Authentication method, network device, storage medium and computer program product

By adding an authentication sub-process to the drone network registration process, and comparing the authentication information in the identity recognition module with the pre-stored information, the problems of multiple interfaces and complex processes in the drone authentication system are solved, and the processing efficiency when authentication fails is improved.

CN121126338APending Publication Date: 2025-12-12CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510246371.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Existing drone authentication systems have numerous interfaces and complex processes, and their effectiveness is poor when drones that have already taken off and are connected to the network fail authentication.

Method used

An authentication sub-process is added to the drone network registration process. By comparing the authentication information in the first identity recognition module with the pre-stored second authentication information, the network registration process is stopped if they do not match, thus achieving unified interface and single process.

Benefits of technology

It improves the efficiency of handling drones that fail authentication, ensuring that drones cannot connect to the network when authentication fails, and simplifies the processing procedure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121126338A_ABST
    Figure CN121126338A_ABST
Patent Text Reader

Abstract

The invention provides an authentication method, a network device, a storage medium and a computer program product, and the method comprises the steps: obtaining first authentication information from a first identity recognition module after a network residing request of a first device is received; the first identity recognition module is an identity recognition module which is currently inserted into the first equipment; and if second authentication information corresponding to the first equipment is found and at least part of information in the first authentication information is not matched with the second authentication information, stopping the resident network process of the first equipment. Unified interfaces and single process can be realized, and the effectiveness of subsequent processing of the unmanned aerial vehicle is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security, and more particularly to an authentication method and network devices, storage media, and computer program products. Background Technology

[0002] "Black flights" refer to flights without a private pilot's license or without the drone's legal status, i.e., unregistered flights. "Black flights" are inherently dangerous, and with the increasing use of drones, this phenomenon persists despite repeated crackdowns, significantly impacting airspace safety. Therefore, preventing the frequent occurrence of "black flights" has become an urgent problem to solve.

[0003] Currently, drone authentication can be performed using drone authentication systems or by authenticating drones based on flight data. However, drone authentication systems suffer from numerous interfaces and complex processes; authentication based on flight data requires the drone to have already taken off and connected to the network, but if authentication fails, the effectiveness of subsequent processing for drones that have already taken off and connected to the network is poor. Summary of the Invention

[0004] This application provides an authentication method, network device, storage medium, and computer program product. It enables a unified interface, a streamlined process, and improves the efficiency of post-processing for unmanned aerial vehicles (UAVs).

[0005] The technical solution of this application is implemented as follows:

[0006] Firstly, this application proposes an authentication method applied to a first network device, the method comprising:

[0007] Upon receiving the network registration request from the first device, the first authentication information is obtained from the first identity recognition module; the first identity recognition module is the identity recognition module currently inserted into the first device.

[0008] If the second authentication information corresponding to the first device is found, and at least some of the information in the first authentication information does not match the second authentication information, then the network registration process of the first device is stopped.

[0009] Secondly, this application proposes a network device, the network device comprising:

[0010] The acquisition unit is used to acquire first authentication information from the first identity recognition module after receiving the network registration request of the first device; the first identity recognition module is the identity recognition module currently inserted into the first device;

[0011] The processing unit is configured to stop the network registration process of the first device if it finds the second authentication information corresponding to the first device and at least part of the information in the first authentication information does not match the second authentication information.

[0012] Thirdly, this application provides a network device, which includes: a processor, a memory, and a communication bus; the communication bus is used to realize the connection and communication between the processor and the memory; the processor implements the above-mentioned authentication method when executing the running program stored in the memory.

[0013] Fourthly, this application provides a storage medium on which a computer program is stored, which, when executed by a processor, implements the aforementioned authentication method.

[0014] Fifthly, this application provides a computer program product, including a computer program that implements the above-mentioned authentication method when executed by a processor.

