Networking method and device of pico-base station, electronic equipment and computer program product

By introducing neighboring base stations as trust intermediaries during the process of slimming base station networking, and using the trust relationship between neighboring base stations and authentication centers for security verification, the problem of poor security in traditional slimming base station networking solutions is solved, and higher security and network deployment efficiency are achieved.

CN120499657APending Publication Date: 2025-08-15CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510728813.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

The networking scheme of traditional base stations has poor security problems, including user identity exposure, lack of authentication of WLAN access network, plaintext transmission session keys, and vulnerability to WLAN-AN counterfeiting and WAN-UE counterfeiting attacks.

Method used

By sending request messages to the neighboring base station requesting access to the base station gateway, security verification is performed using the trust relationship between the neighboring base station and the authentication center, and configuration information is generated and forwarded, so that the base station can access the base station gateway to ensure the security of the access process.

Benefits of technology

It improves the security of the networking of the slim base station, avoids illegal access, reduces the complexity of the direct communication between the slim base station and the authentication center, improves the flexibility and efficiency of network deployment, and ensures the scalability and security of the wireless communication network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120499657A_ABST
    Figure CN120499657A_ABST
Patent Text Reader

Abstract

The invention discloses a networking method and device of a pico-base station, electronic equipment and a computer program product. The method comprises the following steps: sending a request message for requesting to access a gateway of the pico-base station to an adjacent base station of the pico-base station, the request message at least comprising request information for requesting to access the gateway of the pico-base station and verification information for security verification; configuration information sent by the neighbor base station under the condition that the verification information passes the security verification is received, and the configuration information serves as a basis for accessing a pico-base station gateway and is generated by the authentication center based on the request information; and accessing the pico-base station to the pico-base station gateway based on the configuration information. According to the invention, the technical problem of poor security of the traditional networking scheme of the pico-base station is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and in particular to a method, device, electronic device and computer program product for networking of a pico base station. Background Art

[0002] With the rapid growth of 4G users and the continuous reduction of data traffic prices, traffic is growing exponentially, and more and more traffic is beginning to occur indoors, which puts forward an urgent need to enhance indoor coverage. However, traditional indoor distribution systems (DAS) have problems such as difficulty in fault detection, fault location, fault supervision and fault analysis.

[0003] New indoor equipment, such as pico base stations, offers visualized O&M capabilities and supports cell splitting and expansion, significantly improving O&M efficiency. They also support operators' big data capabilities and open up new revenue streams. However, the open nature of wireless communication networks also presents numerous security concerns, such as unauthorized access, data theft, and network attacks. Therefore, research on secure networking technologies for wireless communication networks is particularly important.

[0004] Currently, most wireless communication networks are deployed over the internet and rely on traditional firewall technologies for network security. However, these traditional firewall technologies are insufficient against certain new types of network attacks. Furthermore, existing secure networking methods still have many shortcomings in effectively isolating network threats and ensuring data security in real time.

[0005] Currently, traditional pico base stations basically use EAP-AKA protocol authentication.

[0006] Among them, EAP-AKA has the following disadvantages:

[0007] (1) User identity exposure: During the authentication process of the EAP-AKA protocol, the user's identity information may be exposed, which may cause the user to be tracked.

[0008] (2) Lack of authentication for WLAN access network: The EAP-AKA protocol does not authenticate the wireless local area network (WLAN) access network during the authentication process, which may lead to security issues in network access.

[0009] (3) Transmission of session keys in plain text: The EAP-AKA protocol uses plain text transmission when transmitting session keys, which will cause the WLAN to lose confidentiality and integrity during communication.

[0010] Among them, EAP-AKA potential vulnerabilities:

[0011] (1) Like the 3G authentication and key distribution protocol AKA, the EAP-AKA protocol does not have a mechanism to update the secret key K shared between the WAN user and the 3G network, which may lead to USIM cloning attacks.

[0012] (2) When a WAN user authenticates for the first time, or the network does not recognize the temporary identifier of a WLAN user, the WAN user needs to send the IMSI in plain text, which affects the confidentiality of the user's identity.

[0013] Among them, EAP-AKA may be vulnerable to the following attacks:

[0014] (1) WLAN-AN Impersonation Attack. The EAP-AKA protocol implements mutual authentication between WLAN users and the 3G network, but neither party authenticates the identity of the WLAN-AN. Furthermore, in step 1 of the protocol, the 3GPP AAA server sends the session key used for confidentiality and integrity protection in WAN communications directly to the WLAN-AN in plain text. If an attacker first compromises the WAN-AN using some means (such as a DoS attack) and then impersonates the WLAN-AN, they can obtain the session key in the WAN, thus compromising the confidentiality of WLAN communications.

[0015] (2) WAN-UE impersonation attack. An attacker can use the intercepted legitimate user identity to launch an attack. In this way, the attacker can impersonate the user to access the network. Because the attacker does not have the session key, the attacker cannot communicate normally at this time. However, if the attacker simultaneously eavesdrops on the communication between the WAN-AN and the 3CPPAAA server, the attacker can obtain the WAN-UE session key. At this point, the attacker can impersonate the user and communicate normally on the 3G and WAN interconnected networks.

[0016] The above-mentioned traditional pico base station networking solutions have the problem of poor security, and no effective solution has been proposed yet. Summary of the Invention

[0017] Embodiments of the present invention provide a method, device, electronic device, and computer program product for networking a pico base station, to at least solve the technical problem of poor security in traditional pico base station networking solutions.

[0018] According to one aspect of an embodiment of the present invention, a networking method for a pico base station is provided, comprising: sending a request message to a neighboring base station of the pico base station requesting access to a pico base station gateway, wherein the request message includes at least: request information for requesting access to the pico base station gateway, and verification information for security verification; receiving configuration information sent by the neighboring base station when the verification information passes the security verification, wherein the configuration information is generated by an authentication center based on the request information as a basis for accessing the pico base station gateway; and connecting the pico base station to the pico base station gateway based on the configuration information.

[0019] Optionally, sending a request message requesting access to the pico base station gateway to a neighboring base station of the pico base station includes: obtaining the gateway address of the pico base station gateway that the pico base station requests to access, wherein the gateway address is the unique hardware address of the pico base station gateway; generating the request message based on the base station information and the gateway address of the pico base station, wherein the base station information includes at least: the base station identity, base station address and verification information of the pico base station, and the base station address is the unique hardware address of the pico base station; sending the request message to the neighboring base station.

[0020] Optionally, the base station information also includes: security protocol information and encryption protocol information; generating the request message based on the base station information of the pico base station and the gateway address includes: generating the request information based on the base station identity, the base station address and the gateway address; generating the verification information based on the security protocol information and the encryption protocol information, wherein, when the security protocol information and the encryption protocol information both pass the security verification of the neighboring base station, it is determined that the verification information passes the security verification; generating the request message based on the request information and the verification information.

[0021] Optionally, sending a request message to a neighboring base station of the pico base station requesting access to the pico base station gateway includes: identifying at least one candidate base station adjacent to the pico base station, wherein the candidate base station is a pico base station or a macro base station that has completed networking; determining a trusted base station among at least one of the candidate base stations, wherein the trusted base station has the ability to communicate with the authentication center and perform security verification; determining the trusted base station as the neighboring base station, and sending a request message to the neighboring base station.

