Method, device, equipment, medium and program product for intercepting illegal terminal network access
By using user data management network elements and an illegal terminal device identifier list database in 4/5G networks for legitimacy detection, the problem of illegal terminal access to the network is solved, and illegal terminals can be intercepted and permanently restricted, thereby improving network security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA MOBILE GROUP DESIGN INST
- Filing Date
- 2024-04-17
- Publication Date
- 2026-07-21
AI Technical Summary
In 4G/5G networks, existing technologies are unable to effectively detect and block unauthorized terminals from accessing the network. Criminals can still use unauthorized terminals to commit fraud by changing the IMSI. The lack of secure automated means leads to a decline in network security.
The user data management network element receives network access registration requests from the access management network element, reads terminal device identification information and subscription information, performs legality checks using the illegal terminal device identification list database, sends the reading results to the access management network element to indicate whether network access is allowed, and permanently restricts access if it is detected as illegal.
It enables secure management and interception of unauthorized user terminals, reduces the possibility of fraud, improves network security, and reduces network implementation complexity and investment.
Smart Images

Figure CN118803786B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method, apparatus, device, medium, and program product for intercepting unauthorized terminals from accessing the network. Background Technology
[0002] Based on current network development trends, 2G networks (MSC / VLR / SGSN, HLR) are gradually being phased out, and future mobile terminals and mobile networks will mainly be based on 4G / 5G standards.
[0003] However, in the 2G / 3G era, EIR devices were used to check the IMEI list to identify the legitimacy of terminal devices accessing the PLMN network. But 4G / 5G networks have undergone significant changes compared to 2G / 3G, and due to technical limitations and investment factors, EIR devices are not deployed in 4G / 5G networks. Therefore, it is impossible to use MME / AMF access management network elements and EIR to verify terminal legitimacy via IMEI. Furthermore, current technology lacks controllable and secure automated means for handling fraudulent IMEI lists, and technically, it does not completely prevent locked illegal terminals from accessing the network. Criminals can still use the illegal terminal by changing the IMSI. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a method, apparatus, device, medium and program product for intercepting illegal terminals from accessing the network. This method can realize the secure management of the list of illegal user terminals, effectively detect illegal user terminals, and permanently block and restrict their access to the network, thereby reducing the possibility of users being defrauded and improving the overall network security level.
[0005] In a first aspect, embodiments of the present invention provide a method for intercepting unauthorized terminals from accessing the network, applied to a user data management network element, comprising:
[0006] Receive network access registration request information from a user terminal sent by an access management network element, and read the device identification information and user subscription information of the user terminal based on the network access registration request information;
[0007] Based on the illegal terminal device identifier list database, the legality of the device identifier information of the user terminal is checked to obtain the detection result;
[0008] Based on the detection results, a read result of reading the user's subscription information is sent to the access management network element. The read result is used to indicate whether the access management network element allows the user terminal to access the network.
[0009] As an improvement to the above solution, the method further includes:
[0010] Receive device identification information of unauthorized terminals sent by the business operation support system;
[0011] The device identification information of illegal terminals sent by the business operation support system is written into a pre-established illegal terminal device identification list database.
[0012] As an improvement to the above solution, the step of performing a legality check on the device identification information of the user terminal based on the illegal terminal device identification list database and obtaining the detection result specifically includes:
[0013] Based on the device identification information of the user terminal, a query is performed on the illegal terminal device identification list database, and a timer of a set duration is started simultaneously.
[0014] When no matching device identifier information is found in the illegal terminal device identifier list database, or when no matching device identifier information is found in the illegal terminal device identifier list database within a set time period, the detection result is that the user terminal is a legitimate user terminal.
[0015] When a device identifier matching the device identifier information of the user terminal is found in the illegal terminal device identifier list database, the detection result is that the user terminal is an illegal user terminal.
