Terminal access control method, apparatus, device, and storage medium

By receiving the registration request from the terminal and using a list of multiple preset locations and communication identifiers for identification, the problem of low accuracy in terminal access control in the prior art is solved, and flexible and precise control of terminal technology access is achieved.

CN116600296BActive Publication Date: 2025-12-23CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310679326.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-08
Publication Date
2025-12-23
Estimated Expiration
2043-06-08

AI Technical Summary

Technical Problem

Existing terminal access control methods in 5G dedicated slices or dedicated networks are relatively simple, resulting in low accuracy of access control and an inability to achieve refined network operation.

Method used

By receiving the registration request from the target terminal, and using a list (first list and second list) containing multiple preset location identifiers and communication identifiers, the system determines whether to allow the target terminal to register based on the type of these identifiers and the discrimination results, thereby achieving flexible control over terminal access.

Benefits of technology

It improves the accuracy of terminal access control, enabling flexible combinations of location and communication identifiers at different granularities to achieve precise access control of target terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116600296B_ABST
    Figure CN116600296B_ABST
Patent Text Reader

Abstract

The application discloses a terminal access control method and device, equipment and storage medium, relates to the technical field of communication, and is used for improving the precision of terminal access control. The method comprises the following steps: receiving a registration request sent by a target terminal, the registration request comprising a location identifier of the target terminal, the location identifier comprising a tracking area (TAC) identifier and a cell identifier; determining whether the location identifier of the target terminal is included in a first list, the first list comprising a plurality of preset location identifiers, the plurality of preset location identifiers being any one of the following types of identifiers: an allowed access type and a forbidden access type, and the plurality of preset location identifiers comprising at least one of the following: a preset TAC identifier and a preset cell identifier; and determining whether to allow the registration of the target terminal based on the types of the plurality of preset location identifiers included in the first list and a first target determination result. The application is applied to a scenario of managing the registration of a network element.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, and particularly relates to a terminal access control method and device, equipment and a storage medium. BACKGROUND

[0002] At present, with the rapid development of the 5th generation mobile communication technology (5G), 5G has been widely applied in many industry fields. In the related technology of 5G dedicated slice or dedicated network, in order to meet the independent carrier demand of customers, the communication operator usually deploys an independent 5G carrier for enterprise customers on some base stations, and through terminal access control and other means, the independent 5G carrier deployed for the enterprise customers is only allowed to access the number card of the enterprise customer terminal, and the number card of the enterprise customer terminal is prohibited from accessing other base stations in the surrounding area, so as to realize the binding of the enterprise customer terminal and the reserved base station carrier, and to realize the high-speed transmission of the enterprise customer traffic data based on the separate carrier allocated for the enterprise.

[0003] In the existing terminal access control, a specific location area, also known as a tracking area code (TAC), is usually configured for an independent carrier on the wireless side, and then based on the access and mobility management function (AMF) network element on the core network side, a blacklist or a whitelist is set to realize the access control of a single terminal or multiple terminals in the specified area of the TAC based on the international mobile subscriber identification number (IMSI) of each terminal. For example, by allowing the terminals in the whitelist to register in the specified TAC area and refusing the terminals in the blacklist to register. In the above method, the terminal access control can only be realized according to the specified location area TAC and the IMSI of the terminal, and the control mode is relatively single and not flexible. Therefore, the existing terminal access control is not accurate enough. SUMMARY

[0004] The present application provides a terminal access control method, device, equipment and storage medium, which can improve the accuracy of terminal access control.

[0005] To achieve the above object, the present application adopts the following technical scheme:

[0006] In a first aspect, a terminal access control method is provided. The method comprises: receiving a registration request sent by a target terminal, the registration request comprising a location identifier of the target terminal, the location identifier comprising: a tracking area (TAC) identifier, a cell identifier; determining whether the location identifier of the target terminal is included in a first list, the first list comprising a plurality of preset location identifiers, the plurality of preset location identifiers being any one of the following types: an allowed access type, a forbidden access type, the plurality of preset location identifiers comprising at least one of the following: a preset TAC identifier, a preset cell identifier; determining whether to allow the registration of the target terminal based on the types of the plurality of preset location identifiers included in the first list and a first target determination result, the first target determination result being any one of the following: the location identifier of the target terminal is included in the first list, the location identifier of the target terminal is not included in the first list.

[0007] In a possible implementation, the determining whether to allow the registration of the target terminal based on the types of the plurality of preset location identifiers included in the first list and the first target determination result comprises: in a case where the types of the plurality of preset location identifiers included in the first list are the allowed access type and the location identifier of the target terminal is included in the first list, allowing the target terminal to register; in a case where the types of the plurality of preset location identifiers included in the first list are the allowed access type and the location identifier of the target terminal is not included in the first list, forbidding the target terminal to register; in a case where the types of the plurality of preset location identifiers included in the first list are the forbidden access type and the location identifier of the target terminal is included in the first list, forbidding the target terminal to register; in a case where the types of the plurality of preset location identifiers included in the first list are the forbidden access type and the location identifier of the target terminal is not included in the first list, allowing the target terminal to register.

[0008] In a possible implementation, the registration request further comprises a communication identifier of the target terminal, the communication identifier comprising: a public land mobile network (PLMN), an international mobile subscriber identity (IMSI); the method further comprises: determining whether the communication identifier of the target terminal is included in a second list, the second list comprising a plurality of preset communication identifiers, the plurality of preset communication identifiers being any one of the following types: an allowed access type, a forbidden access type, the plurality of preset communication identifiers comprising at least one of the following: a preset PLMN, a preset IMSI; determining whether to allow the registration of the target terminal based on the types of the plurality of preset communication identifiers included in the second list and a second target determination result, the second target determination result being any one of the following: the communication identifier of the target terminal is included in the second list, the communication identifier of the target terminal is not included in the second list.

[0009] In a possible implementation, the determining whether to allow the registration of the target terminal based on the types of the plurality of preset communication identities included in the second list and the second target determination result comprises: in a case where the types of the plurality of preset communication identities included in the second list are allowed access types and the communication identity of the target terminal is included in the second list, allowing the target terminal to register; in a case where the types of the plurality of preset communication identities included in the second list are allowed access types and the communication identity of the target terminal is not included in the second list, prohibiting the target terminal from registering; in a case where the types of the plurality of preset communication identities included in the second list are prohibited access types and the communication identity of the target terminal is included in the second list, prohibiting the target terminal from registering; and in a case where the types of the plurality of preset communication identities included in the second list are prohibited access types and the communication identity of the target terminal is not included in the second list, allowing the target terminal to register.

[0010] In a possible implementation, the plurality of preset communication identities in the second list further comprises an IMSI preset field, and the method further comprises: in a case where a target field in the IMSI of the target terminal is consistent with the IMSI preset field, determining that the communication identity of the target terminal is included in the second list.

[0011] In a possible implementation, in a case where the target terminal completes the registration and a location change request sent by the target terminal is received, a location identifier of a changed location corresponding to the location change request is determined, it is determined whether the location identifier of the changed location is included in the first list, and it is determined whether to disconnect the access of the target terminal based on the types of the plurality of preset location identifiers included in the first list and a third target determination result, the third target determination result being any one of the following: the location identifier of the changed location is included in the first list, and the location identifier of the changed location is not included in the first list.

