A method, device, equipment and medium for security management of user-side equipment
By obtaining device and network information when the 5G CPE device is started, locking the CPE and SIM to ensure legal access, the problem of low security of 5G CPE devices is solved and security control of the device and SIM is achieved.
Patent Information
- Application Number
- CN202210796353.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-06
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2042-07-06
AI Technical Summary
In the existing technology, 5G CPE devices lack a clear security mechanism during use, resulting in the inability to ensure the security of the device and the access SIM card, and the inability to control the access of non-designated SIM cards and the access of devices with designated SIM cards.
When the user-side device CPE executes the startup process, it obtains the device description information and network identification area code, and controls the CPE and SIM through a locking mechanism to allow only authorized devices to access, ensuring that the device description information and SIM identity identification code meet legal conditions.
It improves the security of 5G CPE devices during use, clarifies the security mechanism between the device and the access SIM, and ensures that only authorized devices and SIMs can access each other.
Smart Images

Figure CN115134810B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of wireless communication technologies, and in particular to a method, apparatus, device, and medium for security management of user-side equipment. Background Art
[0002] With the popularization of 5th Generation Mobile Communication Technology (5G) wireless devices, more and more 5G devices are being put into use. Therefore, to meet market strategies, the security mechanism between 5G customer premises equipment (CPE) and the connected subscriber identity module (SIM) has become increasingly important.
[0003] However, existing technologies lack a clear security mechanism between 5G CPE and the connected SIM card. This makes it impossible to manage the 5G CPE device when a non-designated SIM card is connected to the device. When a designated SIM card is connected to the 5G CPE device, there is no guarantee that the device connected to the SIM card is the designated 5G CPE device. Consequently, the security of the 5G CPE device during use cannot be guaranteed. Therefore, improving the security of 5G CPE devices during use and clarifying the security mechanism between 5G CPE and the connected SIM card are currently urgent issues that need to be addressed. Summary of the Invention
[0004] The present invention provides a method, apparatus, device, and medium for security management of user-side equipment, which can improve the security of 5G CPE equipment during use.
[0005] According to one aspect of the present invention, a security management method for a user-side device is provided, comprising:
[0006] When the user-side device CPE performs a startup process, obtaining device description information of the CPE and an identification area code of the network to which it belongs;
[0007] When it is determined that the device description information meets the legal device conditions and the identification area code matches the authorized area code of the authorized user identity module SIM of the CPE, locking the CPE to control the CPE to access only the authorized SIM;
[0008] When it is determined that the current area code of the target SIM inserted in the CPE is consistent with the authorized area code, obtaining the identity identification code of the target SIM;
[0009] When it is determined that the identity identification code meets the legal identification code condition, the target SIM is locked to control the target SIM to be accessible only to the CPE.
[0010] According to another aspect of the present invention, a security management device for a user-side device is provided, comprising:
[0011] A first information acquisition module is configured to acquire device description information of a user-side device CPE and an identification area code of a network to which the CPE belongs when the CPE performs a startup process;
[0012] a first information verification module, configured to lock the CPE when determining that the device description information satisfies the legal device condition and the identification area code matches the authorized area code of the authorized user identity module SIM of the CPE, so as to control the CPE to only be able to access the authorized SIM;
[0013] a second information acquisition module, configured to acquire an identity identification code of the target SIM card inserted in the CPE when determining that the current area code of the target SIM card is consistent with the authorized area code;
[0014] The second information verification module is used to lock the target SIM card when it is determined that the identity identification code meets the legal identification code condition, so as to control the target SIM card to be accessible only to the CPE.
[0015] According to another aspect of the present invention, an electronic device is provided, comprising:
[0016] at least one processor; and
[0017] a memory communicatively connected to the at least one processor; wherein,
[0018] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the security management method of the user-side device described in any embodiment of the present invention.
[0019] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the security management method for a user-side device according to any embodiment of the present invention when executed.