[0015] This application provides an authentication method, network device, storage medium, and computer program product. The method includes: upon receiving a network registration request from a first device, obtaining first authentication information from a first identity recognition module; the first identity recognition module is the identity recognition module currently inserted into the first device; if second authentication information corresponding to the first device is found, and at least part of the information in the first authentication information does not match the second authentication information, then stopping the network registration process of the first device. By adding an authentication sub-process for the first device to the network registration process of the first device, authentication can be uniformly performed on all drones that need to connect to the network, achieving unified interface and a single process; by comparing the first authentication information in the first identity recognition module with the second authentication information pre-stored on the first network device corresponding to the first device to authenticate the first device, if the second authentication information corresponding to the first device is pre-stored on the first network device, and at least part of the information in the first authentication information does not match the second authentication information, a result indicating that the first device has failed authentication is obtained. At this point, the network registration process of the first device is stopped, and the first device that has failed authentication is promptly prevented from connecting to the network, improving the effectiveness of subsequent processing of drones that have failed authentication. Attached Figure Description

[0016] Figure 1 A flowchart illustrating an authentication method provided in an embodiment of this application;

[0017] Figure 2 This is a schematic flowchart illustrating an exemplary authentication method inserted after the main authentication process, provided for an embodiment of this application.

[0018] Figure 3A schematic diagram illustrating an exemplary UDM process for performing drone authentication, provided as an embodiment of this application;

[0019] Figure 4 A schematic diagram of the structure of a network device provided in this application embodiment. Figure 1 ;

[0020] Figure 5 A schematic diagram of the structure of a network device provided in this application embodiment. Figure 2 . Detailed Implementation

[0021] In order to gain a more detailed understanding of the features and technical content of the embodiments of this application, the implementation of the embodiments of this application will be described in detail below with reference to the accompanying drawings. The accompanying drawings are for reference and illustration only and are not intended to limit the embodiments of this application.

[0022] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0023] In the following description, references to "some embodiments" refer to a subset of all possible embodiments. It is understood that "some embodiments" may be the same or different subsets of all possible embodiments and may be combined with each other without conflict. It should also be noted that the terms "first, second, third" used in the embodiments of this application are merely for distinguishing similar objects and do not represent a specific ordering of objects. It is understood that "first, second, third" may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0024] This application provides an authentication method, such as... Figure 1 As shown, applied to a first network device, the method may include:

[0025] S101. After receiving the network access request from the first device, obtain the first authentication information from the first identity recognition module; the first identity recognition module is the identity recognition module of the currently inserted first device.

[0026] In this embodiment, the first network device is a user data management (UDM) device on the core network side. The specific device can be selected based on actual circumstances, and this embodiment does not impose any specific limitations.

[0027] In this embodiment, the first device can be a network-connected device such as a drone, and the specific device can be selected according to the actual situation. This embodiment does not impose any specific limitations.

[0028] In this embodiment, the identity recognition module can be an IoT card or other communication card that provides network connectivity for connected devices. The specific card can be selected according to the actual situation, and this embodiment does not impose any specific limitations.

[0029] The authentication method proposed in this application is applied to the scenario of network-connected devices registering on the network. It should be noted that the authentication process proposed in this application can be added after the main authentication process in the network registration scenario, after a certain authentication process within the main authentication process in the network registration scenario, before the main authentication process in the network registration scenario, or before or after other processes in the network registration scenario. The specific timing for adding the authentication process proposed in this application in the network registration scenario can be selected according to the actual situation, and this application does not impose specific limitations.

[0030] In this embodiment of the application, after receiving the network registration request of the first device, the network registration process for the first device is initiated. The network side executes the network registration process in sequence until the authentication process is reached. Then, the UDM obtains the first authentication information from the first identity recognition module.

[0031] It should be noted that drones have their own unique number range. After the authentication process begins, UDM first determines whether the device requesting network access is a drone by identifying the number range. After determining that the device requesting network access is a drone, UDM obtains the first authentication information from the first identity recognition module.

[0032] In this embodiment, the first authentication information is written to the first identity recognition module after the second device is first inserted and started; the second device is the device that the first identity recognition module is first inserted and started. That is, when the first identity recognition module is first inserted into the second device, and the second device is first inserted with a card for the first identity recognition module, the first authentication information is written to the first identity recognition module.

[0033] Optionally, the first authentication information includes at least one of the following: the International Mobile Subscriber Identity (IMSI) of the first identification module, the International Mobile Equipment Identity (IMEI) of the communication module of the second device, and the unique identifier of the second device; the second device is the device that the first identification module is first inserted into and started. The specific selection can be made according to the actual situation, and this application embodiment does not impose specific limitations.

[0034] In one embodiment, the IMEI of the communication module can be collected using the Universal Subscriber Identity Module Application Toolkit (USAT) mechanism of the first identity recognition module.