[0022] Optionally, connecting the pico base station to the pico base station gateway based on the configuration information includes: receiving the configuration information sent by the neighboring base station to the pico base station, and detecting whether the configuration information is encrypted by the authentication center, wherein the authentication center is also used to encrypt the configuration information using the public key corresponding to the pico base station; decrypting the configuration information using the private key pre-configured by the pico base station, wherein the private key in the pico base station and the public key for encrypting the configuration information belong to the same key pair; using the decrypted configuration information to negotiate with the pico base station gateway to generate a communication channel between the pico base station and the pico base station gateway, wherein the pico base station accesses the pico base station gateway based on the communication channel.

[0023] According to another aspect of an embodiment of the present invention, a networking method for a pico base station is also provided, including: a neighboring base station of the pico base station receives a request message from the pico base station requesting access to a pico base station gateway, wherein the request message includes at least: request information requesting access to the pico base station gateway, and verification information for security verification; the neighboring base station performs security verification on the verification information; if the verification information passes the security verification, the neighboring base station forwards the request information to an authentication center, and receives configuration information generated by the authentication center based on the request information, wherein the configuration information serves as a basis for accessing the pico base station gateway; the configuration information is forwarded to the pico base station, wherein the pico base station accesses the pico base station gateway based on the configuration information.

[0024] According to another aspect of an embodiment of the present invention, a networking method for a pico base station is also provided, including: an authentication center receives request information forwarded by a neighboring base station of the pico base station, wherein the neighboring base station is used to receive a request message from the pico base station requesting access to the pico base station gateway, and perform security verification on the verification information in the request message, and the request message also includes: the request information requesting access to the pico base station gateway; querying the configuration policy pre-registered by the pico base station based on the request information, and generating configuration information according to the configuration policy, wherein the configuration information serves as a basis for accessing the pico base station gateway; sending the configuration information to the neighboring base station, wherein the neighboring base station is also used to forward the configuration information to the pico base station, instructing the pico base station to access the pico base station gateway based on the configuration information.

[0025] Optionally, querying the configuration policy pre-registered by the pico base station based on the request information, and generating configuration information according to the configuration policy includes: identifying the base station identity of the pico base station, the base station address of the pico base station, and the gateway address of the pico base station gateway from the request information, wherein the base station address is the unique hardware address of the pico base station, and the gateway address is the unique hardware address of the pico base station gateway; querying the configuration policy corresponding to the base station identity among the multiple configuration policies pre-stored in the authentication center; generating the configuration information for establishing a communication channel between the base station address and the gateway address based on the queried configuration policy, wherein the pico base station accesses the pico base station gateway based on the communication channel.

[0026] Optionally, the configuration strategy also includes: a public key corresponding to the pico base station; after generating the configuration information for establishing a communication channel between the base station address and the gateway address based on the queried configuration strategy, the method also includes: using the public key corresponding to the pico base station to encrypt the configuration information, wherein the pico base station includes: a pre-configured private key, the private key is at least used to decrypt the encrypted configuration information, and the private key in the pico base station and the public key for encrypting the configuration information belong to the same key pair.

[0027] According to another aspect of an embodiment of the present invention, a networking device for a pico base station is also provided, including: a first sending module, used to send a request message to a neighboring base station of the pico base station, requesting access to a pico base station gateway, wherein the request message includes at least: request information requesting access to the pico base station gateway, and verification information for security verification; a first receiving module, used to receive configuration information sent by the neighboring base station when the verification information passes the security verification, wherein the configuration information is generated by an authentication center based on the request information as a basis for accessing the pico base station gateway; a networking module, used to connect the pico base station to the pico base station gateway based on the configuration information.

[0028] According to another aspect of an embodiment of the present invention, a networking device for a pico base station is also provided, including: a second receiving module, used for a neighboring base station of the pico base station to receive a request message from the pico base station requesting access to the pico base station gateway, wherein the request message includes at least: request information requesting access to the pico base station gateway, and verification information for security verification; a verification module, used for the neighboring base station to perform security verification on the verification information; a first forwarding module, used for forwarding the request information to an authentication center if the verification information passes the security verification, and receiving configuration information generated by the authentication center based on the request information, wherein the configuration information serves as a basis for accessing the pico base station gateway; a second forwarding module, used for forwarding the configuration information to the pico base station, wherein the pico base station accesses the pico base station gateway based on the configuration information.

[0029] According to another aspect of an embodiment of the present invention, a networking device for a pico base station is also provided, including: a third receiving module, used by an authentication center to receive request information forwarded by a neighboring base station of the pico base station, wherein the neighboring base station is used to receive a request message from the pico base station requesting access to the pico base station gateway, and perform security verification on the verification information in the request message, and the request message also includes: the request information requesting access to the pico base station gateway; a query module, used to query the configuration policy pre-registered by the pico base station based on the request information, and generate configuration information according to the configuration policy, wherein the configuration information serves as a basis for accessing the pico base station gateway; a second sending module, used to send the configuration information to the neighboring base station, wherein the neighboring base station is also used to forward the configuration information to the pico base station, instructing the pico base station to access the pico base station gateway based on the configuration information.

[0030] According to another aspect of an embodiment of the present invention, an electronic device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to execute the above-mentioned pico base station networking method through the computer program.

[0031] According to another aspect of an embodiment of the present invention, a computer program product is provided, comprising computer instructions, which, when executed by a processor, implement the steps of the above-mentioned method for networking pico base stations.

[0032] In an embodiment of the present invention, when a pico base station requests to access a pico base station gateway, the trust relationship between the neighboring base station and the authentication center is utilized to perform security verification on the request message sent by the pico base station. Only when the security verification is passed will the request information of the pico base station be forwarded to the authentication center. The configuration information generated by the authentication center is then forwarded to the pico base station by the neighboring base station, ensuring that the process of the pico base station accessing the gateway is safe and reliable. By introducing the neighboring base station of the pico base station as a trust intermediary, not only illegal access is avoided, but also the complexity of direct communication between the pico base station and the authentication center is reduced, and the flexibility and efficiency of network deployment are improved. In the field of wireless communications, the scalability and security of the pico base station network can be ensured, thereby achieving the technical effect of improving the security of the pico base station networking, and further solving the technical problem of poor security in the traditional pico base station networking solution. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0034] Figure 1 This is a process of a method for networking a pico base station according to an embodiment of the present invention. Figure 1 ;

[0035] Figure 2 This is a process of a method for networking a pico base station according to an embodiment of the present invention. Figure 2 ;

[0036] Figure 3 This is a process of a method for networking a pico base station according to an embodiment of the present invention. Figure 3 ;

[0037] Figure 4 is a schematic diagram of a secure networking solution based on pico base stations according to an embodiment of the present invention;

[0038] Figure 5 is a schematic diagram of the flow of pico base station signaling and service data flow according to an embodiment of the present invention;

[0039] Figure 6 is a schematic diagram of neighboring cell authentication of a pico base station according to an embodiment of the present invention;

[0040] Figure 7 This is a schematic diagram of a pico base station networking device according to an embodiment of the present invention. Figure 1 ;

[0041] Figure 8 This is a schematic diagram of a pico base station networking device according to an embodiment of the present invention. Figure 2 ;

[0042] Figure 9 This is a schematic diagram of a pico base station networking device according to an embodiment of the present invention. Figure 3 ;

[0043] Figure 10 It is a structural block diagram of a computer terminal according to an embodiment of the present invention. DETAILED DESCRIPTION

[0044] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0045] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0046] First, some nouns or terms that appear in the description of the embodiments of the present application are subject to the following interpretations:

[0047] Pico base station: It is a miniaturized, low-power, low-consumption micro-cellular base station, mainly used to solve the indoor wireless coverage problem in a specific area.

