Security parameter updating method and apparatus, electronic device, and storage medium

By receiving terminal service security alarm information and triggering intra-cell handover procedures, and combining anomaly detection models to update security parameters, the problem of attacks by users at unknown locations in wireless communication systems is solved, thereby improving the system's security and protection capabilities.

CN115426655BActive Publication Date: 2025-10-24INSPUR COMM TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202210813413.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-11
Publication Date
2025-10-24
Estimated Expiration
2042-07-11

AI Technical Summary

Technical Problem

Existing wireless communication systems lack effective defenses against security attacks launched by users in unknown locations within 5G networks, resulting in insufficient network security.

Method used

By receiving terminal service security alarm information sent by the near real-time control system, updating security parameters, and triggering the terminal's intra-cell handover process, updating security parameters using RRC reconfiguration messages, and combining anomaly detection models to monitor service information in real time, attacks can be detected and defended in a timely manner.

Benefits of technology

It effectively improves the security of wireless communication systems, promptly detects and responds to security attacks launched by users in unknown locations, and enhances the system's protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115426655B_ABST
    Figure CN115426655B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of wireless communication, and provides a security parameter updating method and device, electronic equipment and a storage medium, wherein the method is applied to a network device and comprises the following steps: receiving service security alarm information of a terminal sent by a near real-time control system; updating a security parameter according to the service security alarm information, and sending an RRC reconfiguration message carrying a security parameter updating instruction to the terminal, so that the terminal updates the security parameter and executes an intra-cell handover process. Through the application, the network device can receive the service security alarm information of the terminal sent by the near real-time control system, and after receiving the service security alarm information of the terminal, triggers the intra-cell handover process of the terminal to update the security parameter, so that unknown position users can be found and resisted in time, and the security of a wireless communication system is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of wireless communication, and in particular to a security parameter updating method and device, an electronic device and a storage medium. BACKGROUND

[0002] The development vision of the 5th generation mobile communication (5G) puts forward higher requirements on network bandwidth, user density, network delay, reliable transmission and the like compared with the last generation of mobile communication system, so that it faces greater challenges to provide higher level of security protection without affecting the network function and performance.

[0003] At present, for wireless access attacks in the form of tampering, impersonation, man-in-the-middle forwarding and replay of information content with wireless signals as carriers, traditional authentication and data integrity protection schemes such as Authentication and Key Agreement (AKA), Evolved Packet System (EPS) AKA and the like essentially use identity index-based keys to label signaling and data with labels containing user identity information. Once the root key is compromised, the authentication parameters will be invalid, and the subsequent protection keys can be derived by eavesdropping the AKA authentication process, threatening network security.

[0004] With the continuous improvement of mobile communication rate, due to the contradiction between rate and computational complexity, there is no suitable solution for the integrity protection of service data in the current mobile communication system. Therefore, it is necessary to study means capable of quickly discovering and resisting active attacks initiated by unknown location users for typical scenarios in 5G, in order to meet the security requirements of various scenarios and various levels of 5G. SUMMARY

[0005] The present application provides a security parameter updating method, device, electronic device and storage medium, which can quickly discover and resist security attacks initiated by unknown location users, and improve the security of wireless communication systems.

[0006] In a first aspect, the present application provides a security parameter updating method applied to a network device, comprising:

[0007] receiving service security alarm information of a terminal sent by a near real-time control system;

[0008] updating a security parameter according to the service security alarm information, and sending an RRC reconfiguration message carrying a security parameter update indication to the terminal, so that the terminal updates the security parameter and performs an intra-cell handover process.

[0009] Optionally, before receiving the service security alarm information of the terminal sent by the near real-time control system, the method further comprises:

[0010] sending the service information of the terminal to the near real-time control system.

[0011] Optionally, the sending the service information of the terminal to the near real-time control system comprises:

[0012] receiving a terminal information reporting command sent by the near real-time control system, the terminal information reporting command being used to instruct the network device to periodically report the service information of the served terminal to the near real-time control system;

[0013] according to the terminal information reporting command, sending the service information of the terminal to the near real-time control system.

