Equipment access authentication method and system of wireless communication network

By acquiring device location and throughput, calculating throughput and movement characteristic values, and combining them with fuzzy C-means clustering algorithm to assess the degree of device anomaly, the problem of insufficient security and efficiency of traditional authentication methods in the Industrial Internet of Things is solved, and efficient device access authentication is achieved.

CN120957136AActive Publication Date: 2025-11-14BEIJING ZHONGCHENG TIANQI TECH CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202511111358.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-08
Publication Date
2025-11-14
Estimated Expiration
2045-08-08

AI Technical Summary

Technical Problem

Traditional cryptographic authentication methods are insufficient to meet the security and lightweight requirements of large-scale deployments of the Industrial Internet of Things (IIoT), and cannot effectively identify and filter out abnormal devices, leading to security vulnerabilities.

Method used

By acquiring the device's location and Wi-Fi terminal throughput in real time, calculating throughput and mobility characteristics, and combining fuzzy C-means clustering algorithm and authentication characteristics, the degree of device anomaly is assessed, thereby achieving device classification and access authentication.

Benefits of technology

It improves the security and efficiency of device access authentication, can accurately identify abnormal devices, reduce authentication time, and ensure that normal devices can quickly access the wireless network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120957136A_ABST
    Figure CN120957136A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of wireless communication, in particular to a device access authentication method and system for a wireless communication network, and the method comprises the steps: obtaining the position of each device connected with a wireless access point of an industrial internet in real time, and the throughput of a WIFI terminal of each device; presetting an equipment access authentication period, and obtaining throughput characteristic values of the equipment in the current period according to the accumulation degree and the change condition of the throughput of the equipment in the current period; acquiring a movement characteristic value of each device in the current period according to the movement range of each device in the current period and the change degree of the movement speed of each device; acquiring an authentication feature value of each device in the current period; and assessing the passing condition of the access authentication of each device at the end moment of the current period. The invention aims to improve the security of authentication and reduce the access authentication time of the industrial Internet of Things equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of wireless communication technology, specifically to a device access authentication method and system for wireless communication networks. Background Technology

[0002] The Industrial Internet of Things (IIoT) connects sensors and instruments to industrial applications via the internet. IIoT uses IoT sensing and communication technologies to collect and analyze data from industrial applications to optimize production processes, improve efficiency, reduce manufacturing costs, and enhance product quality, ultimately elevating traditional industries to a new stage of intelligent manufacturing. Wi-Fi technology, due to its advantages such as being unrestricted by wired connections, facilitating rapid access and mobile sharing for terminals and devices, and reducing cabling costs, has become the preferred choice for industrial terminals accessing networks.

[0003] However, the security of the Industrial Internet of Things (IIoT) is paramount, and vulnerabilities can have serious consequences. Device access authentication in the IIoT is a crucial step in ensuring that only legitimate devices and users can access the device, preventing unauthorized access and malicious attacks. Traditional cryptographic authentication methods struggle to meet the security and lightweight requirements of large-scale IIoT deployments because they typically require significant computing resources and complex key management, making them unsuitable for resource-constrained IIoT devices. Summary of the Invention

[0004] In view of the above, it is necessary to provide a device access authentication method and system for wireless communication networks, which improves authentication security and reduces the authentication time for industrial IoT devices compared to traditional device access authentication methods and systems.

[0005] In a first aspect, embodiments of this application provide a device access authentication method for a wireless communication network, the method comprising the following steps:

[0006] The location of each device connected to the wireless access point of the Industrial Internet, as well as the throughput of the WIFI terminal of each device, can be obtained in real time.

[0007] The system presets the device access authentication period and obtains the throughput characteristic value of each device in the current period based on the cumulative degree and change of the throughput of each device in the current period.

[0008] Based on the movement range of each device in the current period and the degree of change in the movement speed of each device, the movement characteristic value of each device in the current period is obtained;

[0009] Based on the throughput characteristic value, movement characteristic value and position of all devices at the end of the current period, all devices are divided into categories, and the membership degree of each device to each category center is obtained. The membership degree of each device to each category center outside its own category is recorded as the subordinate membership degree of each device. The current period is preset with each comparison period. Based on the dispersion of the membership degree of each device to its own category center in all comparison periods, combined with the difference of the subordinate membership degree of each device between any two adjacent comparison periods, the authentication characteristic value of each device in the current period is obtained.