[0012] In a second aspect, a terminal access control apparatus is provided, which comprises a receiving unit and a determining unit. The receiving unit is configured to receive a registration request sent by a target terminal, the registration request comprising a location identifier of the target terminal, the location identifier comprising a tracking area (TAC) identifier and a cell identifier. The determining unit is configured to determine whether the location identifier of the target terminal is included in a first list, the first list comprising a plurality of preset location identifiers, the plurality of preset location identifiers being any one of the following types: allowed access type and prohibited access type, and the plurality of preset location identifiers comprising at least one of the following: preset TAC identifier and preset cell identifier. The determining unit is further configured to determine whether to allow the registration of the target terminal based on the types of the plurality of preset location identifiers included in the first list and a first target determination result, the first target determination result being any one of the following: the location identifier of the target terminal is included in the first list and the location identifier of the target terminal is not included in the first list.

[0013] In a possible implementation, the terminal access control apparatus further includes: a registration unit; the registration unit is configured to allow the target terminal to register in a case where the type of the plurality of preset location identities included in the first list is an allowed access type and the location identity of the target terminal is included in the first list; the registration unit is further configured to prohibit the target terminal from registering in a case where the type of the plurality of preset location identities included in the first list is an allowed access type and the location identity of the target terminal is not included in the first list; the registration unit is further configured to prohibit the target terminal from registering in a case where the type of the plurality of preset location identities included in the first list is a prohibited access type and the location identity of the target terminal is included in the first list; and the registration unit is further configured to allow the target terminal to register in a case where the type of the plurality of preset location identities included in the first list is a prohibited access type and the location identity of the target terminal is not included in the first list.

[0014] In a possible implementation, the determination unit is further configured to determine whether the communication identity of the target terminal is included in the second list, the second list including a plurality of preset communication identities, the plurality of preset communication identities being any one of the following types: an allowed access type, a prohibited access type, and the plurality of preset communication identities including at least one of the following: a preset PLMN, a preset IMSI; and the determination unit is further configured to determine whether to allow the target terminal to register based on the type of the plurality of preset communication identities included in the second list and the second target determination result, the second target determination result being any one of the following: the communication identity of the target terminal is included in the second list, and the communication identity of the target terminal is not included in the second list.

[0015] In a possible implementation, the registration unit is further configured to allow the target terminal to register in a case where the type of the plurality of preset communication identities included in the second list is an allowed access type and the communication identity of the target terminal is included in the second list; the registration unit is further configured to prohibit the target terminal from registering in a case where the type of the plurality of preset communication identities included in the second list is an allowed access type and the communication identity of the target terminal is not included in the second list; the registration unit is further configured to prohibit the target terminal from registering in a case where the type of the plurality of preset communication identities included in the second list is a prohibited access type and the communication identity of the target terminal is included in the second list; and the registration unit is further configured to allow the target terminal to register in a case where the type of the plurality of preset communication identities included in the second list is a prohibited access type and the communication identity of the target terminal is not included in the second list.

[0016] In a possible implementation, the determination unit is further configured to determine that the communication identity of the target terminal is included in the second list in a case where a target field in the IMSI of the target terminal is consistent with an IMSI preset field.

[0017] In a possible implementation, the determining unit is further configured to determine a location identifier of the changed location corresponding to the location change request in a case where the target terminal completes registration and the location change request sent by the target terminal is received; the determining unit is further configured to determine whether the location identifier of the changed location is included in the first list; and the determining unit is further configured to determine whether to disconnect the access of the target terminal based on the types of the plurality of preset location identifiers included in the first list and the third target determination result, the third target determination result being any one of the following: the location identifier of the changed location is included in the first list, and the location identifier of the changed location is not included in the first list.

[0018] In a third aspect, an electronic device is provided, including a processor and a memory; the memory is configured to store one or more programs including computer execution instructions; when the electronic device is running, the processor executes the computer execution instructions stored in the memory to enable the electronic device to perform the terminal access control method according to the first aspect.

[0019] In a fourth aspect, a computer readable storage medium storing one or more programs is provided, the one or more programs including instructions that, when executed by a computer, cause the computer to perform the terminal access control method according to the first aspect.

[0020] The present application provides a terminal access control method, device, equipment and storage medium, which is applied to the scene of controlling the access of a terminal, and is used to improve the accuracy of terminal access control. When a registration request sent by a target terminal is received, whether the location identifier of the target terminal is included in the plurality of preset location identifiers included in the first list is determined based on the location identifier of the target terminal included in the registration request, and a first target determination result is obtained. Then, whether to allow the registration of the target terminal is determined based on the types of the plurality of preset location identifiers included in the first list and the first target determination result, so as to realize the access control of the target terminal. Based on the above method, the access control of the target terminal can be realized based on different granularities through the location identifier including the TAC identifier and the cell identifier, and the preset TAC identifier and the preset cell identifier are flexibly combined based on the first list, so as to realize the access control of the target terminal. Based on specific actual needs, the flexible control of the access of the target terminal is realized, and the accuracy of terminal access control is improved. BRIEF DESCRIPTION OF DRAWINGS

[0021] Figure 1 A related technical terminal access control method flowchart is provided for the embodiments of the present application;

[0022] Figure 2 A terminal access control system structure diagram is provided for the embodiments of the present application;

[0023] Figure 3 A terminal access control method flowchart provided for an embodiment of the present application Figure 1 ;

[0024] Figure 4 A terminal access control method flowchart provided for an embodiment of the present application Figure 2 ;

[0025] Figure 5 A terminal access control method flowchart provided for an embodiment of the present application Figure 3 ;

[0026] Figure 6 A terminal access control method flowchart provided for an embodiment of the present application Figure 4 ;

[0027] Figure 7 A terminal access control method flowchart provided for an embodiment of the present application Figure 5 ;

[0028] Figure 8 A terminal access control method flowchart provided for an embodiment of the present application Figure 6 ;

[0029] Figure 9 A terminal access control method flowchart provided for an embodiment of the present application Figure 7 ;

[0030] Figure 10 A terminal access control method flowchart provided for an embodiment of the present application Figure 8 ;

[0031] Figure 11 A terminal access control method flowchart provided for an embodiment of the present application Figure 9 ;

[0032] Figure 12 A terminal access control method flowchart provided for an embodiment of the present application Figure 10 ;

[0033] Figure 13 A terminal access control method flowchart provided for an embodiment of the present application Figure 10 ;

[0034] Figure 14 A terminal access control device structure diagram provided for an embodiment of the present application

[0035] Figure 15 An electronic device structure diagram provided for an embodiment of the present application DETAILED DESCRIPTION

[0036] The technical solutions in the embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application.

[0037] In the description of the present application, unless otherwise specified, " / " represents the meaning of "or", for example, A / B can represent A or B. "And / or" in this paper only describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent: A exists alone, A and B exist together, and B exists alone. In addition, "at least one" "multiple" means two or more. "First", "second" and the like do not limit the quantity and execution order, and "first", "second" and the like do not necessarily mean different.

[0038] At present, with the rapid development of communication technology, 5G fusion application technology has been widely used in many industries such as industrial field, medical field, education field and transportation field, etc. due to its characteristics of large bandwidth, low latency, wide connection, high security, etc. and plays an enabling effect. It plays an important role in the digital upgrading of traditional industries, the cost reduction and efficiency improvement of enterprises, and the public service and benefit of people's livelihood.

[0039] In 5G related technologies, as shown in Figure 1 The 5G terminal initiates a registration request to the AMF network element of the 5G core network through the radio access network (RAN), and the AMF network element of the core network can enable the blacklist (or whitelist) function to realize access control of a single or multiple IMSIs in a specified area (such as TAC1, TAC2, etc.) in TAC level. That is, in the specified TAC area, specific IMSIs can be allowed to register through the whitelist, and specific IMSIs can be refused (prohibited) to register through the blacklist.

