Security detection authentication method for wireless network
The method improves wireless network security by using multiple access transfer stations for trusted device authentication and real-time data checks, ensuring secure connections and minimizing network failure risks.
Patent Information
- Application Number
- CN202510588738.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-08
- Publication Date
- 2025-07-15
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The equipment authentication methods of existing wireless networks are relatively low in security and lack data security detection and abnormal situation handling methods, which can easily affect network security.
A multi-level access transit station management system is used to identify user equipment through MAC addresses, and a key is generated using quantum encryption technology. Identity authentication is performed based on the level information of the access transit station and the access time range of the device, and security detection is performed during data transmission, and risk connection is disconnected to protect the main server.
It realizes hierarchical management of user equipment, improves the security and stability of wireless networks, reduces the risk of network paralysis, and ensures the safe operation of the main server.
Smart Images

Figure CN120321648A_ABST
Abstract
Description
Technical Field
[0001] A certification method involved in the present invention, in particular, a security detection and certification method for a wireless network applied to the field of wireless communication networks. Background Art
[0002] A so-called wireless network refers to a network that enables the interconnection of various communication devices without the need for cabling. The scope of wireless network technology is very wide, including both global voice and data networks that allow users to establish long-distance wireless connections and infrared and radio frequency technologies optimized for short-distance wireless connections. Wireless networks are generally combined with telecommunications networks and can be interconnected between nodes without cables.
[0003] Wireless networks are also divided into private wireless networks and public wireless networks. The services carried by private wireless networks generally involve security. Therefore, the construction of these networks is not mainly for profit. Ensuring the security and confidentiality of services and the stability and reliability of the network are the main goals of private networks.
[0004] To solve the security and stability problems of private wireless networks, the specification of Chinese Patent CN103686728B discloses a power private wireless network system and a wireless transmission method based on area authentication, including a GPS area authentication gateway, a wireless network switch, and a wireless terminal. Among them, the wireless network switch is connected to the GPS area authentication gateway by wire, the GPS area authentication gateway is connected to the wired office network by wire, and the wireless network switch is wirelessly connected to at least one wireless terminal. A GPS satellite positioning module is provided in the wireless terminal. Through the wireless transmission method, authentication by the GPS area authentication gateway is required when the wireless terminal is wirelessly connected to the wireless network switch, and the wireless terminal is only allowed to connect to the network within the range, preventing personnel outside the area from connecting to the network. It not only achieves the purpose of security but also solves the problem of convenient networking, greatly improving the production work efficiency in the power field.
[0005] The specification of Chinese Patent CN102186168B discloses a private network access method, device, and system. When a dedicated line circuit failure for accessing the private network is detected, it automatically accesses the wireless network to determine the core network packet domain device assigned to the access router for the client in the wireless network. Through the core network packet domain device, a Layer 2 Tunneling Protocol (L2TP) tunnel is established between the access router of the client and the LNS server, where the LNS server is connected to the core network packet domain device and the access router of the private network. Through the L2TP tunnel and the LNS server, the access router accessing the private network establishes a communication connection between the client and the private network. The technical solution of the present invention can establish an end-to-end L2TP tunnel through the wireless network when the dedicated line circuit for accessing the private network fails, so as to establish a communication connection to the private network, effectively ensuring the security of data transmission.
[0006] A dedicated wireless network is generally used by devices in a specific area or group. Therefore, when a device accesses this private network, it needs to perform a secure authentication operation to ensure the security of the device. However, most of the existing authentication methods use the key method. The security of this single and common authentication method is relatively low. Moreover, when the device uses the wireless network for data transmission, there is also a lack of security detection means for data and effective processing means for abnormal situations, which is likely to affect the security of the wireless network. Summary of the Invention
[0007] In view of the above-mentioned prior art, the technical problem to be solved by the present invention is that the existing single authentication method using keys for devices accessing the wireless network has the defect of relatively low security, and when the device uses the wireless network for data transmission, there is a lack of security detection means for data and effective processing means for abnormal situations, which is likely to affect the security of the wireless network.
