ID UE ||Cmd_Req||Nonce}||MAC k {ID UE ||Cmd_Req||Nonce}, where Enc k represents encryption, IDUE Indicates the identity of the terminal, and Cmd_Req (request command) indicates the first request information.
[0093] Optionally, 290: the network device sends a response message to the terminal.
[0094] The response message responds to the request message. The network device can accept the request from the terminal and send a response message to the terminal.
[0095] Optionally, the response information is carried in a response message that responds to the access request message. For example, the response message includes the first response information and may also include at least one of the following: encryption information and identity information of the terminal.
[0096] For example, the reply response message may be: k {ID UE ||Cmd_Ack||Nonce}||MAC k {ID UE ||Cmd_Req||Nonce}, where Cmd_Ack (command_acknowledgement) and other parameters may be the same as described in the access request message.
[0097] Optionally, if the network device determines a period of time T and instructs the terminal to measure the received signal within the period of time T, for example, the network device may send measurement indication information to the terminal, wherein the measurement indication information instructs the terminal to measure the power of the received signal within the period of time T, then the terminal may start measuring the power of the received signal within the period of time T after receiving the first response information. The measurement indication information may be carried in the response message or in other messages. This embodiment of the present application is not limited thereto.
[0098] In the present application, the network device determines whether the terminal is allowed to access the network after double verification. The first verification is based on the first measurement result measured by the network device. If the network device determines that the terminal is not denied access to the network, the network device will perform a second verification based on the authentication information, which is obtained by the terminal based on the second measurement. In this way, the illegal terminal uses high power to send a signal to the network device, the network device measures the received signal, and obtains an incorrect result in the first verification. Since the illegal terminal cannot obtain the correct authentication, the network device will deny the illegal terminal access to the network during the second verification. Therefore, the authentication method proposed in the present application can improve the security of the access network.
[0099] The authentication method has been described above. Figure 3 The quantization process and the safety sketch process mentioned in the above steps 241 and 242 are described in more detail.
[0100] Figure 3 It is a schematic diagram of quantization processing and secure sketch processing on the terminal side.
[0101] The second measurement result includes the signal strength of the second signal and can be obtained through Figure 2 step 220. The signal strength can be expressed as the set X = {x 1 , x 2 , …, x N}.
[0102] 301: The terminal performs quantization processing on the second measurement result.
[0103] Optionally, the terminal can perform noise reduction processing on N signal strength values. For example, the N signal strength values pass through a low-pass filter to reduce the noise components caused by path attenuation. It should be understood that after passing through the low-pass filter, the N signal strength values may only have a small range of attenuation changes.
[0104] Optionally, the terminal encodes the signal strength values after noise reduction processing, and then obtains the encoded quantization value set A = {a 1 , a 2 , …}. For example, the signal strength values after noise reduction processing are converted into bits through multi-bit quantization. The terminal can determine the number of bits N used for encoding the signal strength values. For example, K is calculated as N = log 2 (range_of_values), where range_of_values is obtained by evaluating the signal strength values. Then, the sample bits converted through multi-bit quantization can be divided into M = 2 N quantization levels. For example, M = 4 (four-level) quantization, and each signal strength value is encoded as 2 bits according to the level it belongs to. Optionally, the terminal can use Gray coding so that each encoded signal strength value differs by only 1 bit to minimize the difference. The embodiments of the present application do not limit this.
[0105] 302: The terminal generates auxiliary information, which can be used to assist the network device in recovery processing. The auxiliary information can be expressed as the padding set P = {p 1 , p 2 , …}.
[0106] Optionally, the terminal can generate P according to the quantization mode. For example, if the terminal uses 4-level quantization, A will be encoded as 2 bits. If (7,4) Hamming coding is used, the terminal encodes A as 7 bits, and A will be appended with 5 additional bits. These 5 bits are randomly selected by the terminal and sent to the network device. The padding set P is adjusted according to the Hamming coding and the number of bits used for encoding each signal strength.
[0107] It should be noted that the terminal needs to send auxiliary information to the network device, such as Figure 2 described in step 260 of Figure 4 . Therefore, the network device can use the auxiliary information (e.g., the padding set P) for the recovery processing as described below
[0108] 303: The terminal concatenates the encoded quantized value set A and the padding set P to obtain W = A||P.
[0109] 304: The terminal randomly generates a set R = {r 1 , r 2 ,...}.
[0110] 305: The terminal calculates C = HE(R), where HE is the Hamming code.
[0111] 306: The terminal calculates where is the exclusive OR operation.