[0010] Based on the distribution of authentication feature values ​​of all devices in the current period, assess the access authentication success rate of each device at the end of the current period.

[0011] In one embodiment, the process of obtaining the throughput feature value is as follows:

[0012] Obtain the peak values ​​of the throughput of each device in the current period in the time sequence, and calculate the average time interval between any two adjacent peak values ​​corresponding to each device in the current period.

[0013] Calculate the sum of the throughput of each device in the current period;

[0014] The throughput characteristic value can be further obtained by the sum and the mean.

[0015] In one embodiment, the throughput characteristic value is the ratio of the sum to the mean.

[0016] In one embodiment, the process of obtaining the movement feature value is as follows:

[0017] Calculate the distance between the positions of each device in the current period between two adjacent acquisition times, and denote the dispersion of the distance between each device in the current period between all two adjacent acquisition times as the first dispersion.

[0018] Get the radius of the smallest circumscribed sphere that includes all positions of all devices within the current period;

[0019] By combining the first discreteness and the radius, the movement characteristic value of each device in the current period is obtained.

[0020] In one embodiment, the movement feature value is the product of the first discreteness and the radius.

[0021] In one embodiment, the process of obtaining the authentication feature value is as follows:

[0022] The dispersion of the membership degree of each device to its respective classification center in all control periods is denoted as the second dispersion, and the inverse proportional normalization result of the second dispersion is obtained.

[0023] Each category other than the category to which each device belongs in each period is denoted as a subordinate category of each device in each period. All subordinate membership degrees of each device in each period are arranged in ascending order of the number of devices in the subordinate categories to form a subordinate membership degree vector of each device in each period. The similarity of the subordinate membership degree vector of each device between any two adjacent control periods is calculated. The normalized average value of the similarity between any two adjacent control periods of each device is calculated.

[0024] The authentication feature value is obtained by fusing the inverse proportional normalization result with the average value.

[0025] In one embodiment, the authentication feature value is the sum of the inverse proportional normalization result and the average value.

[0026] In one embodiment, the process of evaluating the access authentication success rate of each device at the end of the current period is as follows:

[0027] Obtain the segmentation threshold of the authentication feature values ​​of all devices in the current period, and calculate the minimum value of the authentication feature values ​​of all devices in the current period;

[0028] The access authentication success rate of each device at the end of the current cycle is evaluated using the segmentation threshold and the minimum value.

[0029] In one embodiment, the evaluation of the access authentication success rate of each device at the end of the current cycle includes:

[0030] The system identifies devices whose authentication feature values ​​fall between the minimum value and the segmentation threshold within the current period, and calculates the percentage of such devices among all devices in the current period.

[0031] If the proportion of the number is less than or equal to a preset first threshold, and the ratio of the segmentation threshold to the minimum value is greater than a preset second threshold, then devices whose authentication feature value is less than the segmentation threshold in the current period are considered abnormal user devices, and access authentication is granted to all other devices in the current period except for abnormal user devices; otherwise, access authentication is granted to all devices in the current period.

[0032] Secondly, embodiments of this application also provide a device access authentication system for a wireless communication network, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements the steps of any one of the device access authentication methods for a wireless communication network described above.

[0033] This application has at least the following beneficial effects:

[0034] This application monitors changes in device location and communication status by acquiring the device's location and the throughput of its Wi-Fi terminal. By calculating throughput characteristic values ​​based on cumulative and changing throughput, the degree of communication status anomalies can be quantified without complex calculations. Motion characteristic values ​​are obtained by measuring the device's movement range and speed, aiding in the identification of devices with abnormal location changes. Combining throughput, motion characteristic values, and location, all devices are categorized. Furthermore, authentication characteristic values ​​are obtained by analyzing changes in the membership degree between the device and its category center, as well as changes in the device's subordinate membership degree. This process integrates differences in communication status and location changes among devices, enabling a comprehensive assessment of device anomalies from multiple perspectives, thus improving the accuracy of subsequent assessments based on authentication characteristic values. Moreover, authentication characteristic values ​​accurately identify abnormal devices, ensuring only legitimate industrial equipment can access the Industrial Internet of Things (IIoT), improving the sensitivity of filtering out abnormal user devices and enhancing authentication security. Simultaneously, the elimination of complex calculations reduces the authentication time for IIoT devices, ensuring rapid access to the wireless network for legitimate industrial equipment. Attached Figure Description