[0020] The technical solution of the embodiment of the present invention is to obtain the device description information of the CPE and the identification area code of the network to which it belongs when the user-side device CPE executes the power-on startup process, and when it is determined that the device description information meets the legal device conditions and the identification area code matches the authorized area code of the authorized user identity identification module SIM of the CPE, lock the CPE to control the CPE to only access the authorized SIM; when it is determined that the current area code of the target SIM inserted in the CPE is consistent with the authorized area code, obtain the identity identification code of the target SIM; when it is determined that the identity identification code meets the legal identification code conditions, lock the target SIM to control the target SIM to only be accessed by the CPE, which solves the problem of low security of 5G CPE equipment during use in the prior art, can improve the security of 5G CPE equipment during use, and clarify the security mechanism between 5G CPE and access SIM.
[0021] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0023] Figure 1 This is a flowchart of a security management method for a user-side device provided according to the first embodiment of the present invention;
[0024] Figure 2a This is a flowchart of a security management method for a user-side device provided in accordance with a second embodiment of the present invention;
[0025] Figure 2b 1 is a flow chart of a security management method for a user-side device provided according to a second embodiment of the present invention;
[0026] Figure 3a This is a flowchart of a security management method for a user-side device provided in accordance with a third embodiment of the present invention;
[0027] Figure 3b 1 is a flow chart of a security management method for a user-side device provided according to a third embodiment of the present invention;
[0028] Figure 4 This is a schematic diagram of the structure of a security management device for a user-side device provided in accordance with a fourth embodiment of the present invention;
[0029] Figure 5 It is a structural diagram of an electronic device for implementing the security management method of a user-side device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0030] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0031] It should be noted that the terms "first", "second", "target", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices. The acquisition, storage, use, processing, etc. of data / information in the technical solution of this application comply with the relevant provisions of national laws and regulations.
[0032] Example 1
[0033] Figure 1 A flowchart of a security management method for a user-side device is provided for the first embodiment of the present invention. This embodiment is applicable to the case where security management is performed when a CPE is connected to a SIM card. The method can be executed by a security management device of the user-side device. The security management device of the user-side device can be implemented in the form of hardware and / or software. The security management device of the user-side device can be configured in an electronic device. Figure 1 As shown, the method includes:
[0034] S110 : When the user-side device CPE executes a startup process, obtain device description information of the CPE and an identification area code of the network to which it belongs.
[0035] The device description information of the CPE may refer to the device parameter information of the CPE, and may include, for example, the International Mobile Equipment Identity (IMEI) of the CPE or the serial number (SN) of the CPE. The identification area code of the network to which the CPE belongs may refer to the network area under the responsibility of the operator to which the CPE belongs, and may be, for example, the Public Land Mobile Network (PLMN).
[0036] S120: When it is determined that the device description information meets the legal device condition and the identification area code matches the authorized area code of the authorized user identity module SIM of the CPE, lock the CPE to control the CPE to access only the authorized SIM.
[0037] Among them, the legal device condition may refer to a pre-set preliminary screening condition for authorizing the CPE; illustratively, it may be that the device description information satisfies the set naming format, or the device description information satisfies the set naming length, etc., and the embodiment of the present invention does not limit this.
[0038] The authorized user identity module may refer to a SIM that is expected to access the CPE in advance, that is, the SIM that is expected to be authorized. The authorized area code may refer to the area code to which the authorized SIM belongs, and may be, for example, an area code initialized according to a pre-expected expectation.
[0039] Specifically, first, the device description information of the CPE is judged using the legal device conditions. If the device description information of the CPE meets the legal device conditions, the identification area code of the CPE is matched with the authorized area code. If the identification area code of the CPE is consistent with the authorized area code, the CPE is set as an authorized CPE. The CPE can be locked to control the CPE to only access the authorized SIM.
[0040] S130: When it is determined that the current area code of the target SIM inserted in the CPE is consistent with the authorized area code, obtain the identity identification code of the target SIM.
[0041] The target SIM may refer to the SIM connected to the CPE. The current area code may refer to the area code to which the target SIM belongs. The identity code may refer to a number representing the identity of the target SIM, and may be, for example, the personal identification number (PIN) of the target SIM.
[0042] Specifically, when the target SIM accesses the authorized CPE, the current area code of the target SIM is first matched with the authorized area code. When the current area code of the target SIM is matched with the authorized area code, the identity identification code of the target SIM is obtained, providing an effective basis for subsequent target SIM authorization.
[0043] S140: When it is determined that the identity identification code meets the legal identification code condition, the target SIM is locked to control the target SIM to be accessible only to the CPE.