[0048] According to an embodiment of the present invention, an embodiment of a method for networking a pico base station is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0049] Figure 1 This is a process of a method for networking a pico base station according to an embodiment of the present invention. Figure 1 ,like Figure 1 As shown, the method includes the following steps:

[0050] Step S102: Send a request message to a neighboring base station of the pico base station requesting access to the pico base station gateway, wherein the request message includes at least: request information for accessing the pico base station gateway and verification information for security verification;

[0051] Step S104: receiving configuration information sent by the neighboring base station when the verification information passes the security verification, wherein the configuration information serves as the basis for accessing the pico base station gateway and is generated by the authentication center based on the request information;

[0052] Step S106: Connect the pico base station to the pico base station gateway based on the configuration information.

[0053] In an embodiment of the present invention, when a pico base station requests to access a pico base station gateway, the trust relationship between the neighboring base station and the authentication center is utilized to perform security verification on the request message sent by the pico base station. Only when the security verification is passed will the request information of the pico base station be forwarded to the authentication center. The configuration information generated by the authentication center is then forwarded to the pico base station by the neighboring base station, ensuring that the process of the pico base station accessing the gateway is safe and reliable. By introducing the neighboring base station of the pico base station as a trust intermediary, not only illegal access is avoided, but also the complexity of direct communication between the pico base station and the authentication center is reduced, and the flexibility and efficiency of network deployment are improved. In the field of wireless communications, the scalability and security of the pico base station network can be ensured, thereby achieving the technical effect of improving the security of the pico base station networking, and further solving the technical problem of poor security in the traditional pico base station networking solution.

[0054] In the above step S102, the pico base station gateway may be an optical network unit ONU.

[0055] In the above step S102, the pico base station is connected to the Internet through the pico base station gateway to realize the networking of the pico base stations.

[0056] In the above step S102, the request message can be bound to the base station ID of the pico base station, the MAC address of the pico base station and the pico base station network manager, the IP address of the pico base station, security protocol information, encryption protocol information, etc.

[0057] In the above step S102, in the request message, the request information may be determined based on the base station ID of the pico base station, the MAC addresses of the pico base station and the pico base station network manager, and the IP address of the pico base station.

[0058] In the above step S102, in the request message, the verification information may be determined based on the security protocol information and the encryption protocol information.

[0059] In the above step S104, the authentication center acts as the authorized unit for the pico base station to access the pico base station gateway. Before the pico base station requests to access the pico base station, the pico base station needs to register with the authentication center. After registration, the authentication center can record the relevant information of the registered pico base station, such as the base station identity of the pico base station (such as the base station ID), the configuration strategy of the pico base station, and the public key corresponding to the pico base station.

[0060] Optionally, when the pico base station is registered with the authentication center, a key pair for the pico base station may be generated, wherein the private key in the key pair is stored by the pico base station, and the public key in the key pair is stored by the authentication center.

[0061] Optionally, the authentication center can record relevant information of multiple pico base stations (such as configuration policies and public keys), and the relevant information of each pico base station (such as configuration policies and public keys) is based on the base station identity identifier (such as base station ID) of the pico base station as a retrieval identifier.

[0062] In the above step S106, the configuration information serves as the basis for the pico base station to access the pico base station gateway. After the pico base station receives the configuration information, it can negotiate with the pico base station network manager based on the requirements of the configuration information to establish a communication channel for accessing the pico base station gateway.

[0063] Optionally, the communication channel between the pico base station and the pico base station gateway may be an encrypted channel.

[0064] Optionally, the Pico base station gateway can dial into the intranet via VPDN after the Pico base station is connected.

[0065] As an optional embodiment, sending a request message to a neighboring base station of the pico base station requesting access to the pico base station gateway includes: obtaining the gateway address of the pico base station gateway that the pico base station requests access to, wherein the gateway address is the unique hardware address of the pico base station gateway; generating a request message based on the base station information and gateway address of the pico base station, wherein the base station information includes at least: the base station identity, base station address and verification information of the pico base station, and the base station address is the unique hardware address of the pico base station; sending a request message to the neighboring base station.

[0066] In the above embodiment of the present application, the pico base station accesses the pico base station gateway, which requires establishing a communication channel based on the unique hardware addresses of the pico base station and the pico base station gateway. Therefore, when the pico base station requests to access the pico base station gateway, it is necessary to obtain the unique hardware address of the pico base station gateway, that is, the gateway address; and the unique hardware address of the pico base station, that is, the base station address, as well as the base station identity and verification information of the pico base station, and then generate a request message based on the obtained information. Since the request message combines the base station identity, base station address and verification information, the neighboring base station can accurately perform identity authentication and security capability assessment, avoiding misoperation and security vulnerabilities in the access process, and ensuring the communication security of the pico base station networking stage.

[0067] As an optional embodiment, the base station information also includes: security protocol information and encryption protocol information; generating a request message based on the base station information and gateway address of the pico base station includes: generating request information based on the base station identity, base station address and gateway address; generating verification information based on the security protocol information and encryption protocol information, wherein, when the security protocol information and the encryption protocol information both pass the security verification of the neighboring base station, it is determined that the verification information passes the security verification; generating a request message based on the request information and the verification information.

[0068] In the above-mentioned embodiments of the present application, the base station information includes security protocol and encryption protocol information. The security protocol information is used to guide the security communication strategy between the pico base station and the neighboring base station. The encryption protocol information ensures the encryption of data during transmission, preventing the data from being eavesdropped or tampered with, so that the neighboring base station can perform security verification based on the verification information generated based on the security protocol information and the encryption protocol information, avoiding attacks on the authentication center used for pico base station networking, and further enhancing the security of the pico base station access process and the confidentiality of data transmission.

[0069] As an optional embodiment, sending a request message to a neighboring base station of the pico base station requesting access to the pico base station gateway includes: identifying at least one candidate base station adjacent to the pico base station, wherein the candidate base station is a pico base station or a macro base station that has completed networking; determining a trusted base station among at least one candidate base station, wherein the trusted base station has the ability to communicate with the authentication center and perform security verification; determining the trusted base station as a neighboring base station, and sending a request message to the neighboring base station.

[0070] In the above embodiments of the present application, the process of determining a trusted base station is essentially a process of conducting a security assessment of neighboring base stations. By identifying and selecting trusted base stations that have the ability to communicate with the authentication center and verify security, the access path of the pico base station is optimized, the access efficiency and security are improved, and the security and reliability of the data transmission path are ensured.

[0071] Optionally, the neighboring base station that receives the request message can also be a base station with high communication efficiency with the pico base station, such as a low-load base station. Selecting a base station with high communication efficiency as a neighboring base station not only reduces the delay of the pico base station accessing the network, but also enhances the robustness and anti-interference capability of the network by selecting the optimal neighboring base station.

[0072] Optionally, in a wireless communication network, candidate base stations are screened based on parameters including but not limited to signal strength, communication quality, base station load, and the like.

[0073] As an optional embodiment, connecting the pico base station to the pico base station gateway based on configuration information includes: receiving configuration information sent by the neighboring base station to the pico base station, and detecting whether the configuration information is encrypted by the authentication center, wherein the authentication center is also used to encrypt the configuration information using the public key corresponding to the pico base station; using the private key pre-configured by the pico base station to decrypt the configuration information, wherein the private key in the pico base station and the public key for the encrypted configuration information belong to the same key pair; using the decrypted configuration information to negotiate with the pico base station gateway to generate a communication channel between the pico base station and the pico base station gateway, wherein the pico base station accesses the pico base station gateway based on the communication channel.

