Network Authentication via Relay Terminal Correspondence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication technologies lack a method to authenticate terminals accessing a mobile communications network using a relay terminal, which poses challenges in managing network access and ensuring security.
Innovation Solution
An authentication method and device that verify the validity of a terminal accessing a network by using another terminal, through a preset correspondence between terminal types, allowing valid access and storing authentication information for future connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a terminal accesses the network by using a relay terminal, then terminals without network access functions or with strict electricity consumption requirements can connect to the network, but there is no authentication method to verify the validity of such access
Solution Approach 1:
The patent introduces a correspondence relationship between the first terminal and second terminal as an intermediary mechanism. The network device verifies the authentication request by checking this pre-established correspondence, enabling authentication of relayed access without requiring the first terminal to directly communicate with the network device.
Solution Approach 2:
The patent establishes a correspondence relationship between terminals before the actual network access occurs. This preliminary action of creating and storing the correspondence allows the network device to quickly verify the legitimacy of relayed access requests without complex real-time authentication procedures.
2Reliability
If the network device directly authenticates every terminal access request, then authentication security is maintained, but the complexity of the authentication procedure increases for relayed access scenarios
Solution Approach 1:
The correspondence relationship acts as an intermediary that simplifies the authentication process. Instead of the network device directly managing complex authentication for relayed access, it only needs to verify whether the requested terminal pair exists in the pre-established correspondence, significantly reducing procedural complexity.
Solution Approach 2:
The patent creates a simplified verification mechanism by copying the essential authentication information into a correspondence relationship. The network device only needs to check the existence of this correspondence rather than performing full authentication procedures, reducing complexity while maintaining security.
3Reliability
If the network device stores correspondence information for all terminal pairs, then authentication of relayed access is enabled, but the storage requirements and management complexity increase
Solution Approach 1:
The correspondence information is established in advance between terminals before network access is needed. This preliminary action allows the network device to store only essential pairing information rather than complete authentication credentials, reducing storage requirements while enabling verification.
Solution Approach 2:
The patent extracts only the essential correspondence relationship information needed for verification, separating it from complete authentication data. The network device stores and verifies only the pairing correspondence, not the full authentication credentials, minimizing storage requirements.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
This application discloses an authentication method and a device. In this method, a first network device receives an authentication request sent by a second network device, where the authentication request includes an identifier of a first terminal and an identifier of a second terminal; the first network device authenticates, based on a preset correspondence between a first-type terminal and a second-type terminal, validity of accessing, by the first terminal, a network by using the second terminal, where a first-type terminal is allowed to access the network by using a second-type terminal corresponding to the first-type terminal; and the first network device sends an authentication response to the second network device, where the authentication response carries indication information used to indicate whether the first terminal is allowed to access the network by using the second terminal. The foregoing method implements authentication on validity of accessing, by the first terminal, the network by using the second terminal, to prevent a case in which a network-side device fails to detect the access of the first terminal when the first terminal accesses the network by using the second terminal.