An access control method and a communication device based on SIM card information

Through the access control method based on SIM card information, the problem of high IP address consumption and terminal devices being unable to actively enter username and password in enterprise private network access control is solved, and refined access control and management are simplified.

CN115426139BActive Publication Date: 2025-06-24HUAWEI TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210975253.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-11-19
Filing Date
2022-08-15
Publication Date
2025-06-24
Estimated Expiration
2042-08-15

AI Technical Summary

Technical Problem

When the prior art realizes access control of enterprise private networks, there are problems such as high consumption of static IP addresses, complex management, and the inability to actively enter usernames and passwords in the Internet of Things environment.

Method used

The access control method based on SIM card information is adopted to receive access requests from the terminal device through a firewall or a billing forwarding device, convert the IP address to SIM card information, and access control is performed according to the associated access control policy.

Benefits of technology

It realizes differentiated and refined access control of enterprise private network terminal devices, reduces IP address consumption, simplifies the management process, and is suitable for the Internet of Things environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115426139B_ABST
    Figure CN115426139B_ABST
Patent Text Reader

Abstract

The present application provides an access control method and a communication device based on SIM card information. The method includes: a firewall in an enterprise private network receives an access request from a terminal device, and the access request includes the IP address of the terminal device; the firewall determines the SIM card information corresponding to the IP address, and then performs access control on the access request according to the access control policy associated with the SIM card information. Since the SIM card information is bound to each terminal device, based on the SIM card information, differentiated and refined access control can be implemented for the terminal devices within the enterprise private network.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - Reference to Related Applications

[0002] This application claims the priority of a Chinese patent application with an application number of 202111375766.4 and an invention title of "An Access Control Method and Communication Device Based on IMSI Information" filed with the National Intellectual Property Administration of the People's Republic of China on November 19, 2021, the entire content of which is incorporated herein by reference. Technical Field

[0003] This application relates to the field of wireless communication technologies, and in particular, to an access control method and a communication device based on subscriber identity module (SIM) card information. Background Art

[0004] To meet network requirements such as higher bandwidth, lower latency, more flexible and rapid service deployment, and massive connections, multi-access edge computing (MEC) technology has emerged. MEC technology can move computing and storage resources to the network edge closer to users, and perform local traffic splitting by deploying edge user plane function network elements, thereby achieving lower latency.

[0005] For the MEC enterprise private network scenario, enterprises usually need to deploy a firewall at the entrance of the enterprise private network for network access control. Since the terminal devices accessing the enterprise private network have various types (such as terminals and cameras in industrial control), and need to access different application services within the enterprise private network, enterprises need to implement access control policies based on the types of terminal devices.

[0006] To achieve the above purpose, a solution in the prior art is to apply for a static Internet Protocol (IP) address for each terminal device. This solution is expensive, the configuration scheme is not easy to change, the management difficulty is relatively large, and with the expansion of the application scope of the enterprise private network, it will cause a large consumption of the operator's IP addresses. Another solution is to enable user authentication on the firewall of the enterprise private network, and obtain access rights by allowing users to input user names and passwords. In this solution, no matter which authentication method is adopted, generally, the terminal device needs to actively input the user name and password. In some Internet of Things environments, the terminal device is usually a dedicated device and may not have the condition to actively input the user name and password, so the application of this solution is relatively limited. Summary of the Invention

[0007] This application provides an access control method and a communication device based on SIM card information, which are used to implement differentiated and refined access control for terminal devices in an enterprise private network.

[0008] In a first aspect, an embodiment of this application provides an access control method based on SIM card information. This method can be executed by a firewall in an enterprise private network or by a component (such as a chip or a circuit) configured in the firewall. The firewall can perform access control on an access request from a terminal device to an application service in the enterprise private network, thereby protecting the security of the enterprise private network.

[0009] The method includes: The firewall in the enterprise private network receives an access request from a terminal device, and the access request includes the IP address of the terminal device; the firewall determines the SIM card information corresponding to the IP address; the firewall performs access control on the access request according to the access control policy associated with the SIM card information.

[0010] In the above technical solution, the firewall in the enterprise private network can perform effective access control on an access request from a terminal device to an application service in the enterprise private network according to the SIM card information. Among them, when the firewall receives an access request from a terminal device, it can convert the IP address in the access request into the corresponding SIM card information, and then perform access control.

[0011] Among them, the SIM card is an IC card held by a mobile user in a mobile communication system, called a user identification card. Therefore, a SIM card information can be bound to a terminal device one by one (the SIM card can be replaced on different devices). In view of this, in practical applications, the identity of a terminal device can be identified according to the SIM card information, and the type of a terminal device can also be indirectly known. In actual applications, the IP address may be dynamically allocated as needed, that is, the IP address may be a dynamic IP address, and this dynamic IP address is bound to a protocol data unit (PDU) session of the terminal device. However, the identity, type, and other inherent attribute information of the terminal device may not be obtained according to this dynamic IP address. Thus, in this application, the IP address in the access request is first converted into the SIM card information of the terminal device, and then access control is performed, which helps to implement differentiated and refined access control according to the identity, type, and other information of the terminal device, thereby protecting the information security in the enterprise private network.

