An access control method, apparatus and system
By generating access control policies based on terminal identification codes on the AAA server and adapting them to enterprise firewalls, the problem of the inability to control access policies for 5G terminals in existing technologies is solved, and effective network access management for 5G terminals is achieved.
Patent Information
- Application Number
- CN202211483619.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-24
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2042-11-24
AI Technical Summary
In existing technologies, enterprise firewalls cannot control access policies based on the terminal identification code of 5G terminals, resulting in an inability to effectively manage network access of 5G terminals.
By generating a second access control policy based on network address IP on the AAA server, and using terminal identification codes (such as IMSI, IMEI, MSISDN, ULI) for access control, the generated policy is adapted to the enterprise firewall to achieve access control for 5G terminals.
It achieves effective access control for 5G terminals, avoiding access failures caused by dynamic changes in IP addresses, and requires no modification to the enterprise firewall hardware or software.
Smart Images

Figure CN115843032B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to an access control method, apparatus, and system. Background Technology
[0002] Enterprise firewalls primarily use hardware and software to create a protective barrier between internal and external network environments, thereby blocking insecure network factors. However, enterprise firewalls rely on IP addresses for policy control and cannot implement access policy control based on the terminal identification code of 5G terminals. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to address the above-mentioned shortcomings of the prior art by providing an access control method, apparatus and system. The method generates a second access control policy based on the network address IP through a first access control policy and the terminal identification code of the terminal device to control access to the terminal, thereby avoiding direct control of the terminal through the network address IP. This solves the problem in the existing related technologies that it is impossible to control access policy based on the terminal identification code of 5G terminals.
[0004] In a first aspect, the present invention provides an access control method applied to an authentication, authorization, and accounting (AAA) server, comprising:
[0005] The system receives terminal identification codes and network address IP information sent by 5G core network elements, wherein the terminal identification codes and network address IP information are sent by the 5G core network elements after receiving the terminal identification codes and network address IP information uploaded by the terminal devices.
[0006] A second access control policy based on the network address IP is generated according to the preset first access control policy and the terminal identification code.
[0007] The second access control policy is sent to the enterprise firewall so that the enterprise firewall can perform access control on the terminal device according to the second access control policy.
[0008] Preferably, the terminal identification code includes:
[0009] At least one of the following: International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI), International Mobile Number (MSISDN), and User Location Information (ULI).
[0010] Preferably, the first access control policy is adapted to the enterprise firewall;
[0011] Before receiving the terminal identification code and network address IP information sent by the 5G core network element, the process also includes:
[0012] Configure a first access control policy that controls access based on the terminal device identification code.
[0013] Preferably, before generating the second access control policy based on the network address IP according to the preset first access control policy and the terminal identification code, the method further includes:
[0014] Perform secondary access authentication on the terminal device.
[0015] Preferably, the step of receiving the terminal identification code and network address IP information sent by the 5G core network element includes:
[0016] Receive terminal identification codes and network address (IP) information sent by 5G core network elements through encrypted or unencrypted tunnels.
[0017] Secondly, the present invention also provides an access control method applied to a 5G core network element, comprising:
[0018] Receive terminal identification code and network address (IP) information uploaded by the terminal device;
[0019] The received terminal identification code and network address IP information are sent to the Authentication, Authorization and Accounting (AAA) server, so that the AAA server generates a second access control policy based on the network address IP according to the preset first access control policy and the terminal identification code, and then sends the second access control policy to the enterprise firewall, so that the enterprise firewall performs access control on the terminal device according to the second access control policy.
[0020] Preferably, before receiving the terminal identification code and network address IP information uploaded by the receiving terminal device, the method further includes:
[0021] Perform master access authentication on the terminal device.
[0022] Thirdly, the present invention also provides an access control method applied to an enterprise firewall, comprising:
[0023] The system receives a second access control policy sent by the AAA server (Authorization, Authorization and Accounting), wherein the second access control policy is generated by the AAA server based on the preset first access control policy and the terminal identification code after receiving the terminal identification code and network address IP information sent by the 5G core network element.
[0024] Access control is applied to the terminal device according to the second access control policy.
[0025] Preferably, the terminal identification code includes:
[0026] At least one of the following: International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI), International Mobile Number (MSISDN), and User Location Information (ULI).