[0035] To more clearly illustrate the technical solutions and advantages in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0036] Figure 1 A flowchart illustrating the steps of a device access authentication method for a wireless communication network, as provided in one embodiment of this application;

[0037] Figure 2 This is a schematic diagram illustrating the process of obtaining throughput feature values;

[0038] Figure 3 This is a schematic diagram of the process for obtaining moving feature values. Detailed Implementation

[0039] In the description of the embodiments in this application, the words "exemplary," "or," and "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary," "or," and "for example" is intended to present the relevant concepts in a specific manner.

[0040] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. It should be understood that, unless otherwise stated, " / " in this application means "or".

[0041] It should also be noted that the terms "first" and "second" in this application are used to distinguish similar objects, rather than to describe a specific order or sequence.

[0042] The following description, in conjunction with the accompanying drawings, details the specific scheme of the device access authentication method and system for a wireless communication network provided in this application.

[0043] Please see Figure 1 The diagram illustrates a flowchart of a device access authentication method for a wireless communication network according to an embodiment of this application. The method includes the following steps:

[0044] Step 1: Obtain the location of each device connected to the wireless access point of the Industrial Internet in real time, as well as the throughput of the WIFI terminal of each device.

[0045] Device access authentication, as the first line of defense in wireless communication networks, is crucial for ensuring the security of the Industrial Internet of Things (IIoT). Link-layer characteristics of wireless devices, such as throughput, reflect their communication status and can serve as evidence of their legitimacy. Furthermore, in industrial production, the operating patterns of equipment are relatively stable, and device location information can be used to further enhance the security of access authentication.

[0046] For devices connected to wireless access points (APs) of the Industrial Internet of Things (IIoT) via Wi-Fi terminals, in order to obtain the communication status of each device and improve the reliability of device access authentication, this application uses the Simple Network Management Protocol (SNMP) to obtain the throughput of the Wi-Fi terminals of each device in real time. SNMP is a well-known technology and will not be described in detail here.

[0047] Meanwhile, UWB micro base station cards are installed at each device to obtain the location of each device in real time and achieve accurate positioning of each device. Specifically, in this embodiment, the TDOA (Time Difference Of Arrival) algorithm is used to calculate the distance between each device and each AP within the line of sight by measuring the time difference of the ultra-wideband (UWB) transmitted signal of each device to each AP, thereby obtaining the coordinates of each device. The specific process of obtaining the coordinates of each device using the TDOA algorithm is well known and will not be described in detail in this application.

[0048] In this embodiment, the time interval for acquiring throughput and location is 1 second. The time interval for acquiring throughput and location is preset by the user and can be set by the implementer according to the actual situation. This application does not impose any special restrictions.

[0049] Step 2: Preset the device access authentication period, and obtain the throughput characteristic value of each device in the current period based on the cumulative degree and change of the throughput of each device in the current period.

[0050] To prevent malicious attacks from unauthorized users, a preset device access authentication period is established, with access authentication performed at the end of each period. In this embodiment, the period length is 100 seconds. The period length is preset manually, and the implementer can set it according to actual conditions; this application does not impose any special restrictions.

[0051] In the Industrial Internet of Things (IIoT), different devices interact with the IIoT at different frequencies, and there are significant differences in the communication status between abnormal user devices and normal industrial devices. This can be used to screen abnormal user devices.

[0052] Based on the above analysis, and according to the cumulative degree and changes in the throughput of each device in the current period, the throughput characteristic value of each device in the current period is obtained, expressed as:

[0053] In the formula, F j tp represents the throughput characteristic value of the j-th device in the current period; j This represents the sum of the throughput of the j-th device within the current period; it also retrieves the peak values ​​of the throughput of the j-th device in the current period over time, μ. j This represents the average time interval between any two adjacent peak values ​​corresponding to the j-th device within the current period.

