5g commercial network-based sinking private network data security management method and system and medium
By using the private network data security management system in the 5G commercial network, the card management system generates and distributes keys, and the customer relationship management network performs authentication control, thus solving the problem of low-cost security management of commercial 5G customized networks and realizing security isolation and centralized management.
Patent Information
- Application Number
- CN202211741484.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-31
- Publication Date
- 2026-03-03
- Estimated Expiration
- 2042-12-31
AI Technical Summary
Existing management methods for commercial 5G customized networks cannot achieve low-cost data security management and pose security risks and high management costs.
By using the data security management system of the private network in the 5G commercial network, the card management system generates the initial system key and the encryption verification key, and the customer relationship management network performs authentication and access control to achieve secure access for terminal devices.
It has enabled centralized management of commercial 5G customized networks, reduced data security management costs, and solved the security isolation problem between customized networks and commercial networks, ensuring the stability and security of park services.
Smart Images

Figure CN116321138B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security technology, and in particular to a method, system and medium for managing data security in a private network based on a 5G commercial network. Background Technology
[0002] In commercial 5G customized network projects, there is often a need for the deployment of UDM (Unified Data Management) functionality. However, existing technologies have failed to provide a reasonable and secure solution for reusing resources such as SIM card management, authentication processes, and automated activation from commercial networks. The lack of compliant management makes it impossible to meet the commercial needs of multiple independent 5G customized networks in current applications. Traditionally, there are two approaches to handling SIM cards in 5G customized networks: one disregards security, sharing the SIM card management system of the customized network with the centralized commercial network's SIM card management system, including key sharing; the other prioritizes security, completely customizing the SIM card management system of the customized network, eliminating reliance on any overall planning and avoiding SIM card burning and issuance from the centralized SIM card management system and SIM card vendors, with all parameters customized. The former approach suffers from extremely high security risks. If the security defenses of the customized network are breached, the centralized commercial network is immediately compromised. Since the customized network is deployed on the customer's campus side, it is highly vulnerable to attack. Therefore, this approach is currently not used in any projects. The latter approach has the disadvantage of not being able to enjoy any of the advantages of centralized management. Although protection for centralized commercial networks can be guaranteed, the application cost is high. Therefore, existing management methods for commercial 5G customized networks suffer from the problem of being unable to achieve low-cost data security management. Summary of the Invention
[0003] This invention provides a method, system, and medium for data security management of a private network based on a 5G commercial network, aiming to solve the problem of the inability to perform low-cost data security management in existing management methods for commercial 5G customized networks.
[0004] In a first aspect, embodiments of the present invention provide a data security management method for a private network based on a 5G commercial network. This method is applied to a data security management system for a private network based on a 5G commercial network. The system includes a customer relationship management network (CRM), a card management system, a user subscription data synchronization center, and a service subnet. A network connection is established between the CRM and the card management system to transmit data information. A network connection is established between the service subnet and the user subscription data synchronization center or the CRM to transmit data information. A network connection is established between the user subscription data synchronization center and the CRM to transmit data information. The method includes:
[0005] If the input key distribution instruction is received, the card management system generates an initial system key corresponding to the key distribution instruction and sends it to the customer relationship management network;
[0006] The customer relationship management network distributes the system initial key to the corresponding terminal devices in the service subnet;
[0007] The card management system generates an encrypted verification key corresponding to the pre-stored user contract data and sends it to the customer relationship management network.
[0008] If an activation message is received from the terminal device, the customer relationship management network authenticates the activation message based on the encryption verification key and obtains an authentication result indicating whether the authentication is successful.
[0009] If the authentication result is successful, the customer relationship management network sends an access command to the corresponding service subnet to control the service subnet to access the terminal device.
[0010] Secondly, embodiments of the present invention provide a data security management system for a private network based on a 5G commercial network. This system includes a customer relationship management (CRM) network, a card management system, a user subscription data synchronization center, and a service subnet. The CRM network and the card management system establish network connections to transmit data information. The service subnet establishes network connections with the user subscription data synchronization center or the CRM network to transmit data information. The user subscription data synchronization center establishes network connections with the CRM network to transmit data information. The system includes a system initial key distribution unit and an encryption verification key sending unit configured in the card management system, and a first sending unit, an authentication unit, and an access instruction sending unit configured in the CRM network.