[0040] However, in the above method, only the specified location area TAC and the single or multiple IMSIs can be used to realize access control of the terminal, and the control is not flexible enough to realize fine operation of the network.

[0041] The terminal access control method provided by the embodiments of the present application can be applied to a terminal access control system. Figure 2 A structural schematic diagram of the terminal access control system is shown. As shown in Figure 2 The terminal access control system 20 includes a target terminal 21 and a management module 22.

[0042] The terminal access control system 20 can be used for the Internet of Things. The terminal access control system 20 (such as target terminal 21 and management module 22) may include hardware such as multiple central processing units (CPUs), multiple memories, and storage devices storing multiple operating systems.

[0043] The target terminal 21 is a terminal that has a network access requirement. It is used to send a registration request to the management module 22 so that the network access can be realized if the management module 22 authenticates and allows the registration.

[0044] Management module 22 is used to implement access control for target terminals, such as... Figure 2 As shown, the management module 22 can be an AMF network element. It is used to determine whether to allow the target terminal's registration based on the registration request sent by the target terminal and preset lists (first list, second list, etc.).

[0045] Optional, such as Figure 2 As shown, when the management module 22 is an AMF network element, the target terminal 21 can connect to the management module 22 based on the base station.

[0046] The following description, in conjunction with the accompanying drawings, describes a terminal access control method provided by an embodiment of this application.

[0047] like Figure 3 As shown, an embodiment of this application provides a terminal access control method, including steps S201-S203:

[0048] S201. Receive the registration request sent by the target terminal.

[0049] The registration request includes the location identifier of the target terminal, which includes: Tracking Area (TAC) identifier and Cell identifier.

[0050] Optionally, if the target terminal has not established a network connection (e.g., when the terminal is powered off or in airplane mode), or if a network connection is required (e.g., when the terminal is powered on and needs to use the network or when airplane mode is turned off), the terminal needs to send a registration request to the management module for authentication and to establish a network connection.

[0051] Optionally, in conjunction with the terminal access control system 20, the management module 22 can receive the registration request sent by the target terminal and determine whether to allow the target terminal to register based on the registration request.

[0052] It should be noted that TAC refers to Tracking Area Code, which typically includes multiple cells.

[0053] S202. Determine whether the first list includes the location identifier of the target terminal.

[0054] The first list includes a plurality of preset location identifiers, and the plurality of preset location identifiers are any one of the following types of identifiers: allowed access type and forbidden access type, and the plurality of preset location identifiers include at least one of the following: preset TAC identifier and preset cell identifier.

[0055] It should be noted that the preset cell identifier, i.e., the preset Cell ID, is used to identify a cell covered by the network.

[0056] Optionally, one or more TACs and cells can be selected based on specific use needs, and the identifiers of the one or more TACs and cells are determined as the preset location identifiers in the first list.

[0057] It can be understood that the plurality of preset location identifiers include at least one of the preset TAC identifier and the preset cell identifier, mainly indicating that at least one of the preset TAC identifier and the preset cell identifier can be included, and for each type of identifier, such as the preset TAC identifier, the administrator can set one or more preset TAC identifiers based on actual use needs.

[0058] It should be noted that the type of the preset location identifier can be determined based on specific control needs. For example, when a blacklist needs to be set (i.e., the terminal is controlled to be forbidden to access), the preset location identifier can be determined as an identifier of the forbidden access type; when a whitelist needs to be set (i.e., the terminal is controlled to be allowed to access), the preset location identifier can be determined as an identifier of the allowed access type.

[0059] Optionally, a control judgment priority can also be set to achieve high-precision control of terminal access.

[0060] For example, the identifier type of the preset TAC1 identifier in the first list is an allowed registration identifier (i.e., all TACs except TAC1 are forbidden to register), and the TAC1 includes cell 1, cell 2, and cell 3. The identifier type of the cell 1 identifier can be set as a forbidden registration identifier (i.e., all cells except cell 1 are allowed to register), and it can be first judged whether the TAC identifier of the target terminal is consistent with the preset TAC1 identifier, and in the case that the TAC identifier of the target terminal is consistent with the preset TAC1 identifier, it is further judged whether the cell identifier of the target terminal is consistent with the preset cell 1 identifier, and in the case that the cell identifier of the target terminal is not consistent with the preset cell 1 identifier, the registration of the target terminal is allowed, and the precision and high flexibility of the control of terminal access is achieved.

[0061] Optionally, in some possible implementation manners, control of a specific private network (such as an education park private network or an industrial park private network) can also be achieved based on a plurality of cells.

[0062] For example, there are cell A, cell B and cell C in an industrial park, and the access of the industrial park private network can be allowed or the access of the industrial park private network can be prohibited by determining the identities of the cell A, the cell B and the cell C as the identities in the first list or setting the identities of the cell A, the cell B and the cell C as a specific cell identity group (that is, a private network identity) and determining the type of the identity.

[0063] It can be understood that when there is an identity same as the location identity of the target terminal in the multiple preset location identities in the first list, that is, any preset location identity in the first list is consistent with the location identity of the target terminal, it is determined that the first list includes the location identity of the target terminal; when there is no identity same as the location identity of the target terminal in the multiple preset location identities in the first list, that is, each of the multiple preset location identities in the first list is inconsistent with the location identity of the target terminal, it is determined that the first list does not include the location identity of the target terminal.

[0064] S203, determining whether to allow the registration of the target terminal based on the type of the multiple preset location identities included in the first list and the first target determination result.

[0065] The first target determination result is any of the following: the first list includes the location identity of the target terminal and the first list does not include the location identity of the target terminal.

[0066] It should be noted that allowing the registration of the target terminal can be understood as allowing the target terminal to establish a connection with a related network element to realize network access of the target terminal.

[0067] It can be understood that the first target determination result refers to the determination result of S202.

[0068] In the embodiment of the application, when the registration request sent by the target terminal is received, it is determined whether the location identity of the target terminal included in the registration request is included in the multiple preset location identities included in the first list, and a first target determination result is obtained. Then, it is determined whether to allow the registration of the target terminal based on the type of the multiple preset location identities included in the first list and the first target determination result, so as to realize access control of the target terminal. Based on the above method, the location identity including the TAC identity and the cell identity can be used to realize access control of the target terminal based on different granularities, and the preset TAC identity and the preset cell identity can be flexibly combined based on the first list to realize access control of the target terminal. Based on specific actual needs, flexible control of the access of the target terminal is realized, and the accuracy of terminal access control is improved.

[0069] In a possible implementation manner, as Figure 4As shown, the terminal access control method provided by the embodiment of the present application includes S301-S304 in S203.

[0070] S301, in the case that the type of the plurality of preset location identities included in the first list is the allowed access type and the location identity of the target terminal is included in the first list, the target terminal is allowed to register.

[0071] S302, in the case that the type of the plurality of preset location identities included in the first list is the allowed access type and the location identity of the target terminal is not included in the first list, the target terminal is prohibited to register.

[0072] S303, in the case that the type of the plurality of preset location identities included in the first list is the prohibited access type and the location identity of the target terminal is included in the first list, the target terminal is prohibited to register.

[0073] S304, in the case that the type of the plurality of preset location identities included in the first list is the prohibited access type and the location identity of the target terminal is not included in the first list, the target terminal is allowed to register.

[0074] In a possible implementation, the access control of all regions can also be implemented based on the first list, for example, the first list includes the location identities of all regions, or the management module directly prohibits or allows the access of the target terminals in all regions.

