Independent and persistent authentication of security and attestation zones in data communication network

By combining beamforming and imaging information with cluster controllers and utilizing AI/ML algorithms, the identity of user equipment can be verified and continuously proven in real time, solving the problem of user equipment vulnerability in data communication networks and realizing a more secure virtualized and containerized service environment.

CN120937402APending Publication Date: 2025-11-11DELL PROD LP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202380096546.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-04-01
Filing Date
2023-10-31
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

In data communication networks, the mobility of user devices makes their location and identity vulnerable to attacks. Existing technologies struggle to achieve effective authentication and continuous verification of user devices, especially in virtualized and containerized service environments, where man-in-the-middle attacks and targeted denial-of-service attacks are difficult to prevent.

Method used

By combining beamforming information and image information from imaging devices with the cluster controller, the identity of user equipment is verified and continuously proven in real time. Artificial intelligence/machine learning algorithms are used to predict obstacles and user movement within the RF coverage area, establish a security and verification zone, and identify and isolate unverified user equipment.

Benefits of technology

It improves the security of data communication networks, prevents spoofing attacks, ensures the security of virtualization and containerization services, enables continuous authentication and identity verification of user devices, reduces network connection interruptions, and optimizes data bandwidth allocation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120937402A_ABST
    Figure CN120937402A_ABST
Patent Text Reader

Abstract

A data communication network (100, 200) includes a data communication node (120), an imaging device (130), and an information handling system (110, 300). A data communication node (120) establishes a data connection with a user equipment device (160, 400, 402, 500, 502, 504) and provides beamforming information for the data connection. The imaging device provides image information for a coverage area of the data communication node (120). The information handling system (110, 300) receives the image information, determines that a data connection has been established with the user equipment device (160, 400, 402, 500, 502, 504), authenticates the user equipment device, associates a location of the user equipment device within the coverage area based on beamforming information of the data connection and based on the image information, verifies an identity of the user equipment device, and transmits the user equipment device to the user equipment device (160, 400, 402, 500, 502, 504). And establishing an attestation zone within the coverage area based on the attestation of the identity.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-reference to related applications This application claims priority to U.S. Patent Application No. 18 / 194,623, filed April 1, 2023, entitled “Independent and Continuous Verification of Security and Attestation Zones in a Data Communication Network,” which has been assigned to the current applicant of this application and is incorporated herein by reference in its entirety.

[0002] U.S. Patent Application No. 18 / 194,623 is a continuation-in-part of U.S. Patent Application No. 17 / 711,531, filed April 1, 2022, entitled “REAL-TIME 3DLOCATION SERVICE FOR DETERMINISTIC RF SIGNAL DELIVERY”, and a continuation-in-part of U.S. Patent Application No. 17 / 711,577, filed April 1, 2022, entitled “REAL-TIME 3D TOPOLOGY MAPPING FOR DETERMINISTIC RF SIGNALDELIVERY”, the entire disclosure of which is hereby expressly incorporated by reference.

[0003] The subject matter of co-pending U.S. Patent Application No. 18 / 194,626, filed April 1, 2023, entitled “USER EQUIPMENT DEVICE INTEGRITY PROTECTIONIN A DATA COMMUNICATION NETWORK,” is hereby incorporated by reference. Technical Field

[0004] This disclosure relates generally to communication systems, and more specifically to the independent and continuous verification of security and proof areas in data communication networks. Background Technology

[0005] As the value and use of information continue to grow, individuals and businesses seek additional ways to process and store information. One option is an information processing system. Information processing systems typically process, compile, store, and / or communicate information or data for business, personal, or other purposes. Because technology and information processing needs and requirements can vary across different applications, information processing systems can also vary in terms of what information is processed, how it is processed, how much information is processed, stored, or communicated, and how quickly and efficiently it can be processed, stored, or communicated. Variations in information processing systems allow them to be general-purpose or configured for specific users or purposes (such as financial transaction processing, scheduling, enterprise data storage, or global communications). Furthermore, information processing systems can include a variety of hardware and software resources that can be configured to process, store, and communicate information, and can include one or more computer systems, data storage systems, and networked systems. Summary of the Invention

[0006] A data communication network includes a data communication node and an imaging device. The data communication node establishes a data connection with a user equipment device and provides beamforming information for the data connection. The imaging device provides image information for the coverage area of ​​the data communication node. The network receives the image information, determines that a data connection has been established with the user equipment device, authenticates the user equipment device, associates the location of the user equipment device within the coverage area based on the beamforming information of the data connection and based on the image information, proves the identity of the user equipment device, and establishes an authentication zone within the coverage area based on the authentication of the identity. Attached Figure Description

[0007] It should be understood that, for the sake of simplicity and clarity, the elements shown in the accompanying drawings are not necessarily drawn to scale. For example, the dimensions of some elements are enlarged relative to others. The accompanying drawings illustrate and describe embodiments incorporating the teachings of this disclosure, in which: Figure 1 This is a block diagram illustrating a data communication network according to an embodiment of the present disclosure; Figure 2 It is shown Figure 1 A block diagram of the cluster controller for a data communication network; Figure 3 This is a block diagram illustrating a generalized information processing system according to another embodiment of the present disclosure; and Figure 4 and Figure 5 Various embodiments according to this disclosure are shown. Figure 1 Data communication network.