[0027] Fourthly, the present invention also provides an access control device disposed in an authentication, authorization, and accounting (AAA) server, comprising:
[0028] The first receiving module is used to receive the terminal identification code and network address IP information sent by the 5G core network element, wherein the terminal identification code and network address IP information are sent by the 5G core network element after receiving the terminal identification code and network address IP information uploaded by the terminal device.
[0029] A generation module, connected to the first receiving module, is used to generate a second access control policy based on a network address IP according to a preset first access control policy and a terminal identification code.
[0030] A first sending module, connected to the generating module, is used to send the second access control policy to the enterprise firewall, so that the enterprise firewall can perform access control on the terminal device according to the second access control policy.
[0031] Fifthly, the present invention also provides an access control device, disposed in a 5G core network element, comprising:
[0032] The second receiving module is used to receive the terminal identification code and network address IP information uploaded by the terminal device;
[0033] The second sending module, connected to the second receiving module, is used to send the received terminal identification code and network address IP information to the Authentication, Authorization and Accounting (AAA) server, so that the AAA server generates a second access control policy based on the network address IP according to the preset first access control policy and the terminal identification code, and then sends the second access control policy to the enterprise firewall, so that the enterprise firewall performs access control on the terminal device according to the second access control policy.
[0034] Sixthly, the present invention also provides an access control device, configured in an enterprise firewall, comprising:
[0035] The third receiving module is used to receive the second access control policy sent by the Authentication, Authorization and Accounting (AAA) server. The second access control policy is generated by the Authentication, Authorization and Accounting (AAA) server based on the preset first access control policy and the terminal identification code after receiving the terminal identification code and network address IP information sent by the 5G core network element.
[0036] The control module, connected to the third receiving module, is used to perform access control on the terminal device according to the second access control policy.
[0037] In a seventh aspect, the present invention also provides an access control device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to implement the access control method as described in the first aspect above, or to implement the access control method as described in the second aspect above, or to implement the access control method as described in the third aspect above.
[0038] Eighthly, the present invention also provides an access control system, including an authentication, authorization and accounting AAA server, a 5G core network element, and an enterprise firewall;
[0039] The authentication, authorization, and accounting AAA server is used to perform the access control method described in the first aspect above;
[0040] The 5G core network element is used to execute the access control method described in the first aspect above;
[0041] The enterprise firewall is used to execute the access control method described in the third aspect above.
[0042] The access control method, apparatus, and system provided by this invention
[0043] First, the 5G core network element sends a terminal identification code and network address IP information, wherein the terminal identification code and network address IP information are sent by the 5G core network element after receiving the terminal identification code and network address IP information uploaded by the terminal device. A second access control policy based on the network address IP is generated according to a preset first access control policy and the terminal identification code. The second access control policy is then sent to the enterprise firewall, enabling the enterprise firewall to control access to the terminal device according to the second access control policy. Because this invention generates a second access control policy based on the network address IP using the first access control policy and the terminal device's terminal identification code to control terminal access, it avoids directly controlling the terminal through the network address IP, thus solving the problem in existing related technologies where access policy control based on the terminal identification code of 5G terminals is impossible. Attached Figure Description
[0044] Figure 1 This is a scenario diagram illustrating an access control method according to an embodiment of the present invention.
[0045] Figure 2 This is a flowchart of an access control method according to Embodiment 1 of the present invention;
[0046] Figure 3This is a flowchart of an access control method according to Embodiment 2 of the present invention;
[0047] Figure 4 This is a flowchart of an access control method according to Embodiment 3 of the present invention;
[0048] Figure 5 This is a schematic diagram of the structure of an access control device according to Embodiment 4 of the present invention;
[0049] Figure 6 This is a schematic diagram of the structure of an access control device according to Embodiment 5 of the present invention;
[0050] Figure 7 This is a schematic diagram of an access control device according to Embodiment 6 of the present invention;
[0051] Figure 8 This is a schematic diagram of the structure of an access control device according to Embodiment 7 of the present invention;
[0052] Figure 9 This is a schematic diagram of the structure of an access control system according to Embodiment 8 of the present invention. Detailed Implementation
[0053] To enable those skilled in the art to better understand the technical solution of the present invention, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
[0054] It is understood that the specific embodiments and accompanying drawings described herein are merely for explaining the invention and are not intended to limit the invention.
