Distance-Gated Network Authentication With Dual Signal Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network access security mechanisms are vulnerable to illegal terminals accessing networks by transmitting signals with high power, leading to insecure access control.
Innovation Solution
A dual verification method involving a network device measuring first signals to determine distance and then using authentication information based on secure sketch processing of second signals to confirm access rights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the network device uses signal measurement to determine terminal access rights, then the access control is simplified, but the security is compromised because illegal terminals can transmit high power signals to fake proximity
Solution Approach 1:
The authentication process is divided into two independent phases: first verification using network device measurement and second verification using terminal measurement. Each phase has its own measurement signals and verification criteria, preventing a single point of failure for security breaches.
Solution Approach 2:
The network device performs preliminary measurement of first signals from the terminal before allowing access. This preliminary verification establishes a baseline for legitimate proximity, and any terminal failing this initial check is rejected before reaching the second verification stage.
2Reliability
If the network device implements double verification with secure sketch processing, then the access security is improved, but the verification complexity increases
Solution Approach 1:
The secure sketch processing acts as an intermediary mechanism between the two verification stages. It processes the measurement results to generate authentication information that must be successfully verified in the second phase, providing a structured bridge between preliminary and final verification.
Solution Approach 2:
The system uses feedback from the first verification result to determine whether to proceed to the second verification. The authentication information generated in the first phase is fed back for verification in the second phase, creating a feedback loop that ensures consistency and security.
3Measurement precision
If the terminal performs secure sketch processing on second signal measurements, then the authentication accuracy is improved, but the processing time increases
Solution Approach 1:
The terminal performs secure sketch processing on the second signal measurements as a preliminary authentication step. This preliminary processing ensures that only terminals with accurate measurements proceed to the final verification stage, filtering out inaccurate or fraudulent requests early.
Solution Approach 2:
The system performs more measurement and processing operations than the minimum required (double verification with secure sketch), but this excessive action is necessary to achieve the required security level. The additional processing time is justified by the significant improvement in authentication accuracy and security.
Data Source
AI summary
This application provides an authentication method and communication apparatus. The method includes: measuring, by a network device, at least one first signal from a terminal to obtain a first measurement result, where the first measurement result is used for determining the distance between the terminal and the network device; determining, by the network device, that the terminal is not rejected to access network based on the first measurement result; transmitting, by the network device, at least one second signal to the terminal; receiving, by the network device, authentication information from the terminal, where the authentication information is obtained based on a second measurement result of the at least one second signal; and determining, by the network device, whether the terminal is allowed to access network based on the authentication information.


