Terminal access control method, apparatus, device, and medium
By assessing the security posture in real time and dynamically adjusting the terminal authorization level in the 5G network, the problem of lack of real-time control over terminal access control in the existing technology is solved, and dynamic authorization and security performance of terminals are achieved.
Patent Information
- Application Number
- CN202211350751.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-31
- Publication Date
- 2026-02-13
- Estimated Expiration
- 2042-10-31
AI Technical Summary
In existing 5G/5G-Advanced networks, the terminal access control mechanism lacks the ability to monitor violations and abnormal behaviors during the access process in real time, leading to increased network security risks.
By conducting real-time security situation assessments based on 5G network performance parameters, terminal transmission parameters, and behavioral parameters, the authorization level of terminals is dynamically adjusted, and the permission list is updated to achieve real-time dynamic authorization control over terminals.
It improves network security performance, enables real-time response to changes in network security situation, dynamically adjusts terminal access permissions, and enhances the ability to control violations and abnormal behaviors.
Smart Images

Figure CN115802351B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of mobile communication, and in particular to a terminal access control method, device, equipment and medium. BACKGROUND
[0002] In the 5G / 5G-Advanced era, although the protection of user identity information and the integrity of data are more secure than in 4G, the service-oriented architecture makes it easier for network elements to visit each other, and virtualization increases the exposure of network elements, making network elements and internal network security risks increase and be more vulnerable to attacks, bringing new security challenges. In addition, edge computing is becoming a key enabling technology to help 5G empower thousands of industries. On the one hand, edge computing can provide computing, storage and other infrastructure close to the user side / data source, and process data close to the edge application, with the characteristics of low latency and local traffic offloading. On the other hand, due to the deployment of edge computing resources close to the user side in a relatively open and untrusted domain, the security risk has increased significantly.
[0003] Terminals are relatively weak in the security protection system, and vulnerabilities and backdoors of terminal devices are exposed in the relatively open 5G / 5G-Advanced network, which can be easily used as a source of distributed denial of service (DDoS) attacks, thereby introducing security risks. Terminal access security is an important part of network security, and existing solutions usually only authenticate and authorize the terminal once (access authentication), and there may be a second authentication of the terminal by the application or slice. That is, after the user is authenticated, the user identity compliance check is no longer performed during the entire access process. In the 5G / 5G-Advanced network, the existing access control mechanism performs static authentication and authorization of the terminal, lacks subsequent continuous trust evaluation, and has the defect that it cannot perform real-time control of illegal and abnormal behaviors during the access process. SUMMARY
[0004] The present application provides a terminal access control method, device, equipment and medium to solve the defect that the existing access control mechanism performs static authentication and authorization of the terminal, and cannot perform real-time control of illegal and abnormal behaviors during the access process, and to improve the security performance of the network.
[0005] The present application provides a terminal access control method, comprising:
[0006] Based on the network performance parameters of the 5G network and the terminal transmission parameters, behavior parameters and state information of the terminal, the network security situation is evaluated in real time, and a security evaluation parameter is determined, the security evaluation parameter being used to represent the network security situation;
[0007] Based on the security evaluation parameter, the authorization level of the terminal is determined;
[0008] The authorization level is used to determine an update permission list in which service permission of the terminal is stored, and the update permission list is used to update a related control policy of the terminal in a corresponding network function, and the network function is used to perform access control on the terminal.
[0009] According to the terminal access control method provided by the application, the network performance parameters and the terminal transmission parameters, the behavior parameters and the state information are collected, including:
[0010] Based on the event reporting notification obtained by subscribing to the related event open service identified by the event ID in each network function (NF) of the 5G network, or
[0011] Based on the analysis result derived by the network data analysis function (NWDAF) of the 5G network, the analysis result is obtained by subscribing to the related analysis service identified by the analysis ID.
[0012] Based on the event reporting notification or the analysis result, the network performance parameters and the terminal transmission parameters, the behavior parameters and the state information are determined.
[0013] According to the terminal access control method provided by the application, based on the security evaluation parameters, the authorization level of the terminal is updated, including:
[0014] The authorization level is notified to the unified data management (UDM);
[0015] The UDM determines the updated permission list of the terminal according to the mapping relationship between the authorization level and the terminal permission, and notifies the network function of the updated permission list, so that the network function adjusts the permission related to its function.
