A device access authentication method and system for a wireless communication network
By acquiring device location and throughput, calculating throughput and movement characteristic values, and combining fuzzy C-means clustering algorithm to assess the degree of device anomaly, the problem of high computational resource consumption in traditional methods is solved, and fast and secure access authentication of industrial IoT devices is achieved.
Patent Information
- Application Number
- CN202511111358.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2026-02-13
- Estimated Expiration
- 2045-08-08
AI Technical Summary
Traditional cryptographic authentication methods consume high computational resources in the Industrial Internet of Things (IIoT) and struggle to meet security and lightweight requirements, leading to difficulties in device access authentication.
By acquiring the device's location and Wi-Fi terminal throughput in real time, calculating throughput and mobility characteristic values, and combining fuzzy C-means clustering algorithm and authentication characteristic values, the degree of device anomaly is evaluated, thereby achieving device access authentication.
It improves the security and speed of device access authentication, reduces computational complexity, and ensures that normal devices can quickly access the wireless network.
Smart Images

Figure CN120957136B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of wireless communication, in particular to a device access authentication method and system of a wireless communication network. BACKGROUND
[0002] Industrial Internet of Things (IIoT) connects sensors and instruments to industrial applications through the Internet. Industrial Internet of Things uses Internet of Things sensing and communication technology to collect industrial application data and analyzes the data to optimize production processes, improve production efficiency, reduce manufacturing costs, improve product quality, and ultimately realize the upgrading of traditional industry to the new stage of intelligentization. Wi-Fi technology has become the first choice for industrial terminal network access because of its advantages such as not being limited by wired connection, facilitating terminal and device fast access and mobile sharing, and reducing wiring costs.
[0003] However, the security performance of Industrial Internet of Things is crucial, and security vulnerabilities can lead to serious consequences. Device access authentication of Industrial Internet of Things is a key link to ensure that only legitimate devices and users can access, prevent unauthorized access, and malicious attacks. Traditional identity authentication methods based on cryptography are difficult to meet the security and lightweight requirements in the application scenario of large-scale deployment of Industrial Internet of Things, because identity authentication methods based on cryptography usually require high computing resources and complex key management, which are not suitable for resource-constrained Industrial Internet of Things devices. SUMMARY
[0004] In view of the above, it is necessary to provide a device access authentication method and system of a wireless communication network, which improves the security of authentication and reduces the time of Industrial Internet of Things device access authentication compared with traditional device access authentication methods and systems of a wireless communication network.
[0005] In a first aspect, the embodiments of the present application provide a device access authentication method of a wireless communication network, the method comprising the following steps:
[0006] Real-time acquisition of the positions of each device connected to the wireless access point of the industrial Internet of Things and the throughput of the WIFI terminal of each device;
[0007] Pre-set the period of device access authentication, and obtain the throughput feature value of each device in the current period according to the cumulative degree and change of the throughput of each device in the current period;
[0008] Obtain the moving feature value of each device in the current period according to the moving range of each device in the current period and the change degree of the moving speed of each device;
[0009] According to the throughput characteristic value, the moving characteristic value of all devices in the current period and the position of the end of the period, all devices are divided into categories, and the membership of each device and each classification center is obtained. The membership of each device and each classification center outside the classification to which the device belongs is recorded as the membership of each device. A plurality of control periods of the current period are preset. According to the dispersion of the membership of each device and the classification center to which the device belongs in all control periods, and in combination with the difference between the membership of each device in any two adjacent control periods, the authentication characteristic value of each device in the current period is obtained.
[0010] According to the distribution of the authentication characteristic value of all devices in the current period, the passing situation of the access authentication of each device at the end of the current period is evaluated.
[0011] In one embodiment, the process of obtaining the throughput characteristic value is as follows:
[0012] The peak value of the throughput of each device in the current period is obtained, and the mean value of the time interval of any two adjacent peaks corresponding to each device in the current period is calculated.
[0013] The sum value of the throughput of each device in the current period is calculated.
[0014] The throughput characteristic value can be further obtained by the sum value and the mean value.