[0055] It is understood that, without conflict, the various embodiments and features in the embodiments of the present invention can be combined with each other.
[0056] It is understood that, for ease of description, only the parts related to the present invention are shown in the accompanying drawings, while the parts unrelated to the present invention are not shown in the drawings.
[0057] It is understood that each unit or module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple units or modules may be integrated into one entity structure.
[0058] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this invention may occur in a different order than that marked in the accompanying drawings.
[0059] It is understood that the flowcharts and block diagrams of this invention illustrate the possible architecture, functions, and operations of systems, apparatuses, devices, and methods according to various embodiments of this invention. Each block in the flowchart or block diagram may represent a unit, module, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagram and flowchart can be implemented using a hardware-based system to achieve the specified function, or using a combination of hardware and computer instructions.
[0060] It is understood that the units and modules involved in the embodiments of the present invention can be implemented by software or by hardware. For example, the units and modules can be located in a processor.
[0061] It should be noted that the scenario diagrams described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0062] like Figure 1 The diagram shown is a scenario diagram of an access control method provided in an embodiment of this application, wherein each part is described as follows:
[0063] (1) Terminal equipment: The terminal equipment includes a terminal identification code and an IP address. It can complete the primary authentication in the 5G core network element and the secondary authentication on the AAA server before accessing the enterprise internal network without being blocked by the firewall.
[0064] (2) 5G core network elements: including Service Management Function (SMF) and User Plane Function (UPF), which can send the terminal identification code and IP address sent by the terminal device to the AAA server after the terminal device is authenticated.
[0065] (3) AAA server: After secondary authentication of terminal devices, it can convert the first access control policy based on the terminal identification code into a second access control policy based on the IP address according to the terminal identification code and IP address of the terminal device, and the second access control policy is compatible with the enterprise firewall.
[0066] (4) Enterprise Firewall: An enterprise firewall is a protective barrier created between the internal and external networks of an enterprise through hardware and software. It can control access to the internal network of terminal devices after receiving a second access control policy. Figure 1 The following describes relevant embodiments of the access control method involved in this application, based on the scenario diagram shown.
[0067] Example 1:
[0068] This embodiment provides an access control method, such as... Figure 2 As shown, applied to an AAA server for authentication, authorization, and accounting, the method includes:
[0069] Step S101: Receive the terminal identification code and network address IP information sent by the 5G core network element, wherein the terminal identification code and network address IP information are sent by the 5G core network element after receiving the terminal identification code and network address IP information uploaded by the terminal device.
[0070] In this embodiment, the terminal device can be a 5G terminal. Enterprise staff or operators can modify the Service Management Function (SMF) and User Plane Function (UPF) in the 5G core network elements so that the SMF and UPF can send the collected terminal identification code and network address IP to the AAA server.
[0071] It should be noted that the access control method provided in this embodiment is not only applicable to scenarios where 5G terminals access 5G networks via dynamic IP, but also applicable to scenarios where 5G terminals access 5G networks via static IP.
[0072] Optionally, the terminal identification code includes:
[0073] At least one of the following: International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI), International Mobile Number (MSISDN), and User Location Information (ULI).
[0074] Step S102: Generate a second access control policy based on the network address IP according to the preset first access control policy and the terminal identification code;
[0075] In this embodiment, the firewall mainly uses hardware and software to create a protective barrier between the internal and external network environments, thereby blocking insecure network factors on the computer. Since the firewall is based on IP address for policy control, it cannot control the terminal identification code of the 5G terminal. Controlling access to the terminal through the terminal identification code can avoid the failure of terminal device access due to dynamic changes in IP address. By configuring the terminal identification code policy on the AAA server, the AAA authentication server will automatically convert the terminal identification code-based policy configuration into an IP-based policy for the enterprise firewall and distribute it to the enterprise firewall. This enables policy control of network access of 5G terminals based on the terminal identification code without requiring modifications to the enterprise firewall.
[0076] Optionally, the first access control policy is adapted to the enterprise firewall;
[0077] Before receiving the terminal identification code and network address IP information sent by the 5G core network element, the process also includes:
[0078] Configure a first access control policy that controls access based on the terminal device identification code.