[0008] In different figures, the same reference numerals are used to indicate similar or identical items. Detailed Implementation

[0009] The following description, provided in conjunction with the accompanying drawings, aids in understanding the teachings disclosed herein. The discussion below focuses on specific implementations and embodiments of the teachings. This focus is intended to aid in describing the teachings and should not be construed as limiting the scope or applicability of the teachings. However, other teachings may of course be used in this application as well. These teachings may also be used in other applications and with several different types of architectures, such as distributed computing architectures, client / server architectures, or middleware server architectures, and associated resources.

[0010] Figure 1 A data communication network 100 is illustrated, comprising a cluster controller 110, one or more data communication nodes 120, and one or more imaging devices 130. The data communication network 100 represents a distributed communication network, such as a cellular network for communicating with a distributed group of user equipment (UEs) 160. For example, the data communication network 100 may represent a fifth-generation (5G) cellular network, a WiFi network, a wireless wide area network (WAN), or another type of data communication network. The UE 160 may represent a 5G-enabled mobile cellular device, an Internet of Things (IoT) device, a machine-to-machine interconnect device, etc. In a particular embodiment, the data communication node 120 represents a cellular communication node and is operated, managed, and maintained according to a specific cellular infrastructure standard, such as the General Public Radio Interface (CPRI) standard, wherein the data communication node includes: a radio equipment (RE) component configured to provide wireless data communication according to a specific radio data protocol; and a radio equipment control (REC) component configured to control the RE and provide connectivity to a wider cellular data network infrastructure.

[0011] Details of data communication via data communication networks, and particularly wireless communication via, for example, cellular data communication networks, are known in the art and will not be described further herein unless required to illustrate the current implementation. UE 160 may refer to any device configured to communicate within data communication network 100 and, in particular, with node 120. For example, UE 160 may include a mobile phone, tablet device, computer device (such as a laptop or desktop computer), mobile device (such as a vehicle-based communication system), IoT device, etc.

[0012] Each node 120 is connected to a cluster controller 110. Here, the cluster controller 110 operates to provide monitoring, management, and maintenance services to the nodes 120 as needed or desired. The cluster controller 110 can be understood as being located near the nodes 120, or as being located at the central location of the data communication network 100 (such as a data center associated with the data communication network), and the functions and features of the cluster controller can be performed as needed or desired by a single public information processing system, or by one or more distributed information processing systems. Monitoring, management, and maintenance of data communication networks are known in the art and will not be further described herein unless required to illustrate the current implementation.

[0013] The data communication network 100 is configured such that one or more of the nodes 120 include an integrated or stand-alone imaging device 130. The data communication network 100 is also configured to include one or more additional imaging devices 130 that are not directly associated with any particular node but operate in stand-alone capacity. Whether associated with a node or operating as a stand-alone device, the imaging device 130 refers to a device positioned and configured to provide still images and video surveillance of the RF coverage area of ​​the data communication network 100. The imaging device 130 may include visible light detection devices, invisible light detection devices (such as infrared cameras, lidar systems, etc.), radar imaging devices, acoustic imaging devices, or other types of devices that can be used to generate topology information, as described below. In either case, the cluster controller 110 operates to provide monitoring, management, and maintenance services to the imaging device 130 as needed or desired.

[0014] In a particular embodiment, cluster controller 110 operates to receive image information from the field of view of imaging device 130 and RF coverage information from node 120. Cluster controller 110 uses the image information and RF coverage information to synthesize a 3D map of the physical topology of the RF coverage area of ​​data communication network 100. Cluster controller 110 then associates the connection status of node 120 with various components of UE 160 connected to data communication network 100 within the field of view of each of the imaging devices with the 3D map of the physical topology of the RF coverage area. Specifically, cluster controller 110 determines when a particular component of UE 160 experiences weakened or disconnected connectivity and associates the location where the UE experiences weakened or disconnected connectivity with the 3D map of the physical topology of the RF coverage area. In this way, cluster controller 110 operates to identify features 150 within the 3D map of the physical topology of the RF coverage area that may weaken or block the connection between a particular node 120 and UE 160.

[0015] For example, the cluster controller 110 may operate to determine that a particular node 120 is not currently connected to the UE 160, and associate image information provided by imaging devices 130 within the RF coverage area of ​​that node, including any imaging devices associated with the node and any independent imaging devices that cover the RF coverage area of ​​the node as their field of view. In this way, the cluster controller 110 can synthesize a 3D map of the RF coverage area of ​​each of the nodes 120 into a 3D map of feature 150 within the RF coverage area of ​​the data communication network 100.

[0016] When a specific component of UE 160 is connected to a specific node 120, this connection is maintained by said node until a time when the connection is interrupted, such as when the UE moves out of the node's range or enters the node's coverage blind spot. However, node 120 typically does not know when the connection is lost, and when a component of UE 160 loses coverage, the UE typically initiates a process to initiate other connection options with the first node 120 or establish a new connection with another node 120. That is, from the node's perspective, the connection between UE 160 and node 120 is typically reactive. However, from the UE 160's perspective, this reactive approach can lead to poor performance because of the poor link performance between detecting the loss of connection with the first node 120 and establishing a new connection with the second node 120.

[0017] When establishing and maintaining the connection between the components of node 120 and UE 160, a typical node in a data communication network will utilize a multiple-input multiple-output (MIMO) antenna array to provide communication signals to the UE, and will attempt to provide the communication signals by beamforming the signal with the antenna array to maximize the signal strength received by the UE, while minimizing the node's power output to the communication signal. The node may employ various algorithms and feedback from the UE to adjust the beamforming activity to maintain optimal signal strength between the node and the UE. Details regarding the establishment, maintenance, and optimization of data communication connections between nodes in a data communication network and UEs within the data communication network are known in the art and will not be further described herein unless required to illustrate the current implementation.