[0015] In one embodiment, the throughput characteristic value is the ratio of the sum value to the mean value.
[0016] In one embodiment, the process of obtaining the moving characteristic value is as follows:
[0017] The distance between the positions of each device in the current period at adjacent two collection times is calculated. The dispersion of the distance between all adjacent two collection times of each device in the current period is recorded as the first dispersion.
[0018] The radius of the minimum circumscribed sphere containing all positions of each device in the current period is obtained.
[0019] In combination with the first dispersion and the radius, the moving characteristic value of each device in the current period is obtained.
[0020] In one embodiment, the moving characteristic value is the product of the first dispersion and the radius.
[0021] In one embodiment, the process of obtaining the authentication characteristic value is as follows:
[0022] The dispersion of the membership of each device and the classification center to which the device belongs in all control periods is recorded as the second dispersion, and the inverse proportional normalization result of the second dispersion is obtained.
[0023] each category other than the belonging category of each device in each period is recorded as a subordinate category of each device in each period, all subordinate degrees of each device in each period are arranged in ascending order of the number of devices in the subordinate category, a subordinate degree vector of each device between any two adjacent comparison periods is calculated, and an average value of the normalized values of the similarity of each device between all any two adjacent comparison periods is calculated;
[0024] The authentication feature value is obtained by fusing the inverse proportional normalized result and the average value.
[0025] In one embodiment, the authentication feature value is the cumulative value of the inverse proportional normalized result and the average value.
[0026] In one embodiment, the process of evaluating the passing situation of the access authentication of each device at the end of the current period is:
[0027] A segmentation threshold of the authentication feature value of all devices in the current period is obtained, and the minimum value of the authentication feature value of all devices in the current period is counted.
[0028] The passing situation of the access authentication of each device at the end of the current period is evaluated by the segmentation threshold and the minimum value.
[0029] In one embodiment, the evaluation of the passing situation of the access authentication of each device at the end of the current period includes:
[0030] The number of devices whose authentication feature value is between the minimum value and the segmentation threshold in the current period is counted, and the proportion of the number of devices in all devices in the current period is calculated.
[0031] If the proportion of the number of devices is less than or equal to a preset first threshold, and the ratio of the segmentation threshold to the minimum value is greater than a preset second threshold, the device whose authentication feature value is less than the segmentation threshold in the current period is regarded as an abnormal user device, and the access authentication of the remaining devices except the abnormal user device in the current period is passed; otherwise, the access authentication of all devices in the current period is passed.
[0032] In a second aspect, the embodiments of the present application further provide a device access authentication system of a wireless communication network, which comprises a memory, a processor, and a computer program stored in the memory and running on the processor, and the processor implements the steps of the device access authentication method of the wireless communication network according to any one of the above embodiments when executing the computer program.
[0033] The present application has at least the following beneficial effects:
[0034] The application can monitor the position change and communication state change of the device by obtaining the position of the device and the throughput of the WIFI terminal of the device; the throughput characteristic value is calculated through the accumulation and change of the throughput, which can quantify the abnormal degree of the communication state of the device without complex calculation; the moving characteristic value is obtained through the moving range and moving speed of the device, which is helpful to identify the device with abnormal position change; all devices are classified in combination with the throughput characteristic value, the moving characteristic value and the position of the device, and then the authentication characteristic value of the device is obtained through the membership change of the device and the classification center to which the device belongs and the change of the membership of the device, in which process, the communication state change difference and the position change difference between devices, and the position difference of the device are comprehensively considered, which can comprehensively evaluate the abnormal degree of the device from multiple angles, and is helpful to improve the accuracy of evaluating the abnormal degree of the device according to the authentication characteristic value; further, the abnormal device is accurately identified through the authentication characteristic value, so that only normal industrial devices can access the industrial Internet of Things, the sensitivity of screening abnormal user devices is improved, the security of authentication is improved, at the same time, without complex calculation, the time of industrial Internet of Things device access authentication is reduced, and the normal industrial devices can quickly access the wireless network. BRIEF DESCRIPTION OF DRAWINGS
[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art and the advantages thereof, a brief introduction will be given to the drawings needed in the embodiments or the prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and those skilled in the art can obtain other drawings according to these drawings without creative labor.