[0008] To solve the above problems, the present invention provides a security detection and authentication method for a wireless network, including the following steps:
[0009] S1. After the user device E scans the dedicated wireless network, it sends an access request to the network server. The network server includes a main server, a standby transfer station connected to the main server, and multiple access transfer stations;
[0010] S2. The determination module obtains the MAC address of the user device E and compares it with the MAC addresses of the inherent user devices stored in the device address library to determine whether the user device E belongs to a new user device;
[0011] When the user device E is one of the inherent user devices, step S3 is performed;
[0012] When the user device E is a new user device, step S4 is performed;
[0013] S3. The main server directly performs a login authentication operation on the user device E: sends a key to the user device E, and the user device E completes the login authentication by inputting the key;
[0014] S4. The main server first performs an identity authentication operation on the user device E: randomly sends at least one access transfer station information to the user device E and waits for the user device E to input two pieces of information corresponding to the above access transfer station: one is the level information of the above access transfer station, and the other is the device access duration range corresponding to the above access transfer station;
[0015] When the two pieces of information do not correctly correspond to the access transfer station, the connection between the user device E and the wireless network fails. When both pieces of information correspond to the access transfer station, the identity authentication operation is successful, and at this time, the login authentication operation in S3 is performed;
[0016] S5. After completing the login authentication operation, based on the actual cumulative access duration of the user device E with the access transfer station in the past, establish a connection with the access transfer station at the corresponding level;
[0017] S6. When the user device E performs data transmission, the data is first transmitted to the access transfer station. The access transfer station performs security detection on the data. When the detection result shows that the data is secure, the access transfer station then transmits the data to the corresponding receiving end;
[0018] When the detection result shows that there are security risks in the data, stop the data transmission. The access transfer station issues a security warning to the main server. Subsequently, the access transfer station disconnects the connection with the main server, so that all user devices that have established a connection with the above access transfer station show that the connection is disconnected, and the remaining access transfer stations operate normally;
[0019] S7. According to the security warning information, the main server, on the one hand, issues a network alarm signal, and on the other hand, establishes a connection between the remaining disconnected user devices except the user device E and the standby transfer station, so that the remaining normal user devices can continue to work.
[0020] As a further supplement to this application, the main server includes a determination module, a login authentication module, a device authentication module, and a connection establishment module. The login authentication module is used to perform login authentication operations on user devices. The device authentication module is used to perform identity authentication operations on user devices. The connection establishment module is used to establish a connection between user devices and the corresponding access transfer stations.
[0021] As a further supplement to this application, the determination module is connected to a device address library. The device address library stores the MAC addresses of multiple inherent user devices. The inherent user devices are devices that have established a connection with any access transfer station in the past. The connection establishment module is connected to a dynamic time database. The dynamic time database is used to record the cumulative access duration of all inherent user devices with the access transfer station and update the cumulative access duration in real time.
[0022] As a further supplement to this application, the device authentication module is connected to a platform database. The platform database is used to store the device information of all access transfer stations, as well as their corresponding level information and device access duration ranges. The level information corresponding to different access transfer stations is different, and the device access duration ranges corresponding to them do not overlap.
[0023] As a further supplement to this application, switching switches are electrically connected to multiple access repeaters. The switching switches perform data transmission with the main server through transmission lines.
[0024] As another improvement of the present application, the power transmission line includes line a connected to the main server, line b connected to the switching switch, and a secondary switch connected between line a and line b. A sensing optical fiber is electrically connected between the secondary switch and the access repeater.
[0025] As a supplement to another improvement of the present application, the secondary switch includes a box body and a wiring box fixedly connected to each other. A controller, an optical receiving device, and an air pump are fixedly installed inside the box body. Both the optical receiving device and the air pump are electrically connected to the controller. One end of the sensing optical fiber is electrically connected to the optical receiving device, and the other end is electrically connected to the optical transmitting device in the access transfer station.
[0026] As a supplement to another improvement of the present application, a fixed seat and a moving seat are provided inside the wiring box. One outer end of the fixed seat is fixedly connected to the inner wall of the wiring box. A T-shaped sliding groove is opened on the inner wall of the wiring box. One outer end of the moving seat is fixedly connected with a T-shaped slider slidably connected to the T-shaped sliding groove. One end of the fixed seat and the moving seat close to each other are fixedly connected with contact heads. The end of line a far from the main server fixedly penetrates through the wiring box and the fixed seat until it is electrically connected to the contact head on the fixed seat. The end of line a far from the main server fixedly penetrates through the wiring box and the fixed seat until it is electrically connected to the contact head on the fixed seat. The end of line b far from the switching switch fixedly penetrates through the wiring box and the moving seat until it is electrically connected to the contact head on the moving seat.
