Network device legality identification method and device, storage medium, terminal device, base station

By obtaining and analyzing the device fingerprint of network equipment, identifying whether the device is legal, the problem of attacks on the terminal by pseudo-base stations is solved, and the security of terminal communication and simplification of identification is achieved.

CN114390522BActive Publication Date: 2025-06-13SPREADTRUM COMMUNICATION (SHANGHAI) CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202011134339.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-10-21
Publication Date
2025-06-13
Estimated Expiration
2040-10-21

AI Technical Summary

Technical Problem

The prior art is difficult to effectively identify and prevent pseudo-base stations from attacking terminals and protect terminal communication security.

Method used

By obtaining the device fingerprint of the network device and determining whether the device is legal based on the fingerprint, the legality of the network device can be identified. This method can be implemented through software on the terminal device side, avoiding the distribution and maintenance of complex public key mechanisms.

Benefits of technology

It effectively avoids attacks on terminals by pseudo-network devices, improves the security of terminal communications, and simplifies the process of device legality identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114390522B_ABST
    Figure CN114390522B_ABST
Patent Text Reader

Abstract

A method and apparatus for identifying the legality of a network device, a storage medium, a terminal device, and a base station. Among them, the method includes: obtaining a device fingerprint of the network device; determining whether the network device is legal according to the device fingerprint of the network device. Thus, it is possible to flexibly identify the authenticity of network devices (such as base stations and gateways), effectively avoid attacks on terminal devices by illegal devices, and protect the communication security of terminal devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to a method and apparatus for identifying the legitimacy of a network device, a storage medium, a terminal device, and a base station. Background Art

[0002] A false base station, that is, a forged base station, can imitate a mobile communication network and transmit a radio frequency signal with a certain power by a hardware host, so that a mobile phone near the signal can access the false base station from the existing mobile communication network. After the terminal accesses the false base station, the possible attack risks include: spam messages; illegally broadcasting information such as earthquakes and tsunamis, causing panic; making legal terminals unreachable, forming a denial of service attack, etc. Since false base stations are usually small in size, strong in mobility, and good in concealment, they are difficult to be detected. Please refer to Figure 1 , Figure 1 which provides a schematic diagram of a vehicle-mounted false base station in the prior art. Among them, the false base station network is deployed on a vehicle. From this, it can be seen that the false base station can provide some functions of a legal base station, but the false base station cannot access the operator network and has no core network connection.

[0003] In mobile communication networks after the third-generation mobile communication technology (3rd-generation, abbreviated as 3G), two-way authentication between the terminal and the network has been realized. Therefore, for connected terminals, false base stations do not have the ability to attack, that is, false base stations can only attack non-connected terminals. Because non-connected terminals only receive the broadcast signal of the base station unidirectionally and complete cell reselection according to the received signal, and cannot judge the authenticity of the base station. In addition, the false base station can redirect the user equipment (User Equipment, abbreviated as UE) to a 2G base station, or the UE automatically falls back to a 2G base station (because there is no 3G / 4G / 5G network). The main reason is that in the mobile communication network itself, the information of UE cell reselection is broadcast, and there is no security mechanism.

[0004] Traditionally, a public key mechanism can be introduced to distinguish between legal base stations and false base stations. However, in the public key mechanism, the distribution and validity verification of public key certificates are relatively complex problems. For example, it is necessary to verify the validity of public key certificates in real time in combination with the registration area of the UE. For example, the core network needs to update the public key of the UE according to the area where the UE is registered or located, or the core network sends the public key to the UE when the registration area of the UE is updated, or the public key certificate can be used to determine whether the public key certificate of the base station is valid. Therefore, the distribution and maintenance of the public key are relatively complex, and the workload of key distribution, maintenance, and validity verification is relatively large.

[0005] Therefore, there is an urgent need for a general network device legitimacy identification method that can flexibly identify the authenticity of network devices (such as base stations and gateways) to effectively avoid attacks on terminals by fake network devices and protect terminal communication security. Summary of the Invention

[0006] The technical problem solved by the present invention is how to effectively avoid attacks on terminals by fake network devices and protect terminal communication security.

[0007] To solve the above problems, an embodiment of the present invention provides a method for identifying the legitimacy of network devices, the method comprising: obtaining a device fingerprint of a network device; determining whether the network device is legitimate according to the device fingerprint of the network device.

[0008] Optionally, the obtaining of the network device fingerprint includes: receiving target information sent by the network device; applying a fingerprint extraction algorithm to extract the device fingerprint according to the target information.

[0009] Optionally, before applying the fingerprint extraction algorithm, it further includes: receiving a fingerprint extraction algorithm sent by the network side; or, feeding back one or more fingerprint extraction algorithms supported by the terminal device to the network side and receiving a reply from the network side specifying the fingerprint extraction algorithm to be applied from the one or more fingerprint extraction algorithms.

[0010] Optionally, the determining whether the network device is legitimate according to the device fingerprint of the network device includes: comparing the device fingerprint of the network device with legitimate device fingerprints and / or illegal device fingerprints stored locally to determine whether the network device is legitimate; or, sending the device fingerprint of the network device to the network side and receiving a reply from the network side determining whether the network device is legitimate to determine whether the network device is legitimate.

[0011] Optionally, the method further includes: receiving legitimate device fingerprints and / or illegal device fingerprints sent by the network side and storing them locally.

[0012] Optionally, before receiving the legitimate device fingerprints and / or illegal device fingerprints sent by the network side, it further includes: sending a device fingerprint request signaling to the network side; receiving the legitimate device fingerprints and / or illegal device fingerprints sent by the network side based on the device fingerprint request signaling.

[0013] Optionally, the legitimate device fingerprints and / or illegal device fingerprints are carried by one or more of the following messages: attach accept message, tracking area update accept message, service accept message, registration accept message.

[0014] Optionally, the method further includes: receiving a paging message sent by the network side, where the paging message carries updated fingerprint information.

[0015] Optionally, the updated fingerprint information includes at least one of the legal device fingerprint, the illegal device fingerprint, and the fingerprint update prompt, and the fingerprint update prompt is used to prompt the update of the legal device fingerprint and / or the illegal device fingerprint.

[0016] Optionally, after obtaining the device fingerprint of the network device, the method further includes: sending a fingerprint reporting signaling to the network side, where the fingerprint reporting signaling includes the device fingerprint of the network device.

[0017] Optionally, the fingerprint reporting signaling is carried by one or more of the following messages: attach request, tracking area update request, registration request, service request.

[0018] An embodiment of the present invention further provides a method for identifying the legality of a network device, where the method includes: receiving the device fingerprint of the network device sent by the terminal device, determining whether the network device is legal, and sending a reply indicating whether the network device is legal to the terminal device.

[0019] Optionally, the method further includes: receiving a fingerprint reporting signaling sent by the terminal device, where the fingerprint reporting signaling includes the device fingerprint of the network device.

[0020] Optionally, the fingerprint reporting signaling is carried by one or more of the following messages: attach request, tracking area update request, registration request, service request.

[0021] An embodiment of the present invention further provides a method for identifying the legality of a network device, where the method includes: sending the legal device fingerprint and / or the illegal device fingerprint to the terminal device.

[0022] Optionally, before sending the legal device fingerprint and / or the illegal device fingerprint to the terminal device, the method further includes: receiving a device fingerprint request signaling sent by the terminal device; and sending the legal device fingerprint and / or the illegal device fingerprint to the terminal device based on the device fingerprint request signaling.