[0012] In a possible design, the method further includes: The firewall receives the SIM card information and the IP address of the terminal device from a charging forwarding device or a session management function network element in the enterprise private network; the firewall establishes a mapping relationship between the SIM card information and the IP address, and then the firewall can determine the SIM card information corresponding to the IP address according to this mapping relationship.

[0013] In the above technical solution, the SIM card information and the IP address of the terminal device can be a charging and forwarding device in the enterprise private network. For example, after the terminal device passes the operator authentication, the Authentication, Authorization, and Accounting (AAA) server sends them to the firewall. The firewall can establish a mapping relationship between the two based on the received information, and then, when receiving an access request from the terminal device, perform the conversion from the IP address to the SIM card information according to the mapping relationship, so as to support subsequent access control.

[0014] In a possible design, the access request includes the application service to be accessed; the access control policy includes the application services within the enterprise private network that allow the terminal device corresponding to the SIM card information to access, and / or, the application services within the enterprise private network that do not allow the terminal device corresponding to the SIM card information to access; thus, the firewall performs access control on the access request according to the access control policy associated with the SIM card information, including: if the application service to be accessed is an application service within the enterprise private network that allows the terminal device corresponding to the SIM card information to access, then allow the access request, otherwise block the access request.

[0015] In the above technical solution, the firewall can promptly release reasonable access requests and block unreasonable access requests according to the corresponding access control policy, thereby protecting the information security in the enterprise private network.

[0016] In a possible design, the method further includes: the firewall stores associated configuration information, and the associated configuration information includes the access control policy associated with each SIM card information within the enterprise private network.

[0017] In the above technical solution, an associated access control policy can be set for each SIM card information within the enterprise private network, for example, set according to the type or role of the terminal device bound to the SIM card information, etc., so as to effectively improve the accuracy of access control.

[0018] In a second aspect, an embodiment of the present application provides an access control method based on SIM card information. This method can be executed by a charging and forwarding device in the enterprise private network, or by a component (such as a chip or a circuit) configured in the charging and forwarding device. The charging and forwarding device can be used to perform authentication, authorization, and accounting on the terminal device accessing the enterprise private network, and support the firewall in the enterprise private network to perform access control.

[0019] The method includes: after a terminal device passes operator authentication in an enterprise private network, a charging forwarding device receives charging information from a session management function network element; the charging forwarding device sends the SIM card information and IP address of the terminal device to a firewall in the enterprise private network, where the SIM card information and the IP address are obtained according to the charging information.

[0020] In a possible design, the charging forwarding device sending the SIM card information and IP address of the terminal device to the firewall in the enterprise private network may be: the charging forwarding device converts the formats of the SIM card information and IP address in the charging information, and sends the charging information after format conversion to the firewall, where the SIM card information in the charging information after format conversion may be located in the user name field.

[0021] In a possible design, the charging forwarding device in the enterprise private network receives charging information from a session management function network element through a charging protocol, and the charging protocol is a Remote Authentication Dial-In User Service (RADIUS) protocol or a Diameter protocol.

[0022] In a third aspect, an embodiment of the present application provides a communication device, which may have a function of implementing the firewall in the first aspect above, or may also have a function of implementing the charging forwarding device in the second aspect above. The communication device may be a network device or a chip included in a network device.

[0023] The function of the communication device may be implemented by hardware or by hardware executing corresponding software, and the hardware or software includes one or more modules or units or means corresponding to the above functions.

[0024] In a possible design, the structure of the communication device includes a processing module and a transceiver module. The processing module is configured to support the communication device to execute the corresponding functions of the firewall in the first aspect above. The transceiver module is used to support communication between the communication device and other communication devices. For example, when the communication device is a firewall, the transceiver module may receive an access request from a terminal device. The communication device may further include a storage module, and the storage module is coupled to the processing module. Necessary program instructions and data of the communication device are stored in the storage module. As an example, the processing module may be a processor, the communication module may be a transceiver, and the storage module may be a memory. The memory may be integrated with the processor or may be separately provided from the processor.

[0025] In another possible design, the structure of the communication device includes a processor and may further include a memory. The processor is coupled to the memory and can be used to execute the computer program instructions stored in the memory, so that the communication device executes the method in any one of the possible designs in the first aspect or the second aspect above. Optionally, the communication device further includes a communication interface, and the processor is coupled to the communication interface. When the communication device is a network device, the communication interface can be a transceiver or an input / output interface; when the communication device is a chip included in a network device, the communication interface can be the input / output interface of the chip. Optionally, the transceiver can be a transceiver circuit, and the input / output interface can be an input / output circuit.