[0112] Therefore, the authentication information is obtained.
[0113] The quantization processing and the secure sketch processing have been described above. Below, in combination with Figure 4 for Figure 2 the quantization processing of the first measurement result mentioned in 271 of Figure 2 and the recovery processing of the authentication information mentioned in 272 of
[0114] Figure 4 is a schematic diagram of the quantization processing and the recovery processing on the network device side.
[0115] The first measurement result includes the signal strength of the first signal and can be obtained through Figure 2 step 210 of 1 , y 2 ,..., y M}. The acquisition of the auxiliary information can refer to Figure 2 step 260 of Figure 2 . The acquisition of the authentication information can refer to Figure 3 step 270 of Figure 3 . In addition, the auxiliary information is the same as P in 302 of
[0116] 401: The network device performs quantization processing on the first measurement result to obtain an encoded quantized value set B = {b 1 , b 2 ,...}.
[0117] The network device is the same asFigure 3 Quantization is performed in a manner similar to the terminal quantization described in 301. Details are not repeated here.
[0118] 402: The network device concatenates the encoded quantization value set B and the padding set P to obtain W' = B || P.
[0119] 403: The network device calculates where is an exclusive - or operation, and D' can be the same as C described in Figure 3
[0120] 404: The network device decodes D' to obtain D, for example, D = HD(D'), where HD is Hamming decoding.
[0121] 405: The network device calculates
[0122] It should be noted that only when dis(W_recovery, W') ≤ t, the output W_recovery can be considered as the network device successfully recovering. For example, for Hamming code (7, 4), the distance between W and W' must be less than or equal to 1. If W_recovery is approximately equal to W'.
[0123] From the description of the above method, it can be seen that the network device determines whether the terminal is allowed to access the network after double - verification, which can improve the security of the access network.
[0124] Above, in combination with Figures 2 to 4 the authentication method according to the embodiments of the present application has been described in detail. Below, in combination with Figures 5 to 9 the terminal and network device according to the embodiments of the present application will be described in detail.
[0125] Figure 5 is a schematic block diagram of the network device 500 provided by the embodiments of the present application. As Figure 5 shown, the terminal 500 includes:
[0126] A processing module 510, configured to measure at least one first signal from the terminal to obtain a first measurement result, where the first measurement result is used to determine the distance between the terminal and the network device;
[0127] wherein, the processing module 510 is further configured to determine that the terminal is not rejected from accessing the network according to the first measurement result;
[0128] A transceiver module 520, configured to send at least one second signal to the terminal;
[0129] Among them, the transceiver module 520 is further configured to receive authentication information from the terminal, where the authentication information is obtained according to a second measurement result of at least one second signal;
[0130] The processing module 510 is further configured to determine whether the terminal is allowed to access the network according to the authentication information.
[0131] Optionally, the processing module 510 is further configured to successfully perform recovery processing on the authentication information according to the first measurement result, so that the terminal is allowed to access the network, where the recovery processing corresponds to secure sketch processing.
[0132] Optionally, the processing module 510 is further configured to unsuccessfully perform recovery processing on the authentication information according to the first measurement result, so that the terminal is not allowed to access the network, where the recovery processing corresponds to secure sketch processing.
[0133] Optionally, the transceiver module 520 is further configured to receive request information from the terminal, where the request information requests access to the network; the transceiver module 520 is further configured to send response information to the terminal, where the response information instructs the terminal to send at least one first signal and measure at least one second signal.
[0134] Optionally, the processing module 510 is further configured to perform quantization processing on the first measurement result and perform recovery processing on the authentication information according to the quantized first measurement result.
[0135] Optionally, at least one first signal is measured within a period of time, and at least one second signal is transmitted within the period of time.
[0136] Optionally, the first measurement result includes the signal strength of at least one first signal, and the second measurement result includes the signal strength of at least one second signal.
[0137] Therefore, the network device determines whether the terminal is allowed to access the network after double verification. The first verification is based on the first measurement result measured by the network device. If the network device determines that the terminal is not rejected from accessing the network, the network device will perform a second verification according to the authentication information, and the authentication information is obtained by the terminal according to the second measurement. In this way, an illegal terminal sends a signal to the network device with high power, the network device measures the received signal, and gets an incorrect result during the first verification. Since the illegal terminal cannot obtain the correct authentication, during the second verification, the network device will reject the illegal terminal from accessing the network. Therefore, the authentication method proposed in this application can improve the security of the access network.