[0016] According to the terminal access control method provided by the application, the permission list includes access and mobility management permission information, and the network function includes AMF and PCF;
[0017] The UDM is also used to transmit the access and mobility management permission information to the AMF, and the AMF triggers the access and mobility management policy association update between the PCF, and adjusts the permission corresponding to the access and mobility management permission information after obtaining the updated policy.
[0018] According to the terminal access control method provided by the application, the permission list includes service permission information, and the network function further includes SMF, PCF and UPF;
[0019] The UDM is further configured to transmit the service permission information to the SMF, the SMF triggers session management policy association update between the PCF, updates the N4 session between the UPF after obtaining the updated PCC policy rule sent by the PCF, and instructs the UPF to update the data packet forwarding rule or the QoS implementation rule, so as to adjust the permission corresponding to the service permission information, allow or block the corresponding service traffic.
[0020] The service data flow template filter in the PCC policy rule comprises information for identifying the service traffic.
[0021] According to the terminal access control method provided by the application, the permission list of the terminal comprises a default permission list and a dynamic permission list.
[0022] The default permission list is determined according to the service subscription condition of the terminal, stored in a unified data repository (UDR), and corresponding access control is performed when the terminal is registered.
[0023] The dynamic permission list is dynamically updated according to the change of the network security posture, stored in the UDM, not written into the UDR, and corresponding dynamic adjustment of the access control is performed in the access process of the terminal.
[0024] The application further provides a terminal access control device, comprising:
[0025] A posture assessment module is configured to assess the network security posture in real time based on network performance parameters of a 5G network and terminal transmission parameters, behavior parameters and state information of a terminal, and determine security assessment parameters, which are used to represent the network security posture.
[0026] An authorization level determination module is configured to determine the authorization level of the terminal based on the security assessment parameters.
[0027] The authorization level is used to determine an updated permission list, the permission list stores service permission or not permission of the terminal, and the permission list is used to update related control strategies of the terminal in corresponding network functions, and the network functions are used to perform access control on the terminal.
[0028] The application further provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the terminal access control method according to any one of the above when executing the program.
[0029] The application further provides a non-transitory computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the terminal access control method according to any one of the above.
[0030] The application also provides a computer program product comprising a computer program which, when executed by a processor, implements the terminal access control method according to any one of the above.
[0031] The terminal access control method, device, equipment and medium provided by the application can collect network and terminal related performance parameters, adjust the current authorization level of the terminal according to the network security situation, and update the permission list of the terminal access control according to the authorization level of the terminal, so as to notify the related network function to adjust the access permission of the terminal to realize the access control of the terminal, realize the real-time dynamic authorization access control mechanism of the terminal according to the network security situation, and improve the security performance of the network. BRIEF DESCRIPTION OF DRAWINGS
[0032] In order to more clearly illustrate the technical solutions in the application or prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.
[0033] Figure 1 is one of the flowcharts of the terminal access control method provided by the application;
[0034] Figure 2 is the second flowchart of the terminal access control method provided by the application;
[0035] Figure 3 is an exemplary flowchart of collecting terminal security evaluation related parameters provided by the application;
[0036] Figure 4 is an exemplary flowchart of dynamically adjusting permissions provided by the application;
[0037] Figure 5 is a structural schematic diagram of the electronic equipment provided by the application. DETAILED DESCRIPTION
[0038] In order to make the purpose, technical scheme and advantages of the application more clear, the technical scheme in the application will be described clearly and completely in combination with the drawings in the application. Obviously, the described embodiments are part of the embodiments of the application, not all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor belong to the protection scope of the application.
[0039] The terminal access control method of the application will be described below in combination with Figures 1-4 the drawings.
[0040] Referring to Figure 1 The terminal access control method provided by the application comprises the following steps:
[0041] In step 10, based on the network performance parameters of the 5G network and the terminal transmission parameters, behavior parameters and state information of the terminal, the network security posture is evaluated in real time, and the security evaluation parameter is determined, which is used to represent the network security posture.