[0026] In a fourth aspect, an embodiment of the present application provides a chip system, including: a processor, where the processor is coupled to a memory, and the memory is used to store programs or instructions. When the programs or instructions are executed by the processor, the chip system implements the method in any one of the possible designs in the first aspect or the second aspect above.

[0027] Optionally, the chip system may further include an interface circuit, and the interface circuit is used to interact code instructions from the memory to the processor.

[0028] Optionally, the processor in the chip system can be one or more, and the processor can be implemented by hardware or by software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented by software, the processor can be a general-purpose processor, which is implemented by reading the software code stored in the memory.

[0029] Optionally, the memory in the chip system can also be one or more. The memory can be integrated with the processor or can be separately arranged from the processor. Exemplarily, the memory can be a non-transitory processor, such as a read-only memory ROM, which can be integrated with the processor on the same chip or can be separately arranged on different chips.

[0030] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, on which computer programs or instructions are stored. When the computer programs or instructions are executed, the method in any one of the possible designs in the first aspect or the second aspect above is executed.

[0031] In a sixth aspect, an embodiment of the present application provides a computer program product. When the communication device executes the computer program product, the communication device executes the method in any one of the possible designs in the first aspect or the second aspect above.

[0032] In a seventh aspect, an embodiment of the present application provides a communication system, which includes a firewall and a charging forwarding device in an enterprise private network. The communication system may further include a terminal device. Optionally, the communication system may further include a session management function network element, an access and mobility management function network element, a user plane function network element, and a radio access network device in a public network. The terminal device can access the public network or the above-mentioned enterprise private network, for example, to request access to certain application services in the enterprise private network.

[0033] Specifically, the charging forwarding device is configured to, after the terminal device passes the operator authentication, receive charging information from the session management function network element, and send the user identity identification SIM card information and IP address of the terminal device to the firewall, where the SIM card information and the IP address are obtained according to the charging information;

[0034] The firewall is configured to receive the SIM card information and the IP address of the terminal device from the charging forwarding device, and establish a mapping relationship between the SIM card information and the IP address;

[0035] The firewall is further configured to receive an access request from the terminal device, where the access request includes the IP address of the terminal device, and determine the SIM card information corresponding to the IP address according to the mapping relationship, and perform access control on the access request according to the access control policy associated with the SIM card information.

[0036] In a possible design, the access request includes the application service to be accessed; the access control policy includes the application services within the enterprise private network that allow the terminal device corresponding to the SIM card information to access, and / or, the application services within the enterprise private network that do not allow the terminal device corresponding to the SIM card information to access; specifically, the firewall is configured to: if the application service to be accessed is an application service that allows the terminal device corresponding to the SIM card information to access, then allow the access request, otherwise block the access request.

[0037] In a possible design, the firewall stores associated configuration information, and the associated configuration information includes the access control policy associated with each SIM card information within the enterprise private network.

[0038] In a possible design, the charging forwarding device is specifically configured to: receive the charging information from the session management function network element through a charging protocol, and the charging protocol is a Remote Authentication Dial-In User Service (RADIUS) protocol or a Diameter protocol.

[0039] The technical effects that can be achieved by any one of the second to sixth aspects described above can refer to the technical effects that can be achieved by any possible design in the first aspect or any possible design in the second aspect above. Repeated parts will not be elaborated. Description of the Drawings

[0040] Figure 1 Schematic diagram of the network architecture of a communication system applicable to the embodiments of the present application;

[0041] Figure 2 An application scenario applicable to the embodiments of the present application;

[0042] Figure 3 Schematic flowchart of an access control method based on SIM card information provided by the embodiments of the present application;

[0043] Figure 4 Schematic diagram of the structure of a communication device provided by the embodiments of the present application;

[0044] Figure 5 Schematic diagram of the structure of a communication device provided by the embodiments of the present application. Detailed Description of the Embodiments

[0045] The embodiments of the present application will be further described in detail below with reference to the drawings.

[0046] Figure 1 An exemplary network architecture of a communication system applicable to the embodiments of the present application is shown as Figure 1As shown in the figure, the network architecture includes a terminal device, an operator core network, and an MEC network deployed in an enterprise park (the operator core network includes a session management function (SMF) network element, which is responsible for the session control function of enterprise terminals accessing the enterprise private network, such as the establishment, release, and update of a user's protocol data unit (PDU) session. The MEC network may include a radio access network device and a user plane function (UPF) network element. The radio access network device is responsible for connecting enterprise terminals to the operator network, and the UPF network element is responsible for the connection function of enterprise terminals accessing the enterprise private network. The UPF network element is deployed in the enterprise park and is managed by the operator), a firewall (FW), and server devices for implementing the deployment of one or more enterprise applications (such as enterprise applications 1, 2, N in the figure). A charging forwarding device may also be included. Among them, the charging forwarding device may be an enterprise authentication, authorization, and accounting (AAA) server, and the enterprise AAA server can be used to authenticate enterprise terminals and forward relevant information of the terminal device to the firewall deployed in the enterprise private network. The firewall is responsible for performing role-based and refined access control on the terminal devices accessing the enterprise private network.