[0138] It should be understood that the network device 500 in the embodiments of the present application may correspond to the network device in the authentication method in the embodiments of the present application, and the above management operations and / or functions of each module of the network device 500 and other management operations and / or functions are intended to implement the corresponding steps of the above method. For the sake of brevity, they will not be elaborated here.
[0139] In the embodiments of the present application, the transceiver module 520 may be implemented by a transceiver, and the processing module 510 may be implemented by a processor. As Figure 6 shown, the network device 600 may include a transceiver 610, a processor 620, and a memory 630. The memory 630 may be used to store indication information, and may also be used to store codes and instructions executed by the processor 620, etc.
[0140] Figure 7 is a schematic block diagram of the terminal 700 provided by the embodiments of the present application. As Figure 7 shown, the network device 700 includes:
[0141] A transceiver module 710, configured to send at least one first signal to the network device, where the at least one first signal is used to determine the distance between the terminal and the network device;
[0142] A processing module 720, configured to measure at least one second signal from the network device to obtain a second measurement result;
[0143] Wherein, the processing module 720 is further configured to obtain authentication information according to the second measurement result, where the authentication information is used to determine whether the terminal is allowed to access the network;
[0144] Wherein, the transceiver module 710 is further configured to send the authentication information to the network device.
[0145] Optionally, the processing module 720 is further configured to perform secure sketch processing on the second measurement result to obtain authentication information.
[0146] Optionally, the transceiver module 710 is further configured to send request information to the network device, where the request information requests access to the network; the transceiver module 710 is further configured to receive response information from the network device, where the response information instructs the terminal to send at least one first signal and measure at least one second signal.
[0147] Optionally, the processing module 720 is further configured to perform quantization processing on the second measurement result, and perform secure sketch processing on the quantized second measurement result to obtain authentication information.
[0148] Optionally, at least one second signal is measured within a period of time, and at least one first signal is transmitted within the period of time.
[0149] Optionally, the first measurement result includes the signal strength of at least one first signal, and the second measurement result includes the signal strength of at least one second signal.
[0150] It should be understood that the terminal 700 in the embodiments of the present application may correspond to the terminal in the authentication method in the embodiments of the present application, and the above management operations and / or functions of each module of the terminal 700 and other management operations and / or functions are intended to implement the corresponding steps of the above method. For the sake of brevity, they will not be described in detail here.
[0151] The transceiver module 710 in the embodiments of the present application may be implemented by a transceiver, and the processing module 720 may be implemented by a processor. As Figure 8 shown, the terminal 800 may include a transceiver 810, a processor 820, and a memory 830. The memory 830 may be used to store indication information, and may also be used to store codes and instructions executed by the processor 820, etc.
[0152] It should be understood that the processor 620 or the processor 820 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step in the above method embodiments may be implemented by the hardware integrated logic circuit in the processor or by instructions in software form. The processing module 610 may be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. All the methods, steps, and logic block diagrams disclosed in the embodiments of the present invention may be implemented or executed. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc. The steps of the method disclosed in the embodiments of the present invention may be directly executed and completed by the hardware decoding processor, or may be executed and completed using a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, or a register. This storage medium is located in the memory, and the processor reads the information in the memory and combines it with the hardware of the processor to complete the steps of the above method.
[0153] It can be understood that the memory 630 or the memory 830 in the embodiments of the present invention can be a volatile memory or a non-volatile memory, or can include both a volatile memory and a non-volatile memory. The non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM) and is used as an external cache. By way of example but not limitation, many forms of RAM can be used, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synch link dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM). It should be noted that the storage of the systems and methods described in this specification is intended to include, but is not limited to, these and any other suitable storage.
[0154] An embodiment of the present application also provides a system. As Figure 9 shown, the system 900 includes:
[0155] A network device 500 according to an embodiment of the present application and a terminal 700 according to an embodiment of the present application.
[0156] An embodiment of the present application also provides a computer storage medium, which can store program instructions to execute any of the above methods.
[0157] Optionally, the storage medium can specifically be the memory 630 or 830.
[0158] Those of ordinary skill in the art will appreciate that, in combination with the examples described in the embodiments disclosed in this specification, each unit and algorithm step can be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether the function is executed by hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but it should not be considered that such implementation goes beyond the scope of this application.
[0159] Those skilled in the art can clearly understand that, for the sake of convenience and conciseness of description, regarding the specific working processes of the above-mentioned systems, devices, and units, reference can be made to the corresponding processes in the above-mentioned method embodiments, and details will not be elaborated here.