[0054] In this embodiment, the AMPD (Automatic Multiscale-based Peak Detection) algorithm is used to obtain the peak values ​​of the throughput of the j-th device in the time series within the current period. The AMPD algorithm is a well-known technology and will not be described in detail in this application. As other implementation methods, based on the ability to obtain the peak values ​​of the throughput of the j-th device in the time series within the current period, the implementer may use other existing technologies, such as peak and trough detection algorithms, extreme point detection algorithms, etc. This application does not impose any special restrictions.

[0055] It should be noted that: the more interaction data the j-th device has with the Industrial Internet of Things within the current period, the larger the sum of the throughput of the j-th device within the current period, and thus the larger the throughput characteristic value; simultaneously, the more drastic the changes in the communication status of the j-th device within the current period, the faster the changes in throughput within the current period, and the greater the average value μ of the time interval between any two adjacent peaks corresponding to the j-th device. j The smaller the value, the larger the throughput characteristic value. A larger throughput characteristic value indicates that the j-th device is more likely to be an abnormal user device. A schematic diagram of the throughput characteristic value acquisition process is shown below. Figure 2 As shown.

[0056] Step 3: Based on the movement range of each device in the current cycle and the degree of change in the movement speed of each device, obtain the movement characteristic value of each device in the current cycle.

[0057] In industrial production, some equipment is stationary while others are mobile, with varying speeds. However, the operating range of mobile devices in industrial production is relatively fixed, and their movement trajectories exhibit regularity. Considering the irregular movement of abnormal user equipment, abnormal devices are screened based on their location changes to improve access authentication security.

[0058] Based on the above analysis, and according to the movement range and speed variation of each device in the current cycle, the movement characteristic values ​​of each device in the current cycle are obtained. The specific process is as follows:

[0059] Calculate the metric distance between the positions of each device in the current period between two adjacent acquisition times, and denote the dispersion of the metric distance between each device in the current period between all two adjacent acquisition times as the first dispersion; the larger the first dispersion, the greater the change in the moving speed of each device, and the more likely it is to be an abnormal user device.

[0060] At the same time, obtain the radius of the smallest circumscribed ball that includes all positions of each device in the current period. The larger the radius, the larger the movement range of each device, and the more likely it is to be an abnormal user device.

[0061] Furthermore, based on the first dispersion and the radius of each device in the current period, the movement characteristic value of each device in the current period is obtained, expressed as:

[0062] S j =r j ×σ j In the formula, S j r represents the movement characteristic value of the j-th device in the current period; j σ j Let represent the radius and the first dispersion of the j-th device in the current period, respectively.

[0063] It should be noted that movement characteristic values ​​can be used to reflect the movement status of equipment, thereby distinguishing between normal industrial equipment and abnormal user equipment. The larger the movement characteristic value, the more likely the j-th equipment is to be an abnormal user equipment. A schematic diagram of the movement characteristic value acquisition process is shown below. Figure 3 As shown.

[0064] In this embodiment, the distance metric is Euclidean distance.

[0065] In this embodiment, the dispersion of the distance measurement is specifically the variance. As other implementation methods, based on the ability to measure the unevenness of the distribution of the distance measurement, the implementer may use other existing technologies, such as the coefficient of variation, standard deviation, etc. This application does not impose any special restrictions.

[0066] Step 4: Based on the throughput characteristic value, movement characteristic value and position of all devices at the end of the current period, classify all devices into categories and obtain the membership degree of each device with each category center. Record the membership degree of each device with each category center other than its own category as the subordinate membership degree of each device. Preset each comparison period of the current period. Based on the dispersion of the membership degree of each device with its own category center in all comparison periods, and combined with the difference of the subordinate membership degree of each device between any two adjacent comparison periods, obtain the authentication characteristic value of each device in the current period.

[0067] In the Industrial Internet of Things (IIoT), different areas carry out different production processes, and fixed equipment can be categorized based on its location information. This categorization method enables the IIoT to effectively identify abnormal user equipment appearing in specific areas, thereby preventing them from accessing the network and avoiding data theft or cyberattacks.

[0068] Meanwhile, considering the differences in communication status and location changes between abnormal user equipment and normal industrial equipment, the throughput feature value, movement feature value, and coordinates at the end of the current period are used to form the authentication feature vector of each device in the current period. The authentication feature vector includes five components: throughput feature value, movement feature value, x-axis coordinate, y-axis coordinate, and z-axis coordinate. The authentication feature vectors of all devices in the current period are used as input to a fuzzy C-means clustering algorithm, which outputs the class of all devices in the current period, as well as the membership degree of each device to each classification center. The number of clusters in the fuzzy C-means clustering algorithm is set to 30. The number of clusters can be set by the implementer according to the deployment scale of the industrial internet; this application does not impose any special restrictions.