[0035] In one embodiment, the first identification module sends an instruction to the baseband chip of the second device, and the baseband chip returns the IMSI of the first identification module to the first identification module.

[0036] In one embodiment, the unique identification code of the second device is obtained from the second device through the communication module and transmitted to the first identification module.

[0037] In this embodiment, the first network device sends a request to the first identity recognition module to obtain authentication information; the first identity recognition module sends first authentication information to the first network device; and the first network device returns confirmation information to the first identity recognition module. At this point, the process of the first network device obtaining the first authentication information from the first identity recognition module is complete.

[0038] In this embodiment, the first identity recognition module stores a triplet consisting of the IMSI of the first identity recognition module, the IMEI of the communication module of the second device, and the unique identification code of the second device.

[0039] S102. If the second authentication information corresponding to the first device is found, and at least some of the information in the first authentication information does not match the second authentication information, then the network registration process of the first device is stopped.

[0040] In this embodiment, the first network device searches for the second authentication information corresponding to the first device. If the second authentication information corresponding to the first device is found, the second authentication information is compared with the first authentication information.

[0041] Optionally, the second authentication information is written to the first network device when the identity recognition module is enabled for the first device.

[0042] It should be noted that the number of information types in the first authentication information includes or is equal to the number of information types in the second authentication information. The specific selection can be made according to the actual situation, and this application embodiment does not impose specific limitations.

[0043] It should be noted that when an individual identity recognition module is activated, the SIM card IMSI, communication module IMEI, and drone unique identification code are written into the UDM to achieve strong binding between the communication module, the drone, and the SIM card. In this case, the number of information types in the first authentication information is equal to the number of information types in the second authentication information. It should be noted that the SIM card here refers to the identity recognition module in this embodiment of the application.

[0044] It should be noted that when activating the identity recognition module in batches, since the combination of the communication module, drone, and SIM card is not yet finalized, some authentication information can be written as needed, or wildcards can be used to restrict certain authentication information to achieve weak binding. Later, when the drone first registers on the network after matching and assembling the drone, communication module, and SIM card, the binding will be performed by writing the UDM (User Device Management) information into the SIM card. At this time, the number of information types in the first authentication information includes the number of information types in the second authentication information.

[0045] In this embodiment of the application, if the second authentication information corresponding to the first device is found, and at least part of the information in the first authentication information does not match the second authentication information, it indicates that the first device has failed authentication. At this time, the network registration process of the first device is stopped. At the same time, the first information can be sent to the first identity recognition module; the first information indicates that the first device has failed authentication; so that the first identity recognition module can control the first device to suspend operation.

[0046] For example, if the second authentication information only contains the drone's unique identifier, then the drone's unique identifier in the first authentication information is matched with the drone's unique identifier in the second authentication information. If they do not match, it indicates that the first device's authentication has failed, and the first device's network registration process is stopped; if they match, it indicates that the first device's authentication has passed, and the first device's network registration process continues.

[0047] For example, if the second authentication information includes the SIM card IMSI, the communication module IMEI, and the drone's unique identification code, then the SIM card IMSI, the communication module IMEI, and the drone's unique identification code in the first authentication information are matched against the SIM card IMSI, the communication module IMEI, and the drone's unique identification code in the second authentication information, respectively. If all match, it indicates that the first device has passed authentication, and the network registration process for the first device continues; if at least one of them does not match, it indicates that the first device has failed authentication, and the network registration process for the first device stops.

[0048] Optionally, the first identification module can control the first device to pause operations such as takeoff. The specific type of operation to be paused can be selected according to the actual situation, and this application embodiment does not impose specific limitations.

[0049] Understandably, by adding a drone authentication step to the network registration process, it is possible to determine immediately whether a drone can connect to the network and take off if the authentication fails, thus improving the timeliness and simplifying the handling of drones that have failed authentication.

[0050] Furthermore, in one embodiment, if the second authentication information of the first device is not found, or if the second authentication information of the first device is found and part of the information in the first authentication information matches the second authentication information, it indicates that the first device has passed authentication. At this time, since the first network device has not written the authentication information of the first device, or has only written part of the authentication information, it indicates that the drone is registering on the network for the first time after the drone, communication module, and SIM card are matched and assembled. Therefore, the first authentication information in the first identity recognition module is written to the first network device by the first identity recognition module, which realizes strong binding and continues the network registration process of the first device.