[0011] The system initial key distribution unit is used to generate a system initial key corresponding to the key distribution instruction and send it to the customer relationship management network if it receives the input key distribution instruction.
[0012] The first sending unit is used to distribute the system initial key to the corresponding terminal device in the service subnet;
[0013] The encryption verification key sending unit is used to generate an encryption verification key corresponding to the pre-stored user contract data and send it to the customer relationship management network.
[0014] The authentication unit is used to authenticate the activation information according to the encryption verification key if it receives activation information sent from the terminal device, and obtain an authentication result indicating whether the authentication is successful.
[0015] The access instruction sending unit is configured to send an access instruction to the corresponding service subnet if the authentication result is successful, so as to control the service subnet to access the terminal device.
[0016] Thirdly, embodiments of the present invention also provide a data security management system for a private network based on a 5G commercial network. The system includes a customer relationship management network, a card management system, a user contract data synchronization center, and a service subnet. The card management system includes a first memory, a first processor, and a first computer program stored in the first memory and executable on the first processor. The customer relationship management network includes a second memory, a second processor, and a second computer program stored in the second memory and executable on the second processor. When the first processor executes the first computer program and the second processor executes the second computer program, they jointly implement the data security management method for a private network based on a 5G commercial network as described in the first aspect above.
[0017] Fourthly, embodiments of the present invention also provide a computer-readable storage medium, wherein the computer-readable storage medium stores a first computer program and a second computer program, which together implement the data security management method for a private network based on a 5G commercial network as described in the first aspect above when the first computer program is executed by a first processor and the second computer program is executed by a second processor.
[0018] This invention provides a method, system, and medium for data security management of a private network based on a 5G commercial network. Upon receiving a key distribution instruction, the card management system generates an initial system key and sends it to the customer relationship management network (CRM). The CRM then distributes the initial system key to the corresponding terminal device. The card management system generates an encryption verification key corresponding to the user's subscription data and sends it to the CRM. The CRM authenticates the activation information from the terminal device. If the authentication is successful, an access instruction is sent to the corresponding service subnet to control the service subnet to connect the terminal device. This method flexibly selects the sending of the initial system key and the encryption verification key according to different service subnet types, making it applicable to both centralized and private service subnets. It solves the security isolation problem between customized networks and commercial networks while achieving centralized management of commercial 5G customized networks and reducing the data security management cost of commercial 5G customized networks. Attached Figure Description
[0019] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of the present invention. For those skilled in the art, they can also...
[0020] Other figures can be derived from these figures.
[0021] Figure 1 A flowchart illustrating the data security management method for a private network based on a 5G commercial network provided in an embodiment of the present invention;
[0022] Figure 2 A schematic diagram illustrating an application scenario of the data security management method for a private network based on a 5G commercial network provided in an embodiment of the present invention;
[0023] Figure 3 This is a schematic diagram of a sub-process of the data security management method for a private network based on a 5G commercial network provided in an embodiment of the present invention;
[0024] Figure 4 This is a schematic diagram of another sub-process of the data security management method for private networks based on 5G commercial networks provided in an embodiment of the present invention;
[0025] Figure 5 This is another sub-process diagram of the data security management method for a private network based on a 5G commercial network provided in an embodiment of the present invention;
[0026] Figure 6 This is another sub-process diagram of the data security management method for a private network based on a 5G commercial network provided in an embodiment of the present invention;
[0027] Figure 7 This is a schematic diagram of the last sub-process of the data security management method for a private network based on a 5G commercial network provided in an embodiment of the present invention;
[0028] Figure 8 This is a schematic diagram of another sub-process of the data security management method for a private network based on a 5G commercial network provided in an embodiment of the present invention.
[0029] Figure 9 A schematic block diagram of a private network data security management system based on a 5G commercial network provided in an embodiment of the present invention;
[0030] Figure 10 A schematic block diagram of a computer device provided for an embodiment of the present invention. Detailed Implementation
[0031] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0032] It should be understood that, when used in this specification and the appended claims, the terms "comprising" and "including" indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.
[0033] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.
[0034] It should also be further understood that the term "and / or" as used in this specification and the appended claims refers to any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.
