A method and device for disposing of the risk of harmful encrypted OTT voice application under a 5G environment

By introducing Traffic Risk Assessment (TREF) into 5G networks, emergency response suggestions for harmful OTT voice services are generated, solving the problem that existing technologies cannot identify and control harmful OTT voice services, and realizing fine-grained risk control and security enhancement for OTT voice services.

CN117295060BActive Publication Date: 2026-05-12INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
Filing Date
2022-06-16
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

In a 5G network environment, the existing policy control system cannot effectively identify and control the risks of harmful OTT voice services, especially when OTT service traffic is encrypted through a VPN tunnel, making it difficult to accurately control harmful OTT voice service flows.

Method used

Introducing Traffic Risk Assessment (TREF) into 5G networks involves detecting OTT service traffic and generating emergency response suggestions for harmful OTT voice services. This is combined with user subscription information, location, and mobile network access behavior to generate traffic and network connection policies. The suggestions are then passed to the Policy Control Function (PCF) through a new interface protocol to achieve risk control for harmful OTT services.

Benefits of technology

It enables fine-grained control over harmful OTT voice traffic, accurately identifies and processes harmful OTT services, and enhances the security and risk management capabilities of 5G networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117295060B_ABST
    Figure CN117295060B_ABST
Patent Text Reader

Abstract

The application discloses a kind of harmful encryption OTT voice application risk disposal method and device under 5G environment, comprising: traffic risk assessment function is based on the risk assessment of abnormal OTT service traffic detection result generated by user plane function, generates harmful OTT voice service emergency disposal suggestion;5G policy control system PCF according to the harmful OTT voice service emergency disposal suggestion, 5G network operator security risk policy and corresponding user's subscription information, location, mobile network access behavior information, respectively generate OTT service traffic control policy and OTT service user network connection control policy;Using OTT service traffic control policy and OTT service user network connection control policy, 5G user plane function and control plane function respectively control harmful OTT service traffic and harmful OTT service user network connection, obtain disposal result.The application can more accurately control harmful OTT service traffic by constructing new interface and introducing traffic label in policy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of 5G network communication security technology, and in particular to a method and device for handling risks of harmful encrypted OTT voice applications in a 5G environment. Background Technology

[0002] Mobile communication network services have become widely used in people's daily lives due to their mobility and convenience. With the large-scale deployment of 5G mobile communication networks, more and more people are starting to use 5G network services, especially mobile internet applications (i.e., providing various application services to users via 5G internet (Over-The-Top, OTT)). While enjoying the convenience brought by mobile communication networks, the security risks of mobile internet voice applications have also become an increasingly serious problem.

[0003] In a 5G network environment, there are a large number of OTT voice service users, and hostile users may use OTT voice applications to conduct illegal activities. To cope with potential national cybersecurity reviews, many OTT voice service providers have implemented application-layer encryption or provided services through Virtual Private Network (VPN) proxies. Therefore, effectively mitigating the security risks posed by encrypted OTT voice services in a 5G network environment has become a challenging problem.

[0004] The Policy Control Function (PCF) introduced in 5G networks primarily controls user plane traffic based on user subscription information (priority), OTT service quality requirements, and billing information, prioritizing or controlling the flow rate. Currently, it does not consider traffic control based on the risks / hazards of OTT services. Furthermore, the existing PCF cannot control network connections for relevant OTT service users based on OTT service risks because it is unaware of any potential risks associated with OTT service traffic.

[0005] Therefore, how to effectively control the security risks of harmful OTT voice services when their traffic characteristics are difficult to describe accurately becomes a new problem. Furthermore, the existing 5G policy control system (PCF) itself cannot determine what constitutes a harmful OTT voice service and its degree of harm, thus hindering the implementation of appropriate strategies; therefore, a comprehensive solution is needed. Summary of the Invention

[0006] To address the aforementioned issues, this invention proposes a method and apparatus for handling risks associated with harmful encrypted OTT voice applications in a 5G environment. This method enhances the existing 5G policy control system by introducing an open interface to the 5G Policy Control Function (PCF). This interface allows for the input of emergency response suggestions for abnormal risks in OTT voice services to the PCF. Based on these externally input suggestions, the PCF generates OTT service traffic policies and harmful OTT user network connection policies within the 5G network. Furthermore, it enhances the execution functions of existing 5G control plane and user plane policies to address harmful OTT services.

[0007] The technical content of this invention includes:

[0008] A method for mitigating risks associated with harmful encrypted OTT voice applications in a 5G environment, comprising the following steps:

[0009] 1) The traffic risk assessment function performs risk assessment based on the abnormal OTT service traffic detection results generated by the user plane function, and generates emergency handling suggestions for harmful OTT voice services.

