Abnormal terminal processing method, device and storage medium

By analyzing terminal signaling records to identify and restrict abnormal terminals, the problem of illegal terminal login in the EIR network is solved, and the security of user information is improved.

CN115884191BActive Publication Date: 2025-08-26CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211445702.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-18
Publication Date
2025-08-26
Estimated Expiration
2042-11-18

AI Technical Summary

Technical Problem

In networks where the device identification register (EIR) is not deployed, how to effectively restrict illegal terminals from using replicated user USIM cards to log into the mobile network to protect user information security.

Method used

By analyzing the signaling records of the terminal accessing the mobile network, an abnormal terminal that illegally accesses the network through the copied user USIM card is identified and network access restrictions are restricted, including filtering signaling record information, determining the authentication delay value and terminal type, and determining the abnormal terminal and limiting it when the preset conditions are met.

Benefits of technology

In the scenario where EIR is not deployed, network access of abnormal terminals is effectively identified and restricted, improving user information security protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115884191B_ABST
    Figure CN115884191B_ABST
Patent Text Reader

Abstract

The present application provides a method, device and storage medium for processing abnormal terminals, which relates to the field of communication technology, including: obtaining signaling record information of a terminal accessing a mobile network, the signaling record information including the IMEI and IMSI of the terminal, screening a first number of signaling record information of the terminal to obtain a second number of target signaling record information, wherein the IMEIs of the terminals in the second number of target signaling record information are the same but the IMSIs are different, determining the authentication delay value of the terminal and the type of the terminal based on the target signaling record information, and when the authentication delay value of the terminal and the type of the terminal meet preset conditions, determining the terminal as an abnormal terminal and restricting the network access of the abnormal terminal. Abnormal terminals can be identified based on the signaling record information of the terminal accessing the network, and the access of the abnormal terminal to the network can be restricted, thereby improving the ability to protect the user's network data security in scenarios where EIR is not deployed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a method, device, and storage medium for processing abnormal terminals. Background Art

[0002] A terminal device (eg, a mobile phone) can access a mobile network through a Universal Subscriber Identity Module (USIM).

[0003] With the development of technology, the types of terminal devices are increasing, and a large number of IoT devices are beginning to access mobile networks. IoT devices usually require specific user identification cards to access mobile networks. However, due to some reasons, the user's USIM card data is leaked. After the criminals copy the user's USIM card, they use the copied USIM card to log in to the mobile network through IoT devices, which poses a great threat to the user's information security.

[0004] Operators can restrict terminal devices accessing the network by deploying an Equipment Identity Register (EIR) in the network. However, when the EIR is not deployed, how to restrict illegal terminals from using copied user USIM cards to log in to the network has become an urgent problem that technicians in this field need to solve. Summary of the Invention

[0005] The present application provides a method, device, and storage medium for processing abnormal terminals. In a network where an EIR is not deployed, the signaling records of the terminals accessing the mobile network can be analyzed to identify abnormal terminals that illegally access the network through copied user USIM cards, and network access restrictions can be imposed on the abnormal terminals, thereby improving the ability to protect user information security.

[0006] In a first aspect, the present application provides a method for handling abnormal terminals, comprising:

[0007] Acquire signaling record information of a terminal accessing a mobile network, where the signaling record information is used to indicate a mobile network access event of the terminal, and the signaling record information includes the IMEI and IMSI of the terminal;

[0008] Filtering the first quantity of signaling record information of the terminal to obtain a second quantity of target signaling record information, wherein the terminals in the second quantity of target signaling record information have the same IMEI but different IMSI;

[0009] Determining an authentication delay value of the terminal and a type of the terminal according to the target signaling record information;

[0010] When the authentication delay value of the terminal and the type of the terminal meet preset conditions, the terminal is determined to be an abnormal terminal, and network access restrictions are performed on the abnormal terminal.

[0011] Optionally, the signaling record information further includes time when the terminal accesses the mobile network, and determining the authentication delay value of the terminal according to the target signaling record information includes:

[0012] The authentication delay value of the terminal is determined according to the time when the terminal sends the identity authentication request to the mobile network and the time when the mobile network sends the identity authentication response to the terminal in the target signaling record information.

[0013] Optionally, determining the type of the terminal according to the target signaling record information includes:

[0014] The type allocation code of the terminal is obtained according to the IMEI of the terminal, and the type of the terminal is obtained in a terminal type information table, wherein the terminal type information table stores a correspondence between the type allocation code of the terminal and the type of the terminal.