[0069] To analyze and obtain the characteristics of communication status changes and location changes of each device, and to ensure the access authentication of normal industrial equipment, the current period and the number of adjacent previous preset periods are used as the reference periods for the current period.

[0070] In this embodiment, the preset quantity is 29. The preset quantity is set manually, and the implementer can set it according to the actual situation. This application does not impose any special restrictions. It should be noted that if there is an insufficient number of control periods in each period, the missing data will be filled with the mean in the subsequent processing. Mean filling is a well-known technique and will not be described in detail in this application.

[0071] Abnormal user equipment, in order to steal data or launch network attacks, typically exhibits rapid changes in its communication status and location, as well as rapid changes in its membership degree with different classification centers.

[0072] Based on the methods for obtaining the categories of all devices in the current period and the membership degree of each device to each classification center in the current period, obtain the categories of all devices in each period and the membership degree of each device to each classification center in each period.

[0073] The dispersion of the membership degree of each device to its classification center in all control periods of the current period is denoted as the second dispersion of each device in the current period. The larger the second dispersion, the faster the state of each device changes and the greater the probability that each device is an abnormal user device.

[0074] In this embodiment, the dispersion of membership degree is specifically the coefficient of variation. The calculation of the coefficient of variation is a well-known technique and will not be described in detail in this application. As other implementation methods, based on the ability to measure the unevenness of the distribution of membership degree, the implementer may use other existing techniques, such as variance, standard deviation, etc. This application does not impose any special restrictions.

[0075] The membership degree between each device and each category center outside its own category is denoted as the subordinate membership degree of each device. The categories outside the original category of each device within each period are denoted as the subordinate categories of each device within each period. All subordinate membership degrees of each device within each period are arranged in ascending order of the number of devices in the subordinate categories, forming the subordinate membership degree vector of each device within each period. The similarity of the subordinate membership degree vectors of each device between any two adjacent control periods is calculated to reflect the degree of similarity in state changes between each device and the other devices. In industrial production, there are usually multiple groups of devices with the same function, and devices in the same production process often have similar communication state changes and location changes. Therefore, analyzing the similarity in state changes between devices can effectively identify abnormal user devices. Specifically, when determining the order of components in the subordinate membership degree vector based on the number of devices in the subordinate categories, if there are devices with the same number of devices, taking the j-th device as an example, they are arranged in ascending order of distance between the j-th device and the subordinate category center.

[0076] In this embodiment, the similarity between subordinate membership vectors is cosine similarity. The calculation of cosine similarity is a well-known technique and will not be described in detail here. As other implementation methods, based on the ability to measure the degree of similarity between two subordinate membership vectors, the implementer may adopt other existing techniques, such as the reciprocal of Euclidean distance, etc. This application does not impose any special restrictions.

[0077] Furthermore, based on the second dispersion of each device in the current period and the similarity of the membership vectors of each device between any two adjacent control periods, the authentication feature value of each device in the current period is obtained, expressed as:

[0078] In the formula, T j Let represent the authentication characteristic value of the j-th device in the current period; exp() represents an exponential function with base to the natural constant, used to convert -CV... j Mapped to the range (0,1]; CV j The second dispersion of the j-th device within the current period is represented; N represents the total number of reference periods for the current period; sim n,n+1 This represents the normalized value of the similarity of the membership vectors of the j-th device between the nth and (n+1th)th control periods in the current period.

[0079] In this embodiment, the Min-Max normalization method is used to obtain the normalized value of the similarity between subordinate membership vectors. The Min-Max normalization method is a well-known technique and will not be described in detail in this application.

[0080] It should be noted that: the more drastic the change in the membership degree between the j-th device and its respective classification center, the more rapidly the state of the j-th device changes, resulting in a larger second dispersion and a smaller calculated authentication feature value; simultaneously, the greater the change in the membership degree between the j-th device and the other classification centers, the smaller the second dispersion. The smaller the value, the smaller the calculated authentication feature value; the smaller the calculated authentication feature value, the greater the possibility that the j-th device is judged as an abnormal user device and cannot pass the device access authentication.