[0044] Among them, the legal identification code condition may refer to a pre-set screening condition for authorizing a SIM to access the CPE; illustratively, the identity identification code of the target SIM may satisfy a set naming format, or the identity identification code of the target SIM may satisfy a set naming length, etc., and the embodiment of the present invention does not limit this.
[0045] Specifically, after obtaining the identity identification code of the target SIM, the identity identification code of the target SIM is determined using the legal identification code condition. If the identity identification code of the target SIM meets the legal identification code condition, the target SIM can be set as an authorized SIM and can be locked to control the target SIM to be accessible only to authorized CPEs.
[0046] The technical solution of the embodiment of the present invention is to obtain the device description information of the CPE and the identification area code of the network to which it belongs when the user-side device CPE executes the power-on startup process, and when it is determined that the device description information meets the legal device conditions and the identification area code matches the authorized area code of the authorized user identity identification module SIM of the CPE, lock the CPE to control the CPE to only access the authorized SIM; when it is determined that the current area code of the target SIM inserted in the CPE is consistent with the authorized area code, obtain the identity identification code of the target SIM; when it is determined that the identity identification code meets the legal identification code conditions, lock the target SIM to control the target SIM to only be accessed by the CPE, which solves the problem of low security of 5G CPE equipment during use in the prior art, can improve the security of 5G CPE equipment during use, and clarify the security mechanism between 5G CPE and access SIM.
[0047] Example 2
[0048] Figure 2aThis is a flowchart of a security management method for a user-side device provided in the second embodiment of the present invention. This embodiment is supplemented based on the above embodiment. In this embodiment, the operation after obtaining the device description information of the CPE is supplemented, which may include: generating a first random key and a second random key respectively according to the device description information; refining the operation of determining whether the device description information meets the legal device conditions, which may include: determining whether the first random key and the second random key meet the legal device conditions; wherein the first random key and the second random key are used to unlock the CPE or the target SIM. Figure 2a As shown, the method includes:
[0049] S210: When the user-side device CPE executes a startup process, obtain device description information of the CPE and an identification area code of the network to which it belongs.
[0050] S220 . Generate a first random key and a second random key respectively according to the device description information.
[0051] The first random key and the second random key may refer to keys calculated based on the device description information of the CPE, and may be used to complete authorization screening of the device description information. The first random key and the second random key may also be used when unlocking the CPE or the target SIM.
[0052] In an optional embodiment, a first random key and a second random key are generated based on the device description information, including: using a random number generator to generate a calculation parameter based on a time factor; performing an XOR calculation on the calculation parameter, the device identification code in the device description information, and the device serial number in the device description information to generate the first random key; performing an XOR calculation on the calculation parameter, the device identification code in the device description information, and the device serial number in the device description information to generate the second random key. Specifically, first, a calculation parameter is generated based on a time factor using a random number generator to ensure the randomization of the calculation parameter; then, an XOR calculation is performed on the calculation parameter, the device identification code in the device description information, and the device serial number to generate a first random key for unlocking the CPE; and an XOR calculation is performed on the calculation parameter, the device identification code in the device description information, and the device serial number to generate a second random key for unlocking the target SIM.
[0053] It is worth noting that since the device description information of each CPE is different, the first random key and second random key corresponding to each CPE are different. In addition, to ensure the association between the target SIM and the CPE, the key used to unlock the target SIM can be selected as the second random key generated using the device description information of the CPE.
[0054] S230: When it is determined that the first random key and the second random key meet the legal device condition and the identification area code matches the authorized area code of the authorized user identity module SIM of the CPE, lock the CPE to control the CPE to access only the authorized SIM.
[0055] In an optional embodiment, determining whether the first random key and the second random key meet the legal device conditions includes: verifying whether the length of the first random key and the second random key meets the set length requirements; verifying whether the key content of the first random key and the second random key meets the set specification requirements.
[0056] The setting of the length requirement may refer to a pre-set condition for determining the length of the first random key and the second random key. For example, the setting of the random key length may be set to not exceed 10 digits. The setting of the specification requirement may refer to a pre-set condition for determining the generation specification of the first random key and the second random key.