[0036] Figure 1 A step flow chart of a device access authentication method of a wireless communication network provided by an embodiment of the present application;
[0037] Figure 2 An acquisition flowchart of the throughput characteristic value;
[0038] Figure 3 An acquisition flowchart of the moving characteristic value. DETAILED DESCRIPTION
[0039] In the description of the embodiments of the present application, the words such as "exemplary", "or", "for example" are used to mean example, illustration or description. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. On the contrary, the words such as "exemplary", "or", "for example" are used to present the relevant concept in a specific way.
[0040] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used in the present application is for the purpose of describing particular embodiments only and is not intended to be limiting of the present application. It will be understood that the terms "comprises" and "comprising", when used in this specification, specify the presence of stated features, integers, steps, or components, but do not preclude the presence or addition of one or more other features, integers, steps, components, or groups thereof.
[0041] It should also be noted that the terms "first", "second" and "third" are used herein to distinguish between similar objects, and are not used to describe a particular sequential or chronological order.
[0042] The specific scheme of the device access authentication method and system of a wireless communication network provided by the present application will be described in detail below in combination with the accompanying drawings.
[0043] Referring to Figure 1 , a flow chart of steps of a device access authentication method of a wireless communication network is shown, which comprises the following steps:
[0044] Step 1, real-time acquisition of the positions of each device connected with the wireless access point of the industrial internet, and the throughput of the WIFI terminal of each device.
[0045] As the first line of defense of the wireless communication network, device access authentication is of great significance to the security of the industrial internet of things. The link layer characteristics of the wireless device, such as throughput, can reflect the communication state of the device and can be used as the authentication basis for the legitimacy of the device identity. In addition, in industrial production, the operation law of the device is relatively stable, and the position information of the device can be used to further improve the security of the access authentication.
[0046] For each device connected with the wireless access point (AP) of the industrial internet of things by the WIFI terminal, in order to obtain the communication state of each device and improve the reliability of the device access authentication, the present application acquires the throughput of the WIFI terminal of each device in real time through the simple network management protocol (SNMP). The simple network management protocol is a well-known technology, and the present application will not be described in detail.
[0047] Meanwhile, a UWB micro base station card is installed at each device to obtain the position of each device in real time, so as to realize accurate positioning of each device. Specifically, in the embodiment, a TDOA (Time Difference Of Arrival) algorithm is used to measure the time difference of the UWB (Ultra Wideband) transmission signals of each device to each AP, calculate the distance between each device and each AP within the line-of-sight range, and obtain the coordinates of each device. The specific process of obtaining the coordinates of each device by using the TDOA algorithm is known content, and will not be described in detail herein.
[0048] In the embodiment, the interval of the throughput and the position is 1 s, and the interval of the throughput and the position is artificially preset. The implementer can set it according to the actual situation, and the present application does not make special limitations.
[0049] In step 2, the period of device access authentication is preset, and the throughput feature value of each device in the current period is obtained according to the cumulative degree and change of the throughput of each device in the current period.
[0050] In order to avoid malicious attacks by abnormal users, the period of device access authentication is preset, and the access authentication is performed at the end of each period. In the embodiment, the length of the period is 100 s, and the length of the period is artificially preset. The implementer can set it according to the actual situation, and the present application does not make special limitations.
[0051] In the industrial Internet of Things, different devices interact with the industrial Internet of Things at different frequencies, and there is a large difference in the communication state between abnormal user devices and normal industrial devices. Therefore, abnormal user devices can be screened.
[0052] Based on the above analysis, the throughput feature value of each device in the current period is obtained according to the cumulative degree and change of the throughput of each device in the current period, and the expression is:
[0053] In the formula, F j represents the throughput feature value of the jth device in the current period; tp j represents the sum of the throughput of the jth device in the current period; the peak values of the throughput of the jth device in the current period are obtained, μ j represents the average of the time interval of all adjacent peak values corresponding to the jth device in the current period.