[0018] In a particular implementation, the cluster controller 110 operates to correlate image information from the imaging device 130 with beamforming information from the node 120 to identify and manage connection targets between the node and various UEs 160 within the RF coverage area of ​​the data communication network 100. The cluster controller 110 also utilizes motion information to predict the future movement of the UEs 160 within the data communication network 100.

[0019] The cluster controller 110 operates to proactively guide nodes 120 associated with specific components of UE 160 to provide beamforming parameters to improve communication signals to the UE and increase the efficiency of node delivery of communication signals to the UE. Furthermore, utilizing a 3D map of the RF coverage area of ​​node 120, the cluster controller 110 operates to predict when components of UE 160 will enter the blind zone or high attenuation zone of a specific node and proactively switches communication with that UE to another node with a suitable RF path to that UE. In this way, degradation of the connection between components of UE 160 and the data communication network 100 is mitigated, and the user may not experience coverage interruptions because the data communication network 100 proactively manages the connection between node 120 and UE 160 by changing beamforming parameters.

[0020] In another implementation, cluster controller 110 operates to proactively allocate data bandwidth among nodes 120 based on spatial insights from visual information. For example, if the RF coverage area of ​​a particular node 120 appears to be sparsely populated by UEs 160, while another node appears to be densely populated by UEs, cluster controller 110 may operate to allocate more data bandwidth to the densely populated node (if there is still a line of sight to be directed to the UEs associated with the densely populated node). Furthermore, based on historical information, future bandwidth may be prepared for other nodes 120 within the data communication network 100. For example, consider an event venue that is empty after an event. It should be understood that UEs 160 associated with event participants may expect to move from the event venue to a nearby parking garage and then to an adjacent road, and cluster controller 110 may operate to shift backend data bandwidth to the core network between the associated nodes 120 near the venue, the parking garage, and the adjacent road to meet the expected usage pattern. In another implementation, cluster controller 110 operates to associate a user of a particular UE 160 with its associated Service Level Agreement (SLA) and allocate data bandwidth to the UE accordingly.

[0021] In a particular implementation, cluster controller 110 utilizes artificial intelligence / machine learning (AI / ML) algorithms to analyze image information for monitoring and maintaining a 3D map. For example, while feature 150 can generally be understood as representing a fixed feature, such as a building or other fixed signal obstruction, using AI / ML algorithms, cluster controller 110 can add real-time RF path obstacles to the 3D map of the RF coverage area of ​​node 120. Consider a large moving obstacle (such as a bus or large truck) moving through the RF coverage area of ​​a particular node 120. Cluster controller 110 is operable to improve real-time maintenance of the connection, such as blind spot detection, rapidly changing RF environments, and beamforming activities, to better account for moving obstacles in the RF path. It should be further understood that other real-time RF path obstacles, such as human bodies or animals within the 3D map, can be identified. Furthermore, using AI / ML algorithms, cluster controller 110 is operable to predict processing needs for the RF coverage area of ​​node 120 and increase or decrease backend processing power to meet changing demand conditions.

[0022] As described herein, the functions and features of cluster controller 110 may be instantiated in hardware, in software or code, or in a combination of hardware and code configured to perform the described functions and features. Furthermore, the functions and features may be provided at a single location or by a single device (such as an information processing system), or by two or more devices (such as two or more information processing systems) at two or more locations. One or more of the functions and features described herein may each be performed by different information processing systems, and any particular function or feature may be distributed across two or more information processing systems as needed or desired. Furthermore, as described herein, the functions and features of cluster controller 110 can be understood as being provided at any network level as needed or desired.

[0023] For example, if the data communication network 100 comprises separate groups of nodes 120, each group routing through a common access switch, where data flows from the separate access switch groups are aggregated by a common aggregator, and where the processing needs of the aggregator groups are handled by the core data processing network, then the functionality and features of the cluster controller 110 may be provided, as needed or desired, by one or more of the access switches, aggregators, or the core network. Therefore, it might be considered desirable to perform graph synthesis at the core network, where access times are typically longer but data processing capabilities are typically greater, while it might be considered desirable to perform UE motion tracking and connection handover at a processing level closer to the nodes, where access times are typically shorter.

[0024] Figure 2The cluster controller 110 is shown in more detail. The cluster controller 110 is configured to receive imaging input 210 from the imaging device 130. The cluster controller 110 operates to process the imaging input and control the operation of nodes in the data communication network 100, which includes node 120. The cluster controller 110 further operates to provide nodes with pre-configuration 230, resource tracking 232 for UEs within the data communication network 100, including UE 160, and RF power management 234 for the nodes.

[0025] Imaging input 210 represents the output from imaging device 130 and may include any still or moving imaging format as may be known in the art, including proprietary still or moving imaging formats. When a particular imaging device 130 is configured to capture still images (i.e., camera devices), the images will be understood as being received by the cluster controller based on various timestamps (t0, t1, t2, ...) associated with the actual time of still image capture. Still image imaging device 130 may be configured to capture images at a predetermined timetable, such as every five seconds or every ten seconds, or may be configured to capture images based on various inputs of the imaging device (such as based on motion sensors, etc.). Video image imaging device may be configured to provide continuous streaming video images, or may be configured to provide video images based on various timestamps (t0, t1, t2, ...). As needed or desired, imaging device 130 may be configured to capture images in the visible light spectrum, in the near-visible light spectrum, or in other invisible light spectra.