[0079] Optionally, the receipt of the terminal identification code and network address IP information sent by the 5G core network element includes:
[0080] Receive terminal identification codes and network address (IP) information sent by 5G core network elements through encrypted or unencrypted tunnels.
[0081] In this embodiment, the tunnel can be a PDU (Protocol Data Unit) tunnel, and the AAA server can use a combination of IMSI, IMEI, MSISDN and ULI verification to perform secondary authentication of the access terminal. Enterprises can independently implement functions such as SIM card binding, terminal access location control and terminal access time control.
[0082] Step S103: Send the second access control policy to the enterprise firewall so that the enterprise firewall can perform access control on the terminal device according to the second access control policy.
[0083] In this embodiment, the enterprise firewall opens an interface for policy distribution, through which the AAA server distributes a second access control policy to the enterprise firewall.
[0084] Optionally, before generating the second access control policy based on the network address IP according to the preset first access control policy and the terminal identification code, the method further includes:
[0085] Perform secondary access authentication on the terminal device.
[0086] In this embodiment, after the 5G terminal completes primary authentication on the 5G core network element, it performs secondary authentication on the AAA server. After the secondary authentication is successful, the user-side traffic of the 5G terminal can reach the enterprise firewall side. The terminal needs to complete secondary access authentication on the AAA server first, and then the AAA server and the firewall will perform policy integration.
[0087] In one specific embodiment, taking access control based on the terminal's IMSI number as an example, the access control method may include the following steps:
[0088] 1) Configure a first access control policy on the AAA authentication server to control network access of 5G terminals based on the IMSI number;
[0089] 2) When a 5G terminal accesses a 5G core network element, it completes primary authentication;
[0090] 3) The 5G core network element receives information such as IMSI, IMEI, MSISDN, ULI, and IP address of the 5G terminal and transmits it to the AAA server through an encrypted or unencrypted tunnel;
[0091] 4) The AAA server automatically generates a second access control policy based on IP that conforms to the enterprise firewall policy rules according to the first access control policy, and distributes it to the enterprise firewall side through the distribution interface.
[0092] For example, when the IMSI number is 8613504500020 and the IP address is 10.39.2.3, the first access control policy is: rule permit tcp source IMSI 8613504500020 destination 10.38.1.2 0.0.0.0;
[0093] The second access control policy is: rule permit tcp source 10.39.2.3 destination 10.38.1.2 0.0.0.0;
[0094] 5) The 5G terminal performs secondary authentication on the AAA server. After the secondary authentication is successful, the user-side traffic of the 5G terminal can reach the enterprise firewall.
[0095] 6) The enterprise firewall controls network access for user-side traffic of 5G terminals based on the policy configuration received from the AAA authentication server.
[0096] The access control method provided in this invention first receives a terminal identification code and network address IP information sent by a 5G core network element. The terminal identification code and network address IP information are sent by the 5G core network element after receiving the terminal identification code and network address IP information uploaded by the terminal device. A second access control policy based on the network address IP is generated according to a preset first access control policy and the terminal identification code. The second access control policy is then sent to an enterprise firewall, enabling the enterprise firewall to control access to the terminal device according to the second access control policy. Because this invention generates a second access control policy based on the network address IP using the first access control policy and the terminal device's terminal identification code to control terminal access, it avoids directly controlling the terminal via the network address IP, thus solving the problem in existing related technologies where access policy control based on the terminal identification code of a 5G terminal is not possible.
[0097] Example 2:
[0098] This embodiment provides an access control method, such as... Figure 3As shown, this method, applied to 5G core network elements, includes:
[0099] Step S201: Receive the terminal identification code and network address (IP) information uploaded by the terminal device.
[0100] In this embodiment, the terminal device may be a 5G terminal, and the terminal identification code may include at least one of the following: International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI), Mobile International Number (MSISDN), and User Location Information (ULI).
[0101] Optionally, before receiving the terminal identification code and network address IP information uploaded by the receiving terminal device, the method further includes:
[0102] Perform master access authentication on the terminal device.
[0103] In this embodiment, after the 5G terminal completes primary authentication on the 5G core network element, it performs secondary authentication on the AAA server. After the secondary authentication is successful, the user-side traffic of the 5G terminal can reach the enterprise firewall side.