[0047] The above-mentioned SMF can be integrated with the charging forwarding device into a module to perform corresponding operations. The charging forwarding device can also be integrated with the firewall into a module to perform corresponding operations. The UPF can be integrated with the firewall into a module to perform corresponding operations. In addition, the above-mentioned operator core network and MEC network can be set in the operator-side network, and the charging forwarding device, firewall, and enterprise applications can be set in the enterprise-side network. Of course, in actual applications, the charging forwarding device and firewall can also be set in the operator-side network, and this application does not specifically limit this here.

[0048] Among them, the operator-side network can also be referred to as the operator network or the public network, and the enterprise-side network can also be referred to as the enterprise private network, enterprise intranet, campus network, or non-public network.

[0049] Among them, the terminal device can also be referred to as a user equipment (UE), mobile station, mobile terminal, etc. The terminal device can be widely applied to various scenarios, such as device-to-device (D2D), vehicle to everything (V2X) communication, machine-type communication (MTC), Internet of Things (IoT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grid, smart home, smart office, smart wearables, smart transportation, smart city, etc. The terminal device can be a mobile phone, tablet computer, computer with wireless transceiver function, wearable device, vehicle, drone, helicopter, airplane, ship, robot, robotic arm, smart home device, etc. This application does not limit the specific technologies and specific device forms adopted by the terminal device.

[0050] The radio access network device can be a base station, evolved NodeB (eNodeB), transmission reception point (TRP), next generation NodeB (gNB) in a 5G mobile communication system, next generation base station in a 6G mobile communication system, base station in a future mobile communication system, or access node in a wireless fidelity (WiFi) system, etc.; it can also be a module or unit that completes part of the base station functions. For example, it can be a central unit (CU) or a distributed unit (DU). The radio access network device can be a macro base station, a micro base station or an indoor station, and can also be a relay node or a donor node, etc. This application does not limit the specific technologies and specific device forms adopted by the radio access network device.

[0051] It should be noted that the above network elements or functions can be network elements in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (such as a cloud platform). Optionally, the above network elements or functions can be implemented by one device, jointly implemented by multiple devices, or can also be a functional module within a device. This application does not make specific limitations on this.

[0052] It should also be understood that the session management function network element and user plane function network element in this application can be respectively Figure 1The SMF and UPF herein may also be network elements with the functions of the above-mentioned SMF and UPF in future communications such as 6G networks, which is not limited in this application. For the convenience of description, in the embodiments of this application, the SMF and UPF will be used as an example of a session management function network element and a user plane function network element respectively to introduce the technical solutions provided by this application.

[0053] Figure 2 Exemplarily shows a possible application scenario of the embodiments of this application, such as Figure 2 As shown, the terminal devices accessing the enterprise private network have different types, play different roles, and may need to access different application services within the enterprise private network. For example, the terminal devices may include cameras, industrial control terminals, virtual reality terminals, driverless terminals, Internet of Things terminals, and so on. Enterprises often need to set different access control policies for these accesses. For example, for terminal device 1 (such as a camera), only access to App1 (video server) is allowed, and access to App2 (production server) is not allowed.

[0054] Figure 3 Exemplarily shows an access control method based on SIM card information provided by the embodiments of this application. This method can be executed through data interaction among the terminal device, the SMF, and the firewall. Of course, in actual applications, when there are multiple firewalls, it can also be executed through data interaction with the charging and forwarding device, such as Figure 3 As shown, this method includes:

[0055] Step 301, after the terminal device passes the operator authentication, the charging and forwarding device receives the charging information from the SMF network element.

[0056] Step 302, the charging and forwarding device sends the SIM card information and IP address of the terminal device to the firewall in the enterprise private network, and the SIM card information and IP address are obtained according to the charging information.

[0057] Correspondingly, the firewall receives the SIM card information and IP address of the terminal device from the charging and forwarding device.

[0058] Taking the scenario of building an enterprise private network using MEC technology in a 5G network as an example, the terminal device can initiate a request to access the enterprise private network after accessing the 5G network. The SMF network element in the 5G network can receive this request and authenticate the terminal device to confirm whether the terminal device can access the enterprise network.

[0059] Furthermore, the SMF network element may send charging information to a charging forwarding device or a firewall based on a charging protocol. This charging information is used to charge the terminal device and meet other statistical requirements. The charging protocol may be the Remote Authentication Dial-In User Service (RADIUS) protocol or the Diameter protocol, which is not limited. The charging information may include the SIM card information and the IP address of the terminal device. The SIM card information refers to the identification information of the SIM card installed in the terminal device. Different terminal devices (or different SIM cards) have different SIM card information. The IP address refers to the IP address assigned by the SMF network element to the terminal device after the authentication of the terminal device is passed as mentioned above.