[0026] The cluster controller 110 includes a graph synthesis module 220, a motion prediction module 222, a blind spot prediction module 224, an RF coverage mapping module 226, and an optimization / learning module 228. The graph synthesis module 220 receives imaging input 210 and synthesizes a 3D graph of the RF coverage area of ​​the data communication network 100 as described above. It should be understood here that inputs from two or more imaging devices 130 will be used to synthesize a 3D graph of the RF coverage area of ​​the data communication network 100, and the more imaging device inputs received by the cluster controller 110, the better and more accurate the 3D graph synthesized by the graph synthesis module 220 will be. The cluster controller 110 also receives coverage information from nodes 120. For example, the cluster controller 110 may receive an RF signal strength map 226 of the RF coverage area associated with each node 120, including default beamforming settings, coverage angle, RF signal power settings, etc. Here, the blind spot prediction module 224 operates to associate the synthesized 3D map with the received coverage information to generate a baseline RF coverage map, which predicts the presence of feature 150, which is understood to present obstacles that attenuate the RF signal between node 120 and UE 160.

[0027] In a particular implementation, the baseline RF coverage map is synthesized based on real-time information from imaging device 130. Specifically, it should be understood that a particular RF coverage area of ​​a particular node 120 may be continuously filled by one or more UEs 160 and other objects within the field of view of imaging device 130, which may make the generation of the baseline RF coverage map difficult. However, here, the graph synthesis module 220 may utilize the optimization / learning module 228 to create a baseline RF coverage map based on responses learned from the RF coverage area, assuming that the RF coverage area is completely free of UEs 160 and other objects. Furthermore, the graph synthesis module 220 operates to periodically update the baseline RF coverage map based on changing conditions within the RF coverage area. For example, if the RF coverage area represents an activity area, the presence of a moving truck in the loading / unloading area may represent a temporary obstacle within the coverage area of ​​node 120's line of sight to the loading / unloading area. Or, if the RF coverage area represents an office space, the reorganization of cubicles within the office space may affect the updated coverage map of the office area.

[0028] The cluster controller 110 also utilizes artificial intelligence / machine learning (AI / ML) algorithms embodied in the optimization / learning module 228 to analyze image information to monitor and maintain the baseline RF coverage map. For example, while feature 150 can generally be understood as representing fixed or semi-permanent features, such as buildings, parked vehicles, or other fixed signal obstacles, using AI / ML algorithms, the cluster controller 110 can add real-time RF path obstacles to the baseline RF coverage map of the RF coverage area of ​​node 120. Consider large moving obstacles (such as buses or large trucks) moving through the RF coverage area of ​​a particular node 120. The cluster controller 110 is operable to improve real-time maintenance of the connection, such as blind spot detection, rapidly changing RF environments, and beamforming activities, to better account for moving obstacles in the RF path. Furthermore, using AI / ML algorithms, the cluster controller 110 is operable to predict processing needs for the RF coverage area of ​​node 120 and increase or decrease backend processing power to meet changing demand conditions.

[0029] This baseline RF coverage map can be utilized in conjunction with the movement of objects within the RF coverage area, as determined by the motion prediction module 222. Therefore, the movement of vehicles, people, etc., through the RF coverage area can be predicted. The motion detection module 222 further operates to identify the speed and trajectory of objects, thereby distinguishing people from vehicles or other objects within the RF coverage area. Then, based on graph information from the graph synthesis module 220 and object and motion information from the object detection module 222, the blind spot prediction module 224 operates to predict the coverage blind spot of each of the nodes 120. The blind spot can be combined with information from the predetermined RF coverage map module 226 to predict the real-time blind spot of each of the nodes 120.

[0030] Returning to motion prediction module 222, the movement of objects through the RF coverage area of ​​node 120 is combined with information related to the beamforming state of UE 160 within the RF coverage area of ​​each node. Motion prediction module 222 further operates to identify objects associated with the user of UE 160 within the RF coverage area of ​​each node 120, as well as the user's speed and trajectory. Blind spot prediction module 224 further operates to associate the movement of UE 160 with the identified blind spots to determine in advance when a particular UE is expected to lose connection with a particular node 120, and further operates to determine the next optimal node to take over the UE. Optimization / learning module 228 utilizes various AI / ML algorithms to better predict the occurrence of signal blocking obstacles and the expected movement of the user of connected UE 160. As described above, cluster controller 110 ultimately operates to guide the activity of node 120 to proactively maintain optimal connectivity for UEs within the RF coverage area of ​​data communication network 100 by implementing node pre-configuration 230, UE resource tracking 232, and RF power management.

[0031] Figure 4 The data communication network 100 is illustrated at time (t3) when two (2) UEs 400 and 402 are present within the coverage area provided by node 120. The inventors of this disclosure understand that the use of virtualized and containerized services within data communication networks is rapidly increasing. However, the environments in which such virtualized and containerized services are generated (typically data centers or other tightly controlled hardware environments) limit the ability of malicious actors to attack these services. For example, typical man-in-the-middle (MitM) attacks or directed denial-of-service (DDoS) attacks typically require some unprotected hardware components as attack vectors, and data center equipment is generally not a good vector for such attacks. On the other hand, typical data communication networks that utilize UE devices (such as cellular networks or other wireless networks) are favored due to the mobility provided by the UE devices. A negative byproduct of such mobility is that the inherent mobility means that the location and therefore the identity of the UE device are vulnerable to attack.

