5G Device Identity Authentication for Unauthorized Access Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for improving communication network security, such as network access authentication and blocklisting, fail to prevent devices without licenses from accessing the network, compromising network security.
Innovation Solution
Implementing authenticity verification on first identification information of communication apparatuses using authentication credentials when specific trigger conditions are met, including apparatus model or communication capability, to ensure only compliant devices access the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network access authentication is performed to verify device functions, then network security is improved, but devices without licenses can still access the network
Solution Approach 1:
The patent applies preliminary action by performing authenticity verification on device identification information before allowing network access. The authentication credential is verified in advance during the access authentication process, ensuring that only devices with authentic identification information can access the network, thereby preventing unauthorized devices from bypassing license checks
2Reliability
If a blocklist is used to detect device identifiers, then access control is improved, but devices not in the blocklist can still be insecure
Solution Approach 1:
The patent applies inversion by reversing the traditional blocklist approach. Instead of maintaining a list of blocked devices and allowing others by default, the system requires all devices to prove their authenticity through credential verification. The burden of proof is inverted from the network side to the device side, where devices must actively demonstrate their legitimacy rather than being passively allowed or blocked
3Reliability
If authentication credentials are verified for all devices, then network security is enhanced, but authentication complexity increases
Solution Approach 1:
The patent applies merging by combining the authentication credential verification with the existing network access authentication process. The authenticity verification is integrated into the standard authentication flow, so that devices undergo a unified authentication process that simultaneously checks both network access credentials and identification information authenticity, rather than adding a separate complex verification step
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
This application provides a communication method, a communication device, a storage medium, and a program product, and may be applied to the field of 5G new radio technologies. When a communication apparatus meets an authentication trigger condition, authentication information is obtained from the communication apparatus by using an authentication request. The authentication information may be used to verify authenticity of first identification information of the communication apparatus, to implement security authentication on the communication apparatus. When a communication apparatus that passes the security authentication accesses a communication network, security of the communication network can be improved.