[0015] Optionally, when the authentication delay value of the terminal and the type of the terminal meet preset conditions, determining that the terminal is an abnormal terminal includes:

[0016] When the authentication delay value of the terminal is greater than a preset duration and the type of the terminal is an Internet of Things device, the terminal is determined to be an abnormal terminal.

[0017] Optionally, the signaling record information further includes a cell code of the terminal, and the restricting network access of the abnormal terminal includes:

[0018] If the abnormal terminal is determined to be a local network user based on its IMSI, the IMSI and tracking area code of the abnormal terminal are recorded at the MME of the mobile network so that the MME can restrict network access to the abnormal terminal. The tracking area code is determined by the cell code.

[0019] Optionally, if it is determined that the abnormal terminal is a user of a different network based on the IMSI of the abnormal terminal, the method further includes:

[0020] Sending the IMSI of the abnormal terminal to the foreign network operator;

[0021] receiving a response message sent by the foreign network operator, wherein the response message is used to indicate whether the foreign network operator can restrict network access of the abnormal terminal according to the IMEI of the abnormal terminal;

[0022] If the foreign network operator cannot restrict the network access of the abnormal terminal through the IMEI of the abnormal terminal, the IMSI and the tracking area code of the abnormal terminal are recorded at the MME of the mobile network.

[0023] Optionally, obtaining signaling record information of the terminal accessing the network includes:

[0024] querying the signaling record of the terminal accessing the mobile network in the signaling collection system at a preset time interval to obtain a query result;

[0025] The query result is written into a preset signaling record table to obtain the signaling record information.

[0026] In a second aspect, the present application provides a device for processing abnormal terminals, comprising:

[0027] An acquisition module is used to acquire signaling record information of a terminal accessing a mobile network, wherein the signaling record information is used to indicate a mobile network access event of the terminal, and the signaling record information includes the IMEI and IMSI of the terminal;

[0028] a screening module, configured to screen the first quantity of signaling record information of the terminal to obtain a second quantity of target signaling record information, wherein the IMEIs of the terminals in the second quantity of target signaling record information are the same but the IMSIs are different;

[0029] A first determining module is configured to determine an authentication delay value of the terminal and a type of the terminal according to the target signaling record information;

[0030] The second determining module is configured to determine that the terminal is an abnormal terminal and restrict network access to the abnormal terminal when the authentication delay value of the terminal and the type of the terminal meet preset conditions.

[0031] Optionally, the abnormal terminal processing device can execute the abnormal terminal processing method described in any one of the first aspects.

[0032] In a third aspect, the present application provides an electronic device, comprising: a memory and a processor;

[0033] The memory is used to store computer instructions; the processor is used to execute the computer instructions stored in the memory to implement any method in the first aspect.

[0034] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, and the computer program is executed by a processor to implement any one of the methods in the first aspect.

[0035] In a fifth aspect, the present application provides a computer program product, comprising a computer program, which implements any one of the methods in the first aspect when executed by a processor.

[0036] The present application provides a method, device, and storage medium for processing abnormal terminals. By obtaining signaling record information of the terminal accessing the mobile network, the signaling record information is used to indicate the terminal's mobile network access event. The signaling record information includes the terminal's IMEI and IMSI. The first amount of signaling record information of the terminal is screened to obtain a second amount of target signaling record information, wherein the IMEIs of the terminals in the second amount of target signaling record information are the same but the IMSIs are different. The authentication delay value of the terminal and the type of the terminal are determined based on the target signaling record information. When the authentication delay value of the terminal and the type of the terminal meet the preset conditions, the terminal is determined to be an abnormal terminal, and network access restrictions are imposed on the abnormal terminal. Abnormal terminals can be identified based on the signaling record information of the terminal accessing the network, and the access of the abnormal terminal to the network can be restricted, thereby improving the ability to protect the user's network data security in scenarios where EIR is not deployed. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 A schematic diagram of a scenario provided for an embodiment of the present application;

[0038] Figure 2 Schematic diagram of the process of abnormal terminal processing method provided in the embodiment of the application Figure 1 ;

[0039] Figure 3 Schematic diagram of the process of abnormal terminal processing method provided in the embodiment of the application Figure 2 ;

[0040] Figure 4 A schematic diagram of the structure of an abnormal terminal processing device provided in an embodiment of the present application;

[0041] Figure 5 A schematic diagram of the structure of an abnormal terminal processing electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0042] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments.