[0032] In a particular implementation, the cluster controller 110 operates to verify the authenticity of a UE device within the coverage area of ​​the data communication network 100 based on location information of the UE device derived from a combination of beamforming information between the UE device and node 120 and image information from imaging device 130. Specifically, the cluster controller 110 operates to authenticate UE 400 and then associates the beamforming information between node 120 and the UE with image information placing the UE within a 3D map of the coverage area. Initial authentication of UE 400 can be provided by any authentication mechanism known in the art, and such mechanisms will not be further described herein unless necessary to illustrate the current implementation.

[0033] Once UE 400 is authenticated, cluster controller 110 operates to continuously verify UE 400's authentication status based on the persistent association between beamforming information and image information, even as the UE moves within the coverage area of ​​data communication network 100. Specifically, when UE 400 transfers a data communication connection from a first node in node 120 and subsequently establishes a data communication connection with a second node in node 120, cluster controller 110 maintains verification of the UE's authentication status based on the persistent association between beamforming information and image information. As another mechanism for verifying UE 400's authentication status, cluster controller 110 can operate to provide more unique identification information about UE 400 and, in particular, the identity of people, vehicles, etc., associated with that UE. For example, image information may be used by cluster controller 110 to identify the user's facial features, vehicle brand / model and color, or other information used to identify the user of the UE, as needed or desired.

[0034] Based on the authentication status of UE 400, cluster controller 110 operates to detect and identify malicious activities attempting to impersonate the authentication status of UE 400. For example, when UE 402 attempts to impersonate UE 400, cluster controller 110 operates to correlate beamforming information between the UE and node 120 with image information from imaging device 130 to determine, for example, that UE 402 has not been proven to be the authenticated UE 400. Under normal circumstances, UE 402 would be understood as representing its own authenticated status, which is proven by cluster controller 110. However, if UE 402 attempts to impersonate UE 400, the authentication of UE 400 based on beamforming information and image information will easily identify UE 402's attempt as an attempt to intrude into UE 400, and such impersonation attempts will be rejected by cluster controller 110 as malicious data traffic.

[0035] Therefore, the verification of the authentication status of UEs within the coverage area of ​​the data communication network 100 provides a more secure computing environment, thereby allowing for greater use of virtualization and containerized services within the data communication network. Furthermore, since UEs attempting to impersonate the authentication status of a verified UE (such as UE 402) can be easily identified based on beamforming information and image information, suspicious UEs can be located and identified. In the first scenario, when a malicious actor possesses a suspicious UE, the identity of the malicious actor can be determined based on image information, and subsequently, even if the malicious actor reverts to a verified UE, the malicious actor can be tracked and apprehended. In the second scenario, when a malicious actor hijacks an innocent UE, an alert can be provided to the hijacked UE, as needed or desired, indicating that the UE has been hijacked and requires malware removal.

[0036] Figure 5 A data communication network 100 is illustrated at time (t4) when four (4) UEs 400, 500, 502, and 504 are present within the coverage area provided by node 120. The authentication status of UEs 500, 502, and 504 is verified by cluster controller 110 based on beamforming information between the UE and node 120 and imaging device 130, similar to UE 400, as described above. In certain cases, UEs 400, 500, 502, and 504 are themselves verified UEs, and the security provided to verified UEs as described above is provided to these UEs.

[0037] In another scenario, cluster controller 110 operates to establish an enterprise security and authentication zone 510, which authenticates UEs 400, 500, 502, and 504 as a group. Specifically, cluster controller 110 handles data communication between UEs 400, 500, 502, and 504 within the security and authentication zone 510, which functions as a secure room such as a Sensitive Compartment Information Facility (SCIF). The security and authentication zone 510 can be understood as representing a virtual SCIF that can be easily established based on the authentication of UEs 400, 500, 502, and 504.

[0038] A typical SCIF is provided based on a verified location within which confidential information can be freely distributed and viewed. In this regard, the security of certain data transmitted within the Security and Verification Zone 510 may require additional security features and characteristics instantiated on UEs 400, 500, 502, and 504. However, such additional security features and characteristics are known in the art and will not be described further herein unless necessary to illustrate the current implementation.

[0039] In a particular implementation, the security and certification zone 510 is established based on the certification of UEs 400, 500, 502, and 504, as described above, and the security and certification zone can be understood as being independent of the physical characteristics of the 3D map of the coverage area. In other words, the security and certification zone 510 can be understood as representing multiple security and certification islands, each associated with a different UE. Therefore, any location where a particular UE moves within the 3D map of the coverage area constitutes part of the security and certification zone 510.

[0040] In another implementation, the security and authentication zone 510 is established based on a portion of a 3D map of the coverage area. For example, an entity or organization may use this to establish physical security around a portion of the 3D map of the coverage area based on its own criteria. In this implementation, the cluster controller 110 operates to associate that portion of the 3D map as the security and authentication zone 510. Then, in a first case, based on the understanding that the entity or organization is controlling access to the security and authentication zone, any UE granted access to the security and authentication zone 510 can be classified as an authenticated UE. In another case, a UE can be authenticated individually and, upon entering the security and authentication zone 510, can be allowed to join a group of UEs associated with the security and authentication zone. Then, if any unauthenticated UE is detected within the security and authentication zone 510, the cluster controller 110 operates to isolate such unauthenticated UEs. For example, the cluster controller 110 may operate to disconnect data communication connections with unauthenticated UEs, prevent the establishment of data communication connections with unauthenticated UEs, identify the presence of unauthenticated UEs to relevant authorities, etc. In a particular implementation, when the cluster controller 110 detects a data communication connection with an uncertified UE, the cluster controller operates to provide an indication that the uncertified UE has entered the security and certification zone 510, such as by notifying the entity or agency controlling access to the security and certification zone, and by severing the data communication link with the uncertified UE to minimize any chance of security or data breaches.