[0075] Optionally, the type of the plurality of preset location identities included in the first list is the allowed access type, which can also be understood as that the first list is a list of preset location identities of the allowed access type (i.e. a white list); the type of the plurality of preset location identities included in the first list is the prohibited access type, which can also be understood as that the first list is a list of preset location identities of the prohibited access type (i.e. a black list).

[0076] In a possible implementation, the terminal access control process in the embodiment of the present application can be as shown in Figure 5 As shown in Figure 5 Taking the access control based on the black list (i.e. the type of the preset location identity is the prohibited access type) as an example, the management module can first determine whether to perform the access control of the terminal location (region), i.e. whether to start the region black list, if the location control is performed (the region black list is started), the region control process as shown in Figure 5 is entered.

[0077] Specifically, it can be determined whether to perform the limitation of all region levels, i.e. whether to prohibit the access of the terminals in all regions: if the limitation of all region levels is performed, the registration of the target terminal is directly prohibited; if the limitation of all region levels is not performed, the next limitation condition is determined.

[0078] Further, it is determined whether to perform TAC-level restriction, i.e., whether to prohibit the terminal of a specific (preset) TAC from accessing: if the TAC-level restriction is performed, it is determined whether the TAC identifier of the target terminal belongs to the preset TAC identifier; if the TAC identifier of the target terminal belongs to the preset TAC identifier, the registration of the target terminal is prohibited; if the TAC-level restriction is performed and the TAC identifier of the target terminal does not belong to the preset TAC identifier, or the TAC-level restriction is not performed, the next restriction condition is determined.

[0079] Further, it is determined whether to perform cell-level restriction, i.e., whether to prohibit the terminal of a specific (preset) cell from accessing: if the cell-level restriction is performed, it is determined whether the cell identifier of the target terminal belongs to the preset cell identifier; if the cell identifier of the target terminal belongs to the preset cell identifier, the registration of the target terminal is prohibited; if the cell-level restriction is performed and the cell identifier of the target terminal does not belong to the preset cell identifier, or the cell-level restriction is not performed, the registration of the target terminal is allowed, or the subsequent restriction condition (e.g., whether to belong to a park private network, whether to belong to a preset communication identifier, etc.) is determined.

[0080] It can be understood that, based on the description of the above-mentioned Figure 5 and related steps, the access control process based on the white list (i.e., the identifier type of the preset location identifier is the allowed access type) can be obtained as shown in Figure 6 . Since the overall control process is basically the same as the above-mentioned process, only part of the process is described exemplarily, and details are not described herein.

[0081] Exemplarily, taking the TAC-level restriction based on the white list as an example, in combination with Figure 6 , it is first determined whether to perform TAC-level restriction, i.e., whether to allow the terminal of a specific (preset) TAC to access: if the TAC-level restriction is performed, it is determined whether the TAC identifier of the target terminal belongs to the preset TAC identifier; if the TAC identifier of the target terminal belongs to the preset TAC identifier, the registration of the target terminal is allowed; if the TAC-level restriction is performed and the TAC identifier of the target terminal does not belong to the preset TAC identifier, or the TAC-level restriction is not performed, the next restriction condition is determined (if there is a subsequent restriction condition); if there is no subsequent restriction condition, the registration of the target terminal is prohibited.

[0082] In a possible implementation manner, the access control of the terminal can be implemented based on only one determination condition, i.e., the first list in the embodiment of the present application can include only one of the preset TAC identifier and the preset cell identifier.

[0083] Specifically, the judgment of the restriction conditions can be performed in the preset priority (for example, the judgment of whether to perform all area-level restrictions, whether to perform TAC-level restrictions, and whether to perform cell-level restrictions is performed in sequence), and in the case that the location identifier of the target terminal meets a certain restriction condition, the registration of the target terminal is directly prohibited (or allowed), and the judgment of the subsequent restriction conditions is no longer performed, so as to improve the accuracy and control efficiency of the access control.

[0084] In the embodiments of the present application, the multiple preset location identifiers and the types of the multiple preset location identifiers are used to accurately control whether the target terminal is allowed to register based on the location identifier of the target terminal, so as to further improve the accuracy of the terminal access control.

[0085] In a possible implementation, the registration request further includes a communication identifier of the target terminal, and the communication identifier includes a public land mobile network (PLMN) and an international mobile subscriber identity (IMSI). Figure 7 As shown in the method for controlling terminal access provided in the embodiments of the present application, the method further includes S401-S402.

[0086] S401, determining whether the communication identifier of the target terminal is included in the second list.

[0087] The second list includes multiple preset communication identifiers, and the multiple preset communication identifiers are any one of the following types of identifiers: allowed access type and prohibited access type, and the multiple preset communication identifiers include at least one of the following: a preset PLMN and a preset IMSI.

[0088] It should be noted that the PLMN refers to a public land mobile network (public land mobile network, PLMN), which is mainly used in related communication technologies to distinguish networks established and operated by different communication service operators for the purpose of providing public land mobile communication services in a specific region, that is, to distinguish the identifiers of different communication service operators.

[0089] In the embodiments of the present application, the differential access control of the in-network users and the out-of-network users (different network users) can be implemented based on a specific (preset) PLMN.

[0090] It can be understood that the multiple preset communication identifiers include at least one of the preset PLMN and the preset IMSI, which mainly means that at least one of the preset PLMN and the preset IMSI can be included, and for each type of identifier, such as the preset IMSI, the administrator can set one or more preset IMSIs based on actual use requirements.

[0091] In a possible implementation, the preset IMSIs in the second list can also be set in a group manner, such as a first preset IMSI group, a second preset IMSI group, and the like, and each group of preset IMSIs can include one or more, continuous or discontinuous, preset IMSIs, to implement access control on a specific user group.

[0092] Optionally, one or more PLMNs and IMSIs can be selected based on specific use needs, and the one or more PLMNs and IMSIs are determined as the preset communication identifiers in the second list.

[0093] It should be noted that the type of the preset communication identifier can be determined based on specific control needs. For example, when a blacklist needs to be set (that is, the terminal to be controlled is prohibited from accessing), the preset communication identifier can be determined as an identifier of the prohibited access type; when a whitelist needs to be set (that is, the terminal to be controlled is allowed to access), the preset communication identifier can be determined as an identifier of the allowed access type.

[0094] It can be understood that when the same identifier as the communication identifier of the target terminal exists in the multiple preset communication identifiers in the second list, that is, any preset communication identifier in the second list is consistent with the communication identifier of the target terminal, it is determined that the second list includes the communication identifier of the target terminal; when the same identifier as the communication identifier of the target terminal does not exist in the multiple preset communication identifiers in the second list, that is, each of the multiple preset communication identifiers in the second list is inconsistent with the communication identifier of the target terminal, it is determined that the second list does not include the communication identifier of the target terminal.

[0095] S402, determining whether to allow the registration of the target terminal based on the type of the multiple preset communication identifiers included in the second list and the second target discrimination result.

[0096] The second target discrimination result is any of the following: the second list includes the communication identifier of the target terminal, and the second list does not include the communication identifier of the target terminal.

[0097] It can be understood that the second target discrimination result refers to the determination result of S401.

[0098] It should be noted that the access control on the target terminal based on the communication identifier of the target terminal can also be understood as the access control on a number card (telephone card).

[0099] Optionally, in the embodiments of the present application, the management module can first control the access area based on the location identifier of the target terminal and the first list, and then control the access card based on the communication identifier of the target terminal and the second list. Alternatively, the management module can first control the access card based on the communication identifier of the target terminal and the second list, and then control the access area based on the location identifier of the target terminal and the first list. The specific judgment order can be selected according to the use requirement.