[0043] In the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects, and do not limit their order. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity or execution order, and words such as "first" and "second" do not necessarily mean different.

[0044] It should be noted that in the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" or "for example" should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0045] Terminal devices (for example, mobile phones) can access mobile networks through USIM cards. With the development of technology, there are more and more types of terminal devices, and a large number of IoT devices have begun to access mobile networks. IoT devices usually require specific user identification cards to access mobile networks. However, due to some reasons, the user's USIM card data is leaked. After the criminals copy the user's USIM card, they use the copied USIM card (illegal terminal) to log in to the mobile network through the IoT device, which poses a great hidden danger to the user's information security. For example, an illegal terminal copies the USIM card of an overseas operator user in place B in place A to log in to the network, but the user in place A did not actually come to place B, but received a text message prompting him to log in in Shenzhen, which caused user complaints.

[0046] Operators can restrict terminal devices accessing the network by deploying Equipment Identity Registers (EIRs) in the network. However, due to the long-standing existence of a large number of gray-imported and counterfeit mobile phones in the domestic communications market, most domestic operators currently do not deploy EIR devices to restrict the access of these terminals in order to ensure the rights of users to use the network.

[0047] Therefore, when EIR is not deployed, how to restrict illegal terminals from using copied user USIM cards to log in to the mobile network has become a problem that needs to be solved urgently by those skilled in the art.

[0048] In view of this, an embodiment of the present application provides a method, device and storage medium for processing abnormal terminals. By analyzing the signaling records of the terminal accessing the mobile network, the terminal that accesses the mobile network using a copied USIM card through an IoT device is determined to be an abnormal terminal. The access of the abnormal terminal to the mobile network is restricted through the mobility management entity (Mobility Management Entity, MME) of the mobile network, thereby ensuring the user's information security.

[0049] The following specific embodiments are used to describe in detail the technical solution of the present application and how the technical solution of the present application solves the above technical problems. The following specific embodiments can be implemented independently or in combination with each other. For the same or similar concepts or processes, some embodiments may not be described in detail.

[0050] Figure 1 This is a schematic diagram of an application scenario of an embodiment of the present application, such as Figure 1 As shown, it includes: a terminal 101, a mobile network 102, a signaling collection system 103 and an analysis device 104.

[0051] In an embodiment of the present application, the terminal 101 can access the mobile network 102 through the carried USIM card. During the process of the terminal 101 accessing the mobile network 102, the mobile network 102 can obtain the signaling records of the terminal 101 during the process of accessing the mobile network 102 through the signaling collection system 103, such as the access time, the type of terminal accessed, the content of the access, the cell where the terminal is located, etc., to realize the quality monitoring and analysis of the mobile network services, perception optimization, planning support, historical signaling document query and other functions.

[0052] The analysis device 104 can obtain the signaling records generated by the terminal 101 during the process of accessing the mobile network 102 through interaction with the signaling collection system 103. By analyzing the signaling records, it can obtain a list of terminals that use different USIM cards to access the network by the same terminal, and determine the abnormal terminals in the list of terminals, that is, illegal terminals, through preset judgment rules.

[0053] After determining the abnormal terminal, the analysis device 104 may send the abnormal terminal to the mobile network 102 so that the mobile network 102 restricts network access of the abnormal terminal through the MME.

[0054] In the embodiment of the present application, the terminal 101 can be a mobile phone, a computer, an Internet of Things device, etc. The embodiment of the present application does not limit the type of the terminal.

[0055] The above briefly describes the application scenarios of the embodiments of the present application. Figure 1 Taking the analysis device in as an example, the processing method of abnormal terminals provided in the embodiment of the present application is described.

[0056] Figure 2 A flowchart of a method for handling abnormal terminals provided in an embodiment of the present application is shown in FIG. Figure 2 As shown, the following steps are included:

[0057] S201. Acquire signaling record information of a terminal accessing a mobile network. The signaling record information is used to indicate a mobile network access event of the terminal. The signaling record information includes the IMEI and IMSI of the terminal.

[0058] In the embodiment of the present application, terminal access to the mobile network means that the terminal accesses the mobile network provided by the operator, such as 4G network, 5G network, etc., through the carried user's USIM card.