[0035] Please see Figure 1 and Figure 2 , Figure 1 This is a flowchart illustrating the data security management method for a private network based on a 5G commercial network provided in an embodiment of the present invention. Figure 2 This is a schematic diagram illustrating an application scenario of the data security management method for a private network based on a 5G commercial network provided in this embodiment of the invention. This method is applied in a data security management system 10 based on a 5G commercial network. System 10 includes a customer relationship management network 11, a card management system 12, a user subscription data synchronization center 13, and a service subnet 14. A network connection is established between the customer relationship management network 11 and the card management system 12 to transmit data information. A network connection is established between the service subnet 14 and the user subscription data synchronization center 13 or the customer relationship management network 11 to transmit data information. A network connection is also established between the user subscription data synchronization center 13 and the customer relationship management network 11 to transmit data information. A terminal device 15 accesses the 5G commercial network through the service subnet 14. The terminal device is a terminal device capable of accessing the 5G network, such as a smartwatch, smart speaker, or smartphone, etc., a wireless terminal access device (CPE). Figure 1 As shown, the method includes steps S110 to S150.
[0036] S110. If the input key distribution instruction is received, the card management system generates an initial system key corresponding to the key distribution instruction and sends it to the customer relationship management network.
[0037] If a key distribution instruction is received, the card management system generates an initial system key corresponding to the key distribution instruction and sends it to the customer relationship management network. The card management system can receive key distribution instructions; if it receives such an instruction, it generates an initial system key corresponding to the key distribution instruction and sends it to the customer relationship management network.
[0038] In one embodiment, such as Figure 3 As shown, step S110 includes sub-steps S111, S112 and S113.
[0039] S111. Determine whether the key distribution instruction is a first distribution type; S112. If the key distribution instruction is a first distribution type, obtain the pre-stored large network number segment key and the dedicated user key corresponding to the key distribution instruction, combine them as the corresponding system initial key, and send them; S113. If the key distribution instruction is not a first distribution type, obtain the dedicated user key corresponding to the key distribution instruction as the corresponding system initial key and send it.
[0040] The card management system can automatically trigger a key distribution command when issuing a card. This command includes a corresponding distribution type, which can be used to categorize the key system into two types, distributing them to different 5G commercial networks. Specifically, it can determine whether the key distribution command is the first distribution type. If it is, it retrieves the pre-stored main network number segment key and the corresponding dedicated user key to obtain the system's initial key. If the command is not the first distribution type, it directly retrieves the corresponding dedicated user key as the system's initial key and sends it.
[0041] For example, to differentiate between multiple key systems, the key system related to the large network number range for centralized commercial use is referred to as K4, and the key system used for customer-customized networks is referred to as K4+X (X is randomly selected, such as K4P). Service subnets can be divided into centralized service subnets and decentralized service subnets. Centralized service subnets obtain two key systems. If the key distribution instruction is of the first distribution type, corresponding to the centralized service subnet, then K4+K4P is obtained as the initial system key, where K4 is used for the large network number range and K4P is used for the dedicated user's decentralized customized network number card. Decentralized service subnets obtain only one key system. If the key distribution instruction is not of the first distribution type, corresponding to the decentralized service subnet, then K4P is obtained as the initial system key. The decentralized service subnet uses K4P for emergency use.
[0042] S120, The customer relationship management network distributes the system initial key to the corresponding terminal devices in the service subnet.
[0043] The Customer Relationship Management (CRM) network distributes the initial system key to the corresponding terminal devices in the service subnet. The initial system key, distributed through the CRM network to the corresponding terminal devices in the service subnet, contains at least one key system (K4+K4P, or K4P). The terminal device can be configured with a UDM (Unified Data Management) module corresponding to the service subnet; for example, a sinking UDM can be configured for terminal devices in the sinking service subnet. The UDM decrypts the data using the pre-written key K4 to obtain the corresponding decryption information. During the entire card data transmission process, the processing of key K4 is crucial for the secure processing of the entire card data. If the UDM is sinking to the customer side, the K4 value pre-set on the customer-side UDM needs to be distinguished from the K4 value on the commercial network UDM, thereby achieving network isolation between the centralized service subnet and the sinking service subnet.
[0044] The key systems between the sinking service subnets are not interchangeable. For example, the dedicated key system for sinking service subnet A is K4A, and the dedicated key system for sinking service subnet B is K4B.