[0023] Optionally, the legal device fingerprint and / or the illegal device fingerprint are carried by one or more of the following messages: attach accept message, tracking area update accept message, service accept message, registration accept information.

[0024] Optionally, the method further includes: sending a paging message to the terminal device, where the paging message carries updated fingerprint information.

[0025] Optionally, the updated fingerprint information includes at least one of the legal device fingerprint, the illegal device fingerprint, and the fingerprint update prompt, where the fingerprint update prompt is used to prompt the update of the legal device fingerprint and / or the illegal device fingerprint.

[0026] An embodiment of the present invention further provides a method for identifying the legitimacy of a network device. The method includes: sending a fingerprint extraction algorithm to a terminal device; or, receiving one or more fingerprint extraction algorithms supported by the terminal device and fed back by the terminal device, and sending a reply to the terminal device, where the reply is used to specify the fingerprint extraction algorithm applied by the terminal device from the one or more fingerprint extraction algorithms; where the fingerprint extraction algorithm is used by the terminal device to extract the device fingerprint of the network device according to target information, and the target information is sent by the network device and received by the terminal device.

[0027] An embodiment of the present invention further provides a device for identifying the legitimacy of a network device. The device includes: a fingerprint acquisition module, configured to acquire the device fingerprint of the network device; a legitimacy determination module, configured to determine whether the network device is legal according to the device fingerprint of the network device.

[0028] An embodiment of the present invention further provides a device for identifying the legitimacy of a network device. The device includes: a network device determination module, configured to receive the device fingerprint of the network device sent by the terminal device, determine whether the network device is legal, and send a reply indicating whether the network device is legal to the terminal device.

[0029] An embodiment of the present invention further provides a device for identifying the legitimacy of a network device. The device includes: a fingerprint sending module, configured to send the legal device fingerprint and / or the illegal device fingerprint to the terminal device.

[0030] An embodiment of the present invention further provides a device for identifying the legitimacy of a network device. The device includes: an algorithm sending module, configured to send a fingerprint extraction algorithm to the terminal device; or, an algorithm specifying module, configured to receive one or more fingerprint extraction algorithms supported by the terminal device and fed back by the terminal device, and send a reply to the terminal device, where the reply is used to specify the fingerprint extraction algorithm applied by the terminal device from the one or more fingerprint extraction algorithms; where the fingerprint extraction algorithm is used by the terminal device to extract the device fingerprint of the network device according to target information, and the target information is sent by the network device and received by the terminal device.

[0031] An embodiment of the present invention further provides a storage medium, on which a computer program is stored, and when the computer program is run by a processor, it performs the steps of any one of the methods.

[0032] An embodiment of the present invention further provides a terminal device, including a memory and a processor, where a computer program that can run on the processor is stored on the memory, and when the processor runs the computer program, it executes the steps of any one of the above methods.

[0033] An embodiment of the present invention further provides a base station, including a memory and a processor, where a computer program that can run on the processor is stored on the memory, and when the processor runs the computer program, it executes the steps of any one of the above methods.

[0034] Compared with the prior art, the technical solution of the embodiment of the present invention has the following beneficial effects:

[0035] An embodiment of the present invention provides a method for identifying the legitimacy of a network device, including: obtaining the device fingerprint of the network device; determining whether the network device is legitimate according to the device fingerprint of the network device. Compared with the prior art, in the method described in the embodiment of the present invention, before establishing a connection between the terminal device and the network device, it is first determined whether the network device is legitimate according to the device fingerprint of the network device. If it is legitimate, the connection is continued. This method can be implemented only by a software method on the terminal side, and can flexibly identify the authenticity of network devices (such as base stations and gateways) to effectively avoid attacks on the terminal by illegal devices and protect the communication security of the terminal.

[0036] Further, the terminal device can determine the legitimacy of the network device based on the device fingerprints (legitimate device fingerprints and / or illegal device fingerprints) stored locally. The device fingerprints stored locally by the terminal device can be configured by the network side, and the terminal device can determine the legitimacy of the network device in a non-networked state.

[0037] Further, in a networked state, the terminal device can also send the obtained device fingerprint of the network device to the network for the network side to perform the legitimacy determination. Thus, there is no need for the terminal device side to store a device fingerprint library, nor does the terminal device need to perform the determination of whether the network device is legitimate, which can effectively improve the processing efficiency of the terminal device.

[0038] Further, thus, when the terminal device detects the device fingerprint of a new network device, it can report the device to the network to help the network side automatically improve the device fingerprint library.

[0039] Further, a method for passively updating the device fingerprint on the terminal device side triggered by the network side is provided, which can timely update the device fingerprint library stored locally by the terminal device to ensure that the terminal device can always accurately identify illegal network devices and protect the communication security of the terminal device. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 It is a schematic diagram of a vehicle-mounted pseudo base station in the prior art;

[0041] Figure 2 It is a schematic diagram of a method for identifying the security of network devices using the PLS technology in the prior art;

[0042] Figure 3 It is a schematic diagram of a method for identifying the security of network devices in the prior art;

[0043] Figure 4 It is a schematic flowchart of the first method for identifying the legitimacy of network devices according to an embodiment of the present invention;

[0044] Figure 5 It is an application scenario diagram of a method for identifying the legitimacy of network devices according to an embodiment of the present invention;

[0045] Figure 6 It is a schematic flowchart of an active update process of device fingerprint based on the registration process according to an embodiment of the present invention;

[0046] Figure 7 It is a schematic flowchart of an active update process of device fingerprint based on the tracking area update process according to an embodiment of the present invention;

[0047] Figure 8 It is a schematic flowchart of an active update process of device fingerprint based on the service request procedure according to an embodiment of the present invention;

[0048] Figure 9 It is a schematic flowchart of an active update process of device fingerprint based on the registration or registration area update process according to an embodiment of the present invention;

[0049] Figure 10 It is a schematic diagram of a method for passive update of device fingerprint according to an embodiment of the present invention;

[0050] Figure 11 It is a schematic flowchart of the second method for identifying the legitimacy of network devices according to an embodiment of the present invention;

[0051] Figure 12 It is a schematic flowchart of the third method for identifying the legitimacy of network devices according to an embodiment of the present invention;

[0052] Figure 13 It is a schematic flowchart of the fourth method for identifying the legitimacy of network devices according to an embodiment of the present invention;

[0053] Figure 14 It is a schematic structural diagram of the first device for identifying the legitimacy of network devices according to an embodiment of the present invention;

[0054] Figure 15 It is a schematic structural diagram of the second device for identifying the legitimacy of network devices according to an embodiment of the present invention;

[0055] Figure 16 Schematic diagram of the structure of the third network device legality identification device according to an embodiment of the present invention;

[0056] Figure 17 Schematic diagram of the structure of the fourth network device legality identification device according to an embodiment of the present invention. Detailed implementation manners

[0057] As described in the background art, the working and maintenance mechanisms of the existing true and false base station identification methods are relatively complex, with poor universality and flexibility, and cannot effectively avoid attacks on terminals by false base stations and protect terminal communication security.

[0058] Specifically, the rapid development and wide application of wireless communication technologies have enriched people's daily work and life and have become an indispensable part of modern society. However, due to the inherent broadcast nature, openness, and instability of the transmission link of wireless networks, wireless communication systems are more vulnerable to detection, interception, and eavesdropping by illegal users compared to traditional wired communication systems, resulting in data transmission leakage problems, and their security issues cannot be ignored.