[0081] Step 5: Based on the distribution of authentication feature values ​​of all devices in the current period, evaluate the access authentication success rate of each device at the end of the current period.

[0082] Furthermore, based on the distribution of authentication feature values ​​of all devices within the current period, the access authentication success rate of each device at the end of the current period is evaluated. The specific process is as follows:

[0083] Obtain the segmentation threshold of the authentication feature values ​​of all devices in the current period, and count the minimum value of the authentication feature values ​​of all devices in the current period; count the devices whose authentication feature values ​​are between the minimum value and the segmentation threshold in the current period, and calculate the proportion of the statistical result among all devices in the current period;

[0084] If the proportion of the number is less than or equal to a preset first threshold, and the ratio of the segmentation threshold to the minimum value is greater than a preset second threshold, then devices whose authentication feature value is less than the segmentation threshold in the current period are considered abnormal user devices, and access authentication is granted to all other devices in the current period except for abnormal user devices; otherwise, access authentication is granted to all devices in the current period.

[0085] In this embodiment, the Otsu threshold segmentation algorithm is used to obtain the segmentation threshold of the authentication feature value of all devices in the current period. The Otsu threshold segmentation algorithm is a well-known technology and will not be described in detail in this application. As other implementation methods, based on the ability to obtain the segmentation threshold of the authentication feature value of all devices in the current period, the implementer may use other existing technologies, such as global threshold segmentation, iterative threshold segmentation, etc. This application does not impose any special restrictions.

[0086] In this embodiment, the preset first threshold and the preset second threshold are set to 0.05 and 5, respectively. The preset first threshold and the preset second threshold are preset by humans, and the implementer can set them according to the actual situation. This application does not impose any special restrictions.

[0087] Based on the same inventive concept as the above method, this application embodiment also provides a device access authentication system for a wireless communication network, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements the steps of any one of the above-described device access authentication methods for a wireless communication network.

[0088] In summary, this application can monitor changes in device location and communication status by acquiring the device's location and the throughput of its Wi-Fi terminal. By calculating throughput characteristic values ​​based on cumulative and changing throughput, the degree of communication status anomalies can be quantified without complex calculations. Motion characteristic values ​​are obtained by measuring the device's movement range and speed, which helps identify devices with abnormal location changes. By combining throughput characteristic values, motion characteristic values, and location, all devices are classified. Then, by analyzing changes in the membership degree between the device and its classification center, as well as changes in the device's subordinate membership degree, authentication characteristic values ​​are obtained. This process integrates differences in communication status changes, location changes, and device location, enabling a comprehensive assessment of device anomalies from multiple perspectives. This improves the accuracy of subsequent assessments based on authentication characteristic values. Furthermore, authentication characteristic values ​​accurately identify abnormal devices, ensuring that only normal industrial equipment can access the Industrial Internet of Things (IIoT). This improves the sensitivity of filtering out abnormal user devices and enhances authentication security. Simultaneously, the elimination of complex calculations reduces the authentication time for IIoT devices, ensuring rapid access to the wireless network for normal industrial equipment.

[0089] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than that shown in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. In the descriptions corresponding to the flowcharts and block diagrams in the accompanying drawings, the operations or steps corresponding to different blocks may also occur in a different order than disclosed in the description, and sometimes there is no specific order between different operations or steps. For example, two consecutive operations or steps may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. Each block in a block diagram and / or flowchart, and combinations of blocks in a block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0090] It will be apparent to those skilled in the art that this application is not limited to the details of the exemplary embodiments described above, and that this application can be implemented in other specific forms without departing from its essential characteristics. Therefore, the embodiments described above should be considered exemplary and non-limiting in all respects.