[0051] It is understood that the authentication method proposed in this application not only fulfills the security requirement that all components of the networked drone must be bound and cannot be changed once bound, thus ensuring the strictness of authentication, but also allows for the selection of weak or strong binding when issuing cards in batches, thereby providing flexibility in binding.

[0052] Furthermore, in another embodiment, if the second authentication information of the first device is found and the first authentication information matches the second authentication information, it indicates that the first device has already performed the network registration process and the first device has passed the authentication process before the current network connection takes off. At this time, the network side continues the network registration process of the first device.

[0053] Understandably, adding an authentication sub-process for the first device to the network registration process allows for unified authentication of all drones requiring network access across the entire network, achieving interface uniformity and a single process. The first device is authenticated by comparing the first authentication information in the first identity recognition module with the second authentication information pre-stored on the first network device corresponding to the first device. If the second authentication information corresponding to the first device is pre-stored on the first network device, and at least some information in the first authentication information does not match the second authentication information, the first device's authentication fails. At this point, the network registration process for the first device is stopped, and the first device that failed authentication is promptly prevented from connecting to the network, improving the effectiveness of subsequent processing for drones that failed authentication.

[0054] Based on the above embodiments, when a network-connected drone is registered on the network, an authentication method is inserted after the main authentication process, such as... Figure 2 As shown, the method includes:

[0055] 1. Based on the unique number segment of the connected drone, UDM determines that the connected terminal is a drone.

[0056] It should be noted that connected drones have their own unique number range. After the UDM identifies the connected UE as a drone by recognizing the number range, it inserts the drone authentication process; if it is determined to be a non-drone, it continues the UE registration process.

[0057] 2. UDM obtains the IMSI, IMEI of the communication module, and the drone's unique identification code triplet from the IoT card.

[0058] 3. The IoT card sends the triple data it has collected and stored to the UDM.

[0059] 4. UDM sends an acknowledgment message to the IoT card.

[0060] 5. UDM executes the drone authentication process.

[0061] 6. If the drone authentication is successful, continue the UE network registration process.

[0062] 7. If the drone authentication is successful, the UE network access process will be rejected.

[0063] 8. UDM will also send the authentication result of the rejected UE network access process to the IoT card.

[0064] 9. The IoT card allows for further operation of the drone via the communication module's APP.

[0065] For example, a further action could be to prevent the drone from taking off. The specific type of further action to control the drone can be selected based on the actual situation, and this application does not impose specific limitations.

[0066] It should be noted that the specific process of UDM executing the drone authentication procedure in step 5 of the above authentication method can be found in [link to relevant documentation]. Figure 3 Specifically, it includes:

[0067] 1. UDM determines whether the complete triplet data of the drone is stored.

[0068] It should be noted that whether the drone has completed strong binding is determined by whether the complete triplet data of the drone is stored. If the complete triplet data of the drone is stored, the drone has completed strong binding; if the complete triplet data of the drone is not stored, the drone has not completed strong binding.

[0069] 2. If the UDM stores the complete triplet data of the drone, then determine whether the triplet data sent by the IoT card is consistent with the stored complete triplet data.

[0070] It should be noted that if the UDM stores complete triple data, it means that the drone was either strongly bound when the card was activated, or it is not the first time it has connected to the network, and its data was written to the UDM when it first connected to the network.

[0071] 3. If it is determined that the triplet data sent by the IoT card is consistent with the stored complete triplet data, then the drone authentication is successful.

[0072] 4. If it is determined that the triplet data sent by the IoT card is inconsistent with the stored complete triplet data, it indicates that the drone authentication has failed.

[0073] 5. If the UDM does not store the complete triplet data of the drone, then determine whether the UDM stores partial triplet data of the drone.

[0074] It should be noted that whether the drone has completed weak binding is determined by checking whether some of the drone's triplet data has been stored. If some of the drone's triplet data has been stored, then the drone has completed weak binding; if some of the drone's triplet data has not been stored, then the drone has not completed weak binding.

[0075] 6. If the UDM stores part of the drone's triple data, then determine whether the triple data sent by the IoT card matches the partial triple data.