[0027] As a supplement to another improvement of the present application, a soft sleeve is fixedly connected between the fixed seat and the moving seat, and the soft sleeve is sleeved outside the contact head. An annular cavity is opened inside the fixed seat. The air inlet end of the air pump communicates with the inside of the wiring box through an air inlet pipe, and the air outlet end of the air pump communicates with the inside of the annular cavity through an air outlet pipe. Air outlet holes communicating with the inside of the soft sleeve are opened on the inner wall of the annular cavity. In the initial state, a pair of contact heads are in contact with each other, and the soft sleeve is in an inwardly concave state.
[0028] As another improvement of the present application, a ring plate is slidably connected inside the annular cavity. A plurality of uniformly distributed compression springs are fixedly connected between the end of the ring plate far from the contact head and the inner wall of the annular cavity. A tension sensor is fixedly connected to the inner wall of the annular cavity close to the contact head. An elastic band is fixedly connected between the sensing end of the tension sensor and the ring plate. In the initial state, the compression springs are in a contracted state, and the elastic band is in an elastically stretched state. The ring plate is always located on the side of the air outlet pipe far from the air outlet hole. A gas guide pipe communicating with both the annular cavity and the outside is fixedly connected between the fixed seat and the wiring box, and the gas guide pipe is located on the side of the ring plate far from the tension sensor.
[0029] In summary, by setting up multiple access transfer stations, the present application realizes the hierarchical management of user devices. At the same time, it also serves as a verification key for new user devices to access the network and plays a role in security detection of the transmitted data, thereby effectively ensuring the security of the main server. When a certain access transfer station detects that the data sent by a certain user device has a security risk, to ensure the safe operation of the main server, this access transfer station will disconnect the circuit from the main server through two hardware disconnection operations, making it difficult for the risk data to damage the main server. Other access transfer stations and the multiple user devices connected to them are all in normal operation, achieving the stable operation of the main server and other user devices with a relatively small power cost, and minimizing the risk of complete network paralysis to the greatest extent. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 Power connection diagrams for the first, second, and third embodiments of the present application;
[0031] Figure 2 System diagram for the first embodiment of the present application;
[0032] Figure 3 Three-dimensional view of the secondary switch for the second embodiment of the present application;
[0033] Figure 4 Side structure schematic diagram of the secondary switch for the second embodiment of the present application;
[0034] Figure 5 Side structure schematic diagram when line a and cable b are disconnected for the second embodiment of the present application;
[0035] Figure 6 Three-dimensional view of the fixed seat for the third embodiment of the present application;
[0036] Figure 7 Side structure schematic diagram of the secondary switch for the third embodiment of the present application.
[0037] Explanation of the reference numerals in the figures:
[0038] 1 instrument box, 2 junction box, 201 T-shaped chute, 3 controller, 4 optical receiving device, 5 air pump, 501 intake pipe, 502 outlet pipe, 6 fixed seat, 601 annular cavity, 7 moving seat, 8 contact, 9 soft sleeve, 10 ring plate, 11 compression spring, 12 tension sensor, 13 elastic band, 14 air duct. SPECIFIC EMBODIMENTS
[0039] The following describes in detail the three embodiments of the present application with reference to the drawings.
[0040] The first embodiment:
[0041] The present invention provides a security detection and authentication method for a wireless network. Please refer to Figure 1 and Figure 2 , including the following steps:
[0042] S1. After the user device E scans a dedicated wireless network, it sends an access request to the network server. The network server includes a main server, a standby transfer station connected to the main server, and multiple access transfer stations (including access transfer station F1, access transfer station F2... access transfer station Fn).
[0043] The main server includes a determination module, a login authentication module, a device authentication module, and a connection establishment module. The determination module is connected to a device address library, in which the MAC addresses of multiple inherent user devices are stored. The inherent user devices are devices that have established connections with any access transfer station in the past, that is: the inherent user devices are devices that have ever connected to this dedicated wireless network, and recording such devices in the device address library to a certain extent indicates that these devices are dedicated devices within this dedicated wireless network. Compared with new user devices that have not accessed this dedicated wireless network, these devices have a higher level of trustworthiness. Therefore, in the following content, different authentication methods are set for inherent user devices and new user devices respectively (i.e., step S3 and step S4 below).