[0010] 2) Through the interface protocol between the traffic risk assessment function and the 5G policy control system PCF, the 5G policy control system PCF obtains emergency response suggestions for harmful OTT voice services;

[0011] 3) The 5G policy control system PCF generates OTT service traffic policy and OTT service user network connection policy based on the emergency response suggestions for harmful OTT voice services, the security risk policies of 5G network operators, and the corresponding user's subscription information, location, and mobile network access behavior information.

[0012] 4) User plane functions and access and mobility management functions respectively utilize OTT service traffic policies and OTT service user network connection policies to conduct risk control on corresponding abnormal OTT service traffic and harmful OTT service user network connections, and obtain the handling results.

[0013] Furthermore, the interface protocol between the traffic risk assessment function and the 5G policy control system PCF is either the DIAMETER protocol or the SIP protocol.

[0014] Furthermore, emergency response recommendations for harmful OTT voice services include: the level of harm to the OTT service or user, the user ID, the OTT service traffic tag, and emergency measures for the OTT service.

[0015] Furthermore, emergency measures for OTT services include: discarding relevant OTT uplink traffic, discarding relevant OTT downlink traffic, limiting the speed of relevant OTT uplink traffic, limiting the speed of relevant OTT downlink traffic, prohibiting users from accessing OTT services, prohibiting users from accessing the mobile network at certain times and locations, and prohibiting users from accessing one or more of specific types of mobile access networks.

[0016] Furthermore, the user plane function and the access and mobility management function obtain the OTT service traffic control policy and the OTT service user network connection control policy respectively through the following steps:

[0017] 1) Enhance the interface protocol between the existing policy control system and SMF, and send the OTT service traffic control policy and the OTT service user network connection control policy to SMF;

[0018] 2) The SMF sends the OTT service traffic control policy and the OTT service user network connection control policy to the user plane function and access and mobility management function, respectively.

[0019] Furthermore, the OTT service traffic control policy includes: user ID information / IP address, corresponding OTT service traffic label information, OTT service traffic risk measures, and conditions for using OTT service traffic measures.

[0020] Furthermore, OTT service traffic control measures include: discarding OTT traffic corresponding to a tag, limiting the rate of traffic corresponding to a tag, and prohibiting users from accessing the OTT service name list.

[0021] Furthermore, the network connection control policy for OTT service users includes: user ID, network connection risk measures for OTT service users, and conditions for using the network connection risk measures for OTT service users.

[0022] Furthermore, OTT service user network connection control measures include: restricting / terminating network connections of users who are harmful to OTT services and prohibiting the use of specific types of access networks to access OTT services.

[0023] A storage medium storing a computer program, wherein the computer program is configured to execute the method described above at runtime.

[0024] An electronic device includes a memory and a processor, wherein the memory stores a program for performing the methods described above.

[0025] Compared with the prior art, the present invention has the following advantages:

[0026] This invention introduces a traffic risk assessment function to inform the Policy Control Function (PCF) of emergency response measures for OTT service traffic, enabling the PCF to take corresponding control measures against harmful OTT voice services. Furthermore, current PCF handling of OTT traffic requires explicit traffic description information (such as the five-tuple, application layer protocol, etc.). However, when OTT service traffic is encrypted through a VPN tunnel, different OTT service flows can carry different traffic on the same tunnel, making it difficult for existing mechanisms to accurately segment harmful OTT service flows. This invention, by introducing traffic tags into the policy, enables more granular and accurate control over harmful OTT service traffic. Attached Figure Description

[0027] Figure 1 5G-based harmful encrypted OTT voice service architecture.

[0028] Figure 2 Based on 5G malicious encrypted OTT voice service process. Detailed Implementation

[0029] The technical solutions of the present invention will be clearly and completely described below with reference to the embodiments of the present invention. Obviously, the described embodiments are only specific embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0030] The method for mitigating risks of harmful encrypted OTT voice applications in this invention, such as... Figure 1As shown, the existing 5G network architecture is enhanced by introducing a new function, Traffic Risk Evaluation Function (TREF), into the 5G system. TREF assesses the risks of harmful voice traffic, generates contingency plans for harmful encrypted OTT voice services, and sends these plans to the Policy Control Function (PCF) in the 5G network via the interface protocol between TREF and PCF. Based on the contingency plans provided by TREF, PCF, combined with relevant user subscription information, user location, user mobile network access behavior information, and 5G network operator security policies, generates harmful OTT traffic control policies and harmful OTT user network connection control policies. PCF then distributes the harmful OTT traffic control policies to the relevant User Plane Function (UPF) via the Session Management Function (SMF). Based on the OTT traffic control policies distributed by the SMF, the UPF executes the policies to implement contingency plans for the corresponding OTT traffic. Furthermore, PCF distributes the harmful OTT voice user network connection control policies to the Access and Mobility Management Function (AMF) via the SMF. AMF uses this policy to handle emergency situations related to user terminal network access.

