Grouped 5G Terminal Authentication to Reduce Signaling Overhead
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication mechanisms in 5G communication systems, particularly in IoT scenarios, face inefficiencies due to the large number of terminal devices, leading to prolonged authentication times and significant signaling overhead.
Innovation Solution
Implementing an identity-based cryptography (IBC) method where only the first terminal device in a group undergoes a full authentication process, with subsequent devices in the group bypassing authentication, reducing computational and signaling burdens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication mechanism is used for all terminal devices, then authentication security is maintained, but authentication time and computational load increase significantly
Solution Approach 1:
The patent segments terminal devices into different groups (e.g., high-risk and low-risk groups) based on their authentication history and characteristics. Different authentication mechanisms are applied to different groups: full authentication for high-risk devices and simplified authentication for low-risk devices. This segmentation allows the system to maintain security for critical devices while reducing authentication time for trusted devices.
Solution Approach 2:
The patent changes the authentication parameter complexity based on device risk levels. For low-risk devices in the same group as previously authenticated devices, the system reduces authentication parameters and steps, allowing faster authentication. For high-risk or new devices, full authentication parameters are applied. This dynamic parameter adjustment resolves the contradiction between security and speed.
2Reliability
If traditional authentication mechanism is used for all terminal devices, then authentication security is maintained, but computational resources are consumed excessively
Solution Approach 1:
The patent divides terminal devices into segments based on their risk profile and authentication history. Devices identified as low-risk (such as those in the same group as successfully authenticated devices) undergo simplified authentication with reduced computational requirements. High-risk devices undergo full authentication. This segmentation strategy maintains security for critical devices while minimizing computational resource consumption for trusted devices.
Solution Approach 2:
The patent applies partial authentication action for devices in the same group as previously authenticated devices. Instead of performing complete authentication for every device, the system performs only necessary verification steps for low-risk devices, using partial authentication checks. This reduces computational energy consumption while maintaining adequate security through the grouping mechanism.
3Reliability
If authentication is performed for every terminal device, then security verification is ensured, but signaling overhead increases
Solution Approach 1:
The patent merges multiple terminal devices into groups based on their authentication characteristics and risk profiles. Devices in the same group share authentication results, allowing the system to verify one device and extend that verification to other devices in the group. This merging approach reduces the number of individual authentication signaling exchanges, lowering overall signaling overhead while maintaining security through group-based verification.
Solution Approach 2:
The patent creates a universal authentication result that can be applied to multiple devices within the same group. Once one device in a group is authenticated, the authentication result serves universally for other devices in that group, eliminating the need for repeated individual authentication signaling. This multi-functionality of authentication results significantly reduces signaling overhead while maintaining security verification.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the disclosure provide a method, device and computer readable medium for authentication. According to embodiments of the present disclosure, only the first terminal device in a group of terminal devices which requests to connect to a network needs to finish the whole authentication. Upon the first terminal device successfully accesses to the network, the remaining terminal devices in the same group can ignore the authentication. In this way, time for authentication is reduced and the calculation efforts related to authentication is reduced for a large number for terminal devices.