[0057] Specifically, first, the length of the first random key and the second random key is verified using the set length requirement, and then the key content of the first random key and the second random key is verified using the set specification requirement. When the length of the first random key and the second random key meets the set length requirement and the key content of the first random key and the second random key meets the set specification requirement, it can be proved that the first random key and the second random key meet the legal device conditions, that is, the CPE corresponding to the first random key and the second random key meets the legal device conditions.
[0058] S240: When it is determined that the current area code of the target SIM inserted in the CPE is consistent with the authorized area code, obtain the identity identification code of the target SIM.
[0059] S250: When it is determined that the identity identification code meets the legal identification code condition, the target SIM is locked to control the target SIM to be accessible only to the CPE.
[0060] In an optional embodiment, after locking the CPE, it also includes: using a random number generator to generate an analog identification code based on a time factor, and adding the analog identification code to a set of legal identification codes; determining that the identity identification code meets the legal identification code conditions, including: matching the identity identification code with each analog identification code in the set of legal identification codes; if there is an analog identification code that is consistent with the identity identification code, determining that the identity identification code meets the legal identification code conditions.
[0061] The simulated identification code may refer to a pre-generated and stored identification code, and the legal identification code set may refer to a set consisting of various simulated identification codes.
[0062] Specifically, after obtaining the target SIM's identity code, a determination is made as to whether a simulated identity code that matches the target SIM's identity code exists in the set of legal identity codes. If so, the identity code is determined to meet the legal identity code conditions; if not, the identity code is determined to not meet the legal identity code conditions. If it is determined that the identity code meets the legal identity code conditions, the target SIM can be locked to control access to the target SIM only by authorized CPEs.
[0063] The technical solution of the embodiment of the present invention is to obtain the device description information of the CPE and the identification area code of the network to which it belongs when the user-side device CPE executes the power-on startup process; and generate a first random key and a second random key respectively according to the device description information; when it is determined that the first random key and the second random key meet the legal device conditions and the identification area code matches the authorized area code of the authorized user identity identification module SIM of the CPE, the CPE is locked to control the CPE to only access the authorized SIM; thereafter, when it is determined that the current area code of the target SIM inserted in the CPE is consistent with the authorized area code, the identity identification code of the target SIM is obtained; and when it is determined that the identity identification code meets the legal identification code conditions, the target SIM is locked to control the target SIM to only be accessed by the authorized CPE, thereby solving the problem of low security of 5G CPE devices during use in the prior art, improving the security of 5G CPE devices during use, and clarifying the security mechanism between 5G CPE and access SIM.
[0064] It is worth noting that after locking the CPE and the target SIM, a SIM reset function needs to be performed to make the above locking function take effect.
[0065] Figure 2bIt is a flow chart of a security management method for user-side equipment provided in accordance with the second embodiment of the present invention; specifically, when the CPE executes the power-on startup process, the IMEI information and SN serial number of the CPE and the identification area code of the network to which it belongs are obtained; the SIMLOCK key (i.e., the first random key) and the PINLOCK key (i.e., the second random key) are independently calculated and stored; further, the default PLMN (i.e., the authorized area code) is obtained; the SIMLOCK locking process (i.e., the CPE locking process) is executed to determine whether the first random key and the second random key meet the legal device conditions, and whether the identification area code matches the authorized area code of the authorized user identity module SIM of the CPE. If not, it proves that the CPE locking has failed and the SIM reset function needs to be performed to re-lock the CPE; if so, it proves that the CPE If the lock is successful, a random PIN code (i.e., simulated identification code) can be generated by a random number generator according to the time factor, and the random PIN code can be added to the legal identification code set; the PINLOCK locking process (i.e., target SIM locking process) is executed: determine whether the current area code of the target SIM inserted in the CPE is consistent with the authorized area code. If they are consistent, obtain the PIN code (i.e., identity identification code) of the target SIM, and match the PIN code of the target SIM with each random PIN code in the legal identification code set; if there is a random PIN code that is consistent with the PIN code, it is determined that the PIN code meets the legal identification code conditions, and the target SIM can be locked; finally, the SIM reset function is executed. If there is a reset result, it proves that the SIMLOCK function (i.e., CPE locking) and the PINLOCK function (i.e., target SIM locking) are effective.