[0042] The network performance parameters refer to parameters that can reflect the characteristics of the network, which can include the traffic, resource usage and load of the network, etc. The terminal transmission parameters can include the uplink and downlink rate and round-trip delay RTT of the terminal, etc. The terminal behavior parameters can include the switching, wake-up, location change, IP address change, access type change, wireless link failure, service access frequency, etc. The state information of the terminal can include the connection state, session state, roaming state, etc. In the embodiment of the application, the network performance parameters and the terminal transmission parameters, behavior parameters and state information are used for security evaluation.
[0043] The network performance parameters of the 5G network and the terminal transmission parameters, behavior parameters and state information of the terminal are collected. Through the network performance parameters of the 5G network and the terminal transmission parameters, behavior parameters and state information of the terminal, the network security posture is evaluated in real time, and the security evaluation parameter used to represent the network security posture is determined.
[0044] In step 20, based on the security evaluation parameter, the authorization level of the terminal is determined.
[0045] The authorization level is used to determine the update permission list, and the permission list stores the service permission of the terminal. The permission list is used to update the related control strategy of the terminal in the corresponding network function, and the network function is used to control the access of the terminal.
[0046] The security evaluation parameter is used to represent the network security situation. It should be noted that the network security situation changes when the security evaluation parameter changes. When the security evaluation parameter changes, it indicates that the current network security situation changes. If the change is large enough to require adjustment of the current authorization level of the terminal, the 5G network is notified to re-adjust the access rights of the network to the terminal. Specifically, when the security evaluation parameter changes, the current authorization level of the terminal is adjusted according to the security evaluation parameter, and the permission list of the terminal access control is updated according to the authorization level of the terminal, so that the control policy of the terminal in the corresponding network function can be updated according to the permission list to realize the access control of the terminal, and the real-time dynamic authorization access control mechanism of the terminal according to the network security situation is realized. Generally speaking, the network security situation is severe, and the authorization level of the terminal needs to be adjusted to reduce the authorization level of the terminal. Correspondingly, the access control of the terminal is strict; the network security situation is alleviated, and the authorization level of the terminal can be adjusted to improve the authorization level of the terminal. Correspondingly, the access control of the terminal can be relaxed, so as to realize the real-time dynamic adjustment of the authorization of the terminal.
[0047] Further, when the network situation changes, the dynamic permission list of the terminal can be determined according to the update of the authorization level of the terminal according to the security evaluation model.
[0048] For example, the current authorization level of the terminal is 7, the network security situation is severe, and the authorization level of the terminal needs to be adjusted to reduce the authorization level of the terminal to 4, and the number of services with access rights corresponding to the terminal is reduced.
[0049] The terminal access control method, device, equipment and medium provided by the application collect network and terminal related performance parameters, adjust the current authorization level of the terminal according to the network security situation, and update the permission list of the terminal access control according to the authorization level of the terminal, so as to notify the related network function to adjust the access rights of the terminal to realize the access control of the terminal, realize the real-time dynamic authorization access control mechanism of the terminal according to the network security situation, and improve the security performance of the network.
[0050] In a possible embodiment, please refer to Figure 2 , step 10, collecting the network performance parameters and the terminal transmission parameters, the behavior parameters and the state information, including:
[0051] Step 101, based on subscribing to event open service with event ID as identifier to each network function in the 5G network, obtaining event reporting notification; or,
[0052] Step 102, based on subscribing to related analysis service with analysis ID as identifier to network data analysis function (NWDAF) of the 5G network, obtaining analysis result derived by the NWDAF;
[0053] Step 103, based on the event reporting notification or the analysis result, determining the network performance parameters and the terminal transmission parameters, behavior parameters and state information.
[0054] The collection of network performance parameters and terminal transmission parameters, behavior parameters and state information can be achieved by directly subscribing to relevant event exposure services of each network function in the 5G network, or by subscribing to relevant analysis IDs to the network data analysis function (NWDAF). At this time, the NWDAF derives the analysis result by subscribing to event exposure services of each network function and collecting relevant data from the OAM.