[0014] Optionally, the service information comprises at least one of the following:

[0015] service type information;

[0016] service data flow information.

[0017] In a second aspect, the application further provides a security parameter updating method applied to a near real-time control system, comprising:

[0018] determining that the service information of a terminal is abnormal;

[0019] sending service security alarm information of the terminal to a network device accessed by the terminal, the service security alarm information being used to trigger the network device to update a security parameter and send an RRC reconfiguration message carrying a security parameter updating instruction to the terminal, so that the terminal updates the security parameter and performs an intra-cell handover process.

[0020] Optionally, the determining that the service information of a terminal is abnormal comprises:

[0021] receiving service information of the terminal sent by the network device;

[0022] based on an abnormality detection model, determining that the service information of the terminal is abnormal;

[0023] wherein the abnormality detection model is obtained based on historical service data of the terminal.

[0024] Optionally, before receiving the service information of the terminal sent by the network device, the method further comprises:

[0025] The network device is sent a terminal information reporting command, and the terminal information reporting command is used to instruct the network device to periodically report service information of a served terminal to the near real-time control system.

[0026] Optionally, the service information includes at least one of the following:

[0027] service type information;

[0028] service data flow information.

[0029] Optionally, the anomaly detection model includes a DBSCAN algorithm model or a SARIMA algorithm model.

[0030] In a third aspect, the present application further provides a security parameter updating apparatus applied to a network device, comprising:

[0031] a first receiving module configured to receive service security alarm information of a terminal sent by a near real-time control system;

[0032] a first sending module configured to update a security parameter according to the service security alarm information, and send an RRC reconfiguration message carrying a security parameter update indication to the terminal, so that the terminal updates the security parameter and performs an intra-cell handover process.

[0033] In a fourth aspect, the present application further provides a security parameter updating apparatus applied to a near real-time control system, comprising:

[0034] an anomaly detection module configured to determine service information anomaly of a terminal;

[0035] a second sending module configured to send service security alarm information of the terminal to a network device accessed by the terminal, so as to trigger the network device to update a security parameter and send an RRC reconfiguration message carrying a security parameter update indication to the terminal, so that the terminal updates the security parameter and performs an intra-cell handover process.

[0036] In a fifth aspect, the present application further provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the security parameter updating method of the first aspect or the security parameter updating method of the second aspect when executing the program.

[0037] In a sixth aspect, the present application further provides a non-transitory computer readable storage medium having a computer program stored thereon, and the computer program is executable on a processor to implement the security parameter updating method of the first aspect or the security parameter updating method of the second aspect.

[0038] The application provides a security parameter updating method and device, electronic equipment and a storage medium, wherein the network equipment can receive service security alarm information of a terminal sent by a near real-time control system, and trigger a cell handover process of the terminal to update the security parameter after receiving the service security alarm information of the terminal, so that unknown location user initiated security attacks can be found and resisted in time, and the security of the wireless communication system is effectively improved. BRIEF DESCRIPTION OF DRAWINGS

[0039] In order to more clearly illustrate the technical solutions in the application or prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative effort on the basis of these drawings.

[0040] Figure 1 Fig. 1 is one of the flow diagrams of the security parameter updating method provided by the application;

[0041] Figure 2 Fig. 2 is another of the flow diagrams of the security parameter updating method provided by the application;

[0042] Figure 3 Fig. 3 is one of the implementation diagrams of the security parameter updating method provided by the application;

[0043] Figure 4 Fig. 4 is another of the implementation diagrams of the security parameter updating method provided by the application;

[0044] Figure 5 Fig. 5 is one of the structural diagrams of the security parameter updating device provided by the application;

[0045] Figure 6 Fig. 6 is another of the structural diagrams of the security parameter updating device provided by the application;

[0046] Figure 7 Fig. 7 is the structural diagram of the electronic equipment provided by the application. DETAILED DESCRIPTION

[0047] In order to make the objects, technical solutions and advantages of the application clearer, the technical solutions in the application will be described clearly and completely below with reference to the drawings in the application. Obviously, the described embodiments are some embodiments of the application, but not all the embodiments. Based on the embodiments in the application, all the other embodiments obtained by those skilled in the art without creative effort belong to the protection scope of the application.