[0066] Example 3
[0067] Figure 3a This is a flowchart of a security management method for a user-side device provided in the third embodiment of the present invention. This embodiment is supplemented based on the above embodiment. In this embodiment, it is specifically supplemented after the target SIM is locked. Specifically, it may include: when receiving an unlock instruction sent by the unlocking party, obtaining the unlock target in the unlock instruction; obtaining the first random key and / or the second random key corresponding to the unlock target; according to the current network status of the CPE, using the first random key and / or the second random key to execute the unlock instruction to complete the unlock target. Figure 3a As shown, the method includes:
[0068] S310: When the user-side device CPE executes a startup process, obtain device description information of the CPE and an identification area code of the network to which it belongs.
[0069] S320: Generate a first random key and a second random key according to the device description information.
[0070] S330: When it is determined that the first random key and the second random key meet the legal device condition and the identification area code matches the authorized area code of the authorized user identity module SIM of the CPE, the CPE is locked to control the CPE to access only the authorized SIM.
[0071] S340: When it is determined that the current area code of the target SIM inserted in the CPE is consistent with the authorized area code, obtain the identity identification code of the target SIM.
[0072] S350: When it is determined that the identity identification code meets the legal identification code condition, the target SIM is locked to control the target SIM to be accessible only to the CPE.
[0073] S360: When receiving an unlock instruction sent by the unlocking party, obtain the unlock target in the unlock instruction.
[0074] The unlocking party may refer to a user who needs to perform the unlocking operation, for example, the CPE administrator. The unlocking instruction may refer to an instruction initiated by the unlocking party to unlock the CPE or target SIM card. The unlocking instruction may include an unlocking target and an unlocking instruction keyword. The unlocking target may refer to the unlocking object, for example, the CPE or target SIM card.
[0075] S370: Obtain a first random key and / or a second random key corresponding to the unlocking target.
[0076] Specifically, after obtaining the unlock target in the unlock instruction, the first random key and / or the second random key corresponding to the unlock target are obtained. For example, if the unlock target is a CPE, the first random key is obtained; if the unlock target is a target SIM, the second random key is obtained; if the unlock target is a CPE and a target SIM, the first random key and the second random key are obtained.
[0077] S380: Execute an unlock instruction using the first random key and / or the second random key according to the current network status of the CPE to complete unlocking the unlock target.
[0078] The current network status may refer to the current network connection status of the CPE, and may be, for example, a networked state or a non-networked state, that is, a disconnected state.
[0079] In an optional embodiment, according to the current network status of the CPE, the unlocking instruction is executed using the first random key and / or the second random key to complete the unlocking of the unlocking target, including: if the CPE is currently in a networked state, a target short message is generated according to the first random key and / or the second random key and the unlocking target, and the target short message is sent to the CPE using a pre-set control number to complete the unlocking of the unlocking target; if the CPE is currently in a disconnected state, the first random key and / or the second random key is transmitted to the unlocking setting interface to complete the unlocking of the unlocking target.
[0080] The target short message may refer to information containing the unlock target and the corresponding unlock key. The control number may refer to a pre-set number for executing the unlock function. The set unlock interface may refer to a pre-set interface for unlocking the unlock target, and the unlock target can be unlocked by identifying the corresponding key of the unlock target.
[0081] Specifically, if the CPE is currently in an online state, a target short message containing the unlocking target and the corresponding unlocking key can be sent to the CPE through the control number to complete the unlocking of the unlocking target; if the CPE is currently not in an online state, the key corresponding to the unlocking target can be transmitted to the setting unlocking interface to complete the unlocking of the unlocking target.
[0082] It is worth noting that if the CPE is currently connected to the Internet, after unlocking the target through the target SMS, it will be permanently unlocked and will not be automatically locked after restarting the CPE; if the CPE is currently not connected to the Internet, after unlocking the target through the setting unlock interface, it will be automatically locked again after restarting the CPE.