[0059] Traditional methods for protecting wireless network security are usually based on the information bit level, that is, at levels above the physical layer (data link layer, network layer, etc.) in the Open System Interconnection Reference Model (OSI for short), and the protection of data integrity and confidentiality and the authentication of the identities of both communication parties are achieved by designing security protocols based on cryptographic mechanisms. Among them, the main technologies applied in identity authentication include key management, digital signature, identity authentication, etc. That is, traditional wireless network security mechanisms are based on computational cryptography and mainly rely on keys that are difficult to crack (such as keys generated according to encryption algorithms with extremely high computational complexity) to improve the security level.

[0060] However, with the improvement of computing power and the diversification of information transmission scenarios, traditional cryptographic systems are increasingly challenged, and their limitations are mainly manifested in the following three aspects: the substantial improvement in computer performance, especially the emergence of quantum computers, poses security risks to modern cryptographic encryption algorithms designed based on computational complexity; the large number of terminal devices accessing the network and the mobility of these devices bring great challenges to the online distribution, maintenance, and management of keys; the diversity and heterogeneity of traditional networks are becoming more and more obvious, and the communication between users and between users and base stations is becoming more and more frequent, and traditional encryption methods cannot play an effective role.

[0061] With the proposal of Physical Layer Security (PLS) technology, a new direction has been opened up for solving the security problems of wireless communication. Its core idea is to ensure the security of the network from the perspective of information theory rather than simply by increasing computational complexity. PLS is a technology that uses the physical characteristics of communication devices and channels to establish a secure access and confidential communication system. The physical layer is the physical basis of all network protocols, and physical layer security technology provides basic security guarantees for transmission lines. Physical layer security technology can be used as an effective supplement to traditional security technologies.

[0062] As Figure 2 shown, Figure 2 Figure 1 is a schematic diagram of a network device security identification method using PLS technology in the prior art. Taking two network devices, Alice and Bob, as an example, the terminal can utilize the characteristics of both devices themselves and the channel characteristics between them to complete technologies such as device identity identification and key extraction, thereby completing processes such as identity authentication and encryption and decryption, and realizing the security of the physical layer. Among them, device identity identification can be achieved using device fingerprints. Device fingerprints, also known as radio frequency fingerprints, are determined by the device's own device hardware and are long-term and unique. Device fingerprints can be used for device identity identification.

[0063] Please refer to Figure 3 , Figure 3 Figure 2 is a security identification method of a network device in the prior art. The switch arranged on the network side can extract the device fingerprint of the network card and then apply to the authentication server in the internal network to authenticate the network card, thereby completing device identity identification and access control. This switch also serves as an access controller.

[0064] As mentioned above, in existing mobile communication systems, the information or signals used for UE cell selection or reselection are all broadcast and sent in plain text, such as synchronization signals, system messages, etc. This is also determined by the characteristics of the mobile communication system itself. Because these signals or information need to be received by all legitimate UEs for legitimate UEs to make normal cell selection and reselection judgments. If these signals or information are encrypted, it will bring great key management difficulties. For example, how a new legitimate UE obtains the broadcast key of a cell, whether the broadcast keys of all cells in a communication system are the same, if they are not the same, how to obtain the key during cell reselection, if they are the same, then an illegal user can obtain the broadcast key of a cell through a legitimate UE and share it with an illegal UE, as well as the issue of broadcast key update, etc. Therefore, when the UE is not connected to the network, it has no way to identify a false base station from these information or signals broadcast by a certain cell. The identification of false base stations has always been a troublesome problem in mobile communication networks and has been under research.

[0065] Technical Report (TR) 33.809 has formulated some false base station identification technology solutions in 3GPP research, including the above-mentioned solution based on the public key mechanism.

[0066] There are also some other solutions, such as using the measurement results of connected UEs to assist the network in detecting false base stations. For example, if a connected UE reports abnormal signal strength of a base station, or detects that the cell identification or frequency information is inconsistent with the deployed ones, etc., it can assist the network in identifying false base stations. Or, for the handover of a connected UE, if the measurement information reported by the UE to the source base station indicates the target cell id, and if the source base station finds that the target cell id does not exist in its database, or the source base station cannot establish an X2 / Xn link with the target cell; or, if the false base station copies the broadcast information of a legal cell, then, in the measurement results reported by the UE, there may be two target cells with the same identification, and the source base station can then consider that the base station of the target cell or one of the base stations of the target cells is a false base station.

[0067] The main problem with the solution based on the public key mechanism is that the workload of key distribution, maintenance, and verification is relatively large. Either the core network needs to send it to the UE during registration, tracking area update, or registration area update, or use the public key certificate to determine whether the public key certificate of the base station is valid.

[0068] The solution based on the measurement feedback of connected UEs is not suitable for non-connected UEs. In fact, the risk of false base station attacks on connected UEs is much smaller than that on non-connected UEs. That is, the solution based on the measurement feedback of connected UEs does not have universality, and the actual application effect will be discounted.

[0069] To solve the above problems, an embodiment of the present invention provides a method for identifying the legitimacy of a network device, the method including: obtaining the device fingerprint of the network device; determining whether the network device is legitimate according to the device fingerprint of the network device.

[0070] Thereby, it can effectively avoid attacks on the terminal by false network devices and protect the communication security of the terminal.

[0071] To make the above objects, features, and beneficial effects of the present invention more obvious and understandable, the following detailed description will be given to the specific embodiments of the present invention with reference to the accompanying drawings.

[0072] Please refer to Figure 4 , Figure 4 A method for identifying the legitimacy of a network device according to an embodiment of the present invention includes the following steps:

[0073] Step S401, obtaining the device fingerprint of the network device;

[0074] Step S402: Determine whether the network device is legal according to the device fingerprint of the network device.

[0075] Among them, network devices may include devices such as base stations and gateways. Each terminal device (which may also be referred to as a terminal or UE), including mobile phones, computers, smart watches, etc., can access the network through network devices.

[0076] The device fingerprint of a network device may include the hardware fingerprint of the device (an identifier reflecting the unique characteristics of the device hardware) and the channel fingerprint of the device (an identifier reflecting the unique characteristics of the channel experienced by the signal sent by the device), such as Radio Frequency Fingerprint (RFF for short), etc. The present invention does not limit the connotation of the device fingerprint. That is, the device fingerprint can at least include the device hardware fingerprint and / or the device channel fingerprint.

[0077] An illegal device is a network device that does not meet the connection requirements, which may be a pseudo base station or a fake gateway device as mentioned in the background art. It should be noted that the standard for determining whether a network device is legal can be set according to actual application requirements. In a specific embodiment, the network device is a base station. Whether the base station is legal may include: whether the base station is a network device deployed by an operator, whether the base station is a pseudo base station, whether the base station is a base station with an attack purpose, etc.

[0078] Before a terminal device accesses a network device, it can first obtain the device fingerprint of the network device to determine whether the network device is legal. If it is legal, it is determined that the network device can be accessed; if it is not legal, the network device is not accessed. And the information of illegal network devices can be stored or sent to the network side for backup as a reference for subsequent determination of whether the network device is legal. The "accessing a network device" includes, but is not limited to, camping on the cell defined by the network device, or establishing a connection with the cell defined by the network device, etc.