[0055] For example, the uplink and downlink rates and round-trip delay RTT of the terminal are collected by the UPF, and the mobility and state conversion events of the terminal are collected by the event exposure services provided by the AMF, SMF and other network functions.
[0056] For ease of understanding, the network performance parameters and terminal transmission parameters, behavior parameters and state information are collected by subscribing to event exposure services of each network function in the network for security evaluation. Please refer to Figure 3 An exemplary collection process is as follows:
[0057] Step 1: The security evaluation server subscribes to the events identified by the Event ID, which can be one or more, and sends an Nnef_EventExposure_Subscribe request to the NEF, carrying the event identifier, the identifier of the relevant UE and the endpoint information for receiving the relevant notification message;
[0058] Step 2: The NEF subscribes to the received events and sends an Nudm_EventExposure_Subscribe request to the UDM, providing the event identifier, the UE identifier and the endpoint of the NEF receiving the relevant notification message to the UDM;
[0059] Step 3: If the relevant event subscription requires the assistance of AMF, SMF, UPF and other NFs, the UDM learns the service NFs through the locally stored UE-related context data, sends an Nnf_EventExposure_Subscribe request to these NFs, carrying the event identifier of the subscription. Since the UDM itself is not the NF receiving the event notification, the endpoint of the NEF receiving the notification message needs to be carried in the request message, and the NF returns an Nnf_EventExposure_Notify response to confirm the subscription;
[0060] Step 4: The UDM sends an Nudm_EventExposure_Notify response to the NEF to confirm the subscription;
[0061] Step 5: The NEF sends an Nnef_EventExposure_Notify response to the security assessment server to confirm the subscription. If the NEF receives the first event reporting notification in step 4, the NEF includes the event reporting notification in the confirmation message;
[0062] Step 6: Each NF (AMF, SMF, UPF, etc.) directly sends an event reporting notification Nnf_EventExposure_Notify message to the NEF when the relevant event reporting condition is met;
[0063] Step 7: The NEF sends an Nnef_EventExposure_Notify to the security assessment server, forwarding the received event reporting notification.
[0064] For ease of understanding, if a network data analysis function is deployed in the network, network performance parameters and terminal transmission parameters, behavior parameters and state information can be collected by subscribing to relevant analysis IDs to the network data analysis function. Please refer to Figure 3 An exemplary specific process for collection is as follows:
[0065] Step 1-2: The security assessment server subscribes to relevant analysis through the NEF using Nnwdaf_AnalyticsSubscription_Subscribe to the NWDAF, and the message carries the analysis ID and the identity of the relevant UE. The analysis ID can be UE communication behavior analysis, UE mobility analysis, and UE abnormal behavior analysis, etc.
[0066] Step 3: The NWDAF sends an Nnf_EventExposure_Subscribe to subscribe to relevant events to the relevant NFs (such as AMF, SMF, and the NWDAF learns the service AMF and SMF of the UE through the Nudm_UECM service provided by the UDM), carrying the event identity and the identity of the relevant UE. The NWDAF can also collect relevant performance parameters from OAM and / or UPF. Each NF confirms the subscription through Nnf_EventExposure_Notify, and sends an event reporting notification to the NWDAF through Nnf_EventExposure_Notify when the event reporting condition is met;
[0067] Step 4: The NWDAF derives the requested analysis result;
[0068] Step 5: The NWDAF sends the analysis result to the security assessment server through the NEF.
[0069] The security evaluation server performs real-time evaluation on the network security situation according to the received event reporting of each NF or the analysis result of the NWDAF, to determine whether the permission level of the UE needs to be dynamically adjusted.
[0070] In an embodiment, after determining the authorization level of the terminal based on the security evaluation parameter, the method comprises:
[0071] notifying the unified data management (UDM) of the authorization level;
[0072] The UDM is configured to determine an updated permission list of the terminal according to the mapping relationship between the authorization level and the terminal permission, and notify the network function of the updated permission list, so that the network function adjusts the permission related to its function.
[0073] According to the real-time network security situation, the authorization level of the UE needs to be dynamically adjusted and the unified data management unit UDM is notified. The unified data management UDM can determine the updated permission list according to the mapping of the authorization level and the corresponding bit in the permission list, and notify the network function AMF and SMF of the updated permission information related to access and mobility and service respectively. The network function AMF and SMF trigger the AM and SM policy control update process between the PCF respectively.