[0048] With the development of mobile network applications and the intensification of homogenization competition of Internet applications, users have higher and higher requirements for service experience. Fluctuation of wireless air interface transmission capacity makes it more and more difficult for traditional relatively semi-static quality of service (QoS) configuration to meet the ever-increasing diversified service experience requirements. In order to better meet the service requirements, it is necessary to accurately obtain user-level real-time service key quality indicators (KQI) and quality of experience (QoE), so as to efficiently adapt the service to the dynamic air interface transmission capacity. In order to achieve the above-mentioned goal, the wireless network needs to realize real-time perception and prediction of service quality experience, so as to provide differentiated and extreme user service experience.

[0049] Based on the open radio access network (O-RAN) alliance E2 interface, the wireless communication industry provides service QoE prediction and QoS parameter control functions based on real-time wireless air interface data. Based on big data, machine learning is introduced for KQI / QoE prediction. Considering the vertical industry-oriented service requirements such as augmented reality (AR) inspection and AR remote control, based on the correlation analysis of air interface data and service experience data, the wireless side and service data are used to predict the service KQI / QoE in real time, and based on the QoE prediction result, the wireless experience rate and delay of the user are guaranteed in real time to provide extreme service experience for the user. The QoE prediction technology includes data collection and reporting of QoE prediction model and available bandwidth prediction model. The reporting is divided into UE-level data reporting and cell-level data reporting. The UE-level data includes the ID information of the UE in the base station, the real-time service type and traffic information of the UE.

[0050] The present application provides a complete integrity protection solution for service data, and timely discovers and resists security attacks initiated by unknown location users, and improves the security of the wireless communication system.

[0051] Figure 1 A flowchart of a security parameter updating method provided by the present application is shown in FIG. 1. The method is applied to a network device (such as a base station), as shown in FIG. 1, which includes the following steps: Figure 1

[0052] Step 100, receiving service security alarm information of a terminal sent by a near real-time control system.

[0053] Step 101, updating the security parameters according to the service security alarm information, and sending an RRC reconfiguration message carrying a security parameter update indication to the terminal, so that the terminal updates the security parameters and executes an intra-cell handover process. ​

[0054] Specifically, in the embodiments of the present application, the security parameter can be an encryption and integrity protection key of signaling and data.

[0055] The near real-time control system can be a near real-time radio access network intelligent controller (RIC) in O-RAN.

[0056] In the embodiments of the present application, the near real-time control system can send service security alarm information of a terminal to a network device (such as a base station) accessed by the terminal in a case where service information of the terminal is determined to be abnormal.

[0057] After the base station receives the service security alarm information of the terminal, a cell handover process of the terminal is triggered, a radio resource control (RRC) reconfiguration message carrying a security parameter update indication is sent to the terminal, and a security parameter update is performed.

[0058] After the terminal receives the RRC reconfiguration message carrying the security parameter update indication, the security parameter is updated, random access is initiated, the original cell is re-accessed, and the cell handover process is completed.

[0059] Optionally, the near real-time control system can determine whether the service information of the terminal is abnormal by judging the service information of the terminal in combination with the trained abnormality detection model based on the service information of the terminal sent by the network device, generate a service security alarm in a case where the service information of the terminal is determined to be abnormal, and trigger a cell handover of the terminal to perform a security parameter update.

[0060] The security parameter update method provided by the present application can enable the network device to receive service security alarm information of a terminal sent by a near real-time control system, and trigger a cell handover process of the terminal to perform a security parameter update after receiving the service security alarm information of the terminal, so as to timely discover and resist security attacks initiated by unknown location users, and effectively improve the security of a wireless communication system.

[0061] Optionally, before receiving the service security alarm information of the terminal sent by the near real-time control system, the method further comprises:

[0062] Sending service information of the terminal to the near real-time control system.

[0063] Specifically, in the embodiments of the present application, the network device can send service information of the terminal to the near real-time control system, so that the near real-time control system can determine whether the service information of the terminal is abnormal by judging the service information of the terminal in combination with a trained abnormality detection model.