[0045] S130, The card management system generates an encrypted verification key corresponding to the pre-stored user contract data and sends it to the customer relationship management network.
[0046] The card management system generates an encrypted verification key corresponding to the pre-stored user contract data and sends it to the customer relationship management network. After sending the initial system key, the card management system can also generate a corresponding encrypted verification key based on the pre-stored user contract data and send it to the customer relationship management network.
[0047] A user subscription data synchronization center is added between the sinking service subnet and the customer relationship management network. The customer relationship management network can then distribute user subscription data to the corresponding managed sinking service subnets via signaling forwarding (signaling interoperability). The user subscription data synchronization center will effectively achieve topology hiding and secure signaling isolation of the centralized commercial network (centralized service subnet), as well as signaling rate limiting / circuit breaking, preventing faults or security risks in the sinking service subnet from being transmitted to the internal structure of the centralized 5GC, thus ensuring the operational security of the centralized commercial network's 5GC.
[0048] In one embodiment, such as Figure 4 As shown, step S130 includes sub-steps S131 and S132.
[0049] S131. Encrypt the verification key corresponding to the user's contract data according to the system initial key to obtain the corresponding encrypted verification key; S132. Send the encrypted verification key to the customer relationship management network corresponding to the management network code according to the management network code of the user's contract data.
[0050] Specifically, the verification key corresponding to the user's contract data can be encrypted using the system's initial key to obtain an encrypted verification key. This encrypted verification key is then sent to the corresponding customer relationship management network (CRM) based on the management network code in the user's contract data. The verification key includes OPC and KI information corresponding to the user's contract data. This OPC and KI information can be encrypted using the DES algorithm, with the initial system key used for encryption. Upon receiving the encrypted verification key, it is decrypted using a corresponding algorithm, again with the initial system key used for decryption.
[0051] The management network code is a unique code that corresponds to each customer relationship management network. Different customer relationship management networks can be identified and distinguished through the management network code.
[0052] In one embodiment, such as Figure 5 As shown, steps S1310 and S1320 are included before step S131.
[0053] S1310. Determine the corresponding service type based on the service subnet code of the user's contract data; S1320. Obtain a set of verification keys corresponding to the user's contract data based on the service type, wherein the verification keys are either centralized verification keys or decentralized verification keys.
[0054] Specifically, the user's contract data includes a service subnet code, which can be used to determine the corresponding service type. For example, the service type can be either a centralized service type or a decentralized service type. The centralized service type corresponds to a centralized service subnet, and the decentralized service type corresponds to a decentralized service subnet.
[0055] A set of verification keys corresponding to the user's contracted data can be obtained based on the service type. If the service type is a centralized service type, the obtained verification key is the centralized verification key; if the service type is a decentralized service type, the obtained verification key is the decentralized verification key.
[0056] In one embodiment, such as Figure 6 As shown, step S1320 includes sub-steps S1321, S1322, S1323 and S1324.
[0057] S1321. Obtain the corresponding operator root key based on the operator information in the user subscription data; S1322. Obtain the corresponding authentication key based on the service type and the service subnet code in the user subscription data; S1323. Combine the operator root key and the authentication key according to the preset calculation rules to obtain the corresponding first verification key; S1324. Combine the first verification key and the authentication key to generate a set of corresponding verification keys.
[0058] The corresponding operator root key can be obtained based on the service type and operator information in the user's subscription data. The operator root key can be represented by OP, which is a 128-bit configurable field. In practical applications, this means that each province's 5G2B private network has a unique OP value. Further, the corresponding authentication key is obtained based on the service type and service subnet code. The authentication key can be represented by Ki, with different service subnet codes and service types corresponding to different authentication keys, each a 128-bit string. The operator root key and authentication key can be combined using calculation rules to obtain the first verification key, which is the OPC information and also a 128-bit string. Combining the first verification key with the authentication key generates a corresponding set of verification keys. In the 5G HE AV five-tuple required for authentication in UDM, the most important input information is the OPC and KI information; therefore, the security of the OPC and KI information must be ensured.