[0031] This invention introduces a new network function, TREF (Over-The-Top Traffic Risk Assessment), into the 5G network architecture, and introduces a new interface protocol between TREF and the 5G PCF (Programmable Flow Function) to implement input of emergency response suggestions for abnormal risks. TREF assesses abnormal risks of OTT services and generates OTT service risk response suggestions. TREF then sends these suggestions to the 5G PCF function through the new interface. Based on the risk response suggestions provided by TREF, and using user subscription information, user mobile network access behavior information, and user location information, the PCF generates harmful OTT service traffic control policies and harmful voice user connection control policies. The PCF distributes the traffic control policies to the 5G UPF function via the SMF (Service Flow Management Function). The 5G UPF executes the traffic control policies to control the corresponding harmful OTT service traffic. Furthermore, the PCF distributes harmful voice user connection control policies to the 5G AMF (Auxiliary Flow Management Function) function via the SMF. The 5G AMF executes the traffic control policies to control the network connections of the corresponding OTT service users.

[0032] The main steps of the method for handling harmful OTT voice applications of the present invention are as follows:

[0033] (1) 5G terminal users access OTT voice services through the 5G network. Users may use VPN proxies to access OTT voice services in order to cope with network regulation and censorship.

[0034] (2) The 5G UPF reports the OTT service traffic detection results to the TREF.

[0035] (3) TREF assesses the risks of 5G OTT voice services to obtain risk levels and generates emergency recommendations for harmful OTT voice services based on the risk levels.

[0036] (4) This invention introduces a new interface protocol between the TREF function and the 5G PCF function. Through this interface protocol, TREF sends an emergency suggestion message for harmful OTT voice services to the 5G PCF. This message contains the following information: the harm level of the OTT service or user, the 5G user ID (IP address), the OTT service traffic label, and emergency measures for the OTT service, such as discarding relevant OTT traffic (uplink, downlink), limiting the traffic rate (uplink, downlink), prohibiting users from accessing OTT services, and prohibiting users from accessing the mobile network (time, location, access method).

[0037] (5) The 5G PCF sends a response message to the TREF to confirm that the relevant emergency recommendations have been successfully received.

[0038] (6) Based on the emergency response recommendations for harmful OTT services provided by TREF, PCF, in conjunction with the security risk strategies of 5G network operators, relevant user subscription information, user location, and user mobile network access behavior information in the 5G system, generates OTT service traffic control policies for the 5G user plane and OTT service user network connection control policies for the 5G control plane within the 5G network. The OTT service traffic control policies include: user ID information / IP address, corresponding OTT service traffic label information, OTT risk control measures (discarding OTT traffic corresponding to the label, limiting the rate of traffic corresponding to the label, prohibiting users from accessing the OTT service name list), and the conditions for using the measures (time, location, etc.). The OTT service user network connection control policies include: user ID (IP address, International Mobile Subscriber Identity (IMSI) / Mobile Subscriber International ISDN / PSTN number, MSISDN, etc.), actions (restricting / terminating network connections of users related to harmful OTT services, prohibiting network access of user terminals), and conditions (time, location, access method, etc.).

[0039] (7) By enhancing the interface protocol between the existing PCF and SMF, the 5G PCF sends the harmful OTT service traffic control policy and the harmful OTT service user network connection control policy to the 5G Session Management Function (SMF).

[0040] (8) The 5G SMF sends a response message to the 5G PCF to confirm that the relevant policy has been successfully received.

[0041] (9) The 5G SMF sends the OTT service traffic control policy to the 5G UPF. The policy includes the following: user ID information / IP address, corresponding OTT service traffic label information, OTT risk measures (discarding the OTT traffic corresponding to the label, limiting the rate of the traffic corresponding to the label, prohibiting users from accessing the OTT service name list, and the conditions for using the measures (time, location, etc.).

[0042] (10) The 5G UPF implements the 5G OTT service traffic control policy to control the risk of the corresponding abnormal OTT service traffic. Specific measures include discarding the OTT traffic corresponding to the tag, limiting the speed of the traffic corresponding to the tag, prohibiting users from accessing the OTT service list, and sending the relevant harmful OTT service traffic to the relevant network service audit server for future query and evidence collection.