[0083] The technical solution of the embodiment of the present invention is to obtain the device description information of the CPE and the identification area code of the network to which it belongs when the user-side device CPE executes the power-on startup process; and generate a first random key and a second random key respectively according to the device description information; when it is determined that the first random key and the second random key meet the legal device conditions and the identification area code matches the authorized area code of the authorized user identity module SIM of the CPE, the CPE is locked to control the CPE to only access the authorized SIM; when it is determined that the current area code of the target SIM inserted in the CPE is consistent with the authorized area code, the identity identification code of the target SIM is obtained; and when it is determined that the identity identification code meets the legal identification code conditions, the target SIM is locked to control the target SIM to only be accessed by the authorized CPE; when an unlocking instruction sent by the unlocking party is received, the unlocking target in the unlocking instruction is obtained, and the first random key and / or the second random key corresponding to the unlocking target are obtained; finally, according to the current network status of the CPE, the unlocking instruction is executed using the first random key and / or the second random key to complete the unlocking of the unlocking target, thereby solving the 5G network security problem in the prior art. To address the low security issue of CPE devices during use, you can unlock the CPE or SIM after it is locked, making it easier to lock the CPE and other SIM cards again. This can improve the security of 5G CPE devices during use and clarify the security mechanism between 5G CPE and access SIM cards.
[0084] Figure 3b : This is a flow chart of a security management method for a user-side device provided according to a third embodiment of the present invention, namely, an unlocking process for unlocking a target; specifically, after receiving an unlocking instruction, it is determined whether the unlocking target is in a locked state according to the storage status of each parameter in the SIMLOCK locking process (i.e., the CPE locking process) and the PINLOCK locking process (i.e., the target SIM locking process); if the unlocking target is not in a locked state, the SIMLOCK locking process (i.e., the CPE locking process) or the PINLOCK locking process (i.e., the target SIM locking process) is returned to be executed; if the unlocking target is in a locked state, the current network status of the CPE is judged. If the CPE is currently in a networked state, a target short message is generated according to the first random key and / or the second random key and the unlocking target, and the target short message is sent to the locked CPE using a pre-set control number to complete the unlocking of the unlocking target; if the CPE is currently in a disconnected state, the first random key and / or the second random key is transmitted to the setting unlocking interface to complete the unlocking of the unlocking target.
[0085] Example 4
[0086] Figure 4 This is a schematic diagram of the structure of a security management device for a user-side device provided in the fourth embodiment of the present invention. Figure 4As shown, the device includes: a first information acquisition module 410, a first information verification module 420, a second information acquisition module 430 and a second information verification module 440;
[0087] The first information acquisition module 410 is configured to acquire device description information and an identification area code of a network to which the CPE belongs when the CPE performs a startup process.
[0088] A first information verification module 420 is configured to lock the CPE when determining that the device description information satisfies the legal device condition and the identification area code matches the authorized area code of the authorized user identity module SIM of the CPE, so as to control the CPE to access only the authorized SIM;
[0089] The second information acquisition module 430 is configured to acquire the identity code of the target SIM when it is determined that the current area code of the target SIM inserted in the CPE is consistent with the authorized area code;
[0090] The second information verification module 440 is configured to lock the target SIM card when determining that the identity identification code satisfies the legal identification code condition, so as to control the target SIM card to be accessible only to the CPE.
[0091] The technical solution of the embodiment of the present invention is to obtain the device description information of the CPE and the identification area code of the network to which it belongs when the user-side device CPE executes the power-on startup process, and when it is determined that the device description information meets the legal device conditions and the identification area code matches the authorized area code of the authorized user identity identification module SIM of the CPE, lock the CPE to control the CPE to only access the authorized SIM; when it is determined that the current area code of the target SIM inserted in the CPE is consistent with the authorized area code, obtain the identity identification code of the target SIM; when it is determined that the identity identification code meets the legal identification code conditions, lock the target SIM to control the target SIM to only be accessed by the CPE, which solves the problem of low security of 5G CPE equipment during use in the prior art, can improve the security of 5G CPE equipment during use, and clarify the security mechanism between 5G CPE and access SIM.
[0092] Optionally, the security management device of the user-side device may further include a key generation module, which may be specifically configured to: after obtaining the device description information of the CPE, generate a first random key and a second random key according to the device description information;
[0093] The first information verification module 420 may be specifically configured to determine whether the first random key and the second random key satisfy a legal device condition; wherein the first random key and the second random key are used when unlocking the CPE or the target SIM.
[0094] Optionally, the key generation module can be specifically used to: use a random number generator to generate calculation parameters based on a time factor; perform an XOR calculation on the calculation parameters, the device identification code in the device description information, and the device serial number in the device description information to generate a first random key; perform an XOR calculation on the calculation parameters, the device identification code in the device description information, and the device serial number in the device description information to generate a second random key.