[0059] Because of the pursuit of high uniformity in card parameter management between the decentralized service subnet and the centralized service subnet, the centralized 5GC (centralized service subnet) needs to share a single set of OPC and KI with the decentralized 5GC (decentralized service subnet). This ensures a unified interface for card parameter management, authentication processes, and service activation. Only in this way can all lightweight 5GC network elements be decentralized within the enterprise, with production business data residing within the enterprise campus via the data network element UPF. Simultaneously, the signaling network elements AMF / SMF / UDM deployed within the campus for emergencies ensure that local business operations within the enterprise network remain unaffected in the event of a major network outage (communication interruption), providing the enterprise with better data and business isolation and reliability. The decentralized UDM and the centralized UDM must ensure card parameter uniformity while guaranteeing complete isolation of the OPC and KI of the two networks, preventing cross-referencing.
[0060] S140. If activation information is received from the terminal device, the customer relationship management network authenticates the activation information according to the encryption verification key and obtains an authentication result indicating whether the authentication is successful.
[0061] If an activation message is received from the terminal device, the Customer Relationship Management Network (CRM) authenticates the activation message using the encrypted verification key to determine whether the authentication is successful. When a user installs a SIM card in a device, the SIM card must first be authenticated. Specifically, the terminal device can send activation information corresponding to the SIM card to the CRM. The CRM authenticates the activation message using a pre-stored encrypted verification key and determines whether the authentication is successful. If the authentication is successful, the terminal device can use the SIM card to access the corresponding service subnet; if the authentication fails, the terminal device is not allowed to access the corresponding service subnet.
[0062] In one embodiment, such as Figure 7 As shown, step S140 includes sub-steps S141 and S142.
[0063] S141. Decrypt the activation information according to the system initial key to obtain the corresponding activation decryption information; S142. Determine whether the activation decryption information is consistent with the verification key corresponding to the encryption verification key, thereby obtaining the authentication result of whether it passes or fails.
[0064] Specifically, to authenticate the activation information, the activation information can be decrypted using key K4 pre-written into the system's initial key. This yields the corresponding activation decryption information, namely, the decrypted OPC and Ki information. After obtaining the activation decryption information, it is determined whether it matches the verification key corresponding to the encryption verification key. In other words, it is determined whether the decrypted OPC and Ki information matches the originally generated OPC and Ki information. If they match, the authentication is successful; otherwise, the authentication fails.
[0065] S150. If the authentication result is successful, the customer relationship management network sends an access instruction to the corresponding service subnet to control the service subnet to access the terminal device.
[0066] If the authentication result is successful, the CRM network sends an access command to the corresponding service subnet to control the service subnet to connect the terminal device. If the authentication result is successful, the CRM network can send an access command to the corresponding service subnet, and the service subnet registers the terminal device and connects the terminal device to the network.
[0067] In one embodiment, such as Figure 8 As shown, step S150 includes sub-steps S151, S152 and S153.
[0068] S151. Determine whether the service subnet code corresponding to the authentication result matches the first service type; S152. If the authentication result matches the first service type, send an access instruction to the service subnet corresponding to the service subnet code; S153. If the authentication result does not match the first service type, send an access instruction and transmit it through the user subscription data synchronization center to the service subnet corresponding to the service subnet code.
[0069] Specifically, it can be determined whether the service subnet code corresponding to the authentication result matches the first service type. If it matches the first service type, it indicates that the application scenario is a centralized service subnet. In this case, an access command is sent to the service subnet corresponding to the service subnet code, and the access of the terminal device is directly controlled through the centralized service subnet. If it does not match the first service type, an access command is sent to the user subscription data synchronization center. The user subscription data synchronization center forwards the access command to the corresponding service subnet and controls the service subnet to connect the corresponding terminal device.
[0070] By using two or more sets of initial system keys and encryption verification keys for data security management, lightweight 5GC services can be centrally managed, sharing all resources of the commercial network. Furthermore, in the event of a commercial network failure, an emergency switch to the decentralized management plane (emergency UDM / SMF / AMF) can be initiated to ensure uninterrupted service stability within the campus. Moreover, the customized decentralized network for the campus poses no security risks to the commercial network from start to finish.