[0074] For ease of understanding, please refer to Figure 4 The unified data management is configured to notify the network function to adjust the corresponding permission. An exemplary permission adjustment step is as follows:
[0075] Step 1: The security evaluation server determines the updated authorization level according to the current network security situation and judges whether the authorization level needs to be adjusted.
[0076] Step 2: The security evaluation server sends a Nnef_ServiceParameter_Update request to the NEF to request to update the authorization level of the UE in the 5GS;
[0077] Step 3: The security evaluation server is authorized by the NEF to provide UE related parameters. The NEF sends a Nudm_ParameterProvision request to the UDM to request to update the authorization level of the UE. The UDM returns a Nudm_ParameterProvision response;
[0078] Step 4: The UDM returns a Nnef_ServiceParameter_Update response to the NEF;
[0079] Step 5: The UDM determines the updated UE permission list according to the mapping of the authorization level and the corresponding bit in the permission list;
[0080] It should be noted that the update of the UE permission list is only performed in the UDM and is not updated to the UDR, and the UDR only stores the default permission list and interacts with the UDM when the UE is registered.
[0081] In an embodiment, the permission list includes access and mobility management permission information, and the network functions include an AMF and a PCF;
[0082] The unified data management UDM is also configured to transmit the access and mobility management permission information to the AMF, and the AMF triggers an access and mobility management policy association update between the AMF and the PCF, and adjusts the permissions corresponding to the access and mobility management permission information after obtaining the updated policy.
[0083] For access and mobility management, the AMF and the RAN perform policy update. The access and mobility related permission adjustment process is as follows (steps 6a-8a):
[0084] Step 6a: The UDM sends an Nudm_SDM_Notification notify message to the AMF to notify the AMF of the access and mobility related permissions in the updated permission list of the subscription data;
[0085] Step 7a: The AMF triggers an AM policy association update process between the AMF and the PCF, and the AMF sends an Npcf_AMpolicyControl_Update request to the PCF to provide the access and mobility restriction trigger condition to the PCF, and the PCF returns an Npcf_AMpolicyControl_Update response to the AMF to provide the updated policy;
[0086] Step 8a: The AMF cooperates with the (R)AN and the UE to apply the access and mobility management related permission adjustment.
[0087] In an embodiment, the permission list includes service permission information, and the network functions further include an SMF, a PCF, and a UPF;
[0088] The UDM is also configured to transmit the service permission information to the SMF, and the SMF triggers a session management policy association update between the SMF and the PCF, and updates the N4 session between the SMF and the UPF after obtaining the updated PCC policy rule sent by the PCF, instructs the UPF to update the packet forwarding rule or the QoS implementation rule, to adjust the permissions corresponding to the service permission information, and allows or blocks the corresponding service traffic.
[0089] The service data flow template filter in the PCC policy rule contains information for identifying the service traffic.
[0090] For service-related permission updates, traffic detection is performed according to a packet flow description (PFD), the PCF converts the change in service flow permissions into corresponding PCC policy, and the SMF is notified, the SMF instructs the UPF to update the packet forwarding rule (FAR) or QoS enforcement rule (QER). The UPF is responsible for performing application detection and performing corresponding packet forwarding / dropping or gating actions according to the received PCC rule to allow or block the corresponding traffic.
[0091] For ease of understanding, an exemplary service-related permission adjustment process (steps 6b-10b) is as follows:
[0092] Step 6b: The UDM sends an Nudm_SDM_Notification notify message to the SMF, notifying the SMF to update the permissions related to the service in the permission list of the subscription data;
[0093] Step 7b: The SMF triggers an SM policy association update procedure between the SMF and the PCF, and the SMF sends an Npcf_SMpolicyControl_Update request to the PCF, requesting to update the SM policy association to receive updated policy information for the PDU session;
[0094] Step 8b: The PCF converts the change in service permissions into PCC policy rules, where the filter of the SDF template contains PFD and IP flow description, and the PFD is identified by a PFD ID and includes at least a three-tuple of protocol, server IP address, and port number used by the application;
[0095] Step 9b: The PCF sends an Npcf_SMpolicyControl_Update response to the SMF, carrying the updated PCC policy information;
[0096] Step 10b: N4 session update procedure between the SMF and the UPF, the SMF maps the SDF template in the PCC rule to the packet detection rule of the UPF, and instructs the UPF to update the packet forwarding rule (FAR) or QoS enforcement rule (QER).