[0064] Optionally, the service information of the terminal is sent to the near real-time control system, comprising:

[0065] The terminal information reporting command sent by the near real-time control system is received, and the terminal information reporting command is used to instruct the network device to periodically report the service information of the served terminal to the near real-time control system.

[0066] According to the terminal information reporting command, the service information of the terminal is sent to the near real-time control system.

[0067] Specifically, in the embodiment of the application, the near real-time control system can issue a terminal information reporting command to the network device after establishing an E2 interface link with the network device, which is used to instruct the network device to periodically report the service information of the served terminal to the near real-time control system, so that the network device can report the service establishment situation and real-time service data situation of the terminal to the near real-time control system according to the terminal information reporting command. The time interval of periodic reporting can be set as needed, such as 100 ms, 1 s, etc., which is not limited here.

[0068] Figure 2 The flowchart of the security parameter updating method provided by the application is shown in Figure 2, which is applied to a near real-time control system, as shown in Figure 2, the method comprises the following steps: Figure 2

[0069] Step 200, determine the abnormal service information of the terminal.

[0070] Step 201, send the service security alarm information of the terminal to the network device accessed by the terminal, and the service security alarm information is used to trigger the network device to update the security parameter, and send the RRC reconfiguration message carrying the security parameter update indication to the terminal, so that the terminal updates the security parameter and performs the intra-cell handover process.

[0071] Specifically, in the embodiment of the application, the security parameter can be the encryption and integrity protection key of signaling and data.

[0072] The near real-time control system can be a near real-time RIC in O-RAN.

[0073] In the embodiment of the application, the near real-time control system can send the service security alarm information of a certain terminal to the network device (such as a base station) accessed by the terminal when determining that the service information of the terminal is abnormal.

[0074] After the base station receives the service security alarm information of the terminal, it triggers the intra-cell handover process of the terminal, sends the RRC reconfiguration message carrying the security parameter update indication to the terminal, and performs a security parameter update.

[0075] ​After the terminal receives the RRC reconfiguration message carrying the security parameter update indication, the security parameter is updated, random access is initiated, the original cell is re-accessed, and the intra-cell handover process is completed.

[0076] The security parameter update method provided by the application can generate a service security alarm and trigger intra-cell handover of the terminal to update the security parameter when the near real-time control system determines that the service information of the terminal is abnormal, so that unknown location user-initiated security attacks can be discovered and resisted in time, and the security of the wireless communication system is effectively improved.

[0077] Optionally, determining that the service information of the terminal is abnormal comprises:

[0078] Receiving the service information of the terminal sent by the network device;

[0079] Determining that the service information of the terminal is abnormal based on an anomaly detection model;

[0080] The anomaly detection model is obtained by training historical service data of the terminal.

[0081] Specifically, in the embodiments of the application, the near real-time control system can determine whether the service information of the terminal is abnormal by judging the service information of the terminal sent by the network device in combination with the trained anomaly detection model, and generate a service security alarm and trigger intra-cell handover of the terminal to update the security parameter when the service information of the terminal is determined to be abnormal.

[0082] Optionally, the service information can include at least one of the following: service type information (which can be used to indicate the service type of the terminal); service data flow information (which can be used to indicate the service data condition of the terminal).

[0083] Optionally, the anomaly detection model can include a DBSCAN algorithm model or a SARIMA algorithm model. The DBSCAN algorithm model is a density-based clustering algorithm model based on density and robust to noise (Density-Based Spatial Clustering of Applications with Noise, DBSCAN), which can be used for anomaly detection of data; the SARIMA algorithm model is a seasonal autoregressive integrated moving average (Seasonal Autoregressive Integrated Moving Average, SARIMA) algorithm model, which is a time series prediction algorithm model and can be used for anomaly detection of time series data.

[0084] The near real-time control system can train an abnormality detection model such as a DBSCAN or SARIMA algorithm model in advance through historical service data of a large number of terminals, that is, intelligent learning is performed through an artificial intelligence (AI) algorithm, terminal service types, service data traffic (service rate), and the like are counted and summarized, relevant rules are obtained, and the trained abnormality detection model is used for abnormality detection on real-time service information of the terminal.