[0059] Signaling refers to the instruction information used to establish, terminate, and maintain communication relationships during the interaction between a terminal and a mobile network. It is used to establish a communication channel between the terminal and the mobile network and maintain the normal operation of the network. Simply put, signaling records can record all interaction information and access information during the terminal's access to the network.

[0060] In the embodiments of the present application, the International Mobile Equipment Identity (IMEI), commonly known as the terminal serial number or terminal "serial number", is used to identify each independent terminal or other mobile communication device in the mobile network, which is equivalent to the terminal's ID card. The serial number has 15 to 17 digits. The International Mobile Subscriber Identity (IMSI) is an identification code used to distinguish different users in the mobile network and is not repeated in all mobile networks. When the terminal accesses the network, it will store the IMSI in a 64-bit field and send it to the mobile network.

[0061] In the embodiment of the present application, operators usually deploy a signaling collection system on the mobile network, which can support quality monitoring and analysis of existing network services, perception optimization, planning support, historical signaling document query and other functions. The analysis equipment can obtain signaling record information of the terminal accessing the mobile network by interacting with the signaling collection system.

[0062] S202: Filter the first number of signaling record information of the terminals to obtain a second number of target signaling record information, wherein the terminals in the second number of target signaling record information have the same IMEI but different IMSI.

[0063] In the embodiment of the present application, generally speaking, the USIM card used by the terminal to access the mobile network at the same time is unique, that is, when the terminal accesses the mobile network, the IMEI and IMSI of the terminal in the signaling record information are one-to-one corresponding.

[0064] In an embodiment of the present application, after obtaining the signaling record information of the terminal accessing the mobile network, when the terminal accesses the network, the terminal with a one-to-one correspondence between IMEI and IMSI can be considered as a legal terminal. Therefore, by setting the same IMEI and different IMSI of the terminal accessing the network as the screening condition, a first number of signaling record information of the terminal is screened to obtain a second number of screened signaling record information, and the screened signaling record information is used as the target signaling record information. It can be considered that there may be illegal terminals in the target signaling record information.

[0065] Optionally, in order to reduce errors in the screening process, when screening the signaling record information of the terminal accessing the mobile network, the screening can be performed in units of days, that is, the signaling record information of the terminal with the same IMEI but different IMSI when accessing the network every day is obtained.

[0066] S203: Determine the authentication delay value of the terminal and the type of the terminal according to the target signaling record information.

[0067] In the embodiment of the present application, the authentication delay value refers to the time required for the terminal to determine the legitimacy of the user's USIM card when accessing the network, and the type of the terminal refers to the specific model of the terminal, such as X mobile phone XX, or X IoT device XX.

[0068] In an embodiment of the present application, the analysis device can determine the authentication delay value of the terminal by the first interaction time between the terminal and the network in the target signaling record information, and determine the type of the terminal by the IMEI of the terminal in the target signaling record information.

[0069] S204: When the authentication delay value of the terminal and the type of the terminal meet preset conditions, determine that the terminal is an abnormal terminal, and restrict network access to the abnormal terminal.

[0070] In an embodiment of the present application, the authentication delay value for a legitimate terminal accessing a mobile network is usually small, and an illegal terminal accessing the network usually accesses the network through an IoT device equipped with a copied user's USIM. Therefore, preset conditions can be set based on the above conditions. For example, a terminal with an authentication delay value exceeding 2 seconds and a terminal type of IoT is determined to be an abnormal terminal.

[0071] In the embodiment of the present application, after an abnormal terminal is determined, the IMEI and IMSI of the terminal may be sent to the mobile network so that the network can restrict access to the terminal using the IMEI and IMSI.

[0072] The abnormal terminal processing method provided by the embodiment of the present application obtains the signaling record information of the terminal accessing the mobile network, the signaling record information is used to indicate the mobile network access event of the terminal, the signaling record information includes the IMEI and IMSI of the terminal, and the first number of signaling record information of the terminal is screened to obtain the second number of target signaling record information, wherein the IMEI of the terminal in the second number of target signaling record information is the same and the IMSI is different, and the authentication delay value of the terminal and the type of the terminal are determined according to the target signaling record information. When the authentication delay value of the terminal and the type of the terminal meet the preset conditions, the terminal is determined to be an abnormal terminal, and the network access of the abnormal terminal is restricted. The abnormal terminal can be identified based on the signaling record information of the terminal accessing the network, and the access of the abnormal terminal to the network can be restricted, thereby improving the ability to protect the user's network data security in scenarios where EIR is not deployed.