[0097] The UPF is responsible for performing application detection and performing corresponding packet forwarding / dropping or gating actions according to the FAR or QER rule to allow or block the corresponding traffic.
[0098] For access and mobility management, policy update is performed by AMF and RAN; for service-related permission update, traffic detection is performed according to a packet flow description (PFD), the PCF converts the change of the service flow permission into a corresponding PCC policy and notifies the SMF, and the SMF instructs the UPF to update the packet forwarding rule (FAR) or the QoS implementation rule (QER); the UPF is responsible for performing application detection and performing corresponding packet forwarding / dropping or gating actions according to the FAR or QER rule to allow or block the corresponding traffic.
[0099] In an embodiment, the permission list of the terminal includes a default permission list and a dynamic permission list;
[0100] The default permission list is determined according to the service subscription of the terminal, stored in a unified data repository (UDR), and corresponding access control is performed when the terminal is registered;
[0101] The dynamic permission list is dynamically updated according to the change of the network security posture, stored in the UDM, not written into the UDR, and dynamic adjustment of corresponding access control is performed in the access process of the terminal.
[0102] The default permission list is determined according to the service subscription of the UE, the UDM obtains the subscription data containing the default permission list from the UDR when the UE is registered, and corresponding control is performed, only the permission limit related to the subscription is performed for the UE, there is no additional control due to network security reasons, and the maximum set of corresponding permissions. The permission list mentioned in the embodiment of the present application refers to the dynamic permission list, which is dynamically updated by the UDM according to the change of the authorization level during the access process of the UE. In order to avoid the overlay operation of the default permission list in the UDR, the dynamic permission list is stored in the UDM and is not updated to the UDR, and its effective period lasts until the next permission level update sent by the security evaluation server is received.
[0103] Therefore, the maximum permission is executed when the UE is registered, and the permission of some services will change from no limit to limit execution as the network security posture changes.
[0104] The terminal access control device provided by the present application is described below, and the terminal access control device described below can be correspondingly referred to the terminal access control method described above.
[0105] The terminal access control device provided by the present application comprises:
[0106] The situation evaluation module is configured to evaluate the network security posture in real time based on the network performance parameters of the 5G network and the terminal transmission parameters, behavior parameters and state information of the terminal, and determine a security evaluation parameter, wherein the security evaluation parameter is used to represent the network security posture.
[0107] an authorization level determination module configured to determine an authorization level of the terminal based on the security evaluation parameter;
[0108] The authorization level is used to determine an update permission list in which permissions of the terminal are stored, and the update permission list is used to update a related control policy of the terminal in a corresponding network function, and the network function is used to perform access control on the terminal.
[0109] Further, the terminal access control apparatus further comprises a parameter acquisition module configured to:
[0110] acquire an event reporting notification based on subscribing to a related event open service identified by an event ID to each network function (NF) in the 5G network, or
[0111] acquire an analysis result derived by a network data analysis function (NWDAF) based on subscribing to a related analysis service identified by an analysis ID to the NWDAF;
[0112] determine the network performance parameter, the terminal transmission parameter, the behavior parameter and the state information based on the event reporting notification or the analysis result.
[0113] Further, the terminal access control apparatus further comprises a notification module configured to:
[0114] notify the authorization level to a unified data management (UDM);
[0115] The UDM determines an updated permission list of the terminal according to a mapping relationship between the authorization level and the terminal permission, and notifies the updated permission list to the network function, so that the network function adjusts the permission related to its function.
[0116] Further, the permission list includes access and mobility management permission information, and the network function includes an AMF and a PCF;
[0117] The UDM is further configured to transmit the access and mobility management permission information to the AMF, and the AMF triggers an access and mobility management policy association update between the AMF and the PCF, and adjusts the permission corresponding to the access and mobility management permission information after obtaining the updated policy.