[0044] The login authentication module is used to perform a login authentication operation on the user device, the device authentication module is used to perform an identity authentication operation on the user device, and the connection establishment module is used to establish a connection between the user device and the corresponding access transfer station.
[0045] The device authentication module is connected to a platform database, which is used to store information about all devices accessing the transfer station, as well as their corresponding level information and device access duration ranges. The level information corresponding to different transfer stations is different, and there is no overlap in the corresponding device access duration ranges. In the specific implementation process, the device access duration ranges can be divided as follows: 0 - T1 (including 0 but not including T1), T1 - T2 (including T1 but not including T2), T2 - T3 (including T2 but not including T3)... Tm - Tn (including Tm but not including Tn), and Tn and above, where 0 < T1 < T2 < T3... < Tm < Tn. If the device access duration range is 0, it means it is a new user device. Then, set the device access duration range corresponding to transfer station F1 as 0 - T1, the device access duration range corresponding to transfer station F1 as T1 - T2, and so on. The device access duration range corresponding to transfer station Fm is Tn - Tm, and the device access duration range corresponding to transfer station Fn is Tn and above. And in the order of increasing device access duration range, set the level of transfer station F1 as level 1, the level of transfer station F2 as level 2, and so on. The level of transfer station Fm is set as level m, and the level of transfer station Fn is set as level n. The above-set level information and device access duration ranges are all confidential data, and using them as verification keys can achieve the identity authentication operation of new user devices in step S3 below.
[0046] The establishment module is connected to a dynamic time database, which is used to record the cumulative access duration of all inherent user devices connected to the transfer station and update the cumulative access duration in real time. Since inherent user devices may be used frequently, the cumulative access duration of their connections to the transfer station will be continuously increasing. Therefore, it is necessary to update the cumulative access time. Devices with different cumulative access times will establish connections with corresponding-level transfer stations. Example: There is an inherent user device whose current cumulative access time is within T1 - T2. When it needs to connect to and use this dedicated wireless network, it will connect to and use the corresponding transfer station F1. During use, its cumulative access time is continuously increasing and being updated. When it needs to connect to this dedicated wireless network again next time, its cumulative access time becomes within T2 - T3. At this time, this inherent user device will connect to and use the corresponding transfer station F2.
[0047] S2. Obtain the MAC address of user device E through the determination module and compare it with the MAC addresses of inherent user devices stored in the device address library to determine whether user device E is a new user device;
[0048] When the user device E is one of the inherent user devices, step S3 is performed;
[0049] When the user device E is a new user device, step S4 is performed;
[0050] Each device in the network has a unique network identifier, which is called the MAC address or network card address and is written inside the hardware by the network device manufacturer during production. The main function of the MAC address is to identify and locate network devices in network communication. In this application, different user devices are distinguished by the unique MAC address, and then it is determined whether they are inherent user devices.
[0051] S3. The main server directly performs a login authentication operation on the user device E: sending a secret key to the user device E, which is generated by quantum encryption technology, and the user device E completes the login authentication by inputting the secret key;
[0052] S4. The main server first performs an identity authentication operation on the user device E: randomly sending at least one access transfer station information to the user device E and waiting for the user device E to input two pieces of information corresponding to the above access transfer station: one is the level information of the above access transfer station, and the other is the device access duration range corresponding to the above access transfer station;
[0053] When the two pieces of information do not correctly correspond to the access transfer station, the user device E fails to connect to the wireless network. When both pieces of information correspond to the access transfer station, the identity authentication operation is successful, and at this time, the login authentication operation in S3 is performed;
[0054] Using the access transfer station and its corresponding level information and device access duration range, which are confidential data, as the first verification key for the new user device. When the verification is successful, to a certain extent, it can indicate that the user of the new user device has sufficient understanding of the network server, so the new user device used also has a certain degree of trustworthiness. Subsequently, a login authentication operation is performed on the user device. For the recorded inherent user devices, they already have trustworthiness, so the login authentication operation is directly performed, effectively saving the authentication time.