[0079] For step S402, the terminal or the network side may execute the step of determining whether the network device is legal. Further, the terminal determines the legality of the network device according to the preset legality determination rule and the device fingerprint of the network device to determine whether the network device is legal. Alternatively, the terminal sends the obtained device fingerprint of the network device to the network side, and the network side determines whether the network device is legal according to the preset legality determination rule and the device fingerprint of the network device, and the network side sends the determined result to the terminal side so that the terminal determines whether the network device is legal. It should be noted that for a mobile communication network, the network device (such as a base station) and the core network device that the terminal device needs to access both belong to network devices, but the core network device and the network device that the UE needs to access are not the same device. To distinguish the two, in the embodiments of the present invention, the network device that the terminal device needs to access (that is, the network device to be determined whether it is legal) is referred to as the network device, and the core network device is represented by the network (or the network side). In this step, to verify the legality of the network device to be accessed (denoted as network device 1), the method may be that the terminal device sends the device fingerprint of the base station to the core network device (denoted as network device 2), and the core network device verifies the legality of network device 1. At this time, network device 1 and network device 2 are not the same device.

[0080] Optionally, when the terminal device discovers an anomaly, for example, when it detects that the signal of a cell or a network device is particularly strong, it executes steps S401 and S402.

[0081] Through Figure 4 The above-mentioned method for identifying the legality of a network device first determines whether the network device is legal according to the device fingerprint of the network device before the terminal device accesses the network device. If it is legal, it continues to access the network device. This method can be implemented only by a software method on the terminal side, and can flexibly identify the authenticity of the network device or the gateway, so as to effectively avoid attacks on the terminal by illegal devices and protect the communication security of the terminal.

[0082] In one embodiment, Figure 4 In step S401 of obtaining the device fingerprint of the network device, it may include: receiving the target information sent by the network device; applying a fingerprint extraction algorithm to extract the device fingerprint according to the target information.

[0083] The fingerprint extraction algorithm is an algorithm used to extract the device fingerprint of a network device. Different algorithms can be used to extract the hardware fingerprint and the channel fingerprint. For example, if extracting the channel fingerprint of a network device, the Haar-like features of the Differential Constellation Trace Figure (DCTF) of the network device can be extracted as the radio frequency features of the network device. At this time, the fingerprint extraction algorithm is the algorithm for obtaining the Haar features of the DCTF of the network device.

[0084] It should be noted that the device fingerprint of a network device includes but is not limited to the above examples. Any identifier that can represent the uniqueness of the network device can be used as the device fingerprint of the network device, and the algorithm for extracting the device fingerprint is the fingerprint extraction algorithm.

[0085] Among them, the target information can be the signal and / or channel sent by the network device. For example, the terminal device can monitor the signal and / or channel sent by the network device.

[0086] Please refer to Figure 5 , Figure 5 which provides an application scenario diagram of a method for identifying the legitimacy of a network device according to an embodiment of the present invention. The terminal device receives the signal and / or channel sent by the network device (i.e., the network (Network) in Figure 5 ), and extracts the device fingerprint of the network device according to the received signal and / or channel, and determines whether the network device is legal.

[0087] Optionally, the signal can be a synchronization signal, a reference signal (such as a cell reference signal, a positioning reference signal, a terminal-specific reference signal, etc.), or a demodulation reference signal, etc. The channel can be a control channel, a data channel, etc. For example, a control channel for scheduling a common message or a data channel for sending a common message, etc.

[0088] Optionally, the fingerprint extraction algorithm can be implemented internally in the terminal device or configured by the network side.

[0089] Specifically, when the fingerprint extraction algorithm is implemented internally in the terminal device, the fingerprint extraction algorithm is configured on the terminal device side, and the device fingerprint of the network device is directly extracted from the received channel and / or signal of the network device using this fingerprint extraction algorithm. Further, when the terminal device side supports multiple fingerprint extraction algorithms, one or more fingerprint extraction algorithms supported by the terminal device can be fed back to the network side, and a reply specifying the fingerprint extraction algorithm applied from the one or more fingerprint extraction algorithms is received from the network side. Thus, the network side designates at least one algorithm from the one or more fingerprint extraction algorithms supported by the terminal device for extracting the device fingerprint.

[0090] In addition, the network side can also send a fingerprint extraction algorithm to the terminal device. For example, the network sends the fingerprint extraction algorithms it supports in a broadcast manner, or after the terminal device accesses the network, the network side separately sends the fingerprint extraction algorithms supported by the network device to the terminal device. When the network side configures multiple fingerprint extraction algorithms for the terminal device, the network side can further specify which one or several algorithms the terminal device specifically uses, or the terminal device selects at least one from the multiple fingerprint extraction algorithms configured by the network side.

[0091] Optionally, after the terminal device confirms the fingerprint extraction algorithm it uses, it can return a confirmation message to the network side indicating which fingerprint extraction algorithm is applied, so that the network side and the terminal device have a consistent understanding of the applied fingerprint extraction algorithm. It should be noted that the mechanism for determining the fingerprint extraction algorithm applied by the terminal device includes, but is not limited to, the above methods, and it may also be necessary for the network side and the terminal device side to have a consistent understanding of the fingerprint extraction algorithm applied by the terminal device.

[0092] In one embodiment, please refer to again Figure 4 , step S402 of determining whether the network device is legal according to the device fingerprint of the network device may include: comparing the device fingerprint of the network device with the legal device fingerprints and / or illegal device fingerprints stored locally to determine whether the network device is legal.

[0093] Optionally, if the UE is in a non-connected state and cannot obtain legal device fingerprints and / or illegal device fingerprints from the network, the legal device fingerprints or illegal device fingerprints stored locally by the UE can be used to determine whether the network device to be identified is legal. At this time, a device fingerprint library needs to be maintained on the UE side, which contains legal device fingerprints or illegal device fingerprints. Further, the comparison of the device fingerprint of the network device with the legal device fingerprints and / or illegal device fingerprints stored locally by the UE means comparing the device fingerprint of the network device with the legal device fingerprints or illegal device fingerprints stored in the device fingerprint library one by one to determine whether the network device is legal. Among them, the legal device fingerprint is also called the device fingerprint whitelist, that is, the device fingerprint that has been determined to be legal; the illegal device fingerprint is also called the device blacklist, that is, the device fingerprint that has been determined to be illegal.

[0094] Optionally, a device fingerprint library can also be maintained on the network side, and the network side can send the legal device fingerprints and / or illegal device fingerprints in the library to the UE for the UE to identify the legality of the network device.

[0095] Further, the network side can select suitable legal device fingerprints and / or illegal device fingerprints for the UE from the device fingerprint whitelist and / or device fingerprint blacklist library based on factors such as the location of the UE, the device type, and the applied fingerprint recognition algorithm, and send them to the UE.

[0096] Optionally, the solution of step S402 may further include: receiving and locally storing the legal device fingerprint and / or illegal device fingerprint sent by the network side. This step may be performed before / after step S402 to configure or update the legal device fingerprint and / or illegal device fingerprint for the UE.

[0097] Optionally, before receiving the legal device fingerprint and / or illegal device fingerprint sent by the network side, it also includes: sending a device fingerprint request signaling to the network side; receiving the legal device fingerprint and / or illegal device fingerprint sent by the network side based on the device fingerprint request signaling.

[0098] The device fingerprint request instruction is an instruction sent by the UE to the network side so that the network side configures or updates the legal device fingerprint and / or illegal device fingerprint for the UE.