[0060] Subsequently, the charging forwarding device may forward the SIM card information and the IP address of the terminal device in the charging information to the firewall. It should be noted that the format and requirements of the information when the SMF and the charging forwarding device interact with each other cannot be directly recognized by the firewall. If the charging forwarding device directly transparently forwards the charging information received from the SMF network element to the firewall, it may cause the firewall to be unable to correctly interpret the SIM card information and the IP address in the charging information, and thus unable to perform effective network access control. Therefore, in order to facilitate the firewall to interpret the information, the charging forwarding device may perform conversion processing on the format and requirements of the SIM card information and the IP address in the charging information to become the format and requirements that the firewall can interpret, and then forward it to the firewall. For example, the charging forwarding device may fill the SIM card information into the user name of the charging information.

[0061] Step 303, the firewall establishes a mapping relationship between the SIM card information and the IP address of the terminal device.

[0062] In this application, the firewall may store associated configuration information, and the associated configuration information includes the access control policy associated with each SIM card information within the enterprise private network. That is, this application may set an associated access control policy for each SIM card information within the enterprise private network and generate corresponding associated configuration information. It should be noted that the associated configuration information may be generated and configured in the firewall by the firewall, or may be generated by other network elements (such as the charging forwarding device, the management plane OAM network element, etc. in the enterprise private network) and then notified to the firewall. This application does not make specific limitations.

[0063] It should be noted that when setting the access control policy associated with the SIM card information in this application, the type or role of the terminal device corresponding to the SIM card information can be considered. For example, certain types of terminal devices are controlled to allow access to a certain type of application service, while other types of terminal devices are not allowed to access this type of application service, so as to achieve refined access control based on the terminal type or role. In this way, when the firewall receives an access request from a terminal device for a certain application service within the enterprise private network, the firewall can map the IP address carried in the access request to the SIM card information according to this mapping relationship, and then perform access control on this access according to the access control policy associated with the SIM card information. This process will be described in detail in the following steps 304 to 306.

[0064] Step 304, the firewall receives an access request from the terminal device, and the access request includes the IP address of the terminal device.

[0065] Exemplarily, the access request includes information such as the source IP address, destination IP address, source port number, destination port number, protocol type, etc., and the IP address of the terminal device refers to the source IP address in the access request.

[0066] Step 305, the firewall determines the SIM card information corresponding to the IP address of the terminal device in the access request according to the above mapping relationship.

[0067] Step 306, the firewall performs access control on the access request according to the access control policy associated with the SIM card information.

[0068] Exemplarily, the access request may include the application service requested by the terminal device to access. For example, the access request may carry some information related to the application service requested by the terminal device to access (such as protocol type, destination IP address, destination port number, etc.). In this way, the firewall can determine which application services the terminal device requests to access according to the information such as protocol type, destination IP address, destination port number, etc. carried in the access request. The access control policy associated with the SIM card information may include: one or more application services within the enterprise private network that allow the terminal device corresponding to the SIM card information to access, and / or, one or more application services within the enterprise private network that do not allow the terminal device corresponding to the SIM card information to access. In this way, the firewall performs access control on the access request of the terminal device according to the access control policy associated with the SIM card information, which can be: if the application service requested by the terminal device to access is an application service within the enterprise internal network that allows the terminal device corresponding to the SIM card information to access, then allow the access request (for example, continue to forward the access request to the corresponding application server), otherwise block the access request.

[0069] In the enterprise private network scenario based on MEC, in the above technical solution, an enterprise can set a reasonable access control policy for the SIM card information corresponding to a terminal device in a firewall according to the type or role of the terminal device. After the terminal device completes authentication, the SMF can transmit the mapping relationship between the IP address of the terminal device and the SIM card information to the firewall, so that the firewall can perform refined access control on the access of the terminal device to the enterprise private network based on the SIM card information and the pre-set access control policy.

[0070] The above technical solution also has the following beneficial effects: First, there is no need to bind the terminal device to a static IP address, reducing the consumption of IP addresses by the operator. Second, there is no need for the terminal device to input a username and password, and the applicable scenarios are more extensive, especially in the Internet of Things scenario where the capabilities of terminal devices are limited. Third, it can reduce the complexity of coordination and cooperation between the operator and the enterprise.

[0071] The embodiment of the present application also provides a communication device. Please refer to Figure 4 , which is a schematic structural diagram of a communication device provided by the embodiment of the present application. The communication device 400 includes a transceiver module 410 and a processing module 420. The communication device can be used to implement the functions of the firewall in the enterprise private network in the above method embodiment, or can be used to implement the functions of the authentication, authorization, and accounting (AAA) server in the enterprise private network in the above method embodiment. The communication device can be a network device, or a device that can support a network device to implement the corresponding functions in the above method embodiment (such as a chip included in a network device), etc.

[0072] Exemplarily, when the communication device executes Figure 3 the operations or steps corresponding to the firewall in the enterprise private network in the method embodiment shown, the transceiver module 410 is used to receive an access request from a terminal device, and the access request includes the IP address of the terminal device; the processing module 420 is used to determine the international mobile subscriber identity (SIM) card information corresponding to the IP address, and perform access control on the access request according to the access control policy associated with the SIM card information.