[0016] As an improvement to the above solution, the step of sending the reading result of the user's subscription information to the access management network element based on the detection result specifically includes:
[0017] If the detection result indicates that the user terminal is a legitimate user terminal, then the result of successfully reading the user's subscription information and the read user subscription information will be sent to the access management network element.
[0018] If the detection result indicates that the user terminal is an illegal user terminal, then the result of failure to read the user's subscription information will be sent to the access management network element.
[0019] As an improvement to the above scheme, after sending the result of failure to read user subscription information to the access management network element if the detection result indicates that the user terminal is an illegal user terminal, the method further includes:
[0020] The system checks whether a registered user exists in the illegal terminal device identifier list database that corresponds to the device identifier information of the user terminal.
[0021] If a corresponding registered user exists, the device identification information of the user terminal is associated with the corresponding registered user, and a deregistration notification is sent to the access management network element; wherein, the deregistration notification includes the registered user corresponding to the device identification information of the user terminal, and is used to instruct the access management network element to interrupt the network connection of the corresponding registered user;
[0022] If no corresponding registered user exists, the device identification information of the user terminal will be updated to the illegal terminal device identification list database.
[0023] Secondly, embodiments of the present invention provide a method for intercepting unauthorized terminals from accessing the network, applied to an access management network element, including:
[0024] Receive network registration request information initiated by user terminals;
[0025] The network access registration request information is sent to the user data management network element; wherein, the network access registration request information is used to instruct the user data management network element to perform a legality check on the user terminal according to the illegal terminal device identifier list database;
[0026] The system receives the reading result of the user subscription information sent by the user data management network element, and determines whether the user terminal is allowed to access the network based on the reading result.
[0027] As an improvement to the above solution, the step of receiving the reading result of the user subscription information sent by the user data management network element, and determining whether the user terminal is allowed to access the network based on the reading result, specifically includes:
[0028] If the system receives a successful read result of the user's subscription information and the read user subscription information, then the user terminal is allowed to access the network and proceed with the normal registration process.
[0029] If a result indicating failure to read user subscription information is received, the user terminal will be denied network access and registration will fail.
[0030] As an improvement to the above solution, the method further includes:
[0031] The system receives a deregistration notification sent by the user data management network element; wherein the deregistration notification includes the registered user corresponding to the device identification information of the user terminal.
[0032] Based on the notification to disconnect from registration, the network connection of the corresponding registered user is interrupted.
[0033] Thirdly, embodiments of the present invention provide a device for intercepting unauthorized terminal access to the network, applied to a user data management network element, comprising:
[0034] The network access registration request information receiving module is used to receive network access registration request information of user terminals sent by the access management network element, and read the device identification information and user subscription information of the user terminals according to the network access registration request information;
[0035] The legitimacy detection module is used to perform legitimacy detection on the device identification information of the user terminal based on the illegal terminal device identification list database, and obtain the detection result;
[0036] The user subscription information reading result sending module is used to send the reading result of the user subscription information to the access management network element according to the detection result. The reading result is used to indicate whether the access management network element allows the user terminal to access the network.
[0037] Fourthly, embodiments of the present invention provide a device for intercepting unauthorized terminal access to the network, applied to an access management network element, comprising:
[0038] The network access registration request information receiving module is used to receive network access registration request information initiated by user terminals;
[0039] The network access registration request information sending module is used to send the network access registration request information to the user data management network element; wherein, the network access registration request information is used to instruct the user data management network element to perform a legality check on the user terminal according to the illegal terminal device identifier list database;
[0040] The user subscription information reading result receiving module is used to receive the user subscription information reading result sent by the user data management network element, and determine whether the user terminal is allowed to access the network based on the reading result.
[0041] Fifthly, embodiments of the present invention provide a device for intercepting unauthorized terminal access to the network, comprising: a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the method for intercepting unauthorized terminal access to the network as described in any of the first aspects, or the method for intercepting unauthorized terminal access to the network as described in any of the second aspects.