[0100] It can be understood that the first list and the second list in the embodiments of the present application can be understood as a blacklist (or a whitelist).

[0101] In a possible implementation manner, as shown in Figure 8 When the target terminal accesses, i.e., sends a registration request, the management module can first determine whether the blacklist / whitelist function is enabled. If the blacklist / whitelist function is enabled, the access control of the terminal is further implemented based on the blacklist or the whitelist. If the blacklist or the whitelist is not enabled, the terminal is allowed to register by default, and the access registration process of the terminal is normally implemented.

[0102] It should be noted that in the embodiments of the present application, the identifier of the allowed registration type means that only the identifier is allowed to register (registration of other identifiers is prohibited), the identifier of the prohibited registration type means that only the identifier is prohibited to register (registration of other identifiers is allowed), and the two types of identifiers are essentially mutually exclusive. Therefore, at least at the same granularity, the types of identifiers need to be unified, i.e., at the same granularity, the allowed registration type identifier and the prohibited registration type identifier cannot be included at the same time.

[0103] The same granularity refers to different granularities in the same dimension, such as TAC identifier granularity and cell identifier granularity in the location identifier, and PLMN granularity and IMSI granularity in the communication identifier.

[0104] For example, if the first list includes a first preset TAC identifier, and the identifier is an allowed registration type identifier, then all the remaining preset TAC identifiers (if any) in the first list need to be allowed registration type identifiers.

[0105] In the embodiments of the present application, the access area of the target terminal is controlled based on the location identifier of the target terminal, and the access card of the target terminal is controlled based on the communication identifier of the target terminal, so as to control the access of the terminal based on the communication identifier of the terminal, and improve the flexibility of the access control of the terminal.

[0106] In a possible implementation manner, as shown in Figure 9 In the terminal access control method provided by the embodiments of the present application, S402 includes S501-S504:

[0107] S501, in a case where the type of the plurality of preset communication identities included in the second list is an allowed access type and the communication identity of the target terminal is included in the second list, allowing the target terminal to register.

[0108] S502, in a case where the type of the plurality of preset communication identities included in the second list is an allowed access type and the communication identity of the target terminal is not included in the second list, prohibiting the target terminal from registering.

[0109] S503, in a case where the type of the plurality of preset communication identities included in the second list is a prohibited access type and the communication identity of the target terminal is included in the second list, prohibiting the target terminal from registering.

[0110] S504, in a case where the type of the plurality of preset communication identities included in the second list is a prohibited access type and the communication identity of the target terminal is not included in the second list, allowing the target terminal to register.

[0111] In a possible implementation, the access control of all terminals can also be implemented based on the second list, for example, the second list includes the communication identities of all terminals, or the management module directly prohibits or allows the access of all target terminals.

[0112] Optionally, the type of the plurality of preset communication identities included in the second list is an allowed access type, which can also be understood as that the second list is a list of preset communication identities of an allowed access type (i.e., a white list); the type of the plurality of preset communication identities included in the second list is a prohibited access type, which can also be understood as that the second list is a list of preset communication identities of a prohibited access type (i.e., a black list).

[0113] In a possible implementation, in combination with Figure 10 Taking the access control based on the black list (i.e., the type of the preset communication identity is a prohibited access type) as an example, the management module can first determine whether to perform the access control of the terminal communication identity (card number), i.e., whether to start the card number black list, if the communication identity control (start the card number black list) is performed, the card number control flow as shown in Figure 10 is entered.

[0114] Specifically, it can be determined whether to perform the all-terminal-level restriction, i.e., whether to prohibit the access of all terminals: if the all-terminal-level restriction is performed, the registration of the target terminal is directly prohibited; if the all-terminal-level restriction is not performed, the next restriction condition is determined.

[0115] Further, it is determined whether to perform the PLMN level restriction, i.e., whether to prohibit the access of a specific (preset) PLMN. If the PLMN level restriction is performed, it is determined whether the PLMN identifier of the target terminal belongs to the preset PLMN. If the PLMN identifier of the target terminal belongs to the preset PLMN, the registration of the target terminal is prohibited. If the PLMN level restriction is performed and the PLMN of the target terminal does not belong to the preset PLMN, or the PLMN level restriction is not performed, the next restriction condition is determined.

[0116] Further, it is determined whether to perform the IMSI level restriction, i.e., whether to prohibit the access of a specific (preset) IMSI. If the IMSI level restriction is performed, it is determined whether the IMSI identifier of the target terminal belongs to the preset IMSI. If the IMSI identifier of the target terminal belongs to the preset IMSI, the registration of the target terminal is prohibited. If the IMSI level restriction is performed and the IMSI of the target terminal does not belong to the preset IMSI, or the IMSI level restriction is not performed, the registration of the target terminal is allowed, or the next restriction condition is determined (if there is another restriction condition).

[0117] It can be understood that, based on the description of the above steps, the access control process based on the white list (i.e., the identifier type of the preset communication identifier is the allowed access type) can be obtained as shown in FIG. 6. Figure 10 Figure 11 The overall control process is basically the same as the above process, and only part of the process is described exemplarily, and details are not described herein.

[0118] Exemplarily, taking the IMSI level restriction based on the white list as an example, it is first determined whether to perform the IMSI level restriction, i.e., whether to allow the terminal access of a specific (preset) IMSI. If the IMSI level restriction is performed, it is determined whether the IMSI of the target terminal belongs to the preset IMSI. If the IMSI of the target terminal belongs to the preset IMSI, the registration of the target terminal is allowed. If the IMSI level restriction is performed and the IMSI identifier of the target terminal does not belong to the preset IMSI identifier, or the IMSI level restriction is not performed, the next restriction condition is determined (if there is a subsequent restriction condition). If there is no subsequent restriction condition, the registration of the target terminal is prohibited. Figure 11

[0119] In the embodiment of the present application, by using the plurality of preset communication identifiers and the types of the plurality of preset communication identifiers, whether to allow the target terminal to register is accurately controlled based on the communication identifier of the target terminal, so as to further improve the accuracy of the terminal access control.

[0120] In a possible implementation, the plurality of preset communication identifiers in the second list further includes an IMSI preset field. In the terminal access control method provided in the embodiment of the present application, S601 is further included.​​

[0121] S601, in a case where the target field in the IMSI of the target terminal is consistent with the IMSI preset field, determining that the communication identity of the target terminal is included in the second list.

[0122] It should be noted that in related communication technologies, the IMSI as a globally unique ID can be used to distinguish each mobile user (terminal), which is composed of a mobile country code (MMC), a mobile network code (MNC), and a mobile subscription identification number (MSIN), and each specific field has a different meaning. Therefore, a communication service operator can limit the specific field according to the use demand, and only allow or prohibit the registration of the terminal with the IMSI whose target field is the preset field.

[0123] For example, the preset field is 880********, that is, in a case where the first three digits of the target terminal are 880, it is considered that the target field in the IMSI of the target terminal is consistent with the IMSI preset field, and it is determined that the communication identity of the target terminal is included in the second list.

[0124] It should be noted that the preset IMSI identity can be understood as controlling the access of the target terminal based on the IMSI identity of the target terminal by means of an IMSI group (one or more preset IMSI identities); and the IMSI preset field can be understood as controlling the access of the target terminal based on the IMSI identity of the target terminal by means of a specific field (i.e., the value of a specific field in the IMSI).