[0054] In this embodiment, the AMPD (Automatic Multiscale-based Peak Detection) algorithm is used to obtain each peak value of the throughput of the jth device in the current period over time. The AMPD algorithm is a known technology, and will not be described herein. As another embodiment, on the basis of being able to obtain each peak value of the throughput of the jth device in the current period over time, the implementer can use other existing technologies, such as a peak-valley detection algorithm, an extreme point detection algorithm, and the like, without special limitation.
[0055] It should be noted that the more the interaction data of the jth device in the current period and the industrial Internet of Things, the greater the sum of the throughput of the jth device in the current period, and the greater the throughput feature value. At the same time, the more drastic the change in the communication state of the jth device in the current period, the faster the change in the throughput in the current period, and the smaller the mean μ of the time interval of all adjacent peak values corresponding to the jth device, the greater the throughput feature value. The greater the throughput feature value, the more likely the jth device is an abnormal user device. The flowchart of obtaining the throughput feature value is shown in FIG. 3. j Figure 2
[0056] Step 3: Obtain a movement feature value of each device in the current period according to the movement range of each device in the current period and the change degree of the movement speed of each device.
[0057] In industrial production, the positions of some devices are fixed, and the positions of some devices are mobile, and the movement speeds of the devices are different. However, the running range of the mobile devices in industrial production is relatively fixed, and the movement trajectory of the mobile devices has regularity. Considering that the movement of the abnormal user device is irregular, the abnormal device is screened according to the position change of the device, so as to improve the security of access authentication.
[0058] Based on the above analysis, a movement feature value of each device in the current period is obtained according to the movement range of each device in the current period and the change degree of the movement speed of each device, and the specific process is as follows:
[0059] The metric distance of each device in the current period between adjacent two collection time points is calculated, and the dispersion of the metric distance of each device in the current period between all adjacent two collection time points is denoted as a first dispersion. The greater the first dispersion, the greater the change in the movement speed of each device, and the more likely the device is an abnormal user device.
[0060] At the same time, the radius of the minimum circumscribed sphere containing all positions of each device in the current period is obtained. The greater the radius, the greater the movement range of each device, and the more likely the device is an abnormal user device.
[0061] Further, according to the first dispersion and the radius of each device in the current period, a moving feature value of each device in the current period is obtained, and the expression is:
[0062] S j = r j × σ j ; in the formula, S j represents the moving feature value of the jth device in the current period; r j , σ j respectively represent the radius and the first dispersion of the jth device in the current period.
[0063] It should be noted that the moving feature value can be used to reflect the moving state of the device, thereby distinguishing normal industrial devices and abnormal user devices. The larger the moving feature value, the more likely the jth device is an abnormal user device. The moving feature value acquisition process is shown in Figure 3 .
[0064] In this embodiment, the metric distance is the Euclidean distance.
[0065] In this embodiment, the dispersion of the metric distance is specifically the variance. As other implementation manners, on the basis of being able to measure the uneven degree of the metric distance distribution, the implementer can use other existing technologies such as the coefficient of variation, the standard deviation, etc., and the present application does not make special limitation.
[0066] Step 4, according to the throughput feature value, the moving feature value of all devices in the current period and the position at the end of the period, all devices are divided into categories, and the membership of each device to each classification center is obtained. The membership of each device to each classification center other than the classification to which it belongs is recorded as the membership of each device. The pre-set control period of the current period, according to the dispersion of the membership of each device to the classification center to which it belongs in all control periods, combined with the difference in membership of each device between any two adjacent control periods, the authentication feature value of each device in the current period is obtained.
[0067] In the industrial Internet of Things, different areas perform different production links, and fixed devices can be divided according to their position information. This division method enables the industrial Internet of Things to effectively identify abnormal user devices that appear in a specific area, thereby preventing them from accessing the network and avoiding data theft or network attacks.