[0055] S5. After completing the login authentication operation, according to the actual cumulative access duration of the user device E with the access transfer station in the past, it establishes a connection with the access transfer station of the corresponding level;
[0056] S6. When the user device E performs data transmission, the data is first transmitted to the access transfer station, and the access transfer station performs a security detection on the data. When the detection result shows that the data is secure, the access transfer station then transmits the data to the corresponding receiving end;
[0057] When the detection result shows that there is a security risk in the data, stop data transmission, connect to the transfer station to send a security warning to the main server. Subsequently, the transfer station disconnects the connection with the main server, so that all user devices that have established a connection with the above transfer station show that the connection is disconnected, and the remaining transfer stations operate normally;
[0058] The function of setting up the transfer station is as follows: a single transfer station corresponds to multiple user devices with the same cumulative access duration, and a single user device only accesses a single transfer station at a time. Therefore, through the transfer station, hierarchical management of multiple user devices is realized, and security detection is carried out on the transmitted data. On the basis of effectively ensuring data security, the data is transmitted in the next step, thus also ensuring the security of the main server. When a certain transfer station detects that the data sent by a certain user device has a security risk, in order to ensure the safe operation of the main server, the above transfer station will immediately disconnect the connection with the main server, so that the risky data is not easy to damage the main server, and thus not easy to affect all user devices connected to this wireless network. At the same time, other transfer stations and the multiple user devices connected to them are all in normal operation. Therefore, through the setting of the transfer station and the dynamic batch management of user devices, the stable operation of the main server and other user devices is effectively guaranteed at a relatively low power cost, and the risk of complete network paralysis is minimized to the greatest extent.
[0059] S7. According to the security warning information, the main server, on the one hand, issues a network alarm signal, and on the other hand, establishes a connection between the remaining disconnected user devices except user device E and the standby transfer station, so that the remaining normal user devices can continue to work;
[0060] Since after the transfer station cuts off the connection with the main server, the user device E and the remaining normal user devices it accesses are all in a network-disconnected state. Although the risky data in user device E is effectively blocked from damaging the main server, it also affects the use of the remaining normal user devices at the same time. Therefore, by setting up a standby transfer station to take over these normal user devices, the normal user devices can continue to carry out network communication, thereby further reducing the influence range of the risky data (Supplementary note: Since the transfer station is normally connected to the main server, the information of the user devices connected to the transfer station is recorded in real time in the main server, so it is convenient to establish a connection between them and the standby transfer station according to the MAC addresses of these user devices).
[0061] A switching switch is electrically connected to each of the multiple access repeaters. The switching switch transmits data to the main server through a power transmission line. The access repeater and the main server are connected by a wired connection. When the access repeater detects risk data, it disconnects from the power transmission line through the switching switch, and then disconnects from the main server.
[0062] The second implementation method:
[0063] Based on the first implementation method, the following specific settings are made for the power transmission line in this implementation method, which can realize the secondary disconnection operation of the access transfer station and the main server, and provide further protection for the safety of the main server in the case where the switching switch fails to disconnect normally: Figure 1 As shown, the power transmission line includes line a connected to the main server, line b connected to the switching switch, and a secondary switch connected between line a and line b. A sensing optical fiber is electrically connected between the secondary switch and the access repeater.
[0064] Please refer to Figure 3 , the secondary switch includes a switch box 1 and a wiring box 2 fixedly connected to each other. A controller 3, an optical receiving device 4 and an air pump 5 are fixedly installed inside the switch box 1. The optical receiving device 4 and the air pump 5 are both electrically connected to the controller 3. One end of the sensing optical fiber is electrically connected to the optical receiving device 4, and the other end is electrically connected to the optical transmitting device in the access transfer station. When the access transfer station detects risk data, while controlling the switching switch to disconnect, it will start the optical transmitting device to input an optical signal into the sensing optical fiber. When the optical receiving device 4 receives the optical signal, it will disconnect the connection between line a and line b.