[0041] Virtual SCIFs can be used within existing data communication networks (such as data communication network 100) by establishing a security and authentication zone 510. Alternatively, data communication networks can be rapidly established as needed or desired to provide coverage for various emergency operations, such as disaster relief, emergency response, law enforcement, and military operations. As needed or desired, relevant departments (emergency services, police, fire responders, military departments, etc.) can place nodes 120 and imaging devices 130 in appropriate locations to form temporary data communication networks to cover emergency operations.

[0042] As described in various embodiments of this disclosure, examples of rendering a 3D map of the physical topology may include associating multiple imaging inputs 210 using neural radiation field (NeRF) algorithms, structure-of-motion (SfM) algorithms, etc.

[0043] Figure 3 A generalized embodiment of an information processing system 300 is illustrated. For the purposes of this disclosure, the information processing system may include any tool or set of tools that can be used to calculate, classify, process, transmit, receive, retrieve, initiate, convert, store, display, indicate, detect, record, reproduce, dispose of, or utilize information, intelligence, or data of any form for commercial, scientific, control, entertainment, or other purposes. For example, the information processing system 300 may be a personal computer, laptop computer, smartphone, tablet device, or other consumer electronic device, web server, network storage device, switching router, or other network communication device, or any other suitable device, and may vary in size, shape, performance, functionality, and price. Furthermore, the information processing system 300 may include processing resources for executing machine-executable code, such as a central processing unit (CPU), a programmable logic array (PLA), an embedded device (such as a system-on-a-chip (SoC)), or other control logic hardware. The information processing system 300 may also include one or more computer-readable media for storing machine-executable code such as software or data. Additional components of the information processing system 300 may include one or more storage devices for storing machine-executable code, one or more communication ports for communicating with external devices, and various input and output (I / O) devices, such as a keyboard, mouse, and video display. The information processing system 300 may also include one or more buses operable to transfer information between various hardware components.

[0044] Information processing system 300 may include one or more of the means or modules described below, and operates to perform one or more of the methods described below. Information processing system 300 includes processors 302 and 304, input / output (I / O) interfaces 310, memory 320 and 325, a graphics interface 330, a Basic Input / Output System / General Purpose Extensible Firmware Interface (BIOS / UEFI) module 340, a disk controller 350, a hard disk drive (HDD) 354, an optical disk drive (ODD) 356, a disk emulator 360 connected to an external solid-state drive (SSD) 364, an I / O bridge 370, one or more expansion resources 374, a Trusted Platform Module (TPM) 376, a network interface 380, a management device 390, and a power supply 395. Processors 302 and 304, I / O interface 310, memory 320 and 325, graphics interface 330, BIOS / UEFI module 340, disk controller 350, HDD 354, ODD 356, disk emulator 360, SSD 364, I / O bridge 370, expansion resources 374, TPM 376, and network interface 380 work together to provide the host environment for information processing system 300, which operates to provide data processing functions for the information processing system. The host environment operates to execute machine-executable code, including platform BIOS / UEFI code, device firmware, operating system code, applications, programs, etc., to perform data processing tasks associated with information processing system 300.

[0045] In a host environment, processor 302 is connected to I / O interface 310 via processor interface 306, while processor 304 is connected to I / O interface 308. Memory 320 is connected to processor 302 via memory interface 322. Memory 325 is connected to processor 304 via memory interface 327. Graphics interface 330 is connected to I / O interface 310 via graphics interface 332 and provides video display output 335 to video display 334. In a particular embodiment, information processing system 300 includes separate memory dedicated to each of processors 302 and 304 via separate memory interfaces. Examples of memories 320 and 325 include random access memory (RAM) such as static RAM (SRAM), dynamic RAM (DRAM), non-volatile RAM (NV-RAM), etc.), read-only memory (ROM), another type of memory, or combinations thereof.

[0046] The BIOS / UEFI module 340, disk controller 350, and I / O bridge 370 are connected to the I / O interface 310 via I / O channel 312. Examples of I / O channels 312 include Peripheral Component Interconnect (PCI) interfaces, extended PCI (PCI-X) interfaces, high-speed PCI-Express (PCIe) interfaces, other industry-standard or proprietary communication interfaces, or combinations thereof. The I / O interface 310 may also include one or more other I / O interfaces, including Industry Standard Architecture (ISA) interfaces, Small Computer Serial Interface (SCSI) interfaces, and Inter-Integrated Circuit (I / O) interfaces. 2 C) Interfaces such as System Packet Interface (SPI), Universal Serial Bus (USB), another interface, or combinations thereof. The BIOS / UEFI module 340 includes BIOS / UEFI code operable to detect resources within the information processing system 300, provide drivers for the resources, initialize the resources, and access the resources. The BIOS / UEFI module 340 includes code operable to detect resources within the information processing system 300, provide drivers for the resources, initialize the resources, and access the resources.

[0047] Disk controller 350 includes disk interface 352 that connects the disk controller to HDD 354, ODD 356, and disk emulator 360. Examples of disk interface 352 include Integrated Drive Electronics (IDE) interface, Advanced Technology Accessories (ATA) interface (such as Parallel ATA (PATA) or Serial ATA (SATA) interface), SCSI interface, USB interface, proprietary interface, or combinations thereof. Disk emulator 360 allows SSD 364 to be connected to information processing system 300 via external interface 362. Examples of external interface 362 include USB interface, IEEE 1394 (FireWire) interface, proprietary interface, or combinations thereof. Alternatively, solid-state drive 364 may be located within information processing system 300.