[0085] The near real-time control system can receive service information of a terminal sent by a network device and perform abnormality detection on the service information of the terminal through an intelligent automatic process, thereby reducing the time and labor cost of manual operation and maintenance.

[0086] Optionally, before receiving the service information of the terminal sent by the network device, the method further includes:

[0087] The network device is sent a terminal information reporting command, and the terminal information reporting command is used to instruct the network device to periodically report service information of a terminal served by the network device to the near real-time control system.

[0088] Specifically, in the embodiment of the application, the near real-time control system can send a terminal information reporting command to the network device after establishing an E2 interface link with the network device, to instruct the network device to periodically report service information of a terminal served by the network device to the near real-time control system, so that the network device can report service establishment and real-time service data of the terminal to the near real-time control system according to the terminal information reporting command. The time interval of periodic reporting can be set as required, such as 100 ms, 1 s, and the like, which is not limited herein.

[0089] The methods provided by the embodiments of the application are based on the same inventive concept, so the implementation of the network device side and the near real-time control system side methods can be referred to each other, and repeated parts will not be described herein.

[0090] The methods provided by the embodiments of the application are based on the same inventive concept, so the implementation of the network device side and the near real-time control system side methods can be referred to each other, and repeated parts will not be described herein.

[0091] Embodiment one: the terminal is normal.

[0092] Figure 3 One of the implementation diagrams of the safety parameter updating method provided by the application is shown in FIG. 1, which mainly includes the following processes: Figure 3

[0093] A large amount of terminal historical data is imported into the near real-time control system, and intelligent learning is performed through an AI algorithm, terminal service types, service rates, and the like are counted and summarized, and relevant rules are obtained. ​

[0094] The base station GNB establishes an E2 interface link with the near real-time control system, the near real-time control system issues a UE information reporting command to the base station, and the base station reports terminal service establishment and real-time service data to the near real-time control system.

[0095] The near real-time control system monitors terminal service type, service rate and the like, and determines whether an exception occurs according to the above-mentioned related rules.

[0096] The near real-time control system determines that the terminal service information is normal, and does not send a terminal service security warning to the base station.

[0097] The terminal service ends.

[0098] Embodiment two: the terminal service is abnormal, and an intra-cell handover is initiated.

[0099] Figure 4 As shown in Figure 2, the safety parameter updating method provided by the present application mainly includes the following processes: Figure 4

[0100] A large amount of terminal historical data is introduced into the near real-time control system, and intelligent learning is performed through an AI algorithm, terminal service type, service rate and the like are counted and summarized, and related rules are obtained.

[0101] The base station GNB establishes an E2 interface link with the near real-time control system, the near real-time control system issues a UE information reporting command to the base station, and the base station reports terminal service establishment and real-time service data to the near real-time control system.

[0102] The near real-time control system monitors terminal service type, service rate and the like, and determines whether an exception occurs according to the above-mentioned related rules.

[0103] The near real-time control system determines that the terminal service information is abnormal, and sends a terminal service security warning to the base station.

[0104] The base station receives a terminal service security warning, triggers an intra-cell handover process, sends an intra-cell handover message (i.e. an RRC reconfiguration message) carrying a safety parameter updating instruction and synchronization information to the terminal, and updates the encryption and integrity protection keys (i.e. security keys) of the signaling and data.

[0105] The terminal updates the encryption and integrity protection keys of the signaling and data after receiving the reconfiguration message, initiates random access, re-enters the original cell, and completes the intra-cell handover process.

[0106] The safety parameter updating device provided by the present application is described below, and the safety parameter updating device described below can be correspondingly referred to the safety parameter updating method described above.

[0107] ​Figure 5 A structure diagram of a security parameter updating device provided by the present application is shown in FIG. 1. The device is applied to a network equipment, such as a base station. Figure 5 As shown in FIG. 1, the device comprises:

[0108] A first receiving module 500 is configured to receive service security alarm information of a terminal sent by a near real-time control system.

