Wireless Access Control for APGs Using Two-Layer Mutual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Ultra-Dense Networks (UDN/UUDN) scenarios, existing access control methods for User Equipment (UE) are inadequate to ensure secure access to dynamically varying Access Points Groups (APGs) due to diverse and flexible deployment modes, leading to potential security attacks from illegal APs pretending to be legal APGs.

Innovation Solution

A two-layer mutual authentication process involving network layer authentication with a Local Service Center (LSC) and access layer authentication with an Access Point (AP) is implemented, where the LSC determines the APG and instructs the AP to perform mutual authentication with the UE using specific authentication parameters, ensuring secure access to the APG after successful authentication at both layers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing access control methods are used in UDN/UUDN scenarios, then deployment flexibility is improved, but access security deteriorates due to illegal APs pretending to be legal APGs

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidaccess security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The authentication process is segmented into two distinct layers: network layer authentication between UE and LSC, and access layer authentication between UE and AP. This segmentation allows each layer to perform specific security functions, with the network layer establishing trusted credentials and the access layer verifying them, thereby maintaining security despite deployment flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The Local Service Center (LSC) acts as an intermediary between the UE and APs. The LSC generates and manages authentication credentials, mediating the authentication process by providing network layer authentication parameters to UE and access layer authentication parameters to APs. This intermediary role ensures secure credential distribution without requiring direct trust relationships between all parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If direct access to eNB/HeNB is used, then access simplicity is improved, but security against attacks by illegal APs deteriorates in UDN/UUDN scenarios

Engineering Contradiction:
Improveaccess simplicityVSAvoidsecurity against illegal APs
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Network layer authentication is performed as a preliminary action before access layer authentication. The UE first authenticates with the LSC to obtain authentication credentials, then uses these credentials during access layer authentication with the AP. This preliminary authentication ensures that only authorized UEs can proceed to access the network, preventing illegal APs from successfully impersonating legal ones.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If two-layer mutual authentication is implemented, then access security is improved, but authentication complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The LSC performs multiple functions: it acts as an authentication server for network layer authentication, generates authentication credentials, manages APG membership information, and distributes authentication parameters to both UE and APs. This multi-functionality consolidates complex authentication management into a single entity, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3562186B1Access control method and device
Publication Date: 2025.10.01 DATANG MOBILE COMM EQUIP CO LTD
  • EP3562186B1 patent drawingFigure 1
  • EP3562186B1 patent drawingFigure 2
  • EP3562186B1 patent drawingFigure 3

AI summary

Embodiments of the present invention relate to the technical field of wireless communications, and in particular to an access control method and device, for use in resolving the problem in the prior art that a user equipment cannot securely access an access point group (APG). According to the embodiments of the present invention, when a user equipment needs to access a network, the user equipment conducts network-layer two-way authentication with a local service center; after the network-layer two-way authentication succeeds, the user equipment conducts access-layer two-way authentication with a corresponding APG so as to enable the user equipment to access the corresponding APG after the access-layer two-way authentication succeeds. The embodiments of the present invention uses dual-layer two-way authentication, and enables the user equipment to access a corresponding APG after the dual-layer two-way authentication succeeds, so that the user equipment can securely access the corresponding APG