[0160] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the described device embodiments are only examples. For example, the unit division is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the shown or described mutual coupling, direct coupling, or communication connection can be achieved through some interfaces. The indirect coupling or communication connection between devices or units can be achieved in electronic, mechanical, or other forms.
[0161] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place, or can be distributed on multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiment.
[0162] In addition, the functional units in the embodiments of this application can be integrated in one processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit.
[0163] When these functions are implemented in the form of software functional units and sold or used as independent products, these functions can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be implemented in the form of a software product. This software product is stored in the storage medium and includes several instructions for instructing a computer device (which can be a personal computer, a server, a network device, etc.) to execute all or part of the steps of the method described in the embodiments of this application. The above storage medium includes any medium that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc.
[0164] The above description is only a specific implementation manner of this application and does not limit the protection scope of this application. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed in this application should belong to the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
Claims
1. An authentication method, characterized in that, it includes: The network device measures at least one first signal from the terminal to obtain a first measurement result, where the first measurement result is used to determine the distance between the terminal and the network device; The network device determines that the terminal is not rejected from accessing the network according to the first measurement result; The network device sends at least one second signal to the terminal; The network device receives authentication information from the terminal, where the authentication information is obtained according to a second measurement result of the at least one second signal; The network device determines whether the terminal is allowed to access the network according to the authentication information.
2. The method according to claim 1, characterized in that, The authentication information is obtained by performing a secure sketch process on the second measurement result. Determining whether the terminal is allowed to access the network according to the authentication information includes: If the recovery process of the authentication information according to the first measurement result is successful, the terminal is allowed to access the network, where the recovery process corresponds to the secure sketch process; or If the recovery process of the authentication information according to the first measurement result is not successful, the terminal is not allowed to access the network.
3. The method according to claim 1 or 2, characterized in that, The method further includes: The network device receives request information from the terminal, where the request information requests access to the network; The network device sends response information to the terminal, where the response information instructs the terminal to send the at least one first signal and measure the at least one second signal.
4. The method according to claim 2 or 3, characterized in that, Performing the recovery process on the authentication information according to the first measurement result includes: Performing quantization processing on the first measurement result, and performing the recovery process on the authentication information according to the quantized first measurement result.
5. The method according to any one of methods 1 to 4, characterized in that, The at least one first signal is measured within a period of time, and the at least one second signal is transmitted within the period of time.
6. The method according to any one of methods 1 to 5, characterized in that, The first measurement result includes the signal strength of the at least one first signal, and the second measurement result includes the signal strength of at least one second signal.
7. An authentication method, characterized in that, it includes: The terminal sends at least one first signal to the network device, where the at least one first signal is used to determine the distance between the terminal and the network device; The terminal measures at least one second signal from the network device to obtain a second measurement result; The terminal obtains authentication information according to the second measurement result, where the authentication information is used to determine whether the terminal is allowed to access the network; The terminal sends the authentication information to the network device.
8. The method according to claim 7, characterized in that, Obtaining the authentication information according to the second measurement result includes: The terminal performs secure sketch processing on the second measurement result to obtain the authentication information.
9. The method according to claim 7 or 8, wherein, the method further includes: The terminal sends a request message to the network device, wherein the request message requests access to the network; The terminal receives a response message from the network device, wherein the response message instructs the terminal to send the at least one first signal and measure the at least one second signal.
10. The method according to claim 8 or 9, wherein, performing the secure sketch processing on the second measurement result to obtain the authentication information includes: Performing quantization processing on the second measurement result, and performing the secure sketch processing on the quantized second measurement result to obtain the authentication information.
11. The method according to any one of claims 7 to 10, wherein, the at least one second signal is measured over a period of time, and the at least one first signal is transmitted over the period of time.
12. The method according to any one of claims 7 to 11, wherein, the first measurement result includes the signal strength of the at least one first signal, and the second measurement result includes the signal strength of the at least one second signal.
13. An apparatus, wherein, the apparatus includes a processor and a memory, the memory stores instructions that can run on the processor, and when the instructions run, the apparatus executes the method according to any one of claims 1 to 6 or executes the method according to any one of claims 7 to 12.
14. An apparatus, wherein, the apparatus includes functions or units for executing the method according to any one of claims 1 to 6 or executing the method according to any one of claims 7 to 12.
15. A communication system, wherein, includes a network device and a terminal, wherein the network device executes the method according to any one of claims 1 to 6, and the terminal executes the method according to any one of claims 7 to 12.
16. A computer-readable storage medium, wherein, includes instructions, wherein when the instructions run on a computer, the computer executes the method according to any one of claims 1 to 6 or the method according to any one of claims 7 to 12.