[0109] A first sending module 510 is configured to update a security parameter according to the service security alarm information, and send an RRC reconfiguration message carrying a security parameter updating indication to the terminal, so that the terminal updates the security parameter and performs an intra-cell handover process.

[0110] Optionally, the first sending module 510 is further configured to:

[0111] send service information of the terminal to the near real-time control system.

[0112] Optionally, the sending of the service information of the terminal to the near real-time control system comprises:

[0113] receiving a terminal information reporting command sent by the near real-time control system, the terminal information reporting command being used to instruct the network equipment to periodically report service information of a terminal served by the network equipment to the near real-time control system;

[0114] sending the service information of the terminal to the near real-time control system according to the terminal information reporting command.

[0115] Optionally, the service information comprises at least one of the following:

[0116] service type information;

[0117] service data flow information.

[0118] Figure 6 A structure diagram of another security parameter updating device provided by the present application is shown in FIG. 2. The device is applied to a near real-time control system. Figure 6 As shown in FIG. 2, the device comprises:

[0119] An abnormality detection module 600 is configured to determine that service information of a terminal is abnormal.

[0120] A second sending module 610 is configured to send service security alarm information of the terminal to a network equipment accessed by the terminal, the service security alarm information being used to trigger the network equipment to update a security parameter, and send an RRC reconfiguration message carrying a security parameter updating indication to the terminal, so that the terminal updates the security parameter and performs an intra-cell handover process.

[0121] Optionally, the determination that the service information of the terminal is abnormal comprises:

[0122] receiving service information of the terminal sent by the network equipment;

[0123] determine service information of the terminal based on the anomaly detection model;

[0124] The anomaly detection model is trained based on historical service data of the terminal.

[0125] Optionally, the second sending module 610 is further configured to:

[0126] send a terminal information reporting command to the network device, the terminal information reporting command being used to instruct the network device to periodically report service information of a terminal served by the network device to a near real-time control system.

[0127] Optionally, the service information comprises at least one of the following:

[0128] service type information;

[0129] service data traffic information.

[0130] Optionally, the anomaly detection model comprises a DBSCAN algorithm model or a SARIMA algorithm model.

[0131] It should be noted that the above device provided by the present application can realize all the method steps achieved by the method embodiment and achieve the same technical effects, and the same parts and beneficial effects of the method embodiment will not be described in detail.

[0132] Figure 7 The structure diagram of the electronic device provided by the present application is shown in the figure Figure 7 As shown in the figure, the electronic device can include a processor 710, a communications interface 720, a memory 730 and a communications bus 740, wherein the processor 710, the communications interface 720 and the memory 730 complete mutual communication through the communications bus 740. The processor 710 can call the logical instructions in the memory 730 to execute any of the safety parameter updating methods provided by the above embodiments.

[0133] In addition, the logic instructions in the memory 730 described above can be implemented in the form of software functional units and sold or used as independent products, and can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the parts that contribute to the prior art or parts of the technical solutions can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.

[0134] It should be noted that the electronic device provided by the present application can realize all the method steps realized by the method embodiments and achieve the same technical effects. Therefore, the same parts and beneficial effects of the present embodiment as the method embodiments will not be described in detail.

[0135] In another aspect, the present application also provides a non-transitory computer readable storage medium having a computer program stored thereon, wherein the computer program is executed by a processor to implement any of the security parameter updating methods provided by the above embodiments.

[0136] It should be noted that the non-transitory computer readable storage medium provided by the present application can realize all the method steps realized by the method embodiments and achieve the same technical effects. Therefore, the same parts and beneficial effects of the present embodiment as the method embodiments will not be described in detail.

[0137] The device embodiments described above are only schematic, and the units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, i.e. they can be located in one place, or distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the present embodiment according to actual needs. Those skilled in the art can understand and implement it without creative labor.