[0104] 5G core network elements transmit terminal identification codes and network address (IP) information through encrypted or unencrypted tunnels.
[0105] In this embodiment, the tunnel can be a PDU (Protocol Data Unit) tunnel, and the AAA server can use a combination of IMSI, IMEI, MSISDN and ULI verification to perform secondary authentication of the access terminal. Enterprises can independently implement functions such as SIM card binding, terminal access location control and terminal access time control.
[0106] Step S202: Send the received terminal identification code and network address IP information to the Authentication, Authorization and Accounting (AAA) server, so that the AAA server generates a second access control policy based on the network address IP according to the preset first access control policy and the terminal identification code, and then sends the second access control policy to the enterprise firewall, so that the enterprise firewall performs access control on the terminal device according to the second access control policy.
[0107] In this embodiment, the first access control policy is adapted to the enterprise firewall, and the enterprise firewall opens an interface for policy distribution. The AAA server distributes the second access control policy to the enterprise firewall through this interface.
[0108] Example 3:
[0109] This embodiment provides an access control method, such as... Figure 4 As shown, this method, applied to enterprise firewalls, includes:
[0110] Step S301: Receive the second access control policy sent by the Authentication, Authorization and Accounting (AAA) server, wherein the second access control policy is generated and sent by the AAA server after receiving the terminal identification code and network address IP information sent by the 5G core network element, based on the preset first access control policy and the terminal identification code.
[0111] In this embodiment, since the firewall uses IP address-based policy control, it cannot control the dynamic IP address of the 5G terminal. By configuring the terminal identification code policy on the AAA server, the AAA authentication server will automatically convert the terminal identification code-based policy configuration into an IP-based policy for the enterprise firewall and send it to the enterprise firewall. This enables policy control of the 5G terminal's network access based on the terminal identification code without requiring any changes to the enterprise firewall.
[0112] Optionally, the terminal identification code includes:
[0113] At least one of the following: International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI), International Mobile Number (MSISDN), and User Location Information (ULI).
[0114] Step S302: Perform access control on the terminal device according to the second access control policy.
[0115] In this embodiment, after the 5G terminal completes primary authentication on the 5G core network element, it performs secondary authentication on the AAA server. After the secondary authentication is successful, the user-side traffic of the 5G terminal can reach the enterprise firewall side. The terminal needs to complete secondary access authentication on the AAA server first, and then the AAA server and the firewall will perform policy integration.
[0116] Example 4:
[0117] like Figure 5 As shown, this embodiment provides an access control device, installed on an authentication, authorization, and accounting (AAA) server, for executing the access control method described in Embodiment 1 above, including:
[0118] The first receiving module 11 is used to receive the terminal identification code and network address IP information sent by the 5G core network element, wherein the terminal identification code and network address IP information are sent by the 5G core network element after receiving the terminal identification code and network address IP information uploaded by the terminal device.
[0119] The generation module 12 is connected to the first receiving module 11 and is used to generate a second access control policy based on the network address IP according to the preset first access control policy and the terminal identification code.
[0120] The first sending module 13, connected to the generating module 12, is used to send the second access control policy to the enterprise firewall, so that the enterprise firewall can perform access control on the terminal device according to the second access control policy.
[0121] Preferably, the terminal identification code includes:
[0122] At least one of the following: International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI), International Mobile Number (MSISDN), and User Location Information (ULI).
[0123] Preferably, the first access control policy is adapted to the enterprise firewall;
[0124] Preferably, the device further includes:
[0125] The configuration module is used to configure a first access control policy for access control based on the terminal device identification code.
[0126] Preferably, the device further includes:
[0127] The secondary authentication module is used to perform secondary access authentication on the terminal device.
[0128] Preferably, the first receiving module 11 includes:
[0129] The tunnel unit is used to receive terminal identification codes and network address (IP) information sent by 5G core network elements through encrypted or unencrypted tunnels.
[0130] Example 5:
[0131] like Figure 6 As shown, this embodiment provides an access control device, disposed in a 5G core network element, for executing the access control method described in Embodiment 2 above, including:
[0132] The second receiving module 21 is used to receive the terminal identification code and network address IP information uploaded by the terminal device;
[0133] The second sending module 22, connected to the second receiving module 21, is used to send the received terminal identification code and network address IP information to the Authentication, Authorization and Accounting (AAA) server, so that the AAA server generates a second access control policy based on the network address IP according to the preset first access control policy and the terminal identification code, and then sends the second access control policy to the enterprise firewall, so that the enterprise firewall performs access control on the terminal device according to the second access control policy.