[0065] Please refer to Figure 4 and Figure 5 , a fixed seat 6 and a movable seat 7 are provided inside the wiring box 2. One outer end of the fixed seat 6 is fixedly connected to the inner wall of the wiring box 2. A T-shaped sliding groove 201 is formed on the inner wall of the wiring box 2. One outer end of the movable seat 7 is fixedly connected to a T-shaped slider slidably connected to the T-shaped sliding groove 201. The surface of the movable seat 7 in sliding contact with the inner wall of the wiring box 2 is in a non-sealed state. Fixed contacts 8 are fixedly connected to the ends of the fixed seat 6 and the movable seat 7 close to each other. The end of line a away from the main server fixedly penetrates through the wiring box 2 and the fixed seat 6 until it is electrically connected to the fixed contact 8 on the fixed seat 6. The end of line a away from the main server fixedly penetrates through the wiring box 2 and the fixed seat 6 until it is electrically connected to the fixed contact 8 on the fixed seat 6. The end of line b away from the switching switch fixedly penetrates through the wiring box 2 and the movable seat 7 until it is electrically connected to the fixed contact 8 on the movable seat 7;
[0066] A soft sleeve 9 is fixedly connected between the fixed seat 6 and the movable seat 7, and the soft sleeve 9 is sleeved outside the contact 8. The soft sleeve 9 is made of an inelastic and airtight flexible material. An annular cavity 601 is provided inside the fixed seat 6. The intake end of the air pump 5 communicates with the inside of the junction box 2 through the intake pipe 501, and the outlet end of the air pump 5 communicates with the inside of the annular cavity 601 through the outlet pipe 502. An air outlet hole communicating with the inside of the soft sleeve 9 is provided on the inner wall of the annular cavity 601. In the initial state, as Figure 4 shown, a pair of contacts 8 are in contact with each other, and at this time, the line a and the line b are in an electrically connected state, and the soft sleeve 9 is in an inwardly concave state. The principle of maintaining the concave state of the soft sleeve 9 is as follows: The internal space of the junction box 2 is divided into two regions. One is the gap region one formed between the fixed seat 6, the movable seat 7, the soft sleeve 9 and the inner wall of the junction box 2, and the other is the gap region two between the soft sleeve 9 and the contact 8. By adjusting the air pressure in the two gap regions through the air pump 5, the soft sleeve 9 can be maintained in an inwardly concave state.
[0067] Please refer to Figure 4 and Figure 5 , when the optical receiving device 4 receives an optical signal, the controller 3 controls the air pump 5 to start, and adjusts the air pressure in the two gap regions, that is, extracts the gas in the gap region one through the intake pipe 501, and then inputs it into the gap region two through the outlet pipe 502, the annular cavity 601 and the air outlet hole in sequence, so that the air pressure inside the soft sleeve 9 gradually increases, and forces the movable seat 7 to move away from the fixed seat 6. At this time, the soft sleeve 9 is in a normal straight state, and a pair of contacts 8 are separated, disconnecting the electrical connection between the line a and the line b; when the electrical connection needs to be restored, start the air pump 5 again, and reverse-extract the gas inside the soft sleeve 9 (i.e., in the gap region two), and then transport it back to the inside of the junction box 2 (i.e., in the gap region one) along the original path. Since the air pressure in the gap region two continuously decreases, it forces the movable seat 7 to approach the fixed seat 6 until a pair of contacts 8 are reattached, and the relaxed soft sleeve 9 gradually sags inward. The air pressure makes a pair of contacts 8 fit stably, and the movable seat 7 is not easy to move;
[0068] In addition, the gases in the gap region one and the gap region two are both inert gases, such as argon. It can not only be used as the driving gas for the above electrical connection and disconnection process, but also protect the connection between a pair of contacts 8, making the arc generated by their connection not easy to spread outward, and at the same time can effectively reduce the oxidation of the surface of the contacts 8.
[0069] The 3rd implementation mode:
[0070] On the basis of the implementation mode 2, the following content is added: Please refer to Figure 6 and Figure 7, a ring plate 10 is slidably connected inside the annular cavity 601. A plurality of uniformly distributed compression springs 11 are fixedly connected between one end of the ring plate 10 away from the contact 8 and the inner wall of the annular cavity 601. A tension sensor 12 is fixedly connected to the inner wall of the annular cavity 601 close to the contact 8. An elastic band 13 is fixedly connected between the sensing end of the tension sensor 12 and the ring plate 10. In the initial state, the compression springs 11 are in a contracted state, and the elastic band 13 is in an elastically stretched state. The ring plate 10 is always located on the side of the air outlet pipe 502 away from the air outlet hole. A gas guide pipe 14 communicating with both the annular cavity 601 and the outside is fixedly connected between the fixed seat 6 and the junction box 2. The air pressure in the area where the compression springs 11 are located is kept stable through the annular cavity 601, which is not likely to impede the movement of the ring plate 10. The gas guide pipe 14 is located on the side of the ring plate 10 away from the tension sensor 12. The tension sensor 12 is electrically connected to the controller 3.