[0076] It should be noted that if the UDM stores some of the drone's triple data (for example, some data is specified in the form of wildcards), it means that the drone was weakly bound when the card was activated, and the trusted enterprise flexibly binds various parts of the drone (such as the drone, communication module, and IoT card).

[0077] 7. If it is determined that the triplet data sent by the IoT card matches the partial triplet data, it indicates that the drone authentication is successful. At this time, the UDM uses this real-time acquired triplet to replace the previously stored partial triplet data.

[0078] 8. If it is determined that the triplet data sent by the IoT card does not match some of the triplet data, it indicates that the drone authentication has failed.

[0079] 9. If the UDM does not store part of the drone's triple data, it indicates that the drone authentication is successful. The UDM stores the real-time acquired triple data, and the drone has completed self-binding. Unbinding is not allowed afterward.

[0080] Based on the above embodiments, this application provides a network device. For example... Figure 4 As shown, the network device 1 includes:

[0081] The acquisition unit 10 is used to acquire first authentication information from the first identity recognition module after receiving the network registration request of the first device; the first identity recognition module is the identity recognition module currently inserted into the first device.

[0082] The processing unit 11 is configured to stop the network registration process of the first device if it finds the second authentication information corresponding to the first device and at least part of the information in the first authentication information does not match the second authentication information.

[0083] Optionally, the processing unit 11 is further configured to: if the second authentication information of the first device is not found, or if the second authentication information of the first device is found and some information in the first authentication information matches the second authentication information, then write the first authentication information into the first identity recognition module and continue the network registration process of the first device; if the second authentication information of the first device is found and the first authentication information matches the second authentication information, then continue the network registration process of the first device.

[0084] Optionally, the network device further includes: a transmitting unit;

[0085] The sending unit is configured to send first information to the first identity recognition module if it finds the second authentication information of the first device and at least part of the information in the first authentication information does not match the second authentication information; the first information indicates that the first device has failed authentication; so that the first identity recognition module can control the first device to suspend operation.

[0086] Optionally, the second authentication information is written to the first network device when the identity recognition module is enabled for the first device.

[0087] Optionally, the first authentication information is written to the first identity recognition module after the second device is first inserted and started; the second device is the device that the first identity recognition module is first inserted and started.

[0088] Optionally, the first authentication information includes at least one of the following: the International Mobile Subscriber Identity (IMSI) of the first identity recognition module, the International Mobile Equipment Identity (IMEI) of the communication module of the second device, and the unique identifier of the second device; the second device is the device to which the first identity recognition module is first inserted and started.

[0089] This application provides a network device that, upon receiving a network registration request from a first device, obtains first authentication information from a first identity recognition module. The first identity recognition module is the identity recognition module currently inserted into the first device. If second authentication information corresponding to the first device is found, and at least some information in the first authentication information does not match the second authentication information, the network registration process of the first device is stopped. Therefore, the network device proposed in this embodiment adds an authentication sub-process for the first device to the network registration process, enabling unified authentication for all drones requiring network access across the entire network, achieving unified interfaces and a single process. By comparing the first authentication information in the first identity recognition module with the second authentication information pre-stored on the first network device corresponding to the first device, the first device is authenticated. If the second authentication information corresponding to the first device is pre-stored on the first network device, and at least some information in the first authentication information does not match the second authentication information, the first device fails authentication. At this point, the network registration process of the first device is stopped, promptly preventing the first device from connecting to the network, thus improving the effectiveness of subsequent processing for drones that have failed authentication.

[0090] Figure 5 A schematic diagram of the composition structure of a network device 1 provided in this application embodiment. Figure 2 In practical applications, based on the same disclosed concept of the above embodiments, such as Figure 5 As shown, the network device 1 in this embodiment includes: a processor 12, a memory 13, and a communication bus 14.

[0091] The processor 12 described above can be at least one of the following: Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), CPU, controller, microcontroller, and microprocessor. It is understood that, for different devices, the electronic device used to implement the above processor function can also be other types, and this embodiment does not impose specific limitations.

[0092] In this embodiment, the communication bus 14 is used to realize the connection communication between the processor 12 and the memory 13; when the processor 12 executes the running program stored in the memory 13, it implements the following authentication method:

[0093] Upon receiving the network registration request from the first device, the first authentication information is obtained from the first identity recognition module; the first identity recognition module is the identity recognition module currently inserted into the first device; if the second authentication information corresponding to the first device is found, and at least part of the information in the first authentication information does not match the second authentication information, the network registration process of the first device is stopped.