[0095] Optionally, the first information verification module 420 can be specifically used to: verify whether the lengths of the first random key and the second random key meet the set length requirements; verify whether the key contents of the first random key and the second random key meet the set specification requirements.
[0096] Optionally, the security management device of the user-side device may further include an analog identification code generation module, which may be specifically configured to: after locking the CPE, generate an analog identification code using a random number generator according to a time factor, and add the analog identification code to the set of legal identification codes;
[0097] The second information verification module 440 can be specifically used to: match the identity identification code with each simulated identification code in the legal identification code set; if there is a simulated identification code consistent with the identity identification code, determine that the identity identification code meets the legal identification code condition.
[0098] Optionally, the security management device of the user-side equipment may also include a function unlocking module, which can be specifically used to: after locking the target SIM, when receiving an unlocking instruction sent by the unlocking party, obtain the unlocking target in the unlocking instruction; obtain the first random key and / or second random key corresponding to the unlocking target; according to the current network status of the CPE, use the first random key and / or the second random key to execute the unlocking instruction to complete the unlocking of the unlocking target.
[0099] Optionally, the function unlocking module can be specifically used for: if the CPE is currently in an online state, generating a target short message based on the first random key and / or the second random key and the unlocking target, and sending the target short message to the CPE using a pre-set control number to complete the unlocking of the unlocking target; if the CPE is currently in an offline state, transmitting the first random key and / or the second random key to the setting unlocking interface to complete the unlocking of the unlocking target.
[0100] The security management device for user-side equipment provided in an embodiment of the present invention can execute the security management method for user-side equipment provided in any embodiment of the present invention, and has functional modules and beneficial effects corresponding to the execution method.
[0101] Example 5
[0102] Figure 5 A schematic diagram of the structure of an electronic device 510 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.
[0103] like Figure 5 As shown, the electronic device 510 includes at least one processor 520 and a memory, such as a read-only memory (ROM) 530, a random access memory (RAM) 540, etc., which is communicatively connected to the at least one processor 520. The memory stores a computer program that can be executed by the at least one processor, and the processor 520 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 530 or the computer program loaded from the storage unit 590 to the random access memory (RAM) 540. Various programs and data required for the operation of the electronic device 510 can also be stored in the RAM 540. The processor 520, ROM 530, and RAM 540 are connected to each other via a bus 550. An input / output (I / O) interface 560 is also connected to the bus 550.
[0104] Multiple components in the electronic device 510 are connected to the I / O interface 560, including an input unit 570, such as a keyboard, a mouse, etc.; an output unit 580, such as various types of displays, speakers, etc.; a storage unit 590, such as a magnetic disk, an optical disk, etc.; and a communication unit 5100, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 5100 allows the electronic device 510 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0105] The processor 520 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the processor 520 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors that run machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 520 executes the various methods and processes described above, such as the security management method for the user-side device.
[0106] The method includes:
[0107] When the user-side device CPE performs a startup process, obtaining device description information of the CPE and an identification area code of the network to which it belongs;
[0108] When it is determined that the device description information meets the legal device conditions and the identification area code matches the authorized area code of the authorized user identity module SIM of the CPE, locking the CPE to control the CPE to access only the authorized SIM;
[0109] When it is determined that the current area code of the target SIM inserted in the CPE is consistent with the authorized area code, obtaining the identity identification code of the target SIM;
[0110] When it is determined that the identity identification code meets the legal identification code condition, the target SIM is locked to control the target SIM to be accessible only to the CPE.
[0111] In some embodiments, the security management method of the user-side device can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 590. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 510 via the ROM 530 and / or the communication unit 5100. When the computer program is loaded into the RAM 540 and executed by the processor 520, one or more steps of the security management method of the user-side device described above can be performed. Alternatively, in other embodiments, the processor 520 can be configured to execute the security management method of the user-side device by any other appropriate means (for example, by means of firmware).