[0071] Through the setting of the above structure, it has the function of effectively detecting the gas leakage situation in the junction box 2. The specific method is as follows: In the initial state, that is, when there is no leakage in the junction box 2, combined with Figure 4 As shown, since the air pressure in the void area one and the void area two is stable, the elastic recovery process of the compression springs 11 is effectively restricted, the position of the ring plate 10 remains stable, and the tension of the elastic band 13 on the tension sensor 12 remains stable; when there is a leakage point m at a certain part of the junction box 2, as Figure 7 As shown, since the inside of the junction box 2 can communicate with the outside, at this time, the compression springs 11 can perform a certain degree of elastic recovery, pushing the ring plate 10 in the direction close to the tension sensor 12. The movement of the ring plate 10 will push the gas in the annular cavity 601 through the air outlet hole towards the inside of the soft sleeve 9, increasing the air pressure inside the soft sleeve 9, and the inwardly concave area of the soft sleeve 9 gradually decreases. At this time, since the distance between the ring plate 10 and the tension sensor 12 decreases, the elastic stretching degree of the elastic band 13 decreases, and the tension on the tension sensor 12 decreases. When the controller 3 receives this data change, it can give a sound warning in time. Therefore, through the change of the tension of the tension sensor 12, it can effectively judge whether there is gas leakage on the junction box 2.
[0072] Combined with the current actual requirements, the above implementation method adopted in this application, the protection scope is not limited to this. Within the knowledge scope of those skilled in the art, various changes made without departing from the concept of this application still fall within the protection scope of the present invention.
Claims
1. A security detection and authentication method for a wireless network, characterized in that: The steps include the following: S1. After the user device E scans the dedicated wireless network, it sends an access request to the network server. The network server includes a main server, a standby transfer station connected to the main server, and multiple access transfer stations; S2. The determination module obtains the MAC address of the user device E and compares it with the MAC addresses of the inherent user devices stored in the device address library to determine whether the user device E is a new user device; When the user device E is one of the inherent user devices, step S3 is performed; When the user device E is a new user device, step S4 is performed; S3. The main server directly performs a login authentication operation on the user device E: sending a secret key to the user device E, and the user device E completes the login authentication by inputting the secret key; S4. The main server first performs an identity authentication operation on the user device E: randomly sending at least one access transfer station information to the user device E and waiting for the user device E to input two pieces of information corresponding to the above access transfer station: one is the level information of the above access transfer station, and the other is the device access duration range corresponding to the above access transfer station; When the two pieces of information do not correctly correspond to the access transfer station, the connection between the user device E and the wireless network fails. When both pieces of information correspond to the access transfer station, the identity authentication operation is successful, and at this time, the login authentication operation in S3 is performed; S5. After completing the login authentication operation, according to the actual cumulative access duration of the user device E with the access transfer station in the past, a connection is established between it and the access transfer station of the corresponding level; S6. When the user device E performs data transmission, the data is first transmitted to the access transfer station, and the access transfer station performs a security detection on the data. When the detection result shows that the data is secure, the access transfer station then transmits the data to the corresponding receiving end; When the detection result shows that there is a security risk in the data, the data transmission is stopped, and the access transfer station gives a security warning to the main server. Subsequently, the access transfer station disconnects the connection with the main server, so that all user devices that have established a connection with the above access transfer station show that the connection is disconnected, and the remaining access transfer stations operate normally; S7. According to the security warning information, the main server, on the one hand, issues a network alarm signal, and on the other hand, establishes a connection between the remaining disconnected user devices except the user device E and the standby transfer station to enable the remaining normal user devices to continue working.
2. The security detection and authentication method for a wireless network according to claim 1, characterized in that: The main server includes a determination module, a login authentication module, a device authentication module, and a connection establishment module. The login authentication module is used to perform a login authentication operation on the user device. The device authentication module is used to perform an identity authentication operation on the user device. The connection establishment module is used to establish a connection between the user device and the corresponding access transfer station.