[0073] In a possible design, the transceiver module 410 is further used to: receive the SIM card information and the IP address of the terminal device from a charging forwarding device in the enterprise private network; the processing module 420 is further used to establish a mapping relationship between the SIM card information and the IP address, and determine the SIM card information corresponding to the IP address according to the mapping relationship.

[0074] In a possible design, the access request includes an application service for which access is requested; the access control policy includes application services within the enterprise private network that allow the terminal device corresponding to the SIM card information to access, and / or application services within the enterprise private network that do not allow the terminal device corresponding to the SIM card information to access; the processing module 420 is specifically configured to: perform access control on the access request according to the access control policy associated with the SIM card information, including: if the application service for which access is requested is an application service within the enterprise private network that allows the terminal device corresponding to the SIM card information to access, then allow the access request; otherwise, block the access request.

[0075] In a possible design, the processing module stores association configuration information, and the association configuration information includes access control policies associated with each SIM card information within the enterprise private network.

[0076] Exemplarily, when the communication device executes Figure 3 the operations or steps corresponding to the charging forwarding device in the enterprise private network in the method embodiment shown, the transceiver module 410 is configured to receive charging information from the session management function network element after the terminal device passes authentication; the processing module 420 is configured to send the international mobile subscriber identity SIM card information and IP address of the terminal device to the firewall in the enterprise private network through the transceiver module 410, and the SIM card information and the IP address are obtained according to the charging information.

[0077] In a possible design, the transceiver module 410 is specifically configured to receive the charging information from the session management function network element through a charging protocol, and the charging protocol is a Remote Authentication Dial-In User Service (RADIUS) protocol or a Diameter protocol.

[0078] The processing module 420 involved in the communication device may be implemented by at least one processor or processor-related circuit components, and the transceiver module 410 may be implemented by at least one transceiver or transceiver-related circuit components or a communication interface. The operations and / or functions of each module in the communication device are respectively for implementing Figure 3 the corresponding processes of the method shown, and for the sake of brevity, they will not be elaborated here. Optionally, the communication device may further include a storage module, and the storage module may be used to store data and / or instructions. The transceiver module 410 and / or the processing module 420 may read the data and / or instructions in the access module, so that the communication device implements the corresponding method. The storage module may be implemented by at least one memory, for example.

[0079] The above storage module, processing module, and transceiver module can exist separately, or all or some of the modules can be integrated. For example, the storage module and the processing module can be integrated, or the processing module and the transceiver module can be integrated, etc.

[0080] Please refer to Figure 5 , which is another structural schematic diagram of a communication device provided in an embodiment of the present application. This communication device can be used to implement the functions corresponding to the firewall in the enterprise private network in the above method embodiment, or can be used to implement the functions of the billing forwarding device in the enterprise private network in the above method embodiment. This communication device can be a network device or a device that can support a network device to implement the corresponding functions in the above method embodiment (such as a chip included in a network device), etc.

[0081] The communication device 500 may include a processor 501 and a memory 502. Among them, the memory 502 is used to store program instructions and / or data, and the processor 501 is used to execute the program instructions stored in the memory 502, so as to implement the method in the above method embodiment.

[0082] Optionally, the memory 502 and the processor 501 are coupled. The coupling is an indirect coupling or communication connection between devices, units, or modules, which can be electrical, mechanical, or other forms, and is used for information interaction between devices, units, or modules.

[0083] Optionally, the communication device 500 may further include a communication interface 503. The communication interface 503 is used to communicate with other devices through a transmission medium. For example, the signal received from other communication devices is transmitted to the processor 501, or the signal from the processor 501 is transmitted to other communication devices. The communication interface 503 can be a transceiver or an interface circuit, such as a transceiver circuit or a transceiver chip.

[0084] In one embodiment, the communication interface 503 can specifically be used to perform the actions of the above transceiver module 410, and the processor 501 can specifically be used to perform the actions of the above processing module 420. This application will not elaborate here.

[0085] In the embodiments of the present application, the specific connection medium between the above processor 501, memory 502, and communication interface 503 is not limited. In the embodiments of the present application Figure 5 it is shown that the processor 501, memory 502, and communication interface 503 are connected through a bus 504. The bus is represented by a thick line in Figure 5 The connection manners between other components are only for illustrative purposes and are not to be construed as limiting. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity of representation, Figure 5 only a thick line is used to represent it in

[0086] An embodiment of the present application further provides a chip system, including: a processor, the processor is coupled to a memory, and the memory is used to store programs or instructions. When the programs or instructions are executed by the processor, the chip system implements the method corresponding to the firewall in the enterprise private network in the above method embodiment, or implements the method corresponding to the charging forwarding device in the enterprise private network in the above method embodiment.