[0134] Preferably, the device further includes:
[0135] The main authentication module is used to perform main access authentication on the terminal device.
[0136] Example 6:
[0137] like Figure 7 As shown, this embodiment provides an access control device, installed in an enterprise firewall, for executing the access control method described in Embodiment 3 above, including:
[0138] The third receiving module 31 is used to receive the second access control policy sent by the Authentication, Authorization and Accounting (AAA) server. The second access control policy is generated by the Authentication, Authorization and Accounting (AAA) server based on the preset first access control policy and the terminal identification code after receiving the terminal identification code and network address IP information sent by the 5G core network element.
[0139] The control module 32 is connected to the third receiving module 31 and is used to perform access control on the terminal device according to the second access control policy.
[0140] Preferably, the terminal identification code includes:
[0141] At least one of the following: International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI), International Mobile Number (MSISDN), and User Location Information (ULI).
[0142] Example 7:
[0143] like Figure 8 As shown, this embodiment provides an access control device for executing the above-described access control method, including a memory 41 and a processor 42. The memory 41 stores a computer program, and the processor 42 is configured to run the computer program to execute the access control method in Embodiment 1, or implement the access control method as described in Embodiment 2, or implement the access control method as described in Embodiment 3.
[0144] The memory 41 is connected to the processor 42. The memory 41 can be a flash memory, a read-only memory or other memory, and the processor 42 can be a central processing unit or a microcontroller.
[0145] Example 8:
[0146] like Figure 9 As shown, this embodiment provides an access control system, including an authentication, authorization, and accounting (AAA) server 51, a 5G core network element 52, and an enterprise firewall 53;
[0147] The AAA server 51, which performs authentication, authorization, and accounting, is used to execute the access control method described in Example 1.
[0148] The 5G core network element 52 is used to execute the access control method described in Embodiment 2;
[0149] The enterprise firewall 53 is used to execute the access control method described in Example 3.
[0150] The access control method, apparatus, and system provided in Examples 2 to 8 first receive a terminal identification code and network address IP information sent by a 5G core network element. The terminal identification code and network address IP information are sent by the 5G core network element after receiving the terminal identification code and network address IP information uploaded by the terminal device. A second access control policy based on the network address IP is generated according to a preset first access control policy and the terminal identification code. The second access control policy is then sent to an enterprise firewall, enabling the enterprise firewall to control access to the terminal device according to the second access control policy. Because this invention generates a second access control policy based on the network address IP using the first access control policy and the terminal device's terminal identification code to control terminal access, it avoids directly controlling the terminal via the network address IP, thus solving the problem in existing related technologies where access policy control based on the terminal identification code of a 5G terminal is not possible.
[0151] It is understood that the above embodiments are merely exemplary implementations used to illustrate the principles of the present invention, and the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.
Claims
1. An access control method, characterized in that, Applied to an AAA server for authentication, authorization, and accounting, the method includes: The system receives terminal identification codes and network address IP information sent by 5G core network elements, wherein the terminal identification codes and network address IP information are sent by the 5G core network elements after receiving the terminal identification codes and network address IP information uploaded by the terminal devices. A second access control policy based on a network address IP is generated based on a preset first access control policy and a terminal identification code. The first access control policy is specifically a first access control policy based on a terminal identification code, and both the first access control policy and the second access control policy are adapted to the enterprise firewall. The second access control policy is sent to the enterprise firewall so that the enterprise firewall can perform access control on the terminal device according to the second access control policy.
2. The access control method according to claim 1, characterized in that, The terminal identification code includes: At least one of the following: International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI), International Mobile Number (MSISDN), and User Location Information (ULI).
3. The access control method according to claim 1, characterized in that, Before receiving the terminal identification code and network address IP information sent by the 5G core network element, the process also includes: Configure a first access control policy that controls access based on the terminal device identification code.
4. The access control method according to claim 1, characterized in that, Before generating the second access control policy based on the network address IP according to the preset first access control policy and the terminal identification code, the method further includes: Perform secondary access authentication on the terminal device.