[0112] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0113] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0114] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0115] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0116] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0117] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0118] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0119] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A security management method for user-side equipment, characterized in that: The method comprises: When the user-side device CPE performs a startup process, obtaining device description information of the CPE and an identification area code of the network to which it belongs; When it is determined that the device description information meets the legal device conditions and the identification area code matches the authorized area code of the authorized user identity module SIM of the CPE, locking the CPE to control the CPE to access only the authorized SIM; When it is determined that the current area code of the target SIM inserted in the CPE is consistent with the authorized area code, obtaining the identity identification code of the target SIM; When it is determined that the identity identification code meets the legal identification code condition, the target SIM is locked to control the target SIM to be accessible only to the CPE; After obtaining the device description information of the CPE, the method further includes: Generating a first random key and a second random key based on the device description information; wherein the first random key and the second random key are keys calculated based on the device description information, and the first random key and the second random key are used to complete the authorization screening of the device description information; the first random key and the second random key are different; Verify that the device description meets the requirements for a valid device, including: Determining that the first random key and the second random key meet a legal device condition; The first random key and the second random key are also used when unlocking the CPE or the target SIM.
2. The method according to claim 1, characterized in that Generating a first random key and a second random key according to the device description information respectively includes: Using a random number generator to generate calculation parameters according to the time factor; Performing an XOR calculation on the calculation parameter, the device identification code in the device description information, and the device serial number in the device description information to generate a first random key; Perform an XOR operation on the calculation parameter, the device identification code in the device description information, and the device serial number in the device description information to generate a second random key.
3. The method according to claim 1, characterized in that Determining that the first random key and the second random key meet a legal device condition includes: Verify whether the lengths of the first random key and the second random key meet the set length requirements; Verify whether the key contents of the first random key and the second random key meet the set specification requirements.
4. The method according to claim 1, wherein After locking the CPE, the method further includes: Generate a simulated identification code using a random number generator according to a time factor, and add the simulated identification code to the set of legal identification codes; Determining that the identity identification code meets the legal identification code conditions includes: Matching the identity identification code with each simulated identification code in the set of legitimate identification codes; If there is a simulated identification code that is consistent with the identity identification code, it is determined that the identity identification code meets the legal identification code condition.
5. The method according to claim 1, wherein After locking the target SIM card, the following steps are also included: When receiving an unlocking instruction sent by the unlocking party, obtaining the unlocking target in the unlocking instruction; Obtaining a first random key and / or a second random key corresponding to the unlocking target; According to the current networking status of the CPE, the unlocking instruction is executed using the first random key and / or the second random key to complete the unlocking of the unlocking target.
6. The method according to claim 5, characterized in that According to the current network status of the CPE, executing an unlock instruction using the first random key and / or the second random key to complete unlocking the unlock target includes: If the CPE is currently in a networked state, a target short message is generated according to the first random key and / or the second random key and the unlocking target, and the target short message is sent to the CPE using a preset control number to complete unlocking the unlocking target; If the CPE is currently in an offline state, the first random key and / or the second random key is transmitted to the setting unlock interface to complete the unlocking of the unlocking target.
7. A security management device for user-side equipment, characterized in that: include: A first information acquisition module is configured to acquire device description information of a user-side device CPE and an identification area code of a network to which the CPE belongs when the CPE performs a startup process; a first information verification module, configured to lock the CPE when determining that the device description information satisfies the legal device condition and the identification area code matches the authorized area code of the authorized user identity module SIM of the CPE, so as to control the CPE to only be able to access the authorized SIM; a second information acquisition module, configured to acquire an identity identification code of the target SIM card inserted in the CPE when determining that the current area code of the target SIM card is consistent with the authorized area code; A second information verification module is configured to lock the target SIM card when determining that the identity identification code satisfies the legal identification code condition, so as to control the target SIM card to be accessible only to the CPE; The security management device of the user-side device further includes a key generation module, specifically configured to: after obtaining the device description information of the CPE, generate a first random key and a second random key according to the device description information; wherein the first random key and the second random key refer to keys calculated according to the device description information, and the first random key and the second random key are used to complete authorization screening of the device description information; the first random key and the second random key are different; The first information verification module is specifically used to: determine whether the first random key and the second random key meet the legal device condition; wherein, the first random key and the second random key are also used to unlock the CPE or the target SIM.
8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the security management method for the user-side device according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the security management method for a user-side device according to any one of claims 1 to 6 when executed.
Citation Information
Patent Citations
Data access method used for CPE (central processing element) and CPE
CN101801059A
Method, system and home subscriber server for obtaining access point name
CN103476019A