[0073] Figure 3 Schematic diagram of the process of handling abnormal terminals provided in the embodiment of the present application Figure 2 ,exist Figure 2 Based on the embodiment shown, the method for processing abnormal terminals provided in the embodiment of the present application is further described. Figure 3 As shown, the following steps are included:

[0074] S301: Acquire signaling record information of a terminal accessing a network.

[0075] In an embodiment of the present application, the analysis device can interact with the signaling collection system to obtain signaling record information of the terminal accessing the network.

[0076] Specifically, the signaling record of the terminal accessing the mobile network is queried in the signaling collection system at preset time intervals to obtain a query result; the query result is written into a preset signaling record table to obtain signaling record information.

[0077] Exemplarily, the analysis device can query the signaling records of the terminal accessing the mobile network from the signaling collection system at intervals of 24 hours to obtain the query results. To ensure accurate analysis of the query results, the embodiment of the present application pre-sets a signaling record table, in which the data filling area is divided according to the signaling information required to identify abnormal devices, for example, network access time, IMSI, IMEI, cell code, message type, etc.

[0078] After the analysis device obtains the signaling record of the terminal accessing the mobile network, it can fill the obtained signaling record into the signaling record table according to the signaling record required in the signaling record table to obtain signaling record information.

[0079] S302: Filter a first amount of signaling record information of the terminal to obtain a second amount of target signaling record information.

[0080] The implementation of S302 in the embodiment of the present application is similar to Figure 2 The implementation of S202 is similar and will not be repeated here.

[0081] S303: Determine the authentication delay value of the terminal according to the target signaling record information.

[0082] In an embodiment of the present application, the authentication delay value of the terminal can be determined based on the time when the terminal first accesses the mobile network.

[0083] Specifically, the authentication delay value of the terminal is determined according to the time when the terminal sends the identity authentication request to the mobile network and the time when the mobile network sends the identity authentication response to the terminal in the target signaling record information.

[0084] Exemplarily, the time corresponding to the AUTHENTICATION REQUEST of the terminal accessing the network minus the time corresponding to the AUTHENTICATION RESPONSE is used as the authentication delay value of the terminal.

[0085] Optionally, after obtaining the authentication delay value of the terminal, a new field may be added to the target signaling record information to write the authentication delay value of the corresponding terminal.

[0086] S304: Determine the type of the terminal according to the target signaling record information.

[0087] In the embodiment of the present application, the analysis device can determine the type of the terminal according to the IMEI of the terminal.

[0088] Specifically, the type allocation code of the terminal is obtained according to the IMEI of the terminal, and the type of the terminal is obtained in the terminal type information table. The terminal type information table stores the correspondence between the type allocation code of the terminal and the type of the terminal.

[0089] For example, the IMEI of a terminal generally consists of 15 digits, divided into 4 parts. The first part is 6 digits, which is the type allocation code of the terminal, indicating the type of the terminal. The second part is 2 digits, which is the assembly number of the terminal, indicating the origin of the terminal. The third part is 6 digits, which is the factory serial number or serial number of the terminal, indicating the production sequence number of the terminal. The fourth part is 1 digit, which represents the check code of the terminal.

[0090] The analysis device extracts the first 6 digits of the terminal's IMEI to obtain the terminal's type allocation code, searches for the type allocation code in a preset terminal type information table, and determines the terminal's type.

[0091] S305: Determine an abnormal terminal according to the authentication delay value of the terminal and the type of the terminal.

[0092] In the embodiments of this application, based on analysis of actual network cases, abnormal terminals are generally IoT terminals. The average authentication delay for normal terminals in existing networks is approximately 200 milliseconds. In scenarios where a duplicate card is logged in using an IoT terminal, the authentication delay is consistently greater than 2 seconds. Therefore, after obtaining the terminal's authentication delay value and terminal type, it is possible to determine whether there is an abnormal terminal.

[0093] Specifically, if the terminal's authentication delay value is greater than a preset time length and the terminal type is an IoT device, the terminal is determined to be an abnormal terminal. For example, the preset time length can be 2 seconds or 1.5 seconds.