3. The security detection and authentication method for a wireless network according to claim 2, wherein: The determination module is connected to a device address library. Multiple MAC addresses of inherent user devices are stored in the device address library. The inherent user devices are devices that have established a connection with any access transfer station in the past. The connection establishment module is connected to a dynamic time database. The dynamic time database is used to record the cumulative access duration of all inherent user devices connected to the access transfer station and update the cumulative access duration in real time.
4. A security detection and authentication method for a wireless network according to claim 3, characterized in that: The device authentication module is connected to a platform database, which is used to store information of all devices accessing the transfer station, their corresponding level information, and the range of device access duration. Different transfer stations have different corresponding level information, and there is no overlapping part in the corresponding device access duration ranges.
5. A security detection and authentication method for a wireless network according to claim 1, characterized in that: A switching switch is electrically connected to each of the plurality of access repeaters, and the switching switch transmits data to the main server through a power transmission line.
6. The security detection and authentication method for a wireless network according to claim 5, characterized in that: The power transmission line includes line a connected to the main server, line b connected to the switching switch, and a secondary switch connected between line a and line b. A sensing optical fiber is electrically connected between the secondary switch and the access repeater.
7. A security detection and authentication method for a wireless network according to claim 6, characterized in that: The secondary switch includes a device box (1) and a wiring box (2) fixedly connected to each other. A controller (3), an optical receiving device (4), and an air pump (5) are fixedly installed inside the device box (1). Both the optical receiving device (4) and the air pump (5) are electrically connected to the controller (3). One end of the sensing optical fiber is electrically connected to the optical receiving device (4), and the other end is electrically connected to an optical transmitting device in the access transfer station.
8. A security detection and authentication method for a wireless network according to claim 7, characterized in that: A fixed seat (6) and a moving seat (7) are provided inside the wiring box (2). One outer end of the fixed seat (6) is fixedly connected to the inner wall of the wiring box (2). A T-shaped sliding groove (201) is formed on the inner wall of the wiring box (2). One outer end of the moving seat (7) is fixedly connected to a T-shaped slider slidably connected to the T-shaped sliding groove (201). Contact heads (8) are fixedly connected to the ends of the fixed seat (6) and the moving seat (7) close to each other. The end of line a away from the main server fixedly penetrates through the wiring box (2) and the fixed seat (6) until it is electrically connected to the contact head (8) on the fixed seat (6). The end of line a away from the main server fixedly penetrates through the wiring box (2) and the fixed seat (6) until it is electrically connected to the contact head (8) on the fixed seat (6). The end of line b away from the switching switch fixedly penetrates through the wiring box (2) and the moving seat (7) until it is electrically connected to the contact head (8) on the moving seat (7).
9. The security detection and authentication method for a wireless network according to claim 8, wherein: A soft sleeve (9) is fixedly connected between the fixed seat (6) and the moving seat (7), and the soft sleeve (9) is sleeved outside the contact head (8). An annular cavity (601) is formed inside the fixed seat (6). The air inlet end of the air pump (5) communicates with the inside of the wiring box (2) through an air inlet pipe (501). The air outlet end of the air pump (5) communicates with the inside of the annular cavity (601) through an air outlet pipe (502). Air outlet holes communicating with the inside of the soft sleeve (9) are formed on the inner wall of the annular cavity (601). In the initial state, the pair of contact heads (8) are in contact with each other, and the soft sleeve (9) is in an inwardly concave state.
10. A security detection and authentication method for a wireless network according to claim 9, characterized in that: A ring plate (10) is slidably connected inside the annular cavity (601). A plurality of uniformly distributed compression springs (11) are fixedly connected between one end of the ring plate (10) away from the contact head (8) and the inner wall of the annular cavity (601). A tension sensor (12) is fixedly connected to the inner wall of the annular cavity (601) near the contact head (8). An elastic band (13) is fixedly connected between the sensing end of the tension sensor (12) and the ring plate (10). In the initial state, the compression springs (11) are in a contracted state, and the elastic band (13) is in an elastically stretched state. The ring plate (10) is always located on the side of the air outlet pipe (502) away from the air outlet hole. A gas guide pipe (14) that is communicated with both the annular cavity (601) and the outside is fixedly connected between the fixed seat (6) and the junction box (2). The gas guide pipe (14) is located on the side of the ring plate (10) away from the tension sensor (12).
Citation Information
Patent Citations
Private network access method, device and system
CN102186168B
Electric power dedicated wireless network system and wireless transmission method based on regional authentication
CN103686728B