[0099] The legal device fingerprint and / or illegal device fingerprint may be carried by one or more of the following messages: an Attach Accept message, a Tracking Area Update Accept message, a Service Accept message, and a Registration Accept message.

[0100] In a specific example, see Figure 6 , Figure 7 , Figure 8 and Figure 9 , Figure 6 This is a schematic diagram of a device fingerprint active update process based on the registration process. Figure 7 A schematic diagram of a device fingerprint active update process based on the tracking area update process. Figure 8 This is a schematic diagram of a device fingerprint active update process based on a service request procedure. Figure 9 The figure is a flow chart of active device fingerprint update based on registration or registration area update process. The active update of device fingerprint (legal device fingerprint and / or illegal device fingerprint) performed by UE refers to the device fingerprint update process initiated by UE.

[0101] for Figure 6 or Figure 7In the solution for active update of device fingerprints based on the registration process, the Attach Accept or Tracking Area Update Accept originally carries the Tracking Area Identity (TAI) list information. These signaling messages are sent from the Network side to the UE. In these signaling messages, the legal device fingerprints in each Tracking Area (TA) can be sent to the UE, or the identified illegal device fingerprints in the TAs corresponding to the TAI list can be sent to the UE. At this time, an indication message can be added to the Attach Request or Tracking Area Update Request message sent by the UE to the Network side, indicating that the purpose of this request is to obtain legal device fingerprints and / or illegal device fingerprints from the Network side, so that the Network side sends an Attach Accept or Tracking Area Update Accept carrying legal device fingerprints and / or illegal device fingerprints to the UE. Optionally, when the UE determines that the device fingerprint database needs to be updated, it triggers Figure 6 or Figure 7 the process. For example, when the UE enters a new TA or discovers an abnormal cell, it triggers Figure 6 or Figure 7 the process.

[0102] For Figure 8 the solution for active update of device fingerprints based on the registration process, in the Service Accept, the originally existing fields can be used or a new field can be added to carry the legal device fingerprints and / or illegal device fingerprints identified in the TA where the UE is located, or the legal device fingerprints and / or illegal device fingerprints in each TA in the TAI list. It is sent to the UE through the Service Accept.

[0103] For Figure 9 the solution for active update of device fingerprints based on the registration or registration area update process, the Registration Accept signaling message originally carries the TAI list information. In this signaling message, the legal device fingerprints and / or illegal device fingerprints in each TA can be sent to the UE. At this time, an indication message is added to the Registration Request message, indicating that the purpose of this request is to obtain legal device fingerprints and / or illegal device fingerprints from the Network side. Optionally, when the UE determines that the device fingerprint database needs to be updated, it triggersFigure 9 procedure. For example, when the UE enters a new TA or discovers an abnormal cell, it triggers Figure 9 procedure.

[0104] Among them, Figures 6 to 9 It can be used in the LTE system or the NR system. In the LTE system, the operations on the network side can be performed by the Mobility Management Entity (MME for short). In the NR system, the operations on the network side can be performed by the device of the Access and Mobility Management Function (AMF for short).

[0105] It should be noted that in addition to the Figures 6 to 9 scheme, the legal device fingerprint and / or the illegal device fingerprint can also be sent to the UE as general data (that is, through a general data frame).

[0106] In this embodiment, the UE can determine whether the network device is legal based on the device fingerprints (legal device fingerprints and / or illegal device fingerprints) stored locally. The device fingerprints stored locally by the UE can be configured by the network side, and the UE can determine whether the network device is legal in a non-networked state.

[0107] In one embodiment, please refer to Figure 4 again. In step S402, determining whether the network device is legal according to the device fingerprint of the network device may further include: sending the device fingerprint of the network device to the network side, and receiving the reply returned by the network side to determine whether the network device is legal, so as to determine whether the network device is legal.

[0108] Optionally, if the UE is in the connected state and can be networked, then the device fingerprint library of the legal device fingerprint and / or the illegal device fingerprint can also be stored on the network side. At this time, after the UE obtains the device fingerprint of the network device, it can send the obtained device fingerprint of the network device to the network, and the network determines whether the network device is legal according to the device fingerprint library stored on the network side, and feeds back the determined result to the UE.

[0109] In this embodiment, in the networked state, the UE can also send the obtained device fingerprint of the network device to the network, and the network side performs the legality determination. Thus, there is no need for the UE side to store the device fingerprint library, nor does the UE need to perform the judgment on whether the network device is legal, which can effectively improve the processing efficiency of the UE.

[0110] In one embodiment, after obtaining the device fingerprint of the network device, the method further includes: sending a fingerprint reporting signaling to the network side, where the fingerprint reporting signaling includes the device fingerprint of the network device.

[0111] Among them, the fingerprint reporting signaling is a signaling sent by the UE to the network to report the device fingerprint detected by the UE to the network side.

[0112] To avoid different UEs from reporting the device fingerprint of the same base station to the network, the base station can broadcast an indication message that its fingerprint has been saved, so that each UE can avoid sending duplicate device fingerprints to the base station.

[0113] Optionally, the fingerprint reporting signaling is carried by one or more of the following messages: Attach Request, Tracking Area Update Request, Registration Request, Service Request.

[0114] Please refer to again Figures 6 to 9 , if the UE discovers an abnormal cell, it can also report the device fingerprint information of the abnormal cell through these processes. The fingerprint reporting signaling can be Figure 6 the Attach Request in Figure 7 the Tracking Area Update Request in Figure 8 the Service Request in Figure 9 the Registration Request in

[0115] Thus, when the UE detects the device fingerprint of a new network device, it can report the device to the network, so as to help the network side automatically improve the device fingerprint library through the device fingerprints reported by each UE.

[0116] In one embodiment, the method may further include a process of the network side automatically updating the device fingerprint library locally stored in the UE (abbreviated as passive update), and this process includes: receiving a paging message (Paging) sent by the network side, where the paging message carries updated fingerprint information.

[0117] Optionally, if the network determines that the device fingerprint library needs to be updated: for example, when a certain UE or base station identifies and reports a false base station fingerprint information, and it is necessary to update the device fingerprint library broadcast for the whole network or update the device fingerprint library for a specific area, the process of passive update is triggered.

[0118] The network side triggers a passive update process and sends information for updating the device fingerprint library stored locally in the UE, that is, update fingerprint information, to the UE, so that the UE updates the device fingerprint library stored locally according to the update fingerprint information. Optionally, the update fingerprint information includes information such as adding and / or reducing one or more legitimate device fingerprints / illegal device fingerprints in the device fingerprint library stored locally in the UE, and so on.

[0119] Optionally, the update fingerprint information includes at least one of the legitimate device fingerprint, the illegal device fingerprint, and the fingerprint update prompt, and the fingerprint update prompt is used to prompt the update of the legitimate device fingerprint and / or the illegal device fingerprint.

[0120] Optionally, the network side can send a paging message only to a specific area, that is, update the device fingerprint library for the UEs in the specific area. Further, the specific area can be determined according to the area where the device fingerprint to be updated is located. For example, if a new illegal network device is found in an area, a Paging for passive update can be sent to other UEs in the area.

[0121] Please refer to Figure 10 , Figure 10 which is a schematic diagram of a method for passive update of device fingerprints. Among them, the network side sends a paging message (Paging) to the UE through the Access Stratum (AS for short), and the update fingerprint information (corresponding to the indication in Figure 10 ) is carried in the paging message. At this time, the network side (that is, the AMF / MME in Figure 10 ) sends a message for requesting paging (Request Paging) to the AS, and the update fingerprint information (corresponding to the indication in Figure 10 ) is carried in the Request Paging.