[0074] In the above-mentioned embodiment of the present application, the authentication center uses the public key of the pico base station to encrypt the configuration information, which is then decrypted by the pico base station using its private key. This ensures the confidentiality and integrity of the configuration information during transmission and effectively prevents the data from being illegally intercepted or tampered with. This mechanism based on public key encryption utilizes the characteristics of asymmetric encryption algorithms. Even if the configuration information is intercepted during transmission, the attacker cannot decrypt the information without the corresponding private key, thereby ensuring the security of the pico base station access process.

[0075] Figure 2 This is a process of a method for networking a pico base station according to an embodiment of the present invention. Figure 2 ,like Figure 2 As shown, the method includes the following steps:

[0076] Step S202: A neighboring base station of the pico base station receives a request message from the pico base station requesting access to the pico base station gateway, wherein the request message includes at least: request information for accessing the pico base station gateway and verification information for security verification;

[0077] Step S204: The neighboring cell base station performs security verification on the verification information;

[0078] Step S206: If the verification information passes the security verification, forward the request information to the authentication center and receive the configuration information generated by the authentication center based on the request information, wherein the configuration information serves as the basis for accessing the pico base station gateway;

[0079] Step S208: forward the configuration information to the pico base station, wherein the pico base station accesses the pico base station gateway according to the configuration information.

[0080] In an embodiment of the present invention, when a pico base station requests to access a pico base station gateway, the trust relationship between the neighboring base station and the authentication center is utilized to perform security verification on the request message sent by the pico base station. Only when the security verification is passed will the request information of the pico base station be forwarded to the authentication center. The configuration information generated by the authentication center is then forwarded to the pico base station by the neighboring base station, ensuring that the process of the pico base station accessing the gateway is safe and reliable. By introducing the neighboring base station of the pico base station as a trust intermediary, not only illegal access is avoided, but also the complexity of direct communication between the pico base station and the authentication center is reduced, and the flexibility and efficiency of network deployment are improved. In the field of wireless communications, the scalability and security of the pico base station network can be ensured, thereby achieving the technical effect of improving the security of the pico base station networking, and further solving the technical problem of poor security in the traditional pico base station networking solution.

[0081] Figure 3 This is a process of a method for networking a pico base station according to an embodiment of the present invention. Figure 3 ,like Figure 3 As shown, the method includes the following steps:

[0082] In step S302, the authentication center receives a request message forwarded by a neighboring base station of the pico base station, wherein the neighboring base station is configured to receive a request message from the pico base station requesting access to the pico base station gateway and perform security verification on verification information in the request message, wherein the request message also includes: request information requesting access to the pico base station gateway;

[0083] Step S304: query the configuration policy pre-registered by the pico base station according to the request information, and generate configuration information according to the configuration policy, wherein the configuration information serves as the basis for accessing the pico base station gateway;

[0084] Step S306: Send configuration information to the neighboring cell base station, wherein the neighboring cell base station is further configured to forward the configuration information to the pico base station, instructing the pico base station to access the pico base station gateway according to the configuration information.

[0085] In an embodiment of the present invention, when a pico base station requests to access a pico base station gateway, the trust relationship between the neighboring base station and the authentication center is utilized to perform security verification on the request message sent by the pico base station. Only when the security verification is passed will the request information of the pico base station be forwarded to the authentication center. The configuration information generated by the authentication center is then forwarded to the pico base station by the neighboring base station, ensuring that the process of the pico base station accessing the gateway is safe and reliable. By introducing the neighboring base station of the pico base station as a trust intermediary, not only illegal access is avoided, but also the complexity of direct communication between the pico base station and the authentication center is reduced, and the flexibility and efficiency of network deployment are improved. In the field of wireless communications, the scalability and security of the pico base station network can be ensured, thereby achieving the technical effect of improving the security of the pico base station networking, and further solving the technical problem of poor security in the traditional pico base station networking solution.

[0086] As an optional embodiment, querying the configuration policy pre-registered by the pico base station based on the request information, and generating configuration information according to the configuration policy includes: identifying the base station identity of the pico base station, the base station address of the pico base station, and the gateway address of the pico base station gateway from the request information, wherein the base station address is the unique hardware address of the pico base station, and the gateway address is the unique hardware address of the pico base station gateway; querying the configuration policy corresponding to the base station identity among the multiple configuration policies pre-stored in the authentication center; generating configuration information for establishing a communication channel between the base station address and the gateway address based on the queried configuration policy, wherein the pico base station accesses the pico base station gateway based on the communication channel.

[0087] As an optional embodiment, the configuration strategy also includes: a public key corresponding to the pico base station; after generating configuration information for establishing a communication channel between the base station address and the gateway address based on the queried configuration strategy, the method also includes: using the public key corresponding to the pico base station to encrypt the configuration information, wherein the pico base station includes: a pre-configured private key, the private key is at least used to decrypt the encrypted configuration information, and the private key in the pico base station and the public key of the encrypted configuration information belong to the same key pair.

[0088] The present invention also provides an optional embodiment, which provides a secure authentication networking system based on pico base stations, designed to optimize the coverage, capacity, and performance of wireless communication networks. The system includes multiple pico base stations, a security controller, and a firewall. The security controller monitors network traffic in real time and enforces security policies, while the firewall isolates network threats and ensures data security.

[0089] Figure 4 is a schematic diagram of a secure networking solution based on a pico base station according to an embodiment of the present invention. Figure 4 As shown, the pico base station can be connected to the Internet through the optical network unit ONU to realize the networking of the pico base station.

[0090] As an optional embodiment, the authentication method for the pico base station access includes the following steps:

[0091] In step S41, the pico base station sends a security capability negotiation request message (ie, an IP datagram) to other nearby neighboring base stations through the Internet access gateway.

[0092] In step S42, the pico base station sends an IP data message, in which the base station ID, MAC address, IP address, security protocol information, encryption protocol and other information are bound.

[0093] In step S43, the neighboring base station receives the security capability negotiation request message, determines whether the pico base station requesting access complies with the relevant protocols, and mainly matches the security protocols and encryption algorithm information of each manufacturer. If the match is successful, a protocol application command is sent to the security gateway, and the security gateway (such as the authentication center) sends a randomly generated encryption file to the neighboring base station where it is located. The neighboring base station sends the random encryption file to the neighboring base station requesting access. The random encryption file takes effect for one minute (if no access message is received after one minute, the file will become invalid).

[0094] In step S44, the pico base station requesting access automatically loads the file after receiving the encrypted file. After the loading is completed, it confirms with the pico base station gateway, starts the access identity authentication process, and negotiates a secure channel authentication key.

[0095] This solution prevents hackers from attacking the pico base station gateway by first negotiating with the neighboring base station and then negotiating encryption for a secure channel with the pico base station gateway. Furthermore, after the pico base station gateway sends the security file, the pico base station requesting access configures itself, completes identity authentication, and establishes an encrypted channel, preventing hackers from simulating the pico base station to attack the network.

[0096] In step S45, after the encrypted channel (ie, the communication channel) is established, the pico base station dials into the intranet through the gateway VPDN, obtains the intranet address, negotiates with the network administrator, and then activates the pico base station.

[0097] Figure 5 Schematic diagram of the flow of pico base station signaling and service data flow according to an embodiment of the present invention, such as Figure 5 As shown in the figure, the flow of Pico base station signaling and service data flow is: Pico base station -> external network -> neighboring base station -> firewall -> aggregation switch -> gateway -> network management -> CE -> EPC core network.