[0087] Optionally, the processor in the chip system can be one or more. The processor can be implemented by hardware or by software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented by software, the processor can be a general-purpose processor, which is implemented by reading the software code stored in the memory.

[0088] Optionally, the memory in the chip system can also be one or more. The memory can be integrated with the processor or can be separately arranged from the processor, which is not limited in the present application. Exemplarily, the memory can be a non-transitory processor, such as a read-only memory (ROM), which can be integrated with the processor on the same chip or can be separately arranged on different chips. The present application does not specifically limit the type of the memory and the setting manner of the memory and the processor.

[0089] Exemplarily, the chip system can be a field programmable gate array (FPGA), can be an application specific integrated circuit (ASIC), can also be a system on chip (SoC), can also be a central processing unit (CPU), can also be a network processor (NP), can also be a digital signal processing circuit (DSP), can also be a microcontroller unit (MCU), can also be a programmable logic device (PLD) or other integrated chips.

[0090] It should be understood that each step in the above method embodiment can be completed by the integrated logic circuit in the hardware of the processor or by the instructions in the form of software. The method steps disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware processor, or can be executed and completed by the combination of the hardware and software modules in the processor.

[0091] The embodiments of the present application further provide a computer-readable storage medium. A computer program or instruction is stored in the computer storage medium. When the computer program or instruction is executed, a communication device is caused to execute the method in the above method embodiment.

[0092] The embodiments of the present application further provide a computer program product. When a communication device reads and executes the computer program product, the communication device is caused to execute the method in the above method embodiment.

[0093] The embodiments of the present application further provide a communication system. The communication system includes a firewall and an Authentication, Authorization, and Accounting (AAA) server in an enterprise private network. The communication system may further include a terminal device. Optionally, the communication system may further include a Session Management Function (SMF) network element, an Access and Mobility Management Function (AMF) network element, a User Plane Function (UPF) network element, and a Radio Access Network (RAN) device in a public network. The terminal device may access the public network or the above enterprise private network, for example, to request access to certain application services in the enterprise private network. The above network elements or functional entities may cooperate with each other to implement the method in the above method embodiment.

[0094] It should be understood that the processor mentioned in the embodiments of the present application may be a CPU, or may also be other general-purpose processors, DSPs, ASICs, FPGAs, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0095] It should also be understood that the memory mentioned in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a ROM, a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).

[0096] It should be noted that when the processor is a general-purpose processor, a DSP, an ASIC, an FPGA, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, the memory (storage module) is integrated in the processor.

[0097] It should be noted that the memory described herein is intended to include, but not be limited to, these and any other suitable types of memory.

[0098] It should be understood that the various digital numbers involved in the various embodiments of the present application are only for the convenience of description and distinction. The magnitude of the serial numbers of the above processes or steps does not mean the order of execution. The order of execution of each process or step should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0099] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in connection with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled professionals may use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0100] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0101] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0102] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0103] In addition, the functional units in each embodiment of this application can be integrated in one processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0104] When the above-mentioned function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs.

[0105] In various embodiments of this application, if there is no special explanation and logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced to each other. The technical features in different embodiments can be combined to form new embodiments according to their internal logical relationships.

Claims

1. An access control method based on SIM card information, which is applied to building an enterprise private network using multi-access edge computing (MEC) technology, is characterized in that The method includes: A firewall in the enterprise private network receives an access request from a terminal device, and the access request includes the Internet Protocol (IP) address of the terminal device. The firewall determines the Subscriber Identity Module (SIM) card information corresponding to the IP address. The firewall performs access control on the access request according to the access control policy associated with the SIM card information.

2. The method according to claim 1, characterized in that, The method further includes: The firewall receives the SIM card information and the IP address of the terminal device from a charging forwarding device or a Session Management Function (SMF) in the enterprise private network. The firewall establishes a mapping relationship between the SIM card information and the IP address. The firewall determines the SIM card information corresponding to the IP address, including: The firewall determines the SIM card information corresponding to the IP address according to the mapping relationship.

3. The method according to claim 1 or 2, characterized in that, The access request includes the application service requested to be accessed. The access control policy includes the application services within the enterprise private network that allow the terminal device corresponding to the SIM card information to access, and / or, the application services within the enterprise private network that do not allow the terminal device corresponding to the SIM card information to access. The firewall performs access control on the access request according to the access control policy associated with the SIM card information, including: If the application service requested to be accessed is an application service within the enterprise private network that allows the terminal device corresponding to the SIM card information to access, the firewall allows the access request; otherwise, the firewall blocks the access request.

4. The method according to any one of claims 1 to 3, characterized in that, The method further includes: The firewall stores associated configuration information, and the associated configuration information includes the access control policy associated with each SIM card information within the enterprise private network.

5. An access control method for SIM card information, which is applied to the construction of an enterprise private network using multi-access edge computing (MEC) technology, is characterized in that, The method includes: A charging forwarding device in the enterprise private network receives charging information from a Session Management Function (SMF) after the terminal device passes the operator authentication. The charging forwarding device in the enterprise private network sends the Subscriber Identity Module (SIM) card information and the Internet Protocol (IP) address of the terminal device to multiple firewalls in the enterprise private network, and the SIM card information and the IP address are obtained according to the charging information.