[0122] Optionally, the Paging can adopt Paging based on a direct indication message (Direct Indication information) (mostly applied to the LTE system) or Paging based on a short message (Short message) (mostly applied to the NR system).

[0123] Please refer to Table 1. Table 1 is an example of the structure of Paging based on a direct indication message:

[0124]

[0125] Please refer to Table 2. Table 2 is an example of the structure of Paging based on a short message:

[0126]

[0127] In the prior art, for a certain paging scheduling (such as a Physical Downlink Control Channel (PDCCH) scrambled by a Public RNTI (Radio Network Temporary Identity) (PCCH of Paging)), a short message or Direct Indication information may be directly transmitted in the PDCCH, or only a paging message is transmitted and carried by a Physical Downlink Shared Channel (PDSCH), or both are transmitted. These several paging schedulings can be used for the paging messages in Table 1 and Table 2.

[0128] Optionally, for the paging messages in Table 1 and Table 2, the paging indication may indicate that this paging scheduling transmits both a short message or Direct Indication information and a paging message.

[0129] The reason is that for the update of the device fingerprint database, since the data for the update of the device fingerprint database may be relatively large, and the capacity of the PDCCH is limited, it may not be possible to transmit directly through the PDCCH. A more appropriate method is to indicate in the PDCCH that it is a paging message for the update of the device fingerprint database (i.e., a fingerprint update prompt), and the specific device fingerprint database update data is transmitted through the subsequent paging message or through general data transmission.

[0130] Optionally, the Paging indicating the update of the device fingerprint database needs to be distinguished from general paging messages (short messages or service paging) so that UEs that do not support the update of the device fingerprint database can not process the Paging indicating the update of the device fingerprint database.

[0131] In this embodiment, a method for passively updating the device fingerprint on the UE side triggered by the network side is provided, which can timely update the device fingerprint database stored locally on the UE to ensure that the UE can always accurately identify illegal network devices and protect the communication security of the UE.

[0132] In one embodiment, please refer to Figure 11 , Figure 11 which is a schematic flowchart of the second method for identifying the legality of network devices. The method includes:

[0133] Step S1101: Receive the device fingerprint of the network device sent by the terminal device, determine whether the network device is legal, and send a reply indicating whether the network device is legal to the terminal device.

[0134] Optionally, the method further includes: receiving a fingerprint reporting signaling sent by the terminal device, where the fingerprint reporting signaling includes the device fingerprint of the network device.

[0135] Optionally, the fingerprint reporting signaling is carried by one or more of the following messages: attach request, tracking area update request, registration request, service request.

[0136] In one embodiment, please refer to Figure 12 , Figure 12 FIG. [0000344] is a schematic flowchart of a third method for identifying the legality of a network device. The method includes:

[0137] Step S1201: Send a legal device fingerprint and / or an illegal device fingerprint to the terminal device.

[0138] Optionally, before step S1201 of sending the legal device fingerprint and / or the illegal device fingerprint to the terminal device, it may further include: receiving a device fingerprint request signaling sent by the terminal device;

[0139] Step S1201 of sending the legal device fingerprint and / or the illegal device fingerprint to the terminal device may include: sending the legal device fingerprint and / or the illegal device fingerprint to the terminal device based on the device fingerprint request signaling.

[0140] Optionally, the legal device fingerprint and / or the illegal device fingerprint is carried by one or more of the following messages: attach accept message, tracking area update accept message, service accept message, registration accept information.

[0141] Optionally, the method further includes: sending a paging message to the terminal device, where the paging message carries updated fingerprint information.

[0142] Optionally, the updated fingerprint information includes at least one of the legal device fingerprint, the illegal device fingerprint, and a fingerprint update prompt, where the fingerprint update prompt is used to prompt an update of the legal device fingerprint and / or the illegal device fingerprint.

[0143] In one embodiment, please refer to Figure 13 , Figure 13 FIG. [0000360] is a schematic flowchart of a fourth method for identifying the legality of a network device. The method includes step S1301 or step S1302, where:

[0144] Step S1301: Send a fingerprint extraction algorithm to the terminal device.

[0145] Step S1302: Receive one or more fingerprint extraction algorithms supported by the terminal device and send a reply to the terminal device. The reply is used to specify the fingerprint extraction algorithm to be applied by the terminal device from the one or more fingerprint extraction algorithms.

[0146] Among them, the fingerprint extraction algorithm is used by the terminal device to extract the device fingerprint of the network device according to the target information, and the target information is sent by the network device and received by the terminal device.

[0147] Figure 11 、 Figure 12 and Figure 13 The above-mentioned method for identifying the legitimacy of the network device can be applied on the network side or on the base station side connected to the UE. For more details about the specific working principle and working mode, reference can be made to Figures 4 to 10 the relevant descriptions about the network side, base station, or MME / AMF therein, which will not be elaborated here.

[0148] Please refer to Figure 14 , Figure 14 FIG. shows the structural schematic diagram of the first device 140 for identifying the legitimacy of the network device. The device 140 for identifying the legitimacy of the network device includes:

[0149] A fingerprint acquisition module 1401, configured to acquire the device fingerprint of the network device;

[0150] A legitimacy determination module 1402, configured to determine whether the network device is legitimate according to the device fingerprint of the network device.

[0151] Regarding Figure 14 more details about the working principle and working mode of the device 140 for identifying the legitimacy of the network device shown in FIG., reference can be made to Figures 4 to 10 the relevant descriptions of the above-mentioned method, which will not be elaborated here.

[0152] Please refer to Figure 15 , Figure 15 FIG. shows the structural schematic diagram of the second device 150 for identifying the legitimacy of the network device. The device 150 for identifying the legitimacy of the network device includes:

[0153] A network device determination module 1501, configured to receive the device fingerprint of the network device sent by the terminal device, determine whether the network device is legitimate, and send a reply indicating whether the network device is legitimate to the terminal device.

[0154] Regarding Figure 15 more details about the working principle and working mode of the device 150 for identifying the legitimacy of the network device shown in FIG., reference can be made to Figure 11 the relevant descriptions of the above-mentioned method, which will not be elaborated here.

[0155] Please refer to Figure 16 , Figure 16 which is a schematic structural diagram of a third-legitimacy identification device 160 for a network device. The legitimacy identification device 160 for the network device includes:

[0156] A fingerprint sending module 1601, configured to send a legitimate device fingerprint and / or an illegal device fingerprint to the terminal device.

[0157] Regarding Figure 16 more content about the working principle and working mode of the legitimacy identification device 160 for the network device shown, reference can be made to Figure 12 the relevant description of the method described above, which will not be elaborated here.

[0158] Please refer to Figure 17 , Figure 17 which is a schematic structural diagram of a fourth-legitimacy identification device 170 for a network device. The legitimacy identification device 170 for the network device includes an algorithm sending module 1701 or an algorithm specifying module 1702, where:

[0159] The algorithm sending module 1701 is configured to send a fingerprint extraction algorithm to the terminal device;

[0160] The algorithm specifying module 1702 is configured to receive one or more fingerprint extraction algorithms supported by the terminal device and fed back by the terminal device, and send a reply to the terminal device, where the reply is used to specify the fingerprint extraction algorithm applied by the terminal device from the one or more fingerprint extraction algorithms;

[0161] wherein, the fingerprint extraction algorithm is used by the terminal device to extract the device fingerprint of the network device according to the target information, and the target information is sent by the network device and received by the terminal device.