[0098] Figure 6 FIG. 1 is a schematic diagram of neighboring cell authentication of a pico base station according to an embodiment of the present invention. Figure 6 As shown in the figure, neighbor cell authentication refers to the process of authenticating and authorizing a pico base station with its neighboring base stations (also known as neighboring cell base stations) to ensure that communications between them are legal and secure. Neighbor cell authentication ensures that communications between the pico base station and its neighboring base stations are encrypted and secure. Furthermore, the fact that neighboring cells are variable over a certain period of time increases the randomness of secure access and prevents unauthorized access and attacks. The neighbor cell authentication process ensures that the identities of both communicating parties are authentic and valid, thereby improving the reliability of the entire network. Pico base stations that have undergone neighbor cell authentication can better interoperate with other base stations, achieving seamless communication coverage and services.

[0099] According to an embodiment of the present invention, an embodiment of a networking device of a pico base station is also provided. It should be noted that the networking device of the pico base station can be used to execute the networking method of the pico base station in the embodiment of the present invention, and the networking method of the pico base station in the embodiment of the present invention can be executed in the networking device of the pico base station.

[0100] Figure 7 This is a schematic diagram of a pico base station networking device according to an embodiment of the present invention. Figure 1 ,like Figure 7 As shown, the device may include: a first sending module 72, used to send a request message to the neighboring base station of the pico base station to request access to the pico base station gateway, wherein the request message includes at least: request information for requesting access to the pico base station gateway, and verification information for security verification; a first receiving module 74, used to receive configuration information sent by the neighboring base station when the verification information passes the security verification, wherein the configuration information is generated by the authentication center based on the request information as the basis for accessing the pico base station gateway; a networking module 76, used to connect the pico base station to the pico base station gateway based on the configuration information.

[0101] It should be noted that the first sending module 72 in this embodiment can be used to execute step S102 in the embodiment of the present application, the first receiving module 74 in this embodiment can be used to execute step S104 in the embodiment of the present application, and the networking module 76 in this embodiment can be used to execute step S106 in the embodiment of the present application. The examples and application scenarios implemented by the above modules and corresponding steps are the same, but are not limited to the contents disclosed in the above embodiments.

[0102] In an embodiment of the present invention, when a pico base station requests to access a pico base station gateway, the trust relationship between the neighboring base station and the authentication center is utilized to perform security verification on the request message sent by the pico base station. Only when the security verification is passed will the request information of the pico base station be forwarded to the authentication center. The configuration information generated by the authentication center is then forwarded to the pico base station by the neighboring base station, ensuring that the process of the pico base station accessing the gateway is safe and reliable. By introducing the neighboring base station of the pico base station as a trust intermediary, not only illegal access is avoided, but also the complexity of direct communication between the pico base station and the authentication center is reduced, and the flexibility and efficiency of network deployment are improved. In the field of wireless communications, the scalability and security of the pico base station network can be ensured, thereby achieving the technical effect of improving the security of the pico base station networking, and further solving the technical problem of poor security in the traditional pico base station networking solution.

[0103] As an optional embodiment, the first sending module includes: an acquisition unit, used to obtain the gateway address of the pico base station gateway that the pico base station requests to access, wherein the gateway address is the unique hardware address of the pico base station gateway; a first generation unit, used to generate a request message based on the base station information and gateway address of the pico base station, wherein the base station information includes at least: the base station identity, base station address and verification information of the pico base station, and the base station address is the unique hardware address of the pico base station; the first sending unit, used to send a request message to the neighboring base station.

[0104] As an optional embodiment, the base station information also includes: security protocol information and encryption protocol information; the first generation unit includes: a first generation subunit, used to generate request information based on the base station identity, base station address and gateway address; a second generation subunit, used to generate verification information based on the security protocol information and encryption protocol information, wherein, when the security protocol information and the encryption protocol information both pass the security verification of the neighboring base station, it is determined that the verification information passes the security verification; a third generation subunit, used to generate a request message based on the request information and the verification information.

[0105] As an optional embodiment, the first sending module includes: a first identification unit, used to identify at least one candidate base station adjacent to the pico base station, wherein the candidate base station is a pico base station or a macro base station that has completed networking; a determination unit, used to determine a trusted base station among at least one candidate base station, wherein the trusted base station has the ability to communicate with the authentication center and perform security verification; a second sending unit, used to determine the trusted base station as a neighboring base station and send a request message to the neighboring base station.

[0106] As an optional embodiment, the networking module includes: a receiving unit, used to receive the configuration information sent by the neighboring base station to the pico base station, and detect whether the configuration information is encrypted by the authentication center, wherein the authentication center is also used to encrypt the configuration information using the public key corresponding to the pico base station; a decryption unit, used to decrypt the configuration information using the private key pre-configured by the pico base station, wherein the private key in the pico base station and the public key for the encrypted configuration information belong to the same key pair; a second generation unit, used to use the decrypted configuration information to negotiate with the pico base station gateway to generate a communication channel between the pico base station and the pico base station gateway, wherein the pico base station accesses the pico base station gateway based on the communication channel.

[0107] Figure 8 This is a schematic diagram of a pico base station networking device according to an embodiment of the present invention. Figure 2 ,like Figure 8As shown, the device may include: a second receiving module 82, which is used for the neighboring base station of the pico base station to receive a request message from the pico base station requesting access to the pico base station gateway, wherein the request message includes at least: request information for requesting access to the pico base station gateway, and verification information for security verification; a verification module 84, which is used for the neighboring base station to perform security verification on the verification information; a first forwarding module 86, which is used to forward the request information to the authentication center when the verification information passes the security verification, and receive configuration information generated by the authentication center based on the request information, wherein the configuration information serves as the basis for accessing the pico base station gateway; a second forwarding module 88, which is used to forward the configuration information to the pico base station, wherein the pico base station accesses the pico base station gateway based on the configuration information.

[0108] It should be noted that the second receiving module 82 in this embodiment can be used to execute step S202 in the embodiment of the present application, the verification module 84 in this embodiment can be used to execute step S204 in the embodiment of the present application, the first forwarding module 86 in this embodiment can be used to execute step S206 in the embodiment of the present application, and the second forwarding module 88 in this embodiment can be used to execute step S208 in the embodiment of the present application. The examples and application scenarios implemented by the above modules and corresponding steps are the same, but are not limited to the contents disclosed in the above embodiments.

[0109] In an embodiment of the present invention, when a pico base station requests to access a pico base station gateway, the trust relationship between the neighboring base station and the authentication center is utilized to perform security verification on the request message sent by the pico base station. Only when the security verification is passed will the request information of the pico base station be forwarded to the authentication center. The configuration information generated by the authentication center is then forwarded to the pico base station by the neighboring base station, ensuring that the process of the pico base station accessing the gateway is safe and reliable. By introducing the neighboring base station of the pico base station as a trust intermediary, not only illegal access is avoided, but also the complexity of direct communication between the pico base station and the authentication center is reduced, and the flexibility and efficiency of network deployment are improved. In the field of wireless communications, the scalability and security of the pico base station network can be ensured, thereby achieving the technical effect of improving the security of the pico base station networking, and further solving the technical problem of poor security in the traditional pico base station networking solution.

[0110] Figure 9 This is a schematic diagram of a pico base station networking device according to an embodiment of the present invention. Figure 3 ,like Figure 9As shown, the device may include: a third receiving module 92, which is used by the authentication center to receive the request information forwarded by the neighboring base station of the pico base station, wherein the neighboring base station is used to receive the request message of the pico base station requesting access to the pico base station gateway, and perform security verification on the verification information in the request message, and the request message also includes: request information requesting access to the pico base station gateway; a query module 94, which is used to query the configuration policy pre-registered by the pico base station based on the request information, and generate configuration information according to the configuration policy, wherein the configuration information serves as the basis for accessing the pico base station gateway; a second sending module 96, which is used to send configuration information to the neighboring base station, wherein the neighboring base station is also used to forward the configuration information to the pico base station, instructing the pico base station to access the pico base station gateway based on the configuration information.