6. The method according to claim 5, characterized in that, The charging forwarding device in the enterprise private network receives charging information from a Session Management Function (SMF), including: The charging forwarding device in the enterprise private network receives charging information from a Session Management Function (SMF) through a charging protocol, and the charging protocol is a Remote Authentication Dial-In User Service (RADIUS) protocol or a Diameter protocol.

7. A communication device, characterized in that, The communication device is deployed in the enterprise private network, and the communication device includes: A transceiver module, configured to receive an access request from a terminal device, where the access request includes the Internet Protocol (IP) address of the terminal device. A processing module, configured to determine the Subscriber Identity Module (SIM) card information corresponding to the IP address. The processing module is further configured to perform access control on the access request according to the access control policy associated with the SIM card information.

8. The device according to claim 7, wherein The transceiver module is further configured to: Receive the SIM card information and the IP address of the terminal device from the charging forwarding device or the session management function network element in the enterprise private network; The processing module is further configured to: establish a mapping relationship between the SIM card information and the IP address, and determine the SIM card information corresponding to the IP address according to the mapping relationship.

9. The device according to claim 7 or 8, characterized in that, The access request includes the application service requested to be accessed. The access control policy includes the application services within the enterprise private network that allow the terminal device corresponding to the SIM card information to access, and / or the application services within the enterprise private network that do not allow the terminal device corresponding to the SIM card information to access; The processing module is specifically configured to: If the application service requested to be accessed is an application service within the enterprise private network that allows the terminal device corresponding to the SIM card information to access, then allow the access request; otherwise, block the access request.

10. The device according to any one of claims 7 to 9, characterized in that The communication device stores associated configuration information, and the associated configuration information includes the access control policy associated with each SIM card information within the enterprise private network.

11. A communication device, characterized in that, The communication device is deployed in the enterprise private network, and the communication device includes: A transceiver module, configured to receive charging information from a session management function network element after the terminal device passes the operator authentication; A processing module, configured to send the user identification SIM card information and the IP address of the terminal device to a firewall in the enterprise private network through the transceiver module, where the SIM card information and the IP address are obtained according to the charging information.

12. The device according to claim 11, wherein The transceiver module is specifically configured to: Receive charging information from a session management function network element through a charging protocol, where the charging protocol is a Remote Authentication Dial-In User Service (RADIUS) protocol or a Diameter protocol.

13. A communication device, characterized in that, It includes a processor and a memory, the processor and the memory are coupled, the memory stores computer program instructions, and the processor realizes the method according to any one of claims 1 to 4 by running the computer program instructions.

14. A communication device, characterized in that, It includes a processor and a memory, the processor and the memory are coupled, the memory stores computer program instructions, and the processor realizes the method according to any one of claims 5 to 6 by running the computer program instructions.

15. A communication system, characterized in that, The communication system includes a firewall and a charging forwarding device in the enterprise private network; wherein, The charging forwarding device is configured to receive charging information from a session management function network element after the terminal device passes the operator authentication, and send the user identification SIM card information and the IP address of the terminal device to the firewall, where the SIM card information and the IP address are obtained according to the charging information; The firewall is configured to receive the SIM card information and the IP address of the terminal device from the charging forwarding device, and establish a mapping relationship between the SIM card information and the IP address; The firewall is further configured to receive an access request from the terminal device, where the access request includes the IP address of the terminal device, and determine the SIM card information corresponding to the IP address according to the mapping relationship, and perform access control on the access request according to the access control policy associated with the SIM card information.

16. The system according to claim 15, characterized in that, The access request includes the application service for which access is requested; The access control policy includes the application services within the enterprise private network that allow the terminal device corresponding to the SIM card information to access, and / or, the application services within the enterprise private network that do not allow the terminal device corresponding to the SIM card information to access; Specifically, the firewall is configured to: If the application service for which access is requested is an application service within the enterprise intranet that allows the terminal device corresponding to the SIM card information to access, then allow the access request; otherwise, block the access request.

17. The system according to claim 15 or 16, characterized in that, The firewall stores associated configuration information, and the associated configuration information includes the access control policy associated with each SIM card information within the enterprise private network.

18. The system according to any one of claims 15 to 17, characterized in that Specifically, the charging forwarding device is configured to: Receive the charging information from the session management function network element through a charging protocol, and the charging protocol is a Remote Authentication Dial In User Service (RADIUS) protocol or a Diameter protocol.

19. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores program instructions, and when the program instructions are executed by the communication device, the method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Method and device for bearing activation by evolution packet switching system

    CN101388828A

  • Method of realizing termination connection, and system of realizing termination connection

    CN104113930A

  • Access service processing method and device, storage medium and electronic equipment

    CN113473417A