[0068] Meanwhile, considering the difference between the communication state change and the position change of the abnormal user equipment and the normal industrial equipment, the throughput feature value and the movement feature value of each equipment in the current period and the coordinates at the end of the current period are combined to form an authentication feature vector of each equipment in the current period, wherein the authentication feature vector includes five components, specifically, the throughput feature value, the movement feature value, the x-axis coordinate, the y-axis coordinate, and the z-axis coordinate. The authentication feature vectors of all the equipment in the current period are taken as the input of the fuzzy C-means clustering algorithm, and the classes of all the equipment in the current period and the membership degrees of each equipment to each classification center are output, wherein the number of the clustering clusters in the fuzzy C-means clustering algorithm is set to 30, and the value of the number of the clustering clusters can be set by the implementer according to the deployment scale of the industrial internet, which is not specially limited in the present application.
[0069] In order to analyze the features of the communication state change and the position change of each equipment and ensure the access authentication of the normal industrial equipment, the current period and its adjacent previous preset number of periods are taken as the control periods of the current period.
[0070] In the embodiment, the value of the preset number is 29, and the value of the preset number is preset by human, which can be set by the implementer according to the actual situation, which is not specially limited in the present application. It should be noted that if the number of the control periods of each period is insufficient, the missing data is filled with the mean value in the subsequent processing process, which is a known technology and will not be described herein.
[0071] The communication state of the abnormal user equipment usually changes rapidly, the position change is also random, and the membership degree to different classification centers changes rapidly for data stealing and network attack.
[0072] According to the method for obtaining the classes of all the equipment in each period and the membership degrees of each equipment to each classification center in each period, the classes of all the equipment in each period and the membership degrees of each equipment to each classification center in each period are obtained.
[0073] The dispersion of the membership degrees of each equipment to the classification center in all the control periods of the current period is recorded as the second dispersion of each equipment in the current period. The greater the second dispersion, the faster the state change of each equipment, and the greater the probability that each equipment is an abnormal user equipment.
[0074] In the embodiment, the dispersion of the membership degree is specifically the coefficient of variation, and the calculation of the coefficient of variation is a known technology, which will not be described herein. As other embodiments, on the basis of being able to measure the unevenness of the distribution of the membership degree, the implementer can use other existing technologies, such as variance and standard deviation, which are not specially limited in the present application.
[0075] The membership of each device to each category center other than the category to which the device belongs is denoted as each subordinate membership of the device, each category other than the category to which each device belongs in each period is denoted as each subordinate category of each device in each period, all subordinate memberships of each device in each period are arranged in order of the number of devices in the subordinate category from small to large to form a subordinate membership vector of each device in each period, and the similarity of the subordinate membership vectors between any two adjacent comparison periods of each device is calculated to reflect the similarity of the state change between each device and the other devices. In industrial production, there are usually multiple groups of devices with the same function, and the devices in the same production link usually have similar communication state change and position change characteristics. Therefore, by analyzing the similarity of the state change between devices, an abnormal user device can be effectively identified. When determining the arrangement order of the components in the subordinate membership vector according to the number of devices in the subordinate category, if there are cases where the number of devices is the same, take the jth device as an example, and arrange in order of the distance between the jth device and the subordinate category center from small to large.
[0076] In this embodiment, the similarity between the subordinate membership vectors is cosine similarity, and the calculation of the cosine similarity is a known technology, which will not be described herein. As other embodiments, on the basis of being able to measure the similarity between two subordinate membership vectors, implementers can use other existing technologies such as the reciprocal of the Euclidean distance, and the present application does not make special limitations.
[0077] Further, according to the second dispersion of each device in the current period and the similarity of the subordinate membership vectors between any two adjacent comparison periods of each device, an authentication feature value of each device in the current period is obtained, and the expression is:
[0078] In the formula, T j represents the authentication feature value of the jth device in the current period; exp() represents an exponential function with a natural constant as the base number, which is used to map -CV j to the range of (0, 1]; CV j represents the second dispersion of the jth device in the current period; N represents the total number of comparison periods in the current period; sim n,n+1 represents the normalized value of the similarity of the subordinate membership vectors between the nth and the n+1th comparison periods of the jth device in the current period.