[0111] It should be noted that the third receiving module 92 in this embodiment can be used to execute step S302 in the embodiment of the present application, the query module 94 in this embodiment can be used to execute step S304 in the embodiment of the present application, and the second sending module 96 in this embodiment can be used to execute step S306 in the embodiment of the present application. The examples and application scenarios implemented by the above modules and corresponding steps are the same, but are not limited to the contents disclosed in the above embodiments.

[0112] In an embodiment of the present invention, when a pico base station requests to access a pico base station gateway, the trust relationship between the neighboring base station and the authentication center is utilized to perform security verification on the request message sent by the pico base station. Only when the security verification is passed will the request information of the pico base station be forwarded to the authentication center. The configuration information generated by the authentication center is then forwarded to the pico base station by the neighboring base station, ensuring that the process of the pico base station accessing the gateway is safe and reliable. By introducing the neighboring base station of the pico base station as a trust intermediary, not only illegal access is avoided, but also the complexity of direct communication between the pico base station and the authentication center is reduced, and the flexibility and efficiency of network deployment are improved. In the field of wireless communications, the scalability and security of the pico base station network can be ensured, thereby achieving the technical effect of improving the security of the pico base station networking, and further solving the technical problem of poor security in the traditional pico base station networking solution.

[0113] As an optional embodiment, the query module includes: a second identification unit, used to identify the base station identity of the pico base station, the base station address of the pico base station, and the gateway address of the pico base station gateway from the request information, wherein the base station address is the unique hardware address of the pico base station, and the gateway address is the unique hardware address of the pico base station gateway; a query unit, which always queries the configuration policy corresponding to the base station identity from multiple configuration policies pre-stored in the authentication center; a third generation unit, which is used to generate configuration information for establishing a communication channel between the base station address and the gateway address based on the queried configuration policy, wherein the pico base station accesses the pico base station gateway based on the communication channel.

[0114] As an optional embodiment, the configuration strategy also includes: a public key corresponding to the pico base station; the device also includes: an encryption submodule, which is used to generate configuration information for establishing a communication channel between the base station address and the gateway address based on the queried configuration strategy, and then use the public key corresponding to the pico base station to encrypt the configuration information, wherein the pico base station includes: a pre-configured private key, the private key is at least used to decrypt the encrypted configuration information, and the private key in the pico base station and the public key of the encrypted configuration information belong to the same key pair.

[0115] An embodiment of the present invention may provide an electronic device, which may be a computer terminal, and the computer terminal may be any computer terminal device in a computer terminal group. Optionally, in this embodiment, the computer terminal may also be replaced by a terminal device such as a mobile terminal.

[0116] Optionally, in this embodiment, the computer terminal may be located in at least one network device among a plurality of network devices of a computer network.

[0117] In this embodiment, the above-mentioned computer terminal can execute the program code of the following steps in the networking method of the pico base station: sending a request message to the neighboring base station of the pico base station requesting access to the pico base station gateway, wherein the request message includes at least: request information for requesting access to the pico base station gateway, and verification information for security verification; receiving configuration information sent by the neighboring base station when the verification information passes the security verification, wherein the configuration information is generated by the authentication center based on the request information as the basis for accessing the pico base station gateway; and connecting the pico base station to the pico base station gateway based on the configuration information.

[0118] In this embodiment, the above-mentioned computer terminal can execute the program code of the following steps in the networking method of the pico base station: the neighboring base station of the pico base station receives the request message of the pico base station requesting access to the pico base station gateway, wherein the request message includes at least: request information requesting access to the pico base station gateway, and verification information for security verification; the neighboring base station performs security verification on the verification information; when the verification information passes the security verification, the request information is forwarded to the authentication center, and the configuration information generated by the authentication center based on the request information is received, wherein the configuration information serves as the basis for accessing the pico base station gateway; the configuration information is forwarded to the pico base station, wherein the pico base station accesses the pico base station gateway based on the configuration information.

[0119] In this embodiment, the above-mentioned computer terminal can execute the program code of the following steps in the networking method of the pico base station: the authentication center receives the request information forwarded by the neighboring base station of the pico base station, wherein the neighboring base station is used to receive the request message of the pico base station requesting access to the pico base station gateway, and perform security verification on the verification information in the request message, and the request message also includes: request information requesting access to the pico base station gateway; querying the configuration policy pre-registered by the pico base station based on the request information, and generating configuration information according to the configuration policy, wherein the configuration information serves as the basis for accessing the pico base station gateway; sending the configuration information to the neighboring base station, wherein the neighboring base station is also used to forward the configuration information to the pico base station, instructing the pico base station to access the pico base station gateway based on the configuration information.

[0120] Figure 10 is a structural block diagram of a computer terminal according to an embodiment of the present invention, such as Figure 10 As shown, the computer terminal 1000 may include: one or more (only one is shown in the figure) processors 1002 and a memory 1004.

[0121] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the networking method and device of the pico base station in the embodiment of the present invention. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implementing the above-mentioned networking method of the pico base station. The memory may include a high-speed random access memory and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely located relative to the processor, and these remote memories may be connected to the terminal 1000 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0122] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: sending a request message to the neighboring base station of the pico base station requesting access to the pico base station gateway, wherein the request message includes at least: request information for requesting access to the pico base station gateway, and verification information for security verification; receiving configuration information sent by the neighboring base station when the verification information passes the security verification, wherein the configuration information is generated by the authentication center based on the request information as the basis for accessing the pico base station gateway; and connecting the pico base station to the pico base station gateway based on the configuration information.

[0123] Optionally, the above-mentioned processor can also execute the program code of the following steps: obtaining the gateway address of the pico base station gateway that the pico base station requests to access, wherein the gateway address is the unique hardware address of the pico base station gateway; generating a request message based on the base station information and gateway address of the pico base station, wherein the base station information includes at least: the base station identity, base station address and verification information of the pico base station, and the base station address is the unique hardware address of the pico base station; sending a request message to the neighboring base station.

[0124] Optionally, the base station information also includes: security protocol information and encryption protocol information; the above-mentioned processor can also execute the program code of the following steps: generate request information based on the base station identity, base station address and gateway address; generate verification information based on the security protocol information and encryption protocol information, wherein, when the security protocol information and the encryption protocol information both pass the security verification of the neighboring base station, it is determined that the verification information passes the security verification; generate a request message based on the request information and the verification information.

[0125] Optionally, the processor can also execute the program code of the following steps: identifying at least one candidate base station adjacent to the pico base station, wherein the candidate base station is a pico base station or a macro base station that has completed networking; determining a trusted base station among at least one candidate base station, wherein the trusted base station has the ability to communicate with the authentication center and perform security verification; determining the trusted base station as a neighboring base station, and sending a request message to the neighboring base station.

[0126] Optionally, the above-mentioned processor can also execute the program code of the following steps: receiving configuration information sent by the neighboring base station to the pico base station, and detecting whether the configuration information is encrypted by the authentication center, wherein the authentication center is also used to encrypt the configuration information using the public key corresponding to the pico base station; using the private key pre-configured by the pico base station to decrypt the configuration information, wherein the private key in the pico base station and the public key for the encrypted configuration information belong to the same key pair; using the decrypted configuration information to negotiate with the pico base station gateway to generate a communication channel between the pico base station and the pico base station gateway, wherein the pico base station accesses the pico base station gateway based on the communication channel.