[0118] Further, the permission list includes service permission information, and the network function further includes an SMF, a PCF and a UPF;
[0119] The UDM is further configured to transmit the service permission information to the SMF, the SMF triggers session management policy association update between the PCF, updates the N4 session between the UPF after obtaining the updated PCC policy rule sent by the PCF, and instructs the UPF to update the data packet forwarding rule or the QoS implementation rule to adjust the permission corresponding to the service permission information, allow or block the corresponding service traffic.
[0120] The service data flow template filter in the PCC policy rule contains information for identifying the service traffic.
[0121] Further, the permission list of the terminal includes a default permission list and a dynamic permission list.
[0122] The default permission list is determined according to the service subscription of the terminal, stored in a unified data repository (UDR), and corresponding access control is performed when the terminal is registered.
[0123] The dynamic permission list is dynamically updated according to the change of the network security posture, stored in the UDM, not written into the UDR, and the dynamic adjustment of the corresponding access control is performed in the access process of the terminal.
[0124] Figure 5 An example of an entity structure diagram of an electronic device is shown in FIG. 1. Figure 5 As shown in FIG. 1, the electronic device can include a processor 510, a communications interface 520, a memory 530, and a communications bus 540, wherein the processor 510, the communications interface 520, and the memory 530 can communicate with each other through the communications bus 540. The processor 510 can invoke the logical instructions in the memory 530 to execute a terminal access control method, which includes: based on the network performance parameters of a 5G network and the terminal transmission parameters, behavior parameters, and state information of a terminal, real-time evaluation of a network security posture is performed, and a security evaluation parameter is determined, the security evaluation parameter is used to represent the network security posture; based on the security evaluation parameter, an authorized level of the terminal is determined; the authorized level is used to determine an updated permission list, the permission list stores the service permission or not permission of the terminal, and the permission list is used to update the related control policy of the terminal in the corresponding network function, and the network function is used to perform access control on the terminal.
[0125] In addition, the logic instructions in the memory 530 described above can be implemented in the form of a software function unit and sold or used as an independent product, which can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0126] In another aspect, the present application also provides a computer program product, which comprises a computer program, the computer program can be stored on a non-transitory computer readable storage medium, and the computer program can be executed by a processor to enable a computer to execute the terminal access control method provided by the above-mentioned methods. The method comprises: based on the network performance parameters of the 5G network and the terminal transmission parameters, behavior parameters and state information of the terminal, real-time evaluation of the network security posture is performed to determine security evaluation parameters, the security evaluation parameters are used to represent the network security posture; based on the security evaluation parameters, the authorization level of the terminal is determined; the authorization level is used to determine an updated permission list, the permission list stores the service permission of the terminal, and the permission list is used to update the related control strategy of the terminal in the corresponding network function, and the network function is used to perform access control on the terminal.
[0127] In another aspect, the present application also provides a computer program product, which comprises a computer program, the computer program can be stored on a non-transitory computer readable storage medium, and the computer program can be executed by a processor to enable a computer to execute the terminal access control method provided by the above-mentioned methods. The method comprises: based on the network performance parameters of the 5G network and the terminal transmission parameters, behavior parameters and state information of the terminal, real-time evaluation of the network security posture is performed to determine security evaluation parameters, the security evaluation parameters are used to represent the network security posture; based on the security evaluation parameters, the authorization level of the terminal is determined; the authorization level is used to determine an updated permission list, the permission list stores the service permission of the terminal, and the permission list is used to update the related control strategy of the terminal in the corresponding network function, and the network function is used to perform access control on the terminal.
[0128] The device embodiments described above are merely illustrative, wherein the units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed to multiple network units. Part or all of the modules can be selected to achieve the purposes of the embodiments according to actual needs. Those skilled in the art can understand and implement without creative labor.
[0129] Through the description of the above embodiments, those skilled in the art can clearly understand that the embodiments can be realized by means of software and the necessary general hardware platform, and of course can also be realized by hardware. Based on such understanding, the above technical solutions can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in each embodiment or some parts of the embodiments.
