Network Device Real-Time Key Generation for IoT Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The centralized storage of symmetric keys and sequence numbers for terminal devices in Home Subscriber Servers (HSS) leads to severe load pressure and elongated network authentication chains, reducing efficiency in IoT devices accessing 5G networks.
Innovation Solution
A network authentication method where a network device generates a symmetric key and sequence number in real time for terminal devices, eliminating the need for HSS storage and reducing the authentication chain by allowing the network device to perform authentication independently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the HSS stores symmetric keys and sequence numbers for each terminal device, then network authentication can be performed, but the HSS experiences severe load pressure
Solution Approach 1:
The patent extracts the symmetric key storage function from the HSS and relocates it to the terminal device. The terminal device now stores its own symmetric key locally, eliminating the need for the HSS to store and manage symmetric keys for each terminal, thereby reducing the HSS storage load while maintaining authentication capability
Solution Approach 2:
The terminal device performs self-authentication by using its locally stored symmetric key to generate authentication tokens independently. This self-service mechanism eliminates the need for the HSS to actively participate in key management and authentication token generation, reducing the processing load on the HSS
2Reliability
If the HSS stores symmetric keys and sequence numbers for each terminal device, then network authentication can be performed, but the network authentication chain becomes elongated
Solution Approach 1:
The patent extracts the symmetric key from the HSS and places it in the terminal device, which removes the HSS from the authentication token generation process. This extraction shortens the authentication chain by eliminating unnecessary interaction steps with the HSS
Solution Approach 2:
The authentication function is segmented between the terminal device (which stores the symmetric key and generates tokens) and the network device (which verifies tokens). This segmentation allows the terminal to perform local authentication operations, reducing the need for lengthy interaction chains involving the HSS
3Reliability
If the HSS stores symmetric keys and sequence numbers for each terminal device, then network authentication can be performed, but network authentication efficiency is reduced
Solution Approach 1:
The terminal device performs self-authentication using its locally stored symmetric key to generate authentication tokens without requiring HSS intervention. This self-service approach significantly improves authentication efficiency by eliminating the need for the terminal to repeatedly query the HSS for authentication data
Solution Approach 2:
The symmetric key is pre-stored in the terminal device during device provisioning or initial setup. This preliminary action enables the terminal to perform fast local authentication operations without needing to retrieve keys from the HSS during each authentication event, thereby improving overall authentication efficiency
Data Source
Figure 1A
Figure 1B
Figure 2
AI summary
This application provides a network authentication method, a network device, a terminal device, and a storage medium. In one aspect, in this application, a network device generates a symmetric key by itself, and generates a correct sequence number of a terminal device in real time by using a first sequence number. In other words, in this application, the network device does not need to store the symmetric key and the correct sequence number of the terminal device, but generates the symmetric key and the correct sequence number of the terminal device in real time. Therefore, storage load of an HSS in the prior art can be reduced. In addition, because a device such as an MME is not required to perform network authentication between the terminal device and the network device in this application, a network authentication chain can be shortened, and network authentication efficiency can be improved. In another aspect, in this application, a first network device obtains an identifier of a terminal device, determines, based on the identifier of the terminal device, a target network authentication manner to be used between network side devices and the terminal device, and then sends indication information to a second network device to indicate the target network authentication manner. Therefore, this application further resolves a problem of notifying a network device of a specific network authentication manner.