[0127] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: the neighboring base station of the pico base station receives the request message from the pico base station requesting access to the pico base station gateway, wherein the request message includes at least: request information requesting access to the pico base station gateway, and verification information for security verification; the neighboring base station performs security verification on the verification information; if the verification information passes the security verification, the request information is forwarded to the authentication center, and the configuration information generated by the authentication center based on the request information is received, wherein the configuration information serves as the basis for accessing the pico base station gateway; the configuration information is forwarded to the pico base station, wherein the pico base station accesses the pico base station gateway based on the configuration information.

[0128] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: the authentication center receives the request information forwarded by the neighboring base station of the pico base station, wherein the neighboring base station is used to receive the request message of the pico base station requesting access to the pico base station gateway, and perform security verification on the verification information in the request message, and the request message also includes: request information requesting access to the pico base station gateway; querying the configuration policy pre-registered by the pico base station based on the request information, and generating configuration information according to the configuration policy, wherein the configuration information serves as the basis for accessing the pico base station gateway; sending the configuration information to the neighboring base station, wherein the neighboring base station is also used to forward the configuration information to the pico base station, instructing the pico base station to access the pico base station gateway based on the configuration information.

[0129] Optionally, the above-mentioned processor can also execute the program code of the following steps: identifying the base station identity of the pico base station, the base station address of the pico base station, and the gateway address of the pico base station gateway from the request information, wherein the base station address is the unique hardware address of the pico base station, and the gateway address is the unique hardware address of the pico base station gateway; querying the configuration policy corresponding to the base station identity among the multiple configuration policies pre-stored in the authentication center; generating configuration information for establishing a communication channel between the base station address and the gateway address based on the queried configuration policy, wherein the pico base station accesses the pico base station gateway based on the communication channel.

[0130] Optionally, the configuration strategy also includes: the public key corresponding to the pico base station; the above-mentioned processor can also execute the program code of the following steps: use the public key corresponding to the pico base station to encrypt the configuration information, wherein the pico base station includes: a pre-configured private key, the private key is at least used to decrypt the encrypted configuration information, and the private key in the pico base station and the public key of the encrypted configuration information belong to the same key pair.

[0131] It can be understood by those skilled in the art that Figure 10 The structure shown is for illustration only, and the computer terminal may also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a handheld computer, a mobile Internet device (MID), a PAD, or other terminal devices. Figure 10 It does not limit the structure of the above electronic device. For example, the computer terminal 1000 may also include Figure 10 More or fewer components (such as network interfaces, display devices, etc.) shown in, or with Figure 10 Different configurations shown.

[0132] A person skilled in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a computer program. The computer program can be stored in a non-volatile medium. The non-volatile storage medium may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0133] The embodiment of the present invention further provides a non-volatile storage medium. Optionally, in this embodiment, the non-volatile storage medium can be used to store the program code executed by the pico base station networking method provided in the above embodiment.

[0134] Optionally, in this embodiment, the non-volatile storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.

[0135] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for executing the following steps: sending a request message to a neighboring base station of the pico base station requesting access to the pico base station gateway, wherein the request message includes at least: request information for requesting access to the pico base station gateway, and verification information for security verification; receiving configuration information sent by the neighboring base station when the verification information passes the security verification, wherein the configuration information is generated by the authentication center based on the request information as the basis for accessing the pico base station gateway; and connecting the pico base station to the pico base station gateway based on the configuration information.

[0136] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for executing the following steps: obtaining the gateway address of the pico base station gateway that the pico base station requests to access, wherein the gateway address is the unique hardware address of the pico base station gateway; generating a request message based on the base station information and gateway address of the pico base station, wherein the base station information includes at least: the base station identity, base station address and verification information of the pico base station, and the base station address is the unique hardware address of the pico base station; sending a request message to the neighboring base station.

[0137] Optionally, in this embodiment, the base station information also includes: security protocol information and encryption protocol information; the non-volatile storage medium is configured to store program code for executing the following steps: generating request information based on the base station identity, base station address and gateway address; generating verification information based on the security protocol information and encryption protocol information, wherein, when the security protocol information and the encryption protocol information both pass the security verification of the neighboring base station, it is determined that the verification information passes the security verification; and generating a request message based on the request information and the verification information.

[0138] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for executing the following steps: identifying at least one candidate base station adjacent to the pico base station, wherein the candidate base station is a pico base station or a macro base station that has completed networking; determining a trusted base station among at least one candidate base station, wherein the trusted base station has the ability to communicate with an authentication center and perform security verification; determining the trusted base station as a neighboring base station, and sending a request message to the neighboring base station.

[0139] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for executing the following steps: receiving configuration information sent by a neighboring base station to the pico base station, and detecting whether the configuration information is encrypted by an authentication center, wherein the authentication center is also used to encrypt the configuration information using a public key corresponding to the pico base station; decrypting the configuration information using a private key pre-configured by the pico base station, wherein the private key in the pico base station and the public key for the encrypted configuration information belong to the same key pair; using the decrypted configuration information to negotiate with the pico base station gateway to generate a communication channel between the pico base station and the pico base station gateway, wherein the pico base station accesses the pico base station gateway based on the communication channel.

[0140] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for executing the following steps: the neighboring base station of the pico base station receives a request message from the pico base station requesting access to the pico base station gateway, wherein the request message includes at least: request information requesting access to the pico base station gateway, and verification information for security verification; the neighboring base station performs security verification on the verification information; if the verification information passes the security verification, the request information is forwarded to the authentication center, and configuration information generated by the authentication center based on the request information is received, wherein the configuration information serves as the basis for accessing the pico base station gateway; the configuration information is forwarded to the pico base station, wherein the pico base station accesses the pico base station gateway based on the configuration information.

[0141] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for executing the following steps: the authentication center receives request information forwarded by a neighboring base station of the pico base station, wherein the neighboring base station is used to receive a request message from the pico base station requesting access to the pico base station gateway, and perform security verification on the verification information in the request message, and the request message also includes: request information requesting access to the pico base station gateway; querying the configuration policy pre-registered by the pico base station based on the request information, and generating configuration information according to the configuration policy, wherein the configuration information serves as the basis for accessing the pico base station gateway; sending the configuration information to the neighboring base station, wherein the neighboring base station is also used to forward the configuration information to the pico base station, instructing the pico base station to access the pico base station gateway based on the configuration information.

[0142] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for executing the following steps: identifying the base station identity of the pico base station, the base station address of the pico base station, and the gateway address of the pico base station gateway from the request information, wherein the base station address is the unique hardware address of the pico base station, and the gateway address is the unique hardware address of the pico base station gateway; querying the configuration policy corresponding to the base station identity among multiple configuration policies pre-stored in the authentication center; generating configuration information for establishing a communication channel between the base station address and the gateway address based on the queried configuration policy, wherein the pico base station accesses the pico base station gateway based on the communication channel.

[0143] Optionally, in this embodiment, the configuration strategy also includes: a public key corresponding to the pico base station; a non-volatile storage medium is configured to store program code for executing the following steps: using the public key corresponding to the pico base station to encrypt the configuration information, wherein the pico base station includes: a pre-configured private key, the private key is at least used to decrypt the encrypted configuration information, and the private key in the pico base station and the public key of the encrypted configuration information belong to the same key pair.

