5G IoT Access Authentication via Device Fingerprinting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of IoT devices accessing 5G networks poses challenges in security management due to varied equipment types and architectures, leading to difficulties in unified safety control and authentication, with traditional security measures becoming overwhelmed by the sheer volume of devices, resulting in vulnerabilities like ID tampering and data attacks.

Innovation Solution

An access method and system for IoT devices in 5G networks that involves generating an authentication ID based on device ID, performing ID authentication, and using SM9 cryptographic algorithms for secure access, including active detection and preprocessing of characteristic parameters to ensure legitimate device access and data integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security access measures (IPSec VPN or SSL VPN) are used for IoT equipment access, then secure access functions (ID mutual authentication, data encryption, access control) are provided, but the computational burden on the security access protection system becomes unbearable due to the huge number of IoT devices

Engineering Contradiction:
Improvesecurity access protectionVSAvoidcomputational burden on security system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into two stages: device fingerprint authentication (lightweight) and optional SM9 cryptographic authentication (heavyweight). This segmentation allows most devices to use the lightweight fingerprint method while providing enhanced security for specific scenarios through the heavier cryptographic method, thereby reducing overall computational burden while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the authentication parameter from traditional complex cryptographic protocols to a simplified device fingerprint-based authentication mechanism. By extracting characteristic parameters from device hardware and software, the system transforms the authentication process into a more efficient parameter comparison task, significantly reducing computational requirements for the security system.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If device ID is used for full life cycle management of IoT equipment, then unified ID management is achieved, but the equipment cannot protect against ID tampering and ID forgery due to limited resources

Engineering Contradiction:
Improveunified ID managementVSAvoidprotection against ID tampering and forgery
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-binding the device fingerprint to the device hardware during manufacturing or initial setup. This pre-established binding creates a trusted root that cannot be easily tampered with, providing inherent protection against ID forgery before any authentication operations occur. The device fingerprint serves as a pre-configured security anchor that persists throughout the device lifecycle.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces the device fingerprint as an intermediary between the device ID and the authentication process. Instead of directly trusting the device ID, the system uses the fingerprint (derived from hardware characteristics) as an intermediate verification layer. This intermediary mechanism prevents direct ID tampering while maintaining unified ID management, as the fingerprint acts as an immutable reference that validates the true device identity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If massive IoT equipments access 5G network, then high-speed and large-capacity access is achieved, but network security issues and hazards increase significantly

Engineering Contradiction:
Improveaccess speed and capacityVSAvoidnetwork security hazards
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent enables self-service by allowing each IoT device to autonomously generate and maintain its own device fingerprint and authentication credentials without requiring intensive centralized security processing. The device itself participates in securing its own access through the fingerprint authentication mechanism, reducing the security burden on the network while maintaining high access capacity for massive devices.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11743726B2Access method and system of internet of things equipment based on 5G, and storage medium
Publication Date: 2023.08.29 SHENZHEN GAS CORP
  • US11743726B2 patent drawing
  • US11743726B2 patent drawing

AI summary

A 5G-based Internet of Things device access method and system, and storage medium. Method includes steps that IoT access platform generates authentication identification of to-be-accessed IoT device according to device identification of to-be-accessed IoT device, and carries out identity authentication of to-be-accessed IoT device through authentication identification, and identity authentication result is sent to to-be-accessed IoT device so when identity authentication result received by to-be-accessed IoT device is that identity authentication is passed, to-be-accessed IoT device accesses IoT access platform and performs encrypted data communication. Method is advantaged in that legal identity of to-be-accessed IoT equipment is verified by taking equipment fingerprint as authentication identifier, and data integrity of to-be-accessed IoT equipment is ensured through access authentication, so illegal terminal is prevented from accessing IoT access platform, and security of data transmission is improved.