Claims

1. A device access authentication method for a wireless communication network, characterized in that, The method includes the following steps: The location of each device connected to the wireless access point of the Industrial Internet, as well as the throughput of the WIFI terminal of each device, can be obtained in real time. The system presets the device access authentication period and obtains the throughput characteristic value of each device in the current period based on the cumulative degree and change of the throughput of each device in the current period. Based on the movement range of each device in the current period and the degree of change in the movement speed of each device, the movement characteristic value of each device in the current period is obtained; Based on the throughput characteristic value, movement characteristic value and position of all devices at the end of the current period, all devices are divided into categories, and the membership degree of each device to each category center is obtained. The membership degree of each device to each category center outside its own category is recorded as the subordinate membership degree of each device. The current period is preset with each comparison period. Based on the dispersion of the membership degree of each device to its own category center in all comparison periods, combined with the difference of the subordinate membership degree of each device between any two adjacent comparison periods, the authentication characteristic value of each device in the current period is obtained. Based on the distribution of authentication feature values ​​of all devices in the current period, assess the access authentication success rate of each device at the end of the current period.

2. The device access authentication method for a wireless communication network as described in claim 1, characterized in that, The process for obtaining the throughput feature values ​​is as follows: Obtain the peak values ​​of the throughput of each device in the current period in the time sequence, and calculate the average time interval between any two adjacent peak values ​​corresponding to each device in the current period. Calculate the sum of the throughput of each device in the current period; The throughput characteristic value can be further obtained by the sum and the mean.

3. The device access authentication method for a wireless communication network as described in claim 2, characterized in that, The throughput characteristic value is the ratio of the sum to the mean.

4. The device access authentication method for a wireless communication network as described in claim 1, characterized in that, The process for obtaining the moving feature value is as follows: Calculate the distance between the positions of each device in the current period between two adjacent acquisition times, and denote the dispersion of the distance between each device in the current period between all two adjacent acquisition times as the first dispersion. Get the radius of the smallest circumscribed sphere that includes all positions of all devices within the current period; By combining the first discreteness and the radius, the movement characteristic value of each device in the current period is obtained.

5. The device access authentication method for a wireless communication network as described in claim 4, characterized in that, The moving feature value is the product of the first discreteness and the radius.

6. The device access authentication method for a wireless communication network as described in claim 1, characterized in that, The process for obtaining the authentication feature value is as follows: The dispersion of the membership degree of each device to its respective classification center in all control periods is denoted as the second dispersion, and the inverse proportional normalization result of the second dispersion is obtained. Each category other than the category to which each device belongs in each period is denoted as the subordinate category of each device in each period. All subordinate membership degrees of each device in each period are arranged in ascending order of the number of devices in the subordinate category to form the subordinate membership degree vector of each device in each period. The similarity of the subordinate membership degree vector of each device between any two adjacent control periods is calculated. Calculate the average of the normalized values ​​of the similarity between each device across all two adjacent control periods; The authentication feature value is obtained by fusing the inverse proportional normalization result with the average value.

7. A device access authentication method for a wireless communication network as described in claim 6, characterized in that, The authentication feature value is the sum of the inverse proportional normalization result and the average value.

8. The device access authentication method for a wireless communication network as described in claim 1, characterized in that, The process of evaluating the access authentication success rate of each device at the end of the current cycle is as follows: Obtain the segmentation threshold of the authentication feature values ​​of all devices in the current period, and calculate the minimum value of the authentication feature values ​​of all devices in the current period; The access authentication success rate of each device at the end of the current cycle is evaluated using the segmentation threshold and the minimum value.

9. A device access authentication method for a wireless communication network as described in claim 8, characterized in that, The evaluation of the access authentication pass status of each device at the end of the current cycle includes: The system identifies devices whose authentication feature values ​​fall between the minimum value and the segmentation threshold within the current period, and calculates the percentage of such devices among all devices in the current period. If the proportion of the number is less than or equal to a preset first threshold, and the ratio of the segmentation threshold to the minimum value is greater than a preset second threshold, then devices whose authentication feature value is less than the segmentation threshold in the current period are considered abnormal user devices, and access authentication is granted to all other devices in the current period except for abnormal user devices; otherwise, access authentication is granted to all devices in the current period.

10. A device access authentication system for a wireless communication network, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the device access authentication method for a wireless communication network as described in any one of claims 1-9.

Citation Information

Patent Citations

  • Data transmission rate regulation method, device and wireless access point

    CN103532669A

  • Zero-power-consumption communication authentication method and device based on radio frequency fingerprint, equipment and medium

    CN117768884A

  • Internet of Things equipment activeness monitoring management method and system

    CN119922108A

  • Trust evaluation method and system based on credit dynamic access control

    CN119995943A

  • Industrial control network data monitoring system based on cloud platform

    CN120050215A