M2M Feature Identifier Authentication for Secure Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security technologies fail to establish secure communication between Machine-to-Machine (M2M) equipment and network sides due to the non-one-to-one correspondence between user identifiers and equipment in M2M communication scenarios, leading to insecure communication.
Innovation Solution
A security authentication method that verifies a feature identifier of M2M equipment after successful authentication and key agreement, obtaining a key based on the legal feature identifier to enable secure communication between the mobility management entity and the terminal equipment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing security technology is used in M2M communication, then the authentication process can be completed, but secure communication cannot be established due to non-one-to-one correspondence between user identifiers and equipment
Solution Approach 1:
The patent segments the identifier system by introducing a feature identifier that is specifically bound to the equipment, separating it from the user identifier. This allows the user identifier to remain general while the feature identifier provides equipment-specific security, resolving the contradiction between maintaining authentication security and adapting to many-to-many M2M relationships.
Solution Approach 2:
The feature identifier acts as an intermediary between the user identifier and the equipment. It is generated based on both the user identifier and equipment information, serving as a bridge that enables secure authentication in M2M scenarios where traditional one-to-one correspondence does not exist.
2Reliability
If feature identifier verification is added to the authentication process, then secure communication is enabled, but the authentication process becomes more complex
Solution Approach 1:
The feature identifier is generated and stored in advance during equipment registration or provisioning. This preliminary action allows the verification process to simply check against a pre-stored value rather than performing complex real-time calculations, thereby enabling security without adding significant complexity to the authentication process.
3Reliability
If a key is obtained based on feature identifier, then secure communication can be performed, but additional key management steps are required
Solution Approach 1:
The patent merges the feature identifier verification with the existing key generation process. The key is generated by combining the feature identifier with other authentication parameters in a unified process, rather than treating it as a separate step. This integration reduces the overall complexity of key management while maintaining secure communication capabilities.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Embodiments of the present invention provide a security authentication method, apparatus, and system, where the method includes: verifying a feature identifier for identifying terminal equipment, where the terminal equipment is machine-to-machine equipment; and obtaining a key corresponding to the feature identifier, so as to perform secure communication with the terminal equipment according to the key. In the embodiments of the present invention, after terminal equipment, a mobility management entity, and a home subscriber system successfully perform authentication and key agreement, it is verified whether a feature identifier of the terminal is legal, and when the feature identifier of the terminal is a legal identifier, a key is obtained according to the feature identifier, so that the mobility management entity and the terminal equipment perform secure communication according to the key, thereby implementing secure communication between M2M equipment and a network side.