[0094] S306: Restrict mobile network access to abnormal terminals.

[0095] In an embodiment of the present application, after an abnormal terminal is determined, network access restrictions can be imposed on the abnormal terminal to improve user data security.

[0096] In the embodiment of the present application, the abnormal terminal can access the network through the USIM card of the local network user or through the USIM card of the roaming user of the other network. Therefore, there are two possible ways to implement mobile network access for the abnormal terminal:

[0097] The first possible implementation:

[0098] If the abnormal terminal is determined to be a local network user based on its IMSI, the IMSI and tracking area code of the abnormal terminal will be recorded in the MME of the mobile network so that the MME can restrict network access to the abnormal terminal. The tracking area code is determined by the cell code.

[0099] In the embodiment of the present application, the terminal's IMSI is stored in the user's USIM card and consists of three parts: the first part is the Mobile Country Code (MCC), which is 3 digits and is used to identify the user's country of origin. The second part is the Mobile Network Number (MNC), which is 2-3 digits and is used to identify the mobile communication network to which the user belongs, such as China Unicom, China Mobile, China Telecom, and China Railway Communications. The third part is the Mobile Subscriber Identification Number (MSIN), which is 10 digits and is used to identify a mobile user within a specific mobile communication network.

[0100] In an embodiment of the present application, the analysis device analyzes the abnormal terminal's IMSI to determine whether the user corresponding to the abnormal terminal is a local network user. If so, the abnormal terminal's IMSI and tracking area code are sent to the mobile network's MME, so that the MME can restrict the abnormal terminal's network access. The tracking area code is used to record the area where the abnormal terminal is located and can be determined by the abnormal terminal's cell code. In simple terms, restricting the abnormal terminal's network access can be done by restricting the terminal (IMEI) from using the IMSI to access the network in the area where the terminal is located.

[0101] The second possible implementation is:

[0102] The IMSI of the abnormal terminal is sent to the foreign network operator; and a response message is received from the foreign network operator, where the response message is used to indicate whether the foreign network operator can restrict the network access of the abnormal terminal based on the IMEI of the abnormal terminal.

[0103] If the foreign network operator cannot restrict the network access of the abnormal terminal through the IMEI of the abnormal terminal, the IMSI and tracking area code of the abnormal terminal will be recorded in the MME of the mobile network.

[0104] In an embodiment of the present application, when the analysis device determines that the user corresponding to the abnormal terminal is a heterogeneous network user, the IMSI of the abnormal terminal is sent to the heterogeneous network operator, and the heterogeneous network operator determines whether the network access of the abnormal terminal can be restricted through MEI (whether the heterogeneous network operator has deployed EIR).

[0105] If feedback is received from a foreign network operator that EIR is not deployed, the same restriction policy as for users of this network will be adopted, which will not be repeated here.

[0106] The method for handling abnormal terminals provided in an embodiment of the present application obtains signaling record information of the terminal accessing the network, filters a first quantity of signaling record information of the terminal, obtains a second quantity of target signaling record information, determines the terminal's authentication delay value based on the target signaling record information, determines the terminal's type based on the target signaling record information, determines an abnormal terminal based on the terminal's authentication delay value and the terminal's type, and restricts mobile network access for the abnormal terminal. Abnormal terminals are identified by using the IMEI and IMSI of the terminal accessing the mobile network, and their access to the network is restricted, thereby improving the ability to protect user network data security in scenarios where an EIR is not deployed.

[0107] Based on the above-mentioned embodiment of the method for processing abnormal terminals, the embodiment of the present application further provides a device for processing abnormal terminals.

[0108] Figure 4 A schematic diagram of the structure of the abnormal terminal processing device 40 provided in the embodiment of the present application is shown as follows: Figure 4 Shown, including:

[0109] The acquisition module 401 is used to acquire signaling record information of a terminal accessing a mobile network. The signaling record information is used to indicate a mobile network access event of the terminal. The signaling record information includes the IMEI and IMSI of the terminal.

[0110] The screening module 402 is configured to screen the first number of signaling record information of the terminal to obtain a second number of target signaling record information, wherein the terminals in the second number of target signaling record information have the same IMEI but different IMSI.

[0111] The first determining module 403 is configured to determine the authentication delay value of the terminal and the type of the terminal according to the target signaling record information.