[0130] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement to part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A terminal access control method, characterized in that, include: Based on the network performance parameters of the 5G network and the terminal transmission parameters, behavior parameters and status information of the terminal, the network security situation is evaluated in real time to determine the security evaluation parameters, which are used to characterize the network security situation. Based on the security assessment parameters, the authorization level of the terminal is determined; The authorization level is used to determine the update permission list, which stores the permission of the terminal to allow or deny services. The permission list is used to update the relevant control policies of the terminal in the corresponding network functions, which are used to perform access control on the terminal. The permission list includes access and mobility management permission information as well as service permission information; The terminal's permission list includes a default permission list and a dynamic permission list; After determining the authorization level for updating the terminal based on the security assessment parameters, the process includes: The authorization level will be communicated to the Unified Data Management (UDM). The UDM determines the updated permission list of the terminal based on the mapping relationship between the authorization level and the terminal permissions, and notifies the network function of the updated permission list so that the network function can make permission adjustments related to its function. The permission adjustments include those related to access and mobility, as well as those related to services.
2. The terminal access control method according to claim 1, characterized in that, The collection of the network performance parameters, terminal transmission parameters, behavioral parameters, and status information includes: By subscribing to relevant event open services identified by event IDs from each network function (NF) in the 5G network, event reporting notifications can be obtained; or, Based on subscribing to the Network Data Analysis Function (NWDAF) of the 5G network with relevant analysis services identified by analysis ID, the analysis results derived by the NWDAF are obtained; Based on the event reporting notification or the analysis results, the network performance parameters, terminal transmission parameters, behavioral parameters, and status information are determined.
3. The terminal access control method according to claim 1, characterized in that, The network functions include AMF and PCF; The UDM is also used to transmit the access and mobility management permission information to the AMF, the AMF triggers an update of the access and mobility management policy association between itself and the PCF, and adjusts the permissions corresponding to the access and mobility management permission information after obtaining the updated policy.
4. The terminal access control method according to claim 1, characterized in that, The network functions also include SMF, PCF, and UPF; The UDM is also used to transmit the service permission information to the SMF. The SMF triggers a session management policy association update with the PCF. After obtaining the updated PCC policy rules sent by the PCF, the UDM updates the N4 session with the UPF and instructs the UPF to update the packet forwarding rules or QoS enforcement rules to adjust the permissions corresponding to the service permission information and allow or block the corresponding service traffic. The service data flow template filter in the PCC policy rule contains information for identifying the service traffic.
5. The terminal access control method according to any one of claims 3-4, characterized in that, The default permission list is determined based on the service subscription status of the terminal and stored in the unified data repository UDR. Corresponding access control is executed when the terminal registers. The dynamic permission list is dynamically updated according to changes in the network security situation, stored in the UDM, and not written to the UDR. During the access process of the terminal, the corresponding access control is dynamically adjusted.
6. A terminal access control device, characterized in that, include: The situation assessment module is used to assess the network security situation in real time based on the network performance parameters of the 5G network and the terminal transmission parameters, behavior parameters and status information of the terminal, and to determine the security assessment parameters, which are used to characterize the network security situation. An authorization level determination module is used to determine the authorization level of the terminal based on the security assessment parameters; The authorization level is used to determine the update permission list, which stores the permission of the terminal to allow or deny services. The permission list is used to update the relevant control policies of the terminal in the corresponding network functions, which are used to perform access control on the terminal. The permission list includes access and mobility management permission information as well as service permission information; The terminal's permission list includes a default permission list and a dynamic permission list; After determining the authorization level for updating the terminal based on the security assessment parameters, the process includes: The authorization level will be communicated to the Unified Data Management (UDM). The UDM determines the updated permission list of the terminal based on the mapping relationship between the authorization level and the terminal permissions, and notifies the network function of the updated permission list so that the network function can make permission adjustments related to its function. The permission adjustments include those related to access and mobility, as well as those related to services.
7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the terminal access control method as described in any one of claims 1 to 5.
8. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the terminal access control method as described in any one of claims 1 to 5.
9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the terminal access control method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Terminal UE management and control method and device
CN110351229A
Terminal access control method and device, storage medium and electronic equipment
CN113536258A