[0071] In the data security management method for a private network based on a 5G commercial network provided in this embodiment of the invention, upon receiving a key distribution instruction, the card management system generates an initial system key and sends it to the customer relationship management network (CRM). The CRM then distributes the initial system key to the corresponding terminal device. The card management system generates an encryption verification key corresponding to the user's subscription data and sends it to the CRM. The CRM authenticates the activation information from the terminal device. If the authentication result is successful, an access instruction is sent to the corresponding service subnet to control the service subnet to access the terminal device. Through this method, the sending of the initial system key and the encryption verification key can be flexibly selected according to different service subnet types. This method is applicable to both centralized service subnets and private service subnets, solving the security isolation problem between customized networks and commercial networks while achieving centralized management of commercial 5G customized networks and reducing the data security management cost of commercial 5G customized networks.
[0072] This invention also provides a data security management system for a private network based on a 5G commercial network. This system is used to execute any of the aforementioned embodiments of the data security management method for a private network based on a 5G commercial network. Specifically, please refer to... Figure 9 , Figure 9This is a schematic block diagram of a private network data security management system based on a 5G commercial network, provided in an embodiment of the present invention.
[0073] like Figure 9 As shown, the data security management system 10 of the 5G commercial network-based private network includes a customer relationship management network 11, a card management system 12, a user contract data synchronization center 13, and a service subnet 14. The customer relationship management network 11 and the card management system 12 establish a network connection to realize the transmission of data information. The service subnet 14 establishes a network connection with the user contract data synchronization center 13 or the customer relationship management network 11 to realize the transmission of data information. The user contract data synchronization center 13 establishes a network connection with the customer relationship management network 11 to realize the transmission of data information. The system includes a system initial key distribution unit 121 and an encryption verification key sending unit 122 configured in the card management system 12, and a first sending unit 111, an authentication unit 112, and an access instruction sending unit 113 configured in the customer relationship management network 11.
[0074] The system initial key distribution unit 121 is used to generate a system initial key corresponding to the key distribution instruction and send it to the customer relationship management network if it receives the input key distribution instruction.
[0075] The first sending unit 111 is used to distribute the system initial key to the corresponding terminal device in the service subnet.
[0076] The encryption verification key sending unit 122 is used to generate an encryption verification key corresponding to the pre-stored user contract data and send it to the customer relationship management network.
[0077] The authentication unit 112 is used to authenticate the activation information according to the encryption verification key if it receives activation information sent from the terminal device, and obtain an authentication result indicating whether the authentication is successful.
[0078] The access instruction sending unit 113 is used to send an access instruction to the corresponding service subnet if the authentication result is successful, so as to control the service subnet to access the terminal device.
[0079] In the data security management system for a private network based on a 5G commercial network provided in this embodiment of the invention, the aforementioned data security management method for a private network based on a 5G commercial network is applied. Upon receiving a key distribution instruction, the card management system generates an initial system key and sends it to the customer relationship management network (CRM). The CRM then distributes the initial system key to the corresponding terminal device. The card management system generates an encryption verification key corresponding to the user's subscription data and sends it to the CRM. The CRM authenticates the activation information from the terminal device. If the authentication result is successful, an access instruction is sent to the corresponding service subnet to control the service subnet to access the terminal device. Through this method, the sending of the initial system key and the encryption verification key can be flexibly selected according to different service subnet types. This method is applicable to both centralized service subnets and private network service subnets, solving the security isolation problem between customized networks and commercial networks while achieving centralized management of commercial 5G customized networks and reducing the data security management cost of commercial 5G customized networks.
[0080] The aforementioned data security management method for private networks based on 5G commercial networks can be implemented as a computer program. The customer relationship management network and card management system within the data security management system for private networks based on 5G commercial networks can both be implemented as computer devices. This computer program can be used in various ways, such as... Figure 10 It runs on the computer device shown.
[0081] Please see Figure 10 , Figure 10 This is a schematic block diagram of a computer device provided in an embodiment of the present invention. The computer device can be a customer relationship management network and card management system used to execute a data security management method for a private network based on a 5G commercial network to achieve data security management of a commercial 5G customized network.
[0082] See Figure 10 The computer device 500 includes a processor 502, a memory, and a network interface 505 connected via a system bus 501. The memory may include a storage medium 503 and internal memory 504.
[0083] The storage medium 503 can store an operating system 5031 and a computer program 5032. When the computer program 5032 is executed, it enables the processor 502 to execute a data security management method for a private network based on a 5G commercial network. The storage medium 503 can be a volatile storage medium or a non-volatile storage medium.
