5G Device Identity Authentication for Unauthorized Access Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for improving communication network security, such as network access authentication and blocklisting, fail to prevent devices without licenses from accessing the network, compromising network security.

Innovation Solution

Implementing authenticity verification on first identification information of communication apparatuses using authentication credentials when specific trigger conditions are met, including apparatus model or communication capability, to ensure only compliant devices access the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network access authentication is performed to verify device functions, then network security is improved, but devices without licenses can still access the network

Engineering Contradiction:
Improvenetwork securityVSAvoidunauthorized device access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing authenticity verification on device identification information before allowing network access. The authentication credential is verified in advance during the access authentication process, ensuring that only devices with authentic identification information can access the network, thereby preventing unauthorized devices from bypassing license checks

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a blocklist is used to detect device identifiers, then access control is improved, but devices not in the blocklist can still be insecure

Engineering Contradiction:
Improveaccess controlVSAvoidunsecured device access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies inversion by reversing the traditional blocklist approach. Instead of maintaining a list of blocked devices and allowing others by default, the system requires all devices to prove their authenticity through credential verification. The burden of proof is inverted from the network side to the device side, where devices must actively demonstrate their legitimacy rather than being passively allowed or blocked

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If authentication credentials are verified for all devices, then network security is enhanced, but authentication complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies merging by combining the authentication credential verification with the existing network access authentication process. The authenticity verification is integrated into the standard authentication flow, so that devices undergo a unified authentication process that simultaneously checks both network access credentials and identification information authenticity, rather than adding a separate complex verification step

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4701252A1Communication method, communication device, storage medium, and program product
Publication Date: 2026.02.25 HUAWEI TECH CO LTD
  • EP4701252A1 patent drawingFigure 1~2
  • EP4701252A1 patent drawingFigure 3~4
  • EP4701252A1 patent drawingFigure 5~6

AI summary

This application provides a communication method, a communication device, a storage medium, and a program product, and may be applied to the field of 5G new radio technologies. When a communication apparatus meets an authentication trigger condition, authentication information is obtained from the communication apparatus by using an authentication request. The authentication information may be used to verify authenticity of first identification information of the communication apparatus, to implement security authentication on the communication apparatus. When a communication apparatus that passes the security authentication accesses a communication network, security of the communication network can be improved.