[0144] An embodiment of the present invention further provides a computer program product, including a computer program. Optionally, in this embodiment, when the computer program is executed by a processor, the steps of the method for networking pico base stations provided in the above embodiment are implemented.

[0145] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.

[0146] In the above embodiments of the present invention, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0147] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0148] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0149] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0150] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a non-volatile storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a non-volatile storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned non-volatile storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk and other media that can store program code.

[0151] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.

Claims

1. A method for networking pico base stations, characterized in that: include: Sending a request message to a neighboring base station of the pico base station requesting access to a pico base station gateway, wherein the request message includes at least: request information for requesting access to the pico base station gateway, and verification information for security verification; receiving configuration information sent by the neighboring cell base station when the verification information passes security verification, wherein the configuration information is used as a basis for accessing the pico base station gateway and is generated by the authentication center based on the request information; The pico base station is connected to the pico base station gateway based on the configuration information.

2. The method according to claim 1, characterized in that The request message sent to the neighboring base station of the pico base station to request access to the pico base station gateway includes: Obtaining a gateway address of the pico base station gateway that the pico base station requests to access, wherein the gateway address is a unique hardware address of the pico base station gateway; Generate the request message based on the base station information of the pico base station and the gateway address, wherein the base station information includes at least: the base station identity, base station address and verification information of the pico base station, and the base station address is the unique hardware address of the pico base station; Send the request message to the neighboring cell base station.

3. The method according to claim 2, characterized in that The base station information further includes: security protocol information and encryption protocol information; generating the request message according to the base station information of the pico base station and the gateway address includes: Generate request information according to the base station identity, the base station address and the gateway address; generating the verification information according to the security protocol information and the encryption protocol information, wherein, if both the security protocol information and the encryption protocol information pass the security verification of the neighboring cell base station, determining that the verification information passes the security verification; Generate the request message according to the request information and the verification information.

4. The method according to claim 1, wherein The request message sent to the neighboring base station of the pico base station to request access to the pico base station gateway includes: Identifying at least one candidate base station adjacent to the pico base station, wherein the candidate base station is a pico base station or a macro base station that has completed networking; Determining a trusted base station from at least one of the candidate base stations, wherein the trusted base station has the capability to communicate with the authentication center and perform security verification; The trusted base station is determined as the neighboring base station, and a request message is sent to the neighboring base station.

5. The method according to claim 1, wherein Connecting the pico base station to the pico base station gateway based on the configuration information includes: receiving the configuration information sent by the neighboring cell base station to the pico base station, and detecting whether the configuration information is encrypted by the authentication center, wherein the authentication center is further configured to encrypt the configuration information using a public key corresponding to the pico base station; Decrypting the configuration information using a private key pre-configured by the pico base station, wherein the private key in the pico base station and the public key used to encrypt the configuration information belong to the same key pair; The decrypted configuration information is used to negotiate with the pico base station gateway to generate a communication channel between the pico base station and the pico base station gateway, wherein the pico base station accesses the pico base station gateway based on the communication channel.

6. A method for networking pico base stations, characterized in that: include: A neighboring base station of the pico base station receives a request message from the pico base station requesting access to the pico base station gateway, wherein the request message includes at least: request information for requesting access to the pico base station gateway, and verification information for security verification; The neighboring cell base station performs security verification on the verification information; If the verification information passes the security verification, forwarding the request information to the authentication center, and receiving configuration information generated by the authentication center based on the request information, wherein the configuration information serves as a basis for accessing the pico base station gateway; The configuration information is forwarded to the pico base station, wherein the pico base station accesses the pico base station gateway according to the configuration information.

7. A method for networking pico base stations, characterized in that: include: The authentication center receives the request information forwarded by the neighboring base station of the pico base station, wherein the neighboring base station is used to receive the request message of the pico base station requesting access to the pico base station gateway, and perform security verification on the verification information in the request message, and the request message also includes: the request information requesting access to the pico base station gateway; Querying the configuration policy pre-registered by the pico base station according to the request information, and generating configuration information according to the configuration policy, wherein the configuration information serves as a basis for accessing the pico base station gateway; The configuration information is sent to the neighboring cell base station, wherein the neighboring cell base station is further used to forward the configuration information to the pico base station, instructing the pico base station to access the pico base station gateway according to the configuration information.

8. The method according to claim 7, characterized in that Querying the configuration policy pre-registered by the pico base station according to the request information, and generating configuration information according to the configuration policy includes: Identify the base station identity of the pico base station, the base station address of the pico base station, and the gateway address of the pico base station gateway from the request information, wherein the base station address is a unique hardware address of the pico base station, and the gateway address is a unique hardware address of the pico base station gateway; Querying the configuration policy corresponding to the base station identity among a plurality of configuration policies pre-stored in the authentication center; According to the configuration strategy obtained by querying, the configuration information for establishing a communication channel between the base station address and the gateway address is generated, wherein the pico base station accesses the pico base station gateway based on the communication channel.

9. The method according to claim 8, characterized in that The configuration strategy also includes: a public key corresponding to the pico base station; after generating the configuration information for establishing a communication channel between the base station address and the gateway address based on the queried configuration strategy, the method further includes: The configuration information is encrypted using the public key corresponding to the pico base station, wherein the pico base station includes: a pre-configured private key, the private key is at least used to decrypt the encrypted configuration information, and the private key in the pico base station and the public key for encrypting the configuration information belong to the same key pair.

10. A networking device for a pico base station, characterized in that: include: A first sending module is configured to send a request message requesting access to a pico base station gateway to a neighboring base station of the pico base station, wherein the request message includes at least: request information requesting access to the pico base station gateway and verification information for security verification; A first receiving module is configured to receive configuration information sent by the neighboring cell base station when the verification information passes security verification, wherein the configuration information is used as a basis for accessing the pico base station gateway and is generated by an authentication center based on the request information; A networking module is used to connect the pico base station to the pico base station gateway based on the configuration information.

11. A networking device for a pico base station, characterized in that: include: a second receiving module, configured to receive, by a neighboring base station of the pico base station, a request message from the pico base station requesting access to the pico base station gateway, wherein the request message includes at least: request information requesting access to the pico base station gateway, and verification information for security verification; A verification module, configured for the neighboring cell base station to perform security verification on the verification information; A first forwarding module is configured to forward the request information to an authentication center when the verification information passes the security verification, and receive configuration information generated by the authentication center based on the request information, wherein the configuration information serves as a basis for accessing the pico base station gateway; The second forwarding module is configured to forward the configuration information to the pico base station, wherein the pico base station accesses the pico base station gateway according to the configuration information.

12. A networking device for a pico base station, characterized in that: include: A third receiving module is configured to receive, by the authentication center, a request message forwarded by a neighboring base station of the pico base station, wherein the neighboring base station is configured to receive a request message from the pico base station requesting access to a pico base station gateway, and perform security verification on the verification information in the request message, wherein the request message further includes: the request information requesting access to the pico base station gateway; a query module, configured to query the configuration policy pre-registered by the pico base station based on the request information, and generate configuration information according to the configuration policy, wherein the configuration information serves as a basis for accessing the pico base station gateway; The second sending module is used to send the configuration information to the neighboring cell base station, wherein the neighboring cell base station is further used to forward the configuration information to the pico base station, instructing the pico base station to access the pico base station gateway according to the configuration information.

13. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to execute the pico base station networking method according to any one of claims 1 to 9 through the computer program.

14. A computer program product comprising computer instructions, characterized in that When the computer instructions are executed by the processor, the steps of the method for networking pico base stations described in any one of claims 1 to 9 are implemented.