[0125] Optionally, as shown in Figure 10 In the implementation of the blacklist-based access control, the management module can determine whether to perform IMSI field-level restriction, that is, whether to prohibit the access of the IMSI containing the IMSI specific (preset) field. If the IMSI field-level restriction is performed, it is determined whether the specific field in the IMSI of the target terminal belongs to the preset IMSI field. If the specific field in the IMSI of the target terminal belongs to the preset IMSI field, the registration of the target terminal is prohibited. If the IMSI field-level restriction is performed and the specific field in the IMSI of the target terminal does not belong to the preset IMSI field, or the IMSI field-level restriction is not performed, the registration of the target terminal is allowed, or the subsequent judgment of the restriction condition is performed (if there is another restriction condition).

[0126] It can be understood that based on Figure 10 and the description of the related steps, the following can be obtained: Figure 11The access control procedure based on the whitelist (i.e., the identification type of the preset communication identification is the allowed access type) is shown.

[0127] Specifically, in combination with Figure 11 , first, it is determined whether to perform the IMSI field level restriction, i.e., whether to allow the access of the IMSI containing the IMSI specific (preset) field: if the IMSI field level restriction is performed, it is determined whether the specific field in the IMSI of the target terminal belongs to the preset IMSI field, and if the specific field in the IMSI of the target terminal belongs to the preset IMSI field, the registration of the target terminal is allowed; if the IMSI field level restriction is performed and the specific field in the IMSI of the target terminal does not belong to the preset IMSI field, or the IMSI field level restriction is not performed, the judgment of the next restriction condition (if there is a subsequent restriction condition) is performed, and if there is no subsequent restriction condition, the registration of the target terminal is prohibited.

[0128] In a possible implementation, the access control of the terminal can be implemented based on only one judgment condition, i.e., the second list in the embodiment of the present application can include only one of the preset PLMN, the preset IMSI and the IMSI preset field.

[0129] Specifically, the judgment of the restriction condition can be performed in the preset priority (such as sequentially judging whether to perform the all terminal level restriction, whether to perform the PLMN level restriction, whether to perform the IMSI level restriction, and whether to perform the IMSI preset field level restriction), and in the case that the communication identification of the target terminal meets a certain restriction condition, the registration of the target terminal is directly prohibited (or allowed), and the judgment of the subsequent restriction condition is no longer performed, so as to improve the accuracy and control efficiency of the access control.

[0130] It should be noted that, as Figure 12 shown, in the embodiment of the present application, the access control of the terminal in all areas (or in a specified area, such as in a preset TAC or a preset cell) covered by the management module (such as the AMF network element) can be implemented based on the first list, the individualized access control of the terminal with different communication identifications (different PLMNs, different IMSIs, etc.) can be implemented based on the second list, and the flexible combination of different dimensions and multiple levels (such as Figure 12 ) can be implemented based on the first list and the second list, so as to further improve the flexibility of the terminal access control.

[0131] In the embodiment of the present application, the IMSI field is set to implement the MISI field level control, so as to further improve the flexibility and control efficiency of the terminal access control.

[0132] In a possible implementation, as Figure 13As shown, the terminal access control method provided by the embodiment of the present application further includes S701-S703.

[0133] S701, in the case that the target terminal completes registration and receives the location change request sent by the target terminal, determining the location identifier of the changed location corresponding to the location change request.

[0134] It should be noted that after the target terminal completes registration, the target terminal may need to change the network access location due to the movement of the target terminal, such as the target terminal moving from the A area to the B area. Due to the limitation of the coverage range of the base station, the target terminal may need to change the network access location, such as the target terminal moving from the A cell to the B cell.

[0135] Further, the A cell may be an allowed access cell, but the B cell may be a forbidden access cell. In this case, in order to ensure the universal control of terminal access, the access control (whether to allow access) of the target terminal can be judged again based on the location change request sent by the target terminal each time the location change occurs after the target terminal establishes a network connection.

[0136] It can be understood that the location identifier of the changed location refers to the location identifier of the location to which the target terminal needs to switch, such as the above-mentioned movement of the target terminal from the A cell to the B cell. The location identifier of the B cell.

[0137] S702, determining whether the location identifier of the changed location is included in the first list.

[0138] It should be noted that the method of determining whether the location identifier of the changed location is included in the first list is basically the same as the method of determining whether the location identifier of the target terminal is included in the first list in S202. Here, it will not be repeated.

[0139] S703, determining whether to disconnect the access of the target terminal based on the type of the plurality of preset location identifiers included in the first list and the third target discrimination result.

[0140] The third target discrimination result is any one of the following: the first list includes the location identifier of the changed location, and the first list does not include the location identifier of the changed location.

[0141] It should be noted that disconnecting the network access of the target terminal refers to disconnecting the network access of the target terminal due to the change of the location of the target terminal after the target terminal establishes a network connection, which causes the location identifier of the target terminal to no longer meet the preset allowed access location identifier.

[0142] It can be understood that the third target discrimination result is the determination result of S702.

[0143] It can be understood that in combination with the above S301-S304, the implementation method of the above S703 specifically includes the following steps: in the case that the type of the plurality of preset location identities included in the first list is the allowed access type and the first list includes the location identity of the changed location, not disconnecting the access of the target terminal; in the case that the type of the plurality of preset location identities included in the first list is the allowed access type and the first list does not include the location identity of the changed location, disconnecting the access of the target terminal; in the case that the type of the plurality of preset location identities included in the first list is the forbidden access type and the first list includes the location identity of the changed location, disconnecting the access of the target terminal; in the case that the type of the plurality of preset location identities included in the first list is the forbidden access type and the first list does not include the location identity of the changed location, not disconnecting the access of the target terminal.

[0144] In the embodiment of the application, after the target terminal establishes a network connection, further in combination with the change of the location of the target terminal, it is judged whether to disconnect the access of the target terminal, so as to realize the quasi-real-time change of the access control based on the changed location in combination with the specific change of the location of the target terminal, so as to further ensure the accuracy of the terminal access control.

[0145] The embodiment of the application can divide the functional modules of a terminal access control device according to the above method examples. For example, each functional module can be divided according to each function, or two or more functions can be integrated in one processing module. The integrated module can be realized in the form of hardware or in the form of a software functional module. Optionally, the division of the modules in the embodiment of the application is illustrative, and is only a logical functional division. In actual implementation, another division mode can be used.

[0146] Figure 14 A structural schematic diagram of a terminal access control device provided in the embodiment of the application is shown in FIG. 1. Figure 14 As shown in FIG. 1, the terminal access control device 140 is used to improve the accuracy of the terminal access control, for example, is used to execute the terminal access control method shown in FIG. 2. Figure 3 The terminal access control device 140 includes a receiving unit 1401, a determining unit 1402 and a registration unit 1403.

[0147] The receiving unit 1401 is used to receive the registration request sent by the target terminal, and the registration request includes the location identity of the target terminal. The location identity includes a tracking area TAC identity and a cell identity.

[0148] The determining unit 1402 is configured to determine whether the location identifier of the target terminal is included in a first list, the first list including a plurality of preset location identifiers, the plurality of preset location identifiers being any one of the following types of identifiers: an allowed access type and a forbidden access type, and the plurality of preset location identifiers including at least one of the following: a preset TAC identifier and a preset cell identifier.

[0149] The determining unit 1402 is further configured to determine whether to allow the registration of the target terminal based on the type of the plurality of preset location identifiers included in the first list and a first target determination result, the first target determination result being any one of the following: the location identifier of the target terminal is included in the first list and the location identifier of the target terminal is not included in the first list.

[0150] In a possible implementation, the registering unit 1403 is configured to allow the registration of the target terminal in a case where the type of the plurality of preset location identifiers included in the first list is the allowed access type and the location identifier of the target terminal is included in the first list.