[0138] The technical solutions provided by the present application can be applied to various systems, especially 5G systems. For example, the applicable systems can be global system of mobile communication (GSM) systems, code division multiple access (CDMA) systems, wideband code division multiple access (WCDMA) general packet radio service (GPRS) systems, long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, LTE time division duplex (TDD) systems, long term evolution advanced (LTE-A) systems, universal mobile systems (UMTS), worldwide interoperability for microwave access (WiMAX) systems, 5G new radio (NR) systems, and the like. Among these various systems, there are terminal devices and network devices. The system can also include a core network part, such as an evolved packet system (EPS), a 5G system (5GS), and the like.

[0139] The terminal to which the present application relates can refer to a device that provides voice and / or data connectivity to a user, a handheld device having a wireless connection function, or other processing devices connected to a wireless modem, etc. In different systems, the name of the terminal can also be different, for example, in the 5G system, the terminal can be called user equipment (User Equipment, UE). The wireless terminal device can communicate with one or more core networks (Core Network, CN) through a radio access network (Radio Access Network, RAN). The wireless terminal device can be a mobile terminal device, such as a mobile phone (also known as a "cellular" phone) and a computer with a mobile terminal device, for example, it can be a portable, pocket, handheld, computer built-in or vehicle-mounted mobile device, which exchanges language and / or data with the radio access network. For example, personal communication service (Personal Communication Service, PCS) phones, cordless phones, session initiation protocol (Session Initiated Protocol, SIP) phones, wireless local loop (Wireless Local Loop, WLL) stations, personal digital assistants (Personal Digital Assistant, PDA) and other devices. The wireless terminal device can also be called a system, a subscriber unit, a subscriber station, a mobile station, a mobile, a remote station, an access point, a remote terminal, an access terminal, a user terminal, a user agent, a user device, which is not limited in the present application.

[0140] The network device can be a base station, which can include multiple cells serving terminals. Depending on the application, the base station can also be referred to as an access point, or can be a device in an access network that communicates with wireless terminal devices over an air interface through one or more sectors, or other names. The network device can be used to exchange received air frames with Internet Protocol (IP) packets as a router between the wireless terminal device and the rest of the access network, which can include an Internet Protocol (IP) communication network. The network device can also coordinate the management of the properties of the air interface. For example, the network device can be a network device (BTS) in the Global System for Mobile Communications (GSM) or Code Division Multiple Access (CDMA), a network device (NodeB) in Wide-band Code Division Multiple Access (WCDMA), an evolved network device (eNB or e-NodeB) in a long term evolution (LTE) system, a 5G base station (gNB) in a next generation system, a home evolved base station (HeNB), a relay node, a femto, a pico, etc. The present application is not limited in this regard. In some network structures, the network device can include a centralized unit (CU) node and a distributed unit (DU) node, and the centralized unit and the distributed unit can also be arranged geographically apart.

[0141] The network device and the terminal can each use one or more antennas for Multi Input Multi Output (MIMO) transmission, which can be Single User MIMO (SU-MIMO) or Multiple User MIMO (MU-MIMO). Depending on the shape and number of antenna combinations, MIMO transmission can be 2D-MIMO, 3D-MIMO, FD-MIMO or massive-MIMO, or can be diversity transmission or precoding transmission or beamforming transmission, etc.

[0142] Those skilled in the art can clearly understand the implementation of the various embodiments by means of software and necessary general hardware platforms through the above description of the embodiments, and of course, the embodiments can also be implemented by hardware. Based on such understanding, the above technical solutions, essentially or in other words, the part of the prior art that makes a contribution, can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in the various embodiments or some parts of the embodiments.

[0143] Finally, it should be noted that: the above examples are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing examples, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing examples, or make equivalent replacement for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present application.

Claims

1. A security parameter update method, characterized by, Applied to a network device, comprising: receiving the terminal service security alarm information sent by the near real-time control system; According to the service security alarm information, update the security parameter, and send the radio resource control (RRC) reconfiguration message carrying the security parameter update indication to the terminal, so that the terminal updates the security parameter and executes the intra-cell handover process; Before the method receives the terminal service security alarm information sent by the near real-time control system, the method further comprises: Send the terminal service information to the near real-time control system, the service information is used for the near real-time control system to determine the abnormality of the terminal service information based on the abnormality detection model, and after determining the abnormality of the terminal service information, send the terminal service security alarm information to the network device accessed by the terminal; Wherein, the abnormality detection model includes DBSCAN algorithm model or SARIMA algorithm model, which is trained based on the historical service data of the terminal; The service information includes at least one of the following: Service type information; Business data flow information.