[0084] The processor 502 provides computing and control capabilities to support the operation of the entire computer device 500.
[0085] The internal memory 504 provides an environment for the computer program 5032 in the storage medium 503 to run. When the computer program 5032 is executed by the processor 502, the processor 502 can execute a data security management method for a private network based on a 5G commercial network.
[0086] The network interface 505 is used for network communication to provide data transmission, including wired and / or wireless network communication. Those skilled in the art will understand that... Figure 10 The structure shown is merely a block diagram of a portion of the structure related to the present invention and does not constitute a limitation on the computer device 500 to which the present invention is applied. The specific computer device 500 may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0087] The processor 502 is used to run the computer program 5032 stored in the memory to implement the corresponding functions in the above-mentioned method for managing the data security of the private network based on the 5G commercial network.
[0088] Those skilled in the art will understand that Figure 10 The embodiments of the computer device shown do not constitute a limitation on the specific configuration of the computer device. In other embodiments, the computer device may include more or fewer components than illustrated, or combine certain components, or have different component arrangements. For example, in some embodiments, the computer device may include only memory and a processor. In such embodiments, the structure and function of the memory and processor are different from those shown. Figure 10 The embodiments shown are consistent and will not be described again here.
[0089] It should be understood that, in this embodiment of the invention, the processor 502 may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.
[0090] In another embodiment of the present invention, a computer-readable storage medium is provided. This computer-readable storage medium may be volatile or non-volatile. The computer-readable storage medium stores a first computer program, a second computer program, or a third computer program, which, when executed by a first processor, a second computer program, and a third computer program, jointly implement the steps included in the above-described method for managing the data security of a private network based on a 5G commercial network.
[0091] Those skilled in the art will readily understand that, for the sake of convenience and brevity, the specific working processes of the devices, apparatuses, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this invention.
[0092] In the embodiments provided by this invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. Units with the same function may be grouped into one unit. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. In addition, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interfaces, devices, or units, or it may be an electrical, mechanical, or other form of connection.
[0093] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of the embodiments of the present invention, depending on actual needs.
[0094] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0095] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a computer-readable storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned computer-readable storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), magnetic disks, or optical disks.
[0096] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A method for managing data security of a 5G commercial network-based private network, characterized in that, The method is applied to a data security management system, the system comprising a customer relationship management network, a card management system, a user subscription data synchronization center and a service subnetwork, a network connection being established between the customer relationship management network and the card management system to realize transmission of data information, a network connection being established between the service subnetwork and the user subscription data synchronization center or the customer relationship management network to realize transmission of data information, a network connection being established between the user subscription data synchronization center and the customer relationship management network to realize transmission of data information, the method comprising: If the input key distribution instruction is received, the card management system generates a system initial key corresponding to the key distribution instruction and sends it to the customer relationship management network; The customer relationship management network distributes the system initial key to the corresponding terminal device in the service subnetwork; The card management system generates an encryption verification key corresponding to the pre-stored user subscription data and sends it to the customer relationship management network; If the activation information sent from the terminal device is received, the customer relationship management network authenticates the activation information according to the encryption verification key to obtain an authentication result of whether to pass; If the authentication result is pass, the customer relationship management network sends an access instruction to the corresponding service subnetwork to control the service subnetwork to access the terminal device; The method comprises: determining whether the key distribution instruction is of a first distribution type; if the key distribution instruction is of the first distribution type, combining a pre-stored large network number segment key and a user-specific key corresponding to the key distribution instruction to obtain a corresponding system initial key for sending; if the key distribution instruction is not of the first distribution type, obtaining a user-specific key corresponding to the key distribution instruction as a corresponding system initial key for sending; The method comprises: encrypting a verification key corresponding to the user subscription data according to the system initial key to obtain a corresponding encryption verification key; sending the encryption verification key to the customer relationship management network corresponding to the management network code according to the management network code of the user subscription data.
2. The 5G commercial network-based private network data security management method of claim 1, wherein, Before the encryption, the method further comprises: determining a corresponding service type according to a service subnetwork code of the user subscription data; obtaining a group of verification keys corresponding to the user subscription data according to the service type, the verification keys being intensive verification keys or sinking verification keys.