[0151] The registering unit 1403 is further configured to prohibit the registration of the target terminal in a case where the type of the plurality of preset location identifiers included in the first list is the allowed access type and the location identifier of the target terminal is not included in the first list.

[0152] The registering unit 1403 is further configured to prohibit the registration of the target terminal in a case where the type of the plurality of preset location identifiers included in the first list is the forbidden access type and the location identifier of the target terminal is included in the first list.

[0153] The registering unit 1403 is further configured to allow the registration of the target terminal in a case where the type of the plurality of preset location identifiers included in the first list is the forbidden access type and the location identifier of the target terminal is not included in the first list.

[0154] In a possible implementation, the determining unit 1402 is further configured to determine whether the communication identifier of the target terminal is included in a second list, the second list including a plurality of preset communication identifiers, the plurality of preset communication identifiers being any one of the following types of identifiers: an allowed access type and a forbidden access type, and the plurality of preset communication identifiers including at least one of the following: a preset PLMN and a preset IMSI.

[0155] The determining unit 1402 is further configured to determine whether to allow the registration of the target terminal based on the type of the plurality of preset communication identifiers included in the second list and a second target determination result, the second target determination result being any one of the following: the communication identifier of the target terminal is included in the second list and the communication identifier of the target terminal is not included in the second list.

[0156] In a possible implementation, the registration unit 1403 is further configured to allow the target terminal to register in the case that the types of the plurality of preset communication identities included in the second list are allowed access types and the communication identity of the target terminal is included in the second list.

[0157] The registration unit 1403 is further configured to prohibit the target terminal from registering in the case that the types of the plurality of preset communication identities included in the second list are prohibited access types and the communication identity of the target terminal is included in the second list.

[0158] The registration unit 1403 is further configured to prohibit the target terminal from registering in the case that the types of the plurality of preset communication identities included in the second list are prohibited access types and the communication identity of the target terminal is included in the second list.

[0159] The registration unit 1403 is further configured to allow the target terminal to register in the case that the types of the plurality of preset communication identities included in the second list are prohibited access types and the communication identity of the target terminal is not included in the second list.

[0160] In a possible implementation, the determination unit 1402 is further configured to determine that the communication identity of the target terminal is included in the second list in the case that the target field in the IMSI of the target terminal is consistent with the IMSI preset field.

[0161] In a possible implementation, the determination unit 1402 is further configured to determine the location identifier of the changed location corresponding to the location change request in the case that the target terminal completes registration and the location change request sent by the target terminal is received.

[0162] The determination unit 1402 is further configured to determine whether the location identifier of the changed location is included in the first list.

[0163] The determination unit 1402 is further configured to determine whether to disconnect the access of the target terminal based on the types of the plurality of preset location identifiers included in the first list and the third target determination result, the third target determination result being any of the following: the location identifier of the changed location is included in the first list, and the location identifier of the changed location is not included in the first list.

[0164] In the case of implementing the functions of the above integrated modules in the form of hardware, the embodiment of the present application provides a possible structural diagram of the electronic device involved in the above embodiments. As shown in the figure, an electronic device 150 is configured to improve the accuracy of terminal access control, for example, to perform the above-mentioned method. Figure 15 Figure 3 ​An electronic device 150 is shown. The electronic device 150 includes a processor 1501, a memory 1502, and a bus 1503. The processor 1501 and the memory 1502 can be connected through the bus 1503.

[0165] The processor 1501 is a control center of the communication device, which can be one processor or a general term of multiple processing elements. For example, the processor 1501 can be a general central processing unit (CPU), or other general-purpose processors, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.

[0166] As an embodiment, the processor 1501 can include one or more CPUs, such as the CPU 0 and the CPU 1 shown in FIG. 1. Figure 15

[0167] The memory 1502 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited thereto.

[0168] As a possible implementation, the memory 1502 can exist independently of the processor 1501. The memory 1502 can be connected to the processor 1501 through the bus 1503, and used to store instructions or program codes. When the processor 1501 invokes and executes the instructions or program codes stored in the memory 1502, the terminal access control method provided in the embodiments of the present application can be implemented.

[0169] In another possible implementation, the memory 1502 can also be integrated with the processor 1501.

[0170] ​The bus 1503 can be an industry standard architecture (ISA) bus, a peripheral component interconnect (PCI) bus, an extended industry standard architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, Figure 15 Only one thick line is used to represent the bus in the figure, but it does not mean that there is only one bus or only one type of bus.

[0171] It should be noted that, Figure 15 The structure shown does not constitute a limitation on the electronic device 150. In addition to Figure 15 the components shown, the electronic device 150 can include more or fewer components than shown, or combine certain components, or different component arrangements.

[0172] As an example, in combination with Figure 14 , the functions implemented by the receiving unit 1401, the determining unit 1402, and the registering unit 1403 in the terminal access control apparatus 140 are the same as the functions of the processor 1501 in Figure 15 .

[0173] Optionally, as shown in Figure 15 , the electronic device 150 provided by the embodiments of the present application can further include a communication interface 1504.

[0174] The communication interface 1504 is configured to connect with other devices through a communication network. The communication network can be an Ethernet, a wireless access network, a wireless local area network (WLAN), or the like. The communication interface 1504 can include a receiving unit for receiving data, and a sending unit for sending data.

[0175] In a possible implementation, in the electronic device provided by the embodiments of the present application, the communication interface can also be integrated in the processor.

[0176] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above division of functional units is taken as an example. In actual application, the above functions can be completed by different functional units according to needs, that is, the internal structure of the device is divided into different functional units to complete all or part of the functions described above. The specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here.

[0177] The embodiment of the present application further provides a computer readable storage medium, which stores instructions, and when a computer executes the instructions, the computer executes each step in the method flow shown in the above method embodiment.

[0178] The embodiment of the present application provides a computer program product containing instructions, which, when executed on a computer, cause the computer to execute a terminal access control method in the above method embodiment.

[0179] The computer readable storage medium may, for example, be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or apparatus, or any combination of the above. More specific examples (a non-exhaustive list) of the computer readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a register, a hard disk, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing, or any other form of computer readable storage medium that is known or to be developed in the future. An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium. Of course, the storage medium can be a part of the processor. The processor and the storage medium can be located in an application specific integrated circuit (ASIC). In the embodiment of the present application, the computer readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus, or device.

[0180] Since the electronic device, the computer readable storage medium, and the computer program product in the embodiment of the present application can be applied to the above method, the technical effects that can be obtained thereby can be referred to the above method embodiment, and the embodiment of the present application will not be described here.

[0181] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited to this. Any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application.

Claims

1. A terminal access control method, characterized by, The method is applied to an access and mobility management function (AMF), and the method comprises: receiving a registration request sent by a target terminal, the registration request comprising a location identifier of the target terminal, the location identifier comprising a tracking area (TAC) identifier or a cell identifier; determining whether the location identifier of the target terminal is included in a first list, the first list comprising a plurality of preset location identifiers, the plurality of preset location identifiers being any one of the following types: an allowed access type or a forbidden access type, and the plurality of preset location identifiers comprising at least one of the following: a preset TAC identifier or a preset cell identifier; determining whether to allow the registration of the target terminal based on the types of the plurality of preset location identifiers included in the first list and a first target determination result, the first target determination result being any one of the following: the location identifier of the target terminal is included in the first list or the location identifier of the target terminal is not included in the first list; the registration request further comprises a communication identifier of the target terminal, the communication identifier comprising a public land mobile network (PLMN) or an international mobile subscriber identity (IMSI); determining whether the communication identifier of the target terminal is included in a second list, the second list comprising a plurality of preset communication identifiers, the plurality of preset communication identifiers being any one of the following types: an allowed access type or a forbidden access type, and the plurality of preset communication identifiers comprising at least one of the following: a preset PLMN or a preset IMSI; determining whether to allow the registration of the target terminal based on the types of the plurality of preset communication identifiers included in the second list and a second target determination result, the second target determination result being any one of the following: the communication identifier of the target terminal is included in the second list or the communication identifier of the target terminal is not included in the second list.