[0162] Regarding Figure 17 more content about the working principle and working mode of the legitimacy identification device 170 for the network device shown, reference can be made to Figure 13 the relevant description of the method described above, which will not be elaborated here.

[0163] An embodiment of the present invention further provides a storage medium, on which a computer program is stored, and when the computer program is run by a processor, it executes the steps of the method shown above Figures 4 to 10 Or, when the computer program is run by a processor, it executes the steps of the method shown above Figure 11 Or, when the computer program is run by a processor, it executes the steps of the method shown above Figure 12 Or, when the computer program is run by a processor, it executes the steps of the method shown above Figure 13Steps of the method shown. The storage medium may be a computer-readable storage medium, for example, it may include non-volatile memory or non-transitory memory, and may also include optical discs, mechanical hard drives, solid-state drives, etc.

[0164] Specifically, in the embodiments of the present invention, the processor may be a central processing unit (CPU for short), and this processor may also be other general-purpose processors, digital signal processors (DSP for short), application specific integrated circuits (ASIC for short), field programmable gate arrays (FPGA for short), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or this processor may also be any conventional processor, etc.

[0165] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0166] The embodiments of the present invention also provide a terminal device, including a memory and a processor, where a computer program capable of running on the processor is stored on the memory, and when the processor runs the computer program, it executes Figures 4 to 10 the steps of the method. The computer device includes but is not limited to devices such as mobile phones, computers, tablet computers, servers, or server clusters, etc. The terminal may be a UE.

[0167] Specifically, the terminal device in the embodiments of the present application may refer to various forms of user equipment (UE), access terminal, user unit, user station, mobile station, mobile station (MS for short), remote station, remote terminal, mobile device, user terminal, terminal equipment, wireless communication device, user agent or user device. The terminal device may also be a cellular phone, cordless phone, Session Initiation Protocol (SIP) phone, Wireless Local Loop (WLL) station, Personal Digital Assistant (PDA), handheld device with wireless communication function, computing device or other processing device connected to a wireless modem, vehicle-mounted device, wearable device, terminal device in the future 5G network or terminal device in the future evolved Public Land Mobile Network (PLMN for short), etc. The embodiments of the present application are not limited thereto.

[0168] The embodiments of the present invention also provide a base station, including a memory and a processor, where a computer program capable of running on the processor is stored on the memory, and when the processor runs the computer program, it executes Figure 11 or Figure 12 or Figure 13 the steps of the method.

[0169] The embodiments of the present invention also provide a legal identification system for a network device. The system may include a UE and a base station. The UE is connected to the base station through a network, or the network connection between the UE and the base station is disconnected. Wherein: Whether the UE is connected to the base station or not, the UE obtains the device fingerprint of the network device, and determines whether the network device is legal according to the device fingerprint of the network device.

[0170] In one embodiment, the UE is used to receive the target information sent by the network device, and apply a fingerprint extraction algorithm to extract the device fingerprint according to the target information.

[0171] In one embodiment, when the UE is connected to the base station through a network, before the UE applies the fingerprint extraction algorithm, it further includes: receiving the fingerprint extraction algorithm sent by the base station.

[0172] Alternatively, the UE feeds back to the base station one or more fingerprint extraction algorithms supported by the UE; the base station receives the device fingerprint of the network device sent by the UE, determines whether the network device is legal, and sends a reply to the UE indicating whether the network device is legal; the UE receives the reply sent by the network side specifying the fingerprint extraction algorithm applied from the one or more fingerprint extraction algorithms.

[0173] In one embodiment, the UE compares the device fingerprint of the network device with the legal device fingerprints and / or illegal device fingerprints stored locally to determine whether the network device is legal. Alternatively, the UE sends the device fingerprint of the network device to the base station; the base station receives the device fingerprint of the network device sent by the UE, determines whether the network device is legal, and sends a reply to the UE indicating whether the network device is legal; the UE receives the reply sent by the base station determining whether the network device is legal to determine whether the network device is legal.

[0174] In one embodiment, the UE also receives the legal device fingerprints and / or illegal device fingerprints sent by the network side and stores them locally.

[0175] In one embodiment, before the UE receives the legal device fingerprints and / or illegal device fingerprints sent by the base station, the UE sends a device fingerprint request signaling to the base station; the base station sends the legal device fingerprints and / or illegal device fingerprints to the UE based on the device fingerprint request signaling; the UE receives the legal device fingerprints and / or illegal device fingerprints sent by the base station based on the device fingerprint request signaling.

[0176] In one embodiment, the legal device fingerprints and / or illegal device fingerprints are carried by one or more of the following messages: attach accept message, tracking area update accept message, service accept message, registration accept information.

[0177] In one embodiment, the base station sends a paging message to the UE, and the paging message carries updated fingerprint information; the UE also receives the paging message sent by the base station, and the paging message carries updated fingerprint information.

[0178] In one embodiment, the updated fingerprint information includes at least one of the legal device fingerprint, illegal device fingerprint, and fingerprint update prompt, and the fingerprint update prompt is used to prompt the update of the legal device fingerprint and / or illegal device fingerprint.

[0179] In one embodiment, after the UE obtains the device fingerprint of the network device, the UE sends a fingerprint reporting signaling to the base station, and the fingerprint reporting signaling includes the device fingerprint of the network device; the base station receives the fingerprint reporting signaling sent by the UE.

[0180] In one embodiment, the fingerprint reporting signaling is carried by one or more of the following messages: Attach Request, Tracking Area Update Request, Registration Request, Service Request.

[0181] For more information about the working principle and mode of the legitimacy identification system of the network device, reference can be made to Figures 4 to 17 For the relevant descriptions of the terminal device (or UE) and the base station, they will not be elaborated here.

[0182] It should be understood that the term "and / or" in this article is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article indicates that the associated objects before and after are in an "or" relationship.

[0183] The "plurality" mentioned in the embodiments of this application refers to two or more.

[0184] The descriptions such as first and second in the embodiments of this application are only for illustration and distinguishing the description objects, without order, nor do they represent special limitations on the number of devices in the embodiments of this application, and cannot constitute any limitation to the embodiments of this application.

[0185] The "connection" mentioned in the embodiments of this application refers to various connection methods such as direct connection or indirect connection to achieve communication between devices, and this application does not make any limitations on this.

[0186] Although the present invention is disclosed as above, the present invention is not limited thereto. Any person skilled in the art can make various changes and modifications without departing from the spirit and scope of the present invention. Therefore, the protection scope of the present invention should be subject to the scope defined by the claims.

Claims

1. A method for identifying the legitimacy of a network device, which is used for a terminal device, characterized in that, the method includes: Obtaining the device fingerprint of the network device; Determining whether the network device is legitimate according to the device fingerprint of the network device and the legitimate device fingerprints and / or illegal device fingerprints stored locally in the device fingerprint library. When it is determined that the device fingerprint library needs to be updated, an attachment request, a tracking area update request message, a service request or a registration request is sent. The attachment request, the tracking area update request message, the service request or the registration request includes indication information, and the indication information is used to indicate obtaining legitimate device fingerprints and / or illegal device fingerprints from the network side.

2. The method according to claim 1, characterized in that, the obtaining of the network device fingerprint includes: Receiving the target information sent by the network device; Applying a fingerprint extraction algorithm to extract the device fingerprint according to the target information.