[0048] I / O bridge 370 includes peripheral interface 372 that connects the I / O bridge to expansion resource 374, TPM 376, and network interface 380. Peripheral interface 372 can be the same type of interface as I / O channel 312, or it can be a different type of interface. Therefore, when peripheral interface 372 and I / O channel 312 are of the same type, I / O bridge 370 expands the capability of the I / O channel; when they are of different types, I / O bridge converts information from a format suitable for the I / O channel to a format suitable for peripheral channel 372. Expansion resource 374 may include a data storage system, an additional graphics interface, a network interface card (NIC), a voice / video processing card, another expansion resource, or a combination thereof. Expansion resource 374 may be located on a main circuit board, on a separate circuit board or expansion card disposed within the information processing system 300, on a device external to the information processing system, or a combination thereof.

[0049] Network interface 380 refers to a NIC, which is located within information processing system 300, on the main circuit board of the information processing system, integrated into another component such as I / O interface 310, located in another suitable location, or a combination thereof. Network interface device 380 includes network channels 382 and 384, which provide interfaces to devices external to information processing system 300. In certain embodiments, network channels 382 and 384 are of a different type from peripheral channel 372, and network interface 380 converts information from a format suitable for the peripheral channel to a format suitable for external devices. Examples of network channels 382 and 384 include InfiniBand channels, Fibre Channel-type channels, Gigabit Ethernet channels, proprietary channel architectures, or combinations thereof. Network channels 382 and 384 can connect to external network resources (not shown). These network resources may include another information processing system, a data storage system, another network, a grid management system, another suitable resource, or a combination thereof.

[0050] Management device 390 refers to one or more processing devices, such as a dedicated backplane management controller (BMC), a system-on-a-chip (SoC) device, one or more associated memory devices, one or more network interface devices, a complex programmable logic device (CPLD), etc., that operate together to provide a management environment for information processing system 300. Specifically, management device 390 connects to various components of the host environment via various internal communication interfaces, such as low pin count (LPC) interfaces, inter-integrated circuit (I2C) interfaces, PCIe interfaces, etc., to provide out-of-band (OOB) mechanisms for retrieving information related to the operation of the host environment, providing BIOS / UEFI or system firmware updates, and managing non-processing components of information processing system 300 (such as system cooling fans and power supplies). Management device 390 may include a network connection to an external management system, and the management device may communicate with the management system to report status information of information processing system 300, receive BIOS / UEFI or system firmware updates, or perform other tasks for managing and controlling the operation of information processing system 300. Management device 390 can operate outside the power plane of components in the host environment, allowing it to receive power to manage information processing system 300 when the information processing system is otherwise shut down. Examples of management device 390 include commercially available BMC products or other devices operating according to the Intelligent Platform Management Initiative (IPMI) specification, Web Services Management (WSMan) interface, Redfish application programming interface (API), another Distributed Management Task Force (DMTF), or other management standards, and may include integrated Dell Remote Access Controller (iDRAC), embedded controllers (EC), etc. Management device 390 may also include associated memory devices, logic devices, security devices, etc., as needed or desired.

[0051] Although only a few exemplary embodiments have been described in detail herein, those skilled in the art will readily recognize that many modifications may be made to the exemplary embodiments without substantially departing from the novel teachings and advantages of the embodiments of this disclosure. Therefore, all such modifications are intended to be included within the scope of the embodiments of this disclosure as defined in the appended claims. In the claims, the entries for "means plus function" are intended to cover structures described herein as performing the described functions, and not only structural equivalents but also equivalent structures.

[0052] The subject matter disclosed above should be considered illustrative rather than restrictive, and the appended claims are intended to cover any and all such modifications, enhancements, and other embodiments falling within the scope of this invention. Therefore, to the fullest extent permitted by law, the scope of this invention is determined by the broadest possible interpretation of the appended claims and their equivalents, and should not be construed as limited by the foregoing detailed description.

Claims

1. A data communication network (100, 200), comprising: A data communication node (120) is configured to establish a data connection with each of a plurality of user equipment devices (160, 400, 402, 500, 502, 504) within the coverage area of ​​the data communication node (120), and for each data connection, provide beamforming information for each data connection, the beamforming information identifying the location of the associated user equipment device within the coverage area; Multiple imaging devices (130) are configured to provide image information for the covered area; as well as An information processing system (110, 300), coupled to the data communication node (120) and the imaging device (130), wherein the information processing system (110, 300) is configured to receive the image information, determine that the data communication node (120) has established a first data connection with a first user equipment device (160, 400, 402, 500, 502, 504), authenticate the first user equipment device, associate a first location of the first user equipment device within the coverage area based on first beamforming information of the first data connection and based on the image information, and based on the first location... The association is used to prove the first identity of the first user equipment device, determine that the data communication node (120) has established a second data connection with the second user equipment device (160, 400, 402, 500, 502, 504), authenticate the second user equipment device, associate the second location of the second user equipment device in the coverage area based on the second beamforming information of the second data connection and based on the image information, prove the second identity of the second user equipment device based on the association of the second location, and establish a verification area in the coverage area based on the verification of the first identity and the second identity.

2. The data communication network (100, 200) as claimed in claim 1, wherein the information processing system (110, 300) is further configured to associate a second location of the first user equipment device within the coverage area based on second beamforming information of the first data connection and based on the image information.