[0079] In this embodiment, the Min-Max normalization method is used to obtain the normalized value of the similarity between the subordinate membership vectors, and the Min-Max normalization method is a known technology, which will not be described herein.
[0080] It should be noted that: the more drastic the change in the membership of the jth device to its own classification center, the more rapid the state change of the jth device, the greater the second dispersion, and the smaller the calculated authentication feature value; at the same time, the greater the change in the membership of the jth device to the remaining classification centers, the smaller the distance between the jth device and the remaining classification centers, the smaller the second dispersion, and the smaller the calculated authentication feature value; the smaller the calculated authentication feature value, the more likely the jth device is determined to be an abnormal user device and unable to pass the device access authentication.
[0081] Step 5: According to the distribution of the authentication feature values of all devices in the current period, the passing of the access authentication of each device at the end of the current period is evaluated.
[0082] Further, according to the distribution of the authentication feature values of all devices in the current period, the passing of the access authentication of each device at the end of the current period is evaluated, and the specific process is as follows:
[0083] Obtain the split threshold of the authentication feature values of all devices in the current period, and count the minimum value of the authentication feature values of all devices in the current period; count the devices whose authentication feature values are between the minimum value and the split threshold in the current period, and calculate the number ratio of the statistical result in all devices in the current period;
[0084] If the number ratio is less than or equal to a preset first threshold, and the ratio of the split threshold to the minimum value is greater than a preset second threshold, the devices whose authentication feature values are less than the split threshold in the current period are regarded as abnormal user devices, and the access authentication of the remaining devices except the abnormal user devices in the current period is passed; otherwise, the access authentication of all devices in the current period is passed.
[0085] In this embodiment, the Otsu threshold segmentation algorithm is used to obtain the split threshold of the authentication feature values of all devices in the current period. The Otsu threshold segmentation algorithm is a known technology, and will not be described herein. As other embodiments, as long as the split threshold of the authentication feature values of all devices in the current period can be obtained, other existing technologies such as global threshold segmentation and iterative threshold segmentation can be used, and the present application does not make special limitations.
[0086] In this embodiment, the preset first threshold and the preset second threshold are 0.05 and 5, respectively. The values of the preset first threshold and the preset second threshold are preset by humans, and the implementer can set them according to the actual situation. The present application does not make special limitations.
[0087] Based on the same inventive concept as the above method, the embodiments of the present application also provide a device access authentication system of a wireless communication network, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor implements the steps of any one of the above device access authentication methods of a wireless communication network when executing the computer program.
[0088] To sum up, by acquiring the position of the device and the throughput of the WIFI terminal of the device, the position change and the communication state change of the device can be monitored; by calculating the throughput characteristic value according to the accumulation and change of the throughput, the abnormality degree of the communication state of the device can be quantified without complex calculation; by acquiring the moving characteristic value according to the moving range and the moving speed of the device, the device with abnormal position change can be identified; by classifying all the devices according to the throughput characteristic value, the moving characteristic value and the position, and then acquiring the authentication characteristic value of the device according to the change of the membership degree of the device to the classified center and the change of the membership of the device, the communication state change difference and the position change difference among the devices, and the position difference of the device are comprehensively considered in the process, the abnormality degree of the device can be comprehensively evaluated from multiple angles, which is conducive to improving the accuracy of evaluating the abnormality degree of the device according to the authentication characteristic value; further, by the authentication characteristic value, the abnormal device can be accurately identified, only the normal industrial device can access the industrial Internet of Things, the sensitivity of screening abnormal user devices is improved, the security of authentication can be improved, meanwhile, without complex calculation, the time of the industrial Internet of Things device access authentication is reduced, the normal industrial device can be quickly accessed to the wireless network.
[0089] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other devices to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0090] It is apparent that a person skilled in the art can make a variety of modifications to the application described herein without departing from the spirit and scope of the application. Therefore, the described embodiments are to be considered in all respects as illustrative and not restrictive.