2. The security parameter update method of claim 1, wherein, The network device sends the terminal service information to the near real-time control system, comprising: Receive the terminal information reporting command sent by the near real-time control system, the terminal information reporting command is used to instruct the network device to periodically report the service information of the served terminal to the near real-time control system; According to the terminal information reporting command, send the terminal service information to the near real-time control system.

3. A security parameter update method, characterized by, Applied to near real-time control system, comprising: Determine the abnormality of the terminal service information; Send the terminal service security alarm information to the network device accessed by the terminal, the service security alarm information is used to trigger the network device to update the security parameter, and send the radio resource control (RRC) reconfiguration message carrying the security parameter update indication to the terminal, so that the terminal updates the security parameter and executes the intra-cell handover process; The method for determining the abnormality of the terminal service information, comprising: Receive the terminal service information sent by the network device; Based on the abnormality detection model, determine the abnormality of the terminal service information; Wherein, the abnormality detection model includes DBSCAN algorithm model or SARIMA algorithm model, which is trained based on the historical service data of the terminal; The service information includes at least one of the following: Service type information; Business data flow information.

4. The security parameter update method of claim 3, wherein, Before the method receives the terminal service information sent by the network device, the method further comprises: Send the terminal information reporting command to the network device, the terminal information reporting command is used to instruct the network device to periodically report the service information of the served terminal to the near real-time control system.

5. The security parameter update method of any of claims 3 to 4, wherein, The service information includes at least one of the following: Service type information; Business data flow information.

6. A security parameter updating device, characterized in that: Applied to a network device, comprising: First receiving module, for receiving the terminal service security alarm information sent by the near real-time control system; The first sending module is configured to update the security parameter according to the service security alarm information, and send a radio resource control (RRC) reconfiguration message carrying a security parameter update indication to the terminal, so that the terminal updates the security parameter and performs an intra-cell handover process. The first sending module is further configured to: Before receiving the service security alarm information of the terminal sent by the near real-time control system, send service information of the terminal to the near real-time control system, where the service information is used by the near real-time control system to determine that the service information of the terminal is abnormal based on an abnormality detection model, and after determining that the service information of the terminal is abnormal, send the service security alarm information of the terminal to a network device to which the terminal accesses; The abnormality detection model includes a DBSCAN algorithm model or a SARIMA algorithm model, and is trained based on historical service data of the terminal; The service information includes at least one of the following: service type information; service data traffic information.

7. A security parameter updating device, characterized in that: The application is applied to a near real-time control system, and includes: an abnormality detection module configured to determine that service information of a terminal is abnormal; a second sending module configured to send service security alarm information of the terminal to a network device to which the terminal accesses, where the service security alarm information is used to trigger the network device to update a security parameter, and send a radio resource control (RRC) reconfiguration message carrying a security parameter update indication to the terminal, so that the terminal updates the security parameter and performs an intra-cell handover process; The abnormality detection module is further configured to: receive service information of the terminal sent by the network device; determine that the service information of the terminal is abnormal based on an abnormality detection model; The abnormality detection model includes a DBSCAN algorithm model or a SARIMA algorithm model, and is trained based on historical service data of the terminal; The service information includes at least one of the following: service type information; service data traffic information.

8. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor implements the security parameter updating method according to any one of claims 1 to 2, or the security parameter updating method according to any one of claims 3 to 5 when executing the program. 9.A non-transitory computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program implements the security parameter updating method according to any one of claims 1 to 2, or the security parameter updating method according to any one of claims 3 to 5 when executed by the processor.

Citation Information

Patent Citations

  • Method for network exception condition monitoring through performance data

    CN101384054A

  • Safety parameter modification method and base station

    CN102833741A

  • Software-defined optical network safe interaction method and system

    CN109039612A

  • Voice service switching method, terminal device, network side device and system

    CN109951878A

  • Business processing method and device and storage medium

    CN114143832A