2. The method of claim 1, wherein, The determination of whether to allow the registration of the target terminal based on the types of the plurality of preset location identifiers included in the first list and the first target determination result comprises: in a case where the types of the plurality of preset location identifiers included in the first list are the allowed access type and the location identifier of the target terminal is included in the first list, allowing the target terminal to register; in a case where the types of the plurality of preset location identifiers included in the first list are the allowed access type and the location identifier of the target terminal is not included in the first list, forbidding the target terminal to register; in a case where the types of the plurality of preset location identifiers included in the first list are the forbidden access type and the location identifier of the target terminal is included in the first list, forbidding the target terminal to register; in a case where the types of the plurality of preset location identifiers included in the first list are the forbidden access type and the location identifier of the target terminal is not included in the first list, allowing the target terminal to register.

3. The method of claim 1, wherein, The determination of whether to allow the registration of the target terminal based on the types of the plurality of preset communication identifiers included in the second list and the second target determination result comprises: In a case where the type of the plurality of preset communication identities included in the second list is an allowed access type and the communication identity of the target terminal is included in the second list, the target terminal is allowed to register; In a case where the type of the plurality of preset communication identities included in the second list is an allowed access type and the communication identity of the target terminal is not included in the second list, the target terminal is prohibited from registering; In a case where the type of the plurality of preset communication identities included in the second list is a prohibited access type and the communication identity of the target terminal is included in the second list, the target terminal is prohibited from registering; In a case where the type of the plurality of preset communication identities included in the second list is a prohibited access type and the communication identity of the target terminal is not included in the second list, the target terminal is allowed to register.

4. The method of claim 1, wherein, The plurality of preset communication identities in the second list further include an IMSI preset field; and the method further includes: In a case where a target field in the IMSI of the target terminal is consistent with the IMSI preset field, it is determined that the communication identity of the target terminal is included in the second list.

5. The method according to claim 1 or 2, characterized in that, The method further includes: In a case where the target terminal completes registration and a location change request sent by the target terminal is received, a location identifier of a changed location corresponding to the location change request is determined; It is determined whether the location identifier of the changed location is included in the first list; Based on the type of the plurality of preset location identifiers included in the first list and a third target determination result, it is determined whether to disconnect the access of the target terminal, the third target determination result being any one of the following: the location identifier of the changed location is included in the first list, or the location identifier of the changed location is not included in the first list.

6. A terminal access control device, characterized by comprising: The terminal access control apparatus applied to an access and mobility management function (AMF) includes a receiving unit and a determination unit. The receiving unit is configured to receive a registration request sent by a target terminal, the registration request including a location identifier of the target terminal, the location identifier including a tracking area (TAC) identifier and a cell identifier. The determination unit is configured to determine whether the location identifier of the target terminal is included in a first list, the first list including a plurality of preset location identifiers, the plurality of preset location identifiers being any one of the following types: an allowed access type or a prohibited access type, and the plurality of preset location identifiers including at least one of the following: a preset TAC identifier or a preset cell identifier. The determination unit is further configured to determine whether to allow the target terminal to register based on the type of the plurality of preset location identifiers included in the first list and a first target determination result, the first target determination result being any one of the following: the location identifier of the target terminal is included in the first list or the location identifier of the target terminal is not included in the first list. The determining unit is further configured to, in a case where the registration request further comprises a communication identity of the target terminal, the communication identity comprising a public land mobile network (PLMN) and an international mobile subscriber identity (IMSI), determine whether the communication identity of the target terminal is included in a second list, the second list comprising a plurality of preset communication identities, the plurality of preset communication identities being any one of the following types: an allowed access type and a forbidden access type, and the plurality of preset communication identities comprising at least one of the following: a preset PLMN and a preset IMSI. The determining unit is further configured to determine, based on the types of the plurality of preset communication identities included in the second list and a second target discrimination result, whether to allow the registration of the target terminal, the second target discrimination result being any one of the following: the communication identity of the target terminal is included in the second list and the communication identity of the target terminal is not included in the second list.

7. The terminal access control apparatus according to claim 6, wherein The terminal access control apparatus further comprises a registration unit. The registration unit is configured to, in a case where the types of the plurality of preset location identities included in the first list are the allowed access type and the location identity of the target terminal is included in the first list, allow the target terminal to register. The registration unit is further configured to, in a case where the types of the plurality of preset location identities included in the first list are the allowed access type and the location identity of the target terminal is not included in the first list, forbid the target terminal to register. The registration unit is further configured to, in a case where the types of the plurality of preset location identities included in the first list are the forbidden access type and the location identity of the target terminal is included in the first list, forbid the target terminal to register. The registration unit is further configured to, in a case where the types of the plurality of preset location identities included in the first list are the forbidden access type and the location identity of the target terminal is not included in the first list, allow the target terminal to register.

8. The terminal access control apparatus according to claim 6, wherein The terminal access control apparatus further comprises a registration unit. The registration unit is further configured to, in a case where the types of the plurality of preset communication identities included in the second list are the allowed access type and the communication identity of the target terminal is included in the second list, allow the target terminal to register. The registration unit is further configured to, in a case where the types of the plurality of preset communication identities included in the second list are the allowed access type and the communication identity of the target terminal is not included in the second list, forbid the target terminal to register. The registration unit is further configured to, in a case where the types of the plurality of preset communication identities included in the second list are the forbidden access type and the communication identity of the target terminal is included in the second list, forbid the target terminal to register. The registration unit is further configured to, in a case where the types of the plurality of preset communication identities included in the second list are the forbidden access type and the communication identity of the target terminal is not included in the second list, allow the target terminal to register.

9. The terminal access control apparatus according to claim 6, wherein The determining unit is further configured to determine that the communication identifier of the target terminal is included in the second list when a target field in the IMSI of the target terminal is consistent with the IMSI preset field.

10. The terminal access control apparatus according to claim 6 or 7, wherein The determining unit is further configured to determine a location identifier of a changed location corresponding to a location change request sent by the target terminal when the target terminal completes registration and the location change request is received. The determining unit is further configured to determine whether the location identifier of the changed location is included in the first list. The determining unit is further configured to determine whether to disconnect the access of the target terminal based on a type of the plurality of preset location identifiers included in the first list and a third target determination result, the third target determination result being any one of: the location identifier of the changed location is included in the first list or the location identifier of the changed location is not included in the first list.

11. An electronic device, comprising: Comprise: A processor and a memory; wherein the memory is configured to store one or more programs, the one or more programs comprising computer execution instructions; when the electronic device is running, the processor executes the computer execution instructions stored in the memory, so that the electronic device executes the terminal access control method in any one of claims 1-5.

12. A computer-readable storage medium storing one or more programs, the one or more programs comprising instructions for: The one or more programs comprise instructions which, when executed by a computer, cause the computer to perform the terminal access control method in any one of claims 1-5.

Citation Information

Patent Citations

  • System and method for detecting malicious attacks in a telecommunication network

    US20160277926A1