5. The access control method according to claim 1, characterized in that, The terminal identification code and network address IP information received from the 5G core network element include: Receive terminal identification codes and network address (IP) information sent by 5G core network elements through encrypted or unencrypted tunnels.
6. An access control method, characterized in that, Applied to 5G core network elements, the method includes: Receive terminal identification code and network address (IP) information uploaded by the terminal device; The received terminal identification code and network address IP information are sent to the Authentication, Authorization, and Accounting (AAA) server. The AAA server then generates a second access control policy based on the network address IP according to a preset first access control policy and the terminal identification code. The second access control policy is then sent to the enterprise firewall, which controls access to the terminal device according to the second access control policy. The first access control policy is specifically a first access control policy based on the terminal identification code, and both the first and second access control policies are compatible with the enterprise firewall.
7. The access control method according to claim 6, characterized in that, Before receiving the terminal identification code and network address IP information uploaded by the receiving terminal device, the following is also included: Perform master access authentication on the terminal device.
8. An access control method, characterized in that, Applications in enterprise firewalls include: The system receives a second access control policy sent by the AAA server (Authentication, Authorization, and Accounting). The second access control policy is generated by the AAA server based on a preset first access control policy and the terminal identification code after receiving the terminal identification code and network address IP information sent by the 5G core network element. The first access control policy is specifically a first access control policy based on the terminal identification code, and both the first access control policy and the second access control policy are adapted to the enterprise firewall. Access control is applied to the terminal device according to the second access control policy.
9. The access control method according to claim 8, characterized in that, The terminal identification code includes: At least one of the following: International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI), International Mobile Number (MSISDN), and User Location Information (ULI).
10. An access control device, characterized in that, The AAA server, configured for authentication, authorization, and accounting, includes: The first receiving module is used to receive the terminal identification code and network address IP information sent by the 5G core network element, wherein the terminal identification code and network address IP information are sent by the 5G core network element after receiving the terminal identification code and network address IP information uploaded by the terminal device. The generation module, connected to the first receiving module, is used to generate a second access control policy based on a network address IP according to a preset first access control policy and a terminal identification code, wherein the first access control policy is specifically a first access control policy based on a terminal identification code, and both the first access control policy and the second access control policy are adapted to the enterprise firewall. A first sending module, connected to the generating module, is used to send the second access control policy to the enterprise firewall, so that the enterprise firewall can perform access control on the terminal device according to the second access control policy.
11. An access control device, characterized in that, Located in 5G core network elements, including: The second receiving module is used to receive the terminal identification code and network address IP information uploaded by the terminal device; The second sending module, connected to the second receiving module, is used to send the received terminal identification code and network address IP information to the Authentication, Authorization, and Accounting (AAA) server. This allows the AAA server to generate a second access control policy based on the network address IP according to a preset first access control policy and the terminal identification code, and then send the second access control policy to the enterprise firewall. The enterprise firewall then controls access to the terminal device according to the second access control policy. Specifically, the first access control policy is a first access control policy based on the terminal identification code, and both the first and second access control policies are compatible with the enterprise firewall.
12. An access control device, characterized in that, Configured in the enterprise firewall, including: The third receiving module is used to receive the second access control policy sent by the Authentication, Authorization and Accounting (AAA) server. The second access control policy is generated by the AAA server after receiving the terminal identification code and network address IP information sent by the 5G core network element, based on the preset first access control policy and the terminal identification code. The first access control policy is specifically a first access control policy based on the terminal identification code, and both the first access control policy and the second access control policy are adapted to the enterprise firewall. The control module, connected to the third receiving module, is used to perform access control on the terminal device according to the second access control policy.
13. An access control device, characterized in that, The device includes a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to implement the access control method as described in any one of claims 1-5, or to implement the access control method as described in any one of claims 6-7, or to implement the access control method as described in any one of claims 8-9.
14. An access control system, characterized in that, This includes authentication, authorization, and accounting AAA servers, 5G core network elements, and enterprise firewalls; The authentication, authorization, and accounting AAA server is used to perform the access control method according to any one of claims 1-5; The 5G core network element is used to execute the access control method according to any one of claims 6-7; The enterprise firewall is used to execute the access control method according to any one of claims 8-9.
Citation Information
Patent Citations
KR20190043921A