Claims
1. A device access authentication method of a wireless communication network, characterized by, The method comprises the following steps: Real-time acquisition of the positions of each device connected to the wireless access point of the industrial internet, and the throughput of the WIFI terminal of each device; Pre-setting a period of device access authentication, and acquiring a throughput characteristic value of each device in the current period according to the cumulative degree and change of the throughput of each device in the current period; Acquiring a moving characteristic value of each device in the current period according to the moving range of each device in the current period and the change degree of the moving speed of each device; According to the throughput characteristic value, the moving characteristic value and the position at the end of the current period, all devices are divided into categories, and the membership of each device to the category center is obtained, the membership of each device to each category center other than the category to which the device belongs is recorded as the membership of each device to each subordinate category, a preset comparison period of the current period, and the dispersion of the membership of each device to the category center to which the device belongs in all comparison periods is acquired, and the difference in the membership of each device between any two adjacent comparison periods is combined to acquire an authentication characteristic value of each device in the current period; According to the distribution of the authentication characteristic value of all devices in the current period, the passing situation of the access authentication of each device at the end of the current period is evaluated; The acquisition process of the throughput characteristic value is as follows: Acquiring each peak value of the throughput of each device in the current period in time sequence, and calculating the mean value of the time interval of any two adjacent peaks corresponding to each device in the current period; Calculating the sum value of the throughput of each device in the current period; The throughput characteristic value is the ratio of the sum value to the mean value.
2. The device access authentication method of a wireless communication network of claim 1, wherein, The acquisition process of the moving characteristic value is as follows: Calculating the distance between the positions of each device at two adjacent acquisition times in the current period, and recording the dispersion of the distance between all adjacent two acquisition times of each device in the current period as a first dispersion; Acquiring the radius of the minimum circumscribed sphere containing all positions of each device in the current period; Combining the first dispersion and the radius to acquire the moving characteristic value of each device in the current period; The moving characteristic value is the product of the first dispersion and the radius.
3. The device access authentication method of a wireless communication network of claim 1, wherein, The acquisition process of the authentication characteristic value is as follows: Recording the dispersion of the membership of each device to the category center to which the device belongs in all comparison periods as a second dispersion, and acquiring the inverse proportional normalization result of the second dispersion; Recording each category other than the category to which each device belongs in each period as each subordinate category of each device in each period, arranging all subordinate memberships of each device in each period in the order from small to large according to the number of devices in the subordinate category to form a subordinate membership vector of each device in each period, and calculating the similarity of the subordinate membership vectors between any two adjacent comparison periods of each device; Calculating the average value of the normalized value of the similarity between all arbitrary two adjacent comparison periods of each device; The authentication characteristic value is acquired by fusing the inverse proportional normalization result and the average value; and the authentication characteristic value is the cumulative value of the inverse proportional normalization result and the average value.
4. The device access authentication method of a wireless communication network of claim 1, wherein, The process of evaluating the passing situation of the access authentication of each device at the end of the current period is as follows: Obtaining a segmentation threshold of authentication feature values of all devices in a current period, and counting a minimum value of the authentication feature values of all devices in the current period; Evaluating passing of access authentication of each device at an end time of the current period by the segmentation threshold and the minimum value.
5. The device access authentication method of a wireless communication network of claim 4, wherein, The evaluating passing of access authentication of each device at the end time of the current period comprises: Counting devices whose authentication feature values are between the minimum value and the segmentation threshold in the current period, and calculating a proportion of a number of the counting result in all devices in the current period; If the proportion is less than or equal to a preset first threshold, and a ratio of the segmentation threshold to the minimum value is greater than a preset second threshold, devices whose authentication feature values are less than the segmentation threshold in the current period are regarded as abnormal user devices, and access authentication of the remaining devices except the abnormal user devices in the current period is passed; otherwise, access authentication of all devices in the current period is passed. 6.A device access authentication system of a wireless communication network, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, The processor implements the steps of the device access authentication method of the wireless communication network according to any one of claims 1-5 when executing the computer program.
Citation Information
Patent Citations
Internet of Things equipment activeness monitoring management method and system
CN119922108A
Industrial control network data monitoring system based on cloud platform
CN120050215A