[0094] Furthermore, the processor 12 is also configured to, if the second authentication information of the first device is not found, or if the second authentication information of the first device is found and part of the information in the first authentication information matches the second authentication information, write the first authentication information in the first identity recognition module and continue the network registration process of the first device; if the second authentication information of the first device is found and the first authentication information matches the second authentication information, continue the network registration process of the first device.

[0095] Furthermore, the processor 12 is also configured to send first information to the first identity recognition module if the second authentication information of the first device is found and at least part of the information in the first authentication information does not match the second authentication information; the first information indicates that the first device has failed authentication; so that the first identity recognition module can control the first device to suspend operation.

[0096] Furthermore, the second authentication information is written to the first network device when the identity recognition module is enabled for the first device.

[0097] Furthermore, the first authentication information is written to the first identity recognition module after the second device is first inserted and started; the second device is the device that the first identity recognition module is first inserted and started.

[0098] Furthermore, the first authentication information includes at least one of the following: the International Mobile Subscriber Identity (IMSI) of the first identity recognition module, the International Mobile Equipment Identity (IMEI) of the communication module of the second device, and the unique identifier of the second device; the second device is the device to which the first identity recognition module is first inserted and started.

[0099] This application provides a storage medium storing a computer program thereon. The computer-readable storage medium stores one or more programs, which can be executed by one or more processors and applied in a network device. The computer program implements the authentication method described above.

[0100] Based on the above embodiments, this application provides a computer program product, including a computer program that can be executed by one or more processors, and the computer program implements the authentication method as described above.

[0101] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0102] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the related technology, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause an image display device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this disclosure.

[0103] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application.

Claims

1. An authentication method, characterized in that, Applied to a first network device, the method includes: Upon receiving the network registration request from the first device, the first authentication information is obtained from the first identity recognition module; the first identity recognition module is the identity recognition module currently inserted into the first device. If the second authentication information corresponding to the first device is found, and at least some of the information in the first authentication information does not match the second authentication information, then the network registration process of the first device is stopped.

2. The method according to claim 1, characterized in that, After obtaining the first authentication information from the first identity recognition module, the method further includes: If the second authentication information of the first device is not found, or if the second authentication information of the first device is found and some information in the first authentication information matches the second authentication information, then the first authentication information is written into the first identity recognition module and the network registration process of the first device continues. If the second authentication information of the first device is found and the first authentication information matches the second authentication information, then the network registration process of the first device continues.

3. The method according to claim 1, characterized in that, After obtaining the first authentication information from the first identity recognition module, the method further includes: If the second authentication information of the first device is found, and at least part of the information in the first authentication information does not match the second authentication information, then the first information is sent to the first identity recognition module; the first information indicates that the first device has failed authentication; so that the first identity recognition module can control the first device to suspend operation.

4. The method according to claim 1, characterized in that, The second authentication information is written to the first network device when the identity recognition module is enabled for the first device.

5. The method according to claim 1, characterized in that, The first authentication information is written to the first identity recognition module after the second device is first inserted and started; the second device is the device that the first identity recognition module is first inserted and started.

6. The method according to claim 1, characterized in that, The first authentication information includes at least one of the following: the International Mobile Subscriber Identity (IMSI) of the first identity recognition module, the International Mobile Equipment Identity (IMEI) of the communication module of the second device, and the unique identifier of the second device; the second device is the device to which the first identity recognition module is first inserted and started.

7. A network device, characterized in that, The network device includes: The acquisition unit is used to acquire first authentication information from the first identity recognition module after receiving the network registration request of the first device; the first identity recognition module is the identity recognition module currently inserted into the first device; The processing unit is configured to stop the network registration process of the first device if it finds the second authentication information corresponding to the first device and at least part of the information in the first authentication information does not match the second authentication information.

8. A network device, characterized in that, The network device includes: a processor, a memory, and a communication bus; the communication bus is used to realize the connection and communication between the processor and the memory; when the processor executes the running program stored in the memory, it implements the method as described in any one of claims 1-6.

9. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-6.

10. A computer program product, comprising a computer program, characterized in that, The computer program, when executed by a processor, implements the method as described in any one of claims 1 to 6.