[0112] The second determining module 404 is configured to determine that a terminal is an abnormal terminal and restrict network access to the abnormal terminal when the authentication delay value of the terminal and the type of the terminal meet preset conditions.

[0113] The acquisition module 401 is further configured to query the signaling record of the terminal accessing the mobile network in the signaling collection system at preset time intervals to obtain query results; and write the query results into a preset signaling record table to obtain signaling record information.

[0114] Optionally, the first determining module 403 is further configured to determine the authentication delay value of the terminal according to the time when the terminal sends the identity authentication request to the mobile network and the time when the mobile network sends the identity authentication response to the terminal in the target signaling record information.

[0115] Optionally, the first determining module 403 is further configured to obtain a terminal type allocation code according to the terminal IMEI, and obtain the terminal type from a terminal type information table, wherein the terminal type information table stores a correspondence between the terminal type allocation code and the terminal type.

[0116] Optionally, the second determining module 404 is further configured to determine that the terminal is an abnormal terminal when the authentication delay value of the terminal is greater than a preset duration and the type of the terminal is an Internet of Things device.

[0117] Optionally, the second determination module 404 is further used to record the IMSI and tracking area code of the abnormal terminal at the MME of the mobile network if the abnormal terminal is determined to be a user of this network based on the IMSI of the abnormal terminal, so that the MME can restrict the network access of the abnormal terminal, and the tracking area code is determined by the cell code.

[0118] Optionally, the second determination module 404 is further used to send the IMSI of the abnormal terminal to the alien network operator if it is determined that the abnormal terminal is a heterogeneous network user based on the IMSI of the abnormal terminal; receive a response message sent by the alien network operator, wherein the response message is used to indicate whether the alien network operator can restrict the network access of the abnormal terminal through the IMEI of the abnormal terminal; if the alien network operator cannot restrict the network access of the abnormal terminal through the IMEI of the abnormal terminal, the IMSI and tracking area code of the abnormal terminal are recorded at the MME of the mobile network.

[0119] The abnormal terminal processing device provided in the embodiment of the present application can execute the technical solution of the above-mentioned abnormal terminal processing method embodiment. Its implementation principle and technical effects are similar and will not be repeated here.

[0120] Figure 5 This is a schematic diagram of the structure of the abnormal terminal processing electronic device provided in the embodiment of the present application. Figure 5 As shown, the abnormal terminal processing electronic device 50 provided in this embodiment may include:

[0121] Processor 501.

[0122] The memory 502 is used to store executable instructions of the terminal device.

[0123] Among them, the processor is configured to execute the technical solution of the above-mentioned abnormal terminal processing method embodiment by executing executable instructions. Its implementation principle and technical effect are similar and will not be repeated here.

[0124] In an embodiment of the present application, a computer-readable storage medium is further provided, on which a computer program is stored. When the computer program is executed by a processor, the technical solution of the above-mentioned abnormal terminal processing method embodiment is implemented. Its implementation principle and technical effect are similar and will not be repeated here.

[0125] In one possible implementation, a computer-readable medium may include random access memory (RAM), read-only memory (ROM), compact disc read-only memory (CD-ROM) or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium designed to carry or store the desired program code in the form of instructions or data structures and accessible by a computer. Moreover, any connection is appropriately referred to as a computer-readable medium. For example, if a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL) or wireless technologies (such as infrared, radio and microwave) are used to transmit software from a website, server or other remote source, the coaxial cable, fiber optic cable, twisted pair, DSL or wireless technologies such as infrared, radio and microwave are included in the definition of medium. Disk and disc as used herein include optical disc, laser disc, optical disc, digital versatile disc (DVD), floppy disk and Blu-ray disc, where disks typically reproduce data magnetically, while optical discs reproduce data optically using lasers. Combinations of the above should also be included within the scope of computer-readable media.

[0126] A computer program product is also provided in an embodiment of the present application, including a computer program. When the computer program is executed by a processor, the technical solution of the above-mentioned abnormal terminal processing method embodiment is implemented. Its implementation principle and technical effects are similar and will not be repeated here.

[0127] In the specific implementation of the above-mentioned terminal device or server, it should be understood that the processor can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of the present application can be directly implemented as a hardware processor, or can be implemented by a combination of hardware and software modules in the processor.