3. The method according to claim 2, characterized in that, before applying the fingerprint extraction algorithm, it further includes: Receiving the fingerprint extraction algorithm sent by the network side; or Feeding back one or more fingerprint extraction algorithms supported by the terminal device to the network side and receiving a reply from the network side of the fingerprint extraction algorithm specified for application from the one or more fingerprint extraction algorithms.

4. The method according to any one of claims 1 to 3, characterized in that, the determining whether the network device is legitimate according to the device fingerprint of the network device includes: Comparing the device fingerprint of the network device with the legitimate device fingerprints and / or illegal device fingerprints stored locally to determine whether the network device is legitimate; or Sending the device fingerprint of the network device to the network side and receiving a reply from the network side determining whether the network device is legitimate to determine whether the network device is legitimate.

5. The method according to claim 4, characterized in that, the method further includes: Receiving the legitimate device fingerprints and / or illegal device fingerprints sent by the network side and storing them locally.

6. The method according to claim 5, characterized in that, the legitimate device fingerprints and / or illegal device fingerprints are carried by one or more of the following messages: attachment acceptance message, tracking area update acceptance message, service acceptance message, registration acceptance information.

7. The method according to claim 5, characterized in that, the method further includes: Receiving a paging message sent by the network side, and the paging message carries updated fingerprint information.

8. The method according to claim 7, characterized in that, the updated fingerprint information includes at least one of the legitimate device fingerprint, the illegal device fingerprint, and the fingerprint update prompt, and the fingerprint update prompt is used to prompt to update the legitimate device fingerprint and / or the illegal device fingerprint.

9. The method according to claim 1, characterized in that, after obtaining the device fingerprint of the network device, it further includes: Sending a fingerprint reporting signaling to the network side, and the fingerprint reporting signaling includes the device fingerprint of the network device.

10. The method according to claim 9, characterized in that, The fingerprint reporting signaling is carried by one or more of the following messages: Attach Request, Tracking Area Update Request, Registration Request, Service Request.

11. A method for identifying the legitimacy of a network device, which is used for a network device, characterized in that the method includes: receiving the device fingerprint of the network device sent by the terminal device, determining whether the network device is legitimate, and sending a reply to the terminal device as to whether the network device is legitimate. Among them, when it is determined that the device fingerprint library needs to be updated, the terminal device sends an Attach Request, a Tracking Area Update Request message, a Service Request or a Registration Request, and the Attach Request, the Tracking Area Update Request message, the Service Request or the Registration Request includes indication information, and the indication information is used to indicate obtaining legitimate device fingerprints and / or illegal device fingerprints from the network side.

12. The method according to claim 11, characterized in that the method further includes: receiving the fingerprint reporting signaling sent by the terminal device, and the fingerprint reporting signaling includes the device fingerprint of the network device.

13. The method according to claim 12, characterized in that the fingerprint reporting signaling is carried by one or more of the following messages: Attach Request, Tracking Area Update Request, Registration Request, Service Request.

14. A method for identifying the legitimacy of a network device, characterized in that the method includes: sending legitimate device fingerprints and / or illegal device fingerprints to the terminal device for the terminal device to determine whether the network device is legitimate according to the device fingerprint of the network device and the legitimate device fingerprints and / or illegal device fingerprints in the locally stored device fingerprint library. Among them, when it is determined that the device fingerprint library needs to be updated, the terminal device sends an Attach Request, a Tracking Area Update Request message, a Service Request or a Registration Request, and the Attach Request, the Tracking Area Update Request message, the Service Request or the Registration Request includes indication information, and the indication information is used to indicate obtaining legitimate device fingerprints and / or illegal device fingerprints from the network side.

15. The method according to claim 14, characterized in that before sending the legitimate device fingerprints and / or illegal device fingerprints to the terminal device, it further includes: receiving the device fingerprint request signaling sent by the terminal device; sending the legitimate device fingerprints and / or illegal device fingerprints to the terminal device includes: sending the legitimate device fingerprints and / or illegal device fingerprints to the terminal device based on the device fingerprint request signaling.

16. The method according to claim 14 or 15, characterized in that the legitimate device fingerprints and / or illegal device fingerprints are carried by one or more of the following messages: Attach Accept Message, Tracking Area Update Accept Message, Service Accept Message, Registration Accept Information.

17. The method according to claim 14, characterized in that the method further includes: sending a paging message to the terminal device, and the paging message carries updated fingerprint information.

18. The method according to claim 17, characterized in that The updated fingerprint information includes at least one of the legal device fingerprint, the illegal device fingerprint, and the fingerprint update prompt, and the fingerprint update prompt is used to prompt for the update of the legal device fingerprint and / or the illegal device fingerprint.

19. A legal identification device for a network device, characterized in that the device includes: a fingerprint acquisition module, configured to acquire the device fingerprint of the network device; a legality determination module, configured to determine whether the network device is legal according to the device fingerprint of the network device and the legal device fingerprint and / or illegal device fingerprint in the locally stored device fingerprint library, wherein when it is determined that the device fingerprint library needs to be updated, an attachment request, a tracking area update request message, a service request, or a registration request is sent, and the attachment request, the tracking area update request message, the service request, or the registration request includes indication information, and the indication information is used to indicate to obtain the legal device fingerprint and / or illegal device fingerprint from the network side.

20. A legal identification device for a network device, characterized in that the device includes: a network device determination module, configured to receive the device fingerprint of the network device sent by the terminal device, determine whether the network device is legal, and send a reply as to whether the network device is legal to the terminal device, wherein when it is determined that the device fingerprint library needs to be updated, the terminal device sends an attachment request, a tracking area update request message, a service request, or a registration request, and the attachment request, the tracking area update request message, the service request, or the registration request includes indication information, and the indication information is used to indicate to obtain the legal device fingerprint and / or illegal device fingerprint from the network side.

21. A legal identification device for a network device, characterized in that the device includes: a fingerprint sending module, configured to send the legal device fingerprint and / or illegal device fingerprint to the terminal device for the terminal device to determine whether the network device is legal according to the device fingerprint of the network device and the legal device fingerprint and / or illegal device fingerprint in the locally stored device fingerprint library, wherein when it is determined that the device fingerprint library needs to be updated, the terminal device sends an attachment request, a tracking area update request message, a service request, or a registration request, and the attachment request, the tracking area update request message, the service request, or the registration request includes indication information, and the indication information is used to indicate to obtain the legal device fingerprint and / or illegal device fingerprint from the network side.

22. A storage medium, on which a computer program is stored, characterized in that when the computer program is run by a processor, it executes the steps of the method according to any one of claims 1 to 18.

23. A terminal device, including a memory and a processor, and a computer program that can run on the processor is stored on the memory, characterized in that when the processor runs the computer program, it executes the steps of the method according to any one of claims 1 to 10.

24. A base station, including a memory and a processor, and a computer program that can run on the processor is stored on the memory, characterized in that when the processor runs the computer program, it executes the steps of the method according to any one of claims 11 to 18.

Citation Information

Patent Citations

  • Provisioning of application categories at a user equipment during network congestion

    CN105103621A

  • Pseudo AP detection method based on RSSI

    CN105472621A

  • Power system APN private network defense method for pseudo base station attacks

    CN106851645A

  • Pseudo-AP (Access Points) detection method and device based on fingerprint feature

    CN108540979A