3. The data communication network (100, 200) of claim 2, wherein the information processing system (110, 300) is further configured to determine, based on the association of the second location, that the first user equipment device has moved from the first location to the second location within the coverage area.

4. The data communication network (100, 200) as claimed in claim 3, wherein the information processing system (110, 300) is further configured to modify the proof area in response to determining that the first user equipment device has been moved.

5. The data communication network (100, 200) as claimed in claim 1, wherein the proof area is further established based on the physical area of ​​the coverage area.

6. The data communication network (100, 200) as claimed in claim 5, wherein the information processing system (110, 300) is further configured to determine that the data communication node (120) has established a third data connection with a third user equipment device (160, 400, 402, 500, 502, 504), and to determine that the third user equipment device is located within the physical area.

7. The data communication network (100, 200) of claim 6, wherein the information processing system (110, 300) is further configured to authenticate the third user equipment device and prove the third identity of the third user equipment device based on the determination that the third user equipment device is located within the physical area, wherein the proof area is further based on the proof of the third identity.

8. The data communication network (100, 200) as claimed in claim 6, wherein the information processing system (110, 300) is further configured to fail to authenticate the second user equipment device.

9. The data communication network (100, 200) of claim 8, wherein the information processing system (110, 300) is further configured to exclude the third user equipment device from the authentication area based on the failure to authenticate the third user equipment device.

10. The data communication network (100, 200) as claimed in claim 1, wherein the proof area includes sensitive compartment information facilities.

11. A method comprising: A data communication node (120) is provided in a data communication network (100, 200), the data communication node being configured to establish a data connection with each of a plurality of user equipment devices (160, 400, 402, 500, 502, 504) within the coverage area of ​​the data communication node (120), and for each data connection, providing beamforming information for each data connection, the beamforming information identifying the location of the associated user equipment device within the coverage area; A plurality of imaging devices (130) are provided in the data communication network (100, 200), the plurality of imaging devices being configured to provide image information for the coverage area; It is determined that the data communication node (120) has established a first data connection with the first user equipment device (160, 400, 402, 500, 502, 504); Authenticate the first user equipment device; Based on the first beamforming information of the first data connection and based on the image information, the first location of the first user equipment device in the coverage area is associated; The first identity of the first user equipment device is proved based on the association of the first location; It is determined that the data communication node (120) has established a second data connection with the second user equipment device (160, 400, 402, 500, 502, 504); Authenticate the second user equipment device; Based on the second beamforming information of the second data connection and based on the image information, the second location of the second user equipment device in the coverage area is associated; The second identity of the second user equipment device is proved based on the association of the second location; as well as A proof area is established within the coverage area based on the proof of the first identity and the second identity.

12. The method of claim 11, further comprising: The second beamforming information based on the first data connection and the image information are used to associate the second location of the first user equipment device within the coverage area.

13. The method of claim 12, further comprising: Based on the association of the second location, it is determined that the first user equipment device has moved from the first location to the second location within the coverage area.

14. The method of claim 13, further comprising: The proof area is modified in response to determining that the first user equipment device has been moved.

15. The method of claim 11, wherein the proof area is further established based on the physical area of ​​the coverage area.

16. The method of claim 15, further comprising: It is determined that the data communication node (120) has established a third data connection with the third user equipment device (160, 400, 402, 500, 502, 504); and It is determined that the third user equipment device is located within the physical area.

17. The method of claim 16, further comprising: Authenticating the third user equipment device; as well as The third identity of the third user equipment device is proved based on the determination that the third user equipment device is located within the physical area, wherein the proof area is further based on the proof of the third identity.

18. The method of claim 16, further comprising: The second user equipment device could not be authenticated.

19. The method of claim 18, further comprising: The third user equipment device is excluded from the proof area based on the failure to authenticate the third user equipment device.

20. An information processing system (110, 300) coupled to a data communication node (120) of a data communication network (100, 200), the data communication node (120) being configured to establish a data connection with each of a plurality of user equipment devices (160, 400, 402, 500, 502, 504) within a coverage area of ​​the data communication node (120), and providing beamforming information for each data connection, the beamforming information identifying the location of the associated user equipment device within the coverage area, the information processing system (110, 300) comprising: A memory device for storing code; as well as Processor, the processor being configured to execute the code to: Image information is received from multiple imaging devices (130) in the data communication network (100, 200); Based on the image information, a three-dimensional map of the coverage area of ​​the data communication network (100, 200) is synthesized; It is determined that the data communication node (120) has established a first data connection with the first user equipment device (160, 400, 402, 500, 502, 504); Authenticate the first user equipment device; Based on the first beamforming information of the first data connection and based on the image information, the first location of the first user equipment device in the coverage area is associated; The first identity of the first user equipment device is proved based on the association of the first location; It is determined that the data communication node (120) has established a second data connection with the second user equipment device (160, 400, 402, 500, 502, 504); Authenticate the second user equipment device; Based on the second beamforming information of the second data connection and based on the image information, the second location of the second user equipment device in the coverage area is associated; The second identity of the second user equipment device is proved based on the association of the second location; as well as A proof area is established within the coverage area based on the proof of the first identity and the second identity.

Citation Information

Patent Citations

  • Real-time 3D topology mapping for deterministic RF signal delivery

    US12154223B2

  • Real-time 3D location service for deterministic RF signal delivery

    US20230319759A1

  • User equipment device integrity protection in a data communication network

    US20230328820A1