[0128] Those skilled in the art will appreciate that all or part of the steps of any of the above method embodiments may be accomplished by hardware associated with program instructions. The aforementioned program may be stored in a computer-readable storage medium, and when the program is executed, all or part of the steps of the above method embodiments are executed.

[0129] If the technical solution of the present application is implemented in the form of software and sold or used as a product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the technical solution of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium and includes a computer program or several instructions. The computer software product enables a computer device (which can be a personal computer, server, network device or similar electronic device) to perform all or part of the steps of the method described in the embodiment of the present application.

[0130] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for handling abnormal terminals, characterized in that: include: Acquire signaling record information of a terminal accessing a mobile network, where the signaling record information is used to indicate a mobile network access event of the terminal, and the signaling record information includes the IMEI and IMSI of the terminal; Filtering the first quantity of signaling record information of the terminal to obtain a second quantity of target signaling record information, wherein the terminals in the second quantity of target signaling record information have the same IMEI but different IMSI; Determining an authentication delay value of the terminal and a type of the terminal according to the target signaling record information; When the authentication delay value of the terminal and the type of the terminal meet preset conditions, the terminal is determined to be an abnormal terminal, and network access restrictions are performed on the abnormal terminal.

2. The method according to claim 1, characterized in that The signaling record information also includes the time when the terminal accesses the mobile network, and determining the authentication delay value of the terminal according to the target signaling record information includes: The authentication delay value of the terminal is determined according to the time when the terminal sends the identity authentication request to the mobile network and the time when the mobile network sends the identity authentication response to the terminal in the target signaling record information.

3. The method according to claim 1, characterized in that The determining the type of the terminal according to the target signaling record information includes: The type allocation code of the terminal is obtained according to the IMEI of the terminal, and the type of the terminal is obtained in a terminal type information table, wherein the terminal type information table stores a correspondence between the type allocation code of the terminal and the type of the terminal.

4. The method according to any one of claims 1 to 3, characterized in that When the authentication delay value of the terminal and the type of the terminal meet preset conditions, determining that the terminal is an abnormal terminal includes: When the authentication delay value of the terminal is greater than a preset duration and the type of the terminal is an Internet of Things device, the terminal is determined to be an abnormal terminal.

5. The method according to claim 4, characterized in that The signaling record information further includes a cell code of the terminal, and the restricting network access of the abnormal terminal includes: If the abnormal terminal is determined to be a local network user based on its IMSI, the IMSI and tracking area code of the abnormal terminal are recorded at the MME of the mobile network so that the MME can restrict network access to the abnormal terminal. The tracking area code is determined by the cell code.

6. The method according to claim 5, characterized in that If it is determined according to the IMSI of the abnormal terminal that the abnormal terminal is a user of a different network, the method further includes: Sending the IMSI of the abnormal terminal to the foreign network operator; receiving a response message sent by the foreign network operator, wherein the response message is used to indicate whether the foreign network operator can restrict network access of the abnormal terminal according to the IMEI of the abnormal terminal; If the foreign network operator cannot restrict the network access of the abnormal terminal through the IMEI of the abnormal terminal, the IMSI and the tracking area code of the abnormal terminal are recorded at the MME of the mobile network.

7. The method according to claim 1, characterized in that The obtaining of signaling record information of the terminal accessing the network includes: querying the signaling record of the terminal accessing the mobile network in the signaling collection system at a preset time interval to obtain a query result; The query result is written into a preset signaling record table to obtain the signaling record information.

8. A device for processing abnormal terminals, characterized in that: include: An acquisition module is used to acquire signaling record information of a terminal accessing a mobile network, wherein the signaling record information is used to indicate a mobile network access event of the terminal, and the signaling record information includes the IMEI and IMSI of the terminal; a screening module, configured to screen the first quantity of signaling record information of the terminal to obtain a second quantity of target signaling record information, wherein the IMEIs of the terminals in the second quantity of target signaling record information are the same but the IMSIs are different; A first determining module is configured to determine an authentication delay value of the terminal and a type of the terminal according to the target signaling record information; The second determining module is configured to determine that the terminal is an abnormal terminal and restrict network access to the abnormal terminal when the authentication delay value of the terminal and the type of the terminal meet preset conditions.

9. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to execute the computer program to implement the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that A computer program is stored thereon, and the computer program is executed by a processor to implement the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method and system for determining legal terminal

    CN102014388A

  • Method and system for preventing illegal terminal from accessing as well as terminal

    CN102056169A