[0043] (11) The 5G UPF sends a response message to the 5G SMF to report the execution status of the traffic policy and whether it was successful or not.

[0044] (12) In addition, the 5G SMF sends the network connection control policy for OTT service users to the 5G AMF. The policy includes the following: user ID information / IP address, measures to prevent network connection risks to harmful OTT voice users (interrupting the user's network connection, restricting certain specific network sessions, prohibiting the terminal user from accessing the network), and the conditions for using the measures (time, location, access method, etc.).

[0045] (13) The 5G AMF implements the network connection control policy for 5G OTT service users and carries out risk control on the network connection of the corresponding harmful OTT service users. Specific measures include interrupting the user's network connection, restricting certain specific network sessions, and prohibiting the terminal user from accessing the network.

[0046] (14) The 5G AMF sends a response message to the 5G SMF to provide feedback on the execution status of the user's network connection policy, indicating whether it was successful or not.

[0047] The description of this invention is given for illustrative and descriptive purposes only, and is not intended to be exhaustive or to limit the invention to the forms disclosed. It will be apparent to those skilled in the art that various modifications and variations can be made to the examples of this invention without departing from the spirit and principles of the invention. The embodiments were chosen and described to better illustrate the principles and practical application of the invention, and to enable those skilled in the art to understand the invention and design various embodiments with various modifications suitable for a particular purpose.

Claims

1. A method for handling risks associated with harmful encrypted OTT voice applications in a 5G environment, comprising the following steps: 1) The traffic risk assessment function performs risk assessment based on the abnormal OTT service traffic detection results generated by the user plane function, and generates emergency handling suggestions for harmful OTT voice services. 2) Through the interface protocol between the traffic risk assessment function and the 5G policy control system PCF, the 5G policy control system PCF obtains emergency response suggestions for harmful OTT voice services; 3) The 5G policy control system PCF generates OTT service traffic control policies and OTT service user network connection control policies based on the emergency response suggestions for harmful OTT voice services, the security risk policies of 5G network operators, and the corresponding user's subscription information, location, and mobile network access behavior information. 4) User plane functions and access and mobility management functions are based on OTT service traffic control policies and OTT service user network connection control policies, respectively, to perform risk control on corresponding harmful OTT service traffic and harmful OTT service user network connections, and obtain the handling results.

2. The method as described in claim 1, characterized in that, Emergency response recommendations for harmful OTT voice services include: the level of harm to the OTT service or user, the user ID, the OTT service traffic tag, and emergency measures for the OTT service.

3. The method as described in claim 2, characterized in that, OTT service emergency measures include: dropping relevant OTT uplink traffic, dropping relevant OTT downlink traffic, limiting the speed of relevant OTT uplink traffic, limiting the speed of relevant OTT downlink traffic, prohibiting users from accessing OTT services, prohibiting users from accessing the mobile network at different times and locations, and prohibiting users from accessing one or more of specific types of mobile access networks.

4. The method as described in claim 1, characterized in that, User plane functions and access and mobility management functions obtain OTT service traffic control policies and OTT service user network connection control policies through the following steps respectively: 1) Enhance the interface protocol between the existing policy control system and the session management function, and send the OTT service traffic control policy and the OTT service user network connection control policy to the session management function; 2) The session management function sends the OTT service traffic control policy and the OTT service user network connection control policy to the user plane function and the access and mobility management function, respectively.

5. The method as described in claim 1, characterized in that, OTT service traffic control policies include: user ID information / IP address, corresponding OTT service traffic label information, OTT service traffic risk measures, and conditions for using OTT service traffic measures.

6. The method as described in claim 5, characterized in that, OTT service traffic control measures include: discarding OTT traffic corresponding to a tag, limiting the rate of traffic corresponding to a tag, and prohibiting users from accessing the OTT service name list.

7. The method as described in claim 1, characterized in that, The OTT service user network connection control policy includes: user ID, OTT service user network connection control measures, and conditions for using OTT service user network connection control measures.

8. The method as described in claim 7, characterized in that, OTT service user network connection control measures include: restricting / terminating network connections of users who are harmful to OTT services and prohibiting user terminals from accessing OTT services using specific types of access networks.

9. A storage medium storing a computer program, wherein, The computer program is configured to execute the method of any one of claims 1-8 at runtime.

10. An electronic device comprising a memory and a processor, the memory storing a computer program, the processor being configured to run the computer program to perform the method as claimed in any one of claims 1-8.