3. The method of claim 2, wherein the method further comprises: The method comprises: obtaining a corresponding operator root key according to operator information in the user subscription data; obtaining a corresponding authentication key according to the service type and the service subnetwork code in the user subscription data; Combining and calculating the operator root key and the authentication key according to preset calculation rules to obtain a corresponding first authentication key; Combining the first authentication key and the authentication key to generate a corresponding set of authentication keys.
4. The 5G commercial network-based private network data security management method of claim 1, wherein, The authentication of the activation information according to the encrypted authentication key to obtain an authentication result of whether to pass or not, comprising: Decrypting the activation information according to the system initial key to obtain corresponding activation decryption information; Judging whether the activation decryption information is consistent with the authentication key corresponding to the encrypted authentication key, thereby obtaining an authentication result of whether to pass or not.
5. The 5G commercial network-based private network data security management method of claim 1, wherein, The sending of the access instruction to the corresponding service subnet to control the service subnet to access the terminal device, comprising: Judging whether the service subnet code corresponding to the authentication result matches the first service type; If the authentication result matches the first service type, sending an access instruction to the service subnet corresponding to the service subnet code; If the authentication result does not match the first service type, sending an access instruction and transmitting it to the service subnet corresponding to the service subnet code through the user subscription data synchronization center.
6. A 5G commercial network-based sinking private network data security management system, characterized in that, The system includes a customer relationship management network, a card management system, a user subscription data synchronization center, and a service subnet, a network connection is established between the customer relationship management network and the card management system to realize the transmission of data information, a network connection is established between the service subnet and the user subscription data synchronization center or the customer relationship management network to realize the transmission of data information, a network connection is established between the user subscription data synchronization center and the customer relationship management network to realize the transmission of data information; the system includes a system initial key distribution unit configured in the card management system, an encrypted authentication key sending unit, a first sending unit, an authentication unit, and an access instruction sending unit configured in the customer relationship management network; The system initial key distribution unit is configured to generate a system initial key corresponding to the key distribution instruction and send it to the customer relationship management network if the input key distribution instruction is received; The first sending unit is configured to distribute the system initial key to the corresponding terminal device in the service subnet; The encrypted authentication key sending unit is configured to generate an encrypted authentication key corresponding to the pre-stored user subscription data and send it to the customer relationship management network; The authentication unit is configured to authenticate the activation information according to the encrypted authentication key if the activation information sent by the terminal device is received, and obtain an authentication result of whether to pass or not; The access instruction sending unit is configured to send an access instruction to the corresponding service subnet to control the service subnet to access the terminal device if the authentication result is passed; The generation of the system initial key corresponding to the key distribution instruction and the sending of it to the customer relationship management network, comprising: Judging whether the key distribution instruction is of the first distribution type; If the key distribution instruction is of a first distribution type, a pre-stored large network number segment key and a special user key corresponding to the key distribution instruction are combined as a corresponding system initial key and sent; If the key distribution instruction is not of the first distribution type, a special user key corresponding to the key distribution instruction is obtained as a corresponding system initial key and sent; The generating and sending to the customer relationship management network of the encryption verification key corresponding to the pre-stored user subscription data comprises: According to the system initial key, the verification key corresponding to the user subscription data is encrypted to obtain a corresponding encryption verification key; According to the management network code of the user subscription data, the encryption verification key is sent to the customer relationship management network corresponding to the management network code.
7. A 5G commercial network-based sinking private network data security management system, the system comprising a customer relationship management network, a card management system, a user subscription data synchronization center and a service subnetwork, the card management system comprising a first memory, a first processor and a first computer program stored on the first memory and capable of running on the first processor, the customer relationship management network comprising a second memory, a second processor and a second computer program stored on the second memory and capable of running on the second processor, characterized in that, The first processor executes the first computer program and the second processor executes the second computer program to jointly implement the 5G commercial network-based sinking private network data security management method of any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a first computer program and a second computer program, and when the first computer program is executed by the first processor and the second computer program is executed by the second processor, the 5G commercial network-based sinking private network data security management method of any one of claims 1-5 is jointly implemented.
Citation Information
Patent Citations
Mobile communication private network key generation method and device and controller
CN110753346A
Data management method, device and system and computer readable storage medium
CN114584967A