Wireless Access Control for APGs Using Two-Layer Mutual Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Ultra-Dense Networks (UDN/UUDN) scenarios, existing access control methods for User Equipment (UE) are inadequate to ensure secure access to dynamically varying Access Points Groups (APGs) due to diverse and flexible deployment modes, leading to potential security attacks from illegal APs pretending to be legal APGs.
Innovation Solution
A two-layer mutual authentication process involving network layer authentication with a Local Service Center (LSC) and access layer authentication with an Access Point (AP) is implemented, where the LSC determines the APG and instructs the AP to perform mutual authentication with the UE using specific authentication parameters, ensuring secure access to the APG after successful authentication at both layers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing access control methods are used in UDN/UUDN scenarios, then deployment flexibility is improved, but access security deteriorates due to illegal APs pretending to be legal APGs
Solution Approach 1:
The authentication process is segmented into two distinct layers: network layer authentication between UE and LSC, and access layer authentication between UE and AP. This segmentation allows each layer to perform specific security functions, with the network layer establishing trusted credentials and the access layer verifying them, thereby maintaining security despite deployment flexibility.
Solution Approach 2:
The Local Service Center (LSC) acts as an intermediary between the UE and APs. The LSC generates and manages authentication credentials, mediating the authentication process by providing network layer authentication parameters to UE and access layer authentication parameters to APs. This intermediary role ensures secure credential distribution without requiring direct trust relationships between all parties.
2Ease of operation
If direct access to eNB/HeNB is used, then access simplicity is improved, but security against attacks by illegal APs deteriorates in UDN/UUDN scenarios
Solution Approach 1:
Network layer authentication is performed as a preliminary action before access layer authentication. The UE first authenticates with the LSC to obtain authentication credentials, then uses these credentials during access layer authentication with the AP. This preliminary authentication ensures that only authorized UEs can proceed to access the network, preventing illegal APs from successfully impersonating legal ones.
3Reliability
If two-layer mutual authentication is implemented, then access security is improved, but authentication complexity increases
Solution Approach 1:
The LSC performs multiple functions: it acts as an authentication server for network layer authentication, generates authentication credentials, manages APG membership information, and distributes authentication parameters to both UE and APs. This multi-functionality consolidates complex authentication management into a single entity, reducing overall system complexity while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the present invention relate to the technical field of wireless communications, and in particular to an access control method and device, for use in resolving the problem in the prior art that a user equipment cannot securely access an access point group (APG). According to the embodiments of the present invention, when a user equipment needs to access a network, the user equipment conducts network-layer two-way authentication with a local service center; after the network-layer two-way authentication succeeds, the user equipment conducts access-layer two-way authentication with a corresponding APG so as to enable the user equipment to access the corresponding APG after the access-layer two-way authentication succeeds. The embodiments of the present invention uses dual-layer two-way authentication, and enables the user equipment to access a corresponding APG after the dual-layer two-way authentication succeeds, so that the user equipment can securely access the corresponding APG