[0042] In a sixth aspect, embodiments of the present invention provide a computer-readable storage medium storing a computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform a method for intercepting illegal terminal access to the network as described in any one of the first aspects, or a method for intercepting illegal terminal access to the network as described in any one of the second aspects.
[0043] In a seventh aspect, embodiments of the present invention provide a computer program product, including a computer program / instruction, which, when executed by a processor, implements the method for intercepting illegal terminal access to the network as described in any of the first aspects, or the method for intercepting illegal terminal access to the network as described in any of the second aspects.
[0044] Compared to existing technologies, this invention provides a method, apparatus, device, medium, and program product for intercepting unauthorized terminals from accessing the network. The method first receives a user terminal's network access registration request information sent by an access management network element through a user data management network element. Based on the network access registration request information, it reads the user terminal's device identification information and user subscription information. Then, based on an unauthorized terminal device identification list, it performs a legality check on the user terminal's device identification information to obtain a detection result. Finally, based on the detection result, it sends a result of reading the user subscription information to the access management network element, instructing the access management network element whether to allow the user terminal to access the network. This invention can achieve secure management of the list of unauthorized user terminals, effectively detect unauthorized user terminals, and permanently restrict their access to the network, thereby reducing the possibility of users being defrauded and improving the overall network security level. Attached Figure Description
[0045] To more clearly illustrate the technical solution of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0046] Figure 1 This is a flowchart of a method for intercepting unauthorized terminals from accessing the network, provided by an embodiment of the present invention;
[0047] Figure 2 This is a schematic diagram illustrating the legality detection interaction of a method for intercepting unauthorized terminal access to the network provided in an embodiment of the present invention;
[0048] Figure 3 This is another legality detection interaction diagram of a method for intercepting illegal terminal access to the network provided by an embodiment of the present invention;
[0049] Figure 4 This is another flowchart of a method for intercepting illegal terminal access to the network provided by an embodiment of the present invention;
[0050] Figure 5 This is an overall interactive schematic diagram of a method for intercepting illegal terminal access to the network provided by an embodiment of the present invention;
[0051] Figure 6This is a user registration process interaction diagram of a method for intercepting illegal terminal access to the network provided by an embodiment of the present invention;
[0052] Figure 7 This is a schematic diagram illustrating the process of deleting the list of illegal terminals in a method for intercepting illegal terminal access to the network provided by an embodiment of the present invention.
[0053] Figure 8 This is a structural block diagram of a device for intercepting illegal terminal access to the network provided in an embodiment of the present invention;
[0054] Figure 9 This is another structural block diagram of a device for intercepting illegal terminal access to the network provided in an embodiment of the present invention;
[0055] Figure 10 This is a structural block diagram of a device for intercepting illegal terminal access to the network provided in an embodiment of the present invention. Detailed Implementation
[0056] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0057] To clearly describe the technical solutions in the embodiments of the present invention, please refer to Table 1, which provides a brief explanation of some terms and concepts involved in the embodiments of the present invention.
[0058] Table 1. Explanation of Terminology and Concepts
[0059]
[0060]
[0061] Please see Figure 1 , Figure 1 This is a flowchart of a method for intercepting unauthorized terminal access to the network provided by an embodiment of the present invention. The method for intercepting unauthorized terminal access to the network is applied to a user data management network element and includes:
[0062] S11: Receive network access registration request information from a user terminal sent by an access management network element, and read the device identification information and user subscription information of the user terminal according to the network access registration request information;
[0063] S12: Based on the illegal terminal device identifier list database, perform a legality check on the device identifier information of the user terminal and obtain the detection result;
[0064] S13: Based on the detection result, send the reading result of the user's subscription information to the access management network element. The reading result is used to indicate whether the access management network element allows the user terminal to access the network.
[0065] This invention provides a method for intercepting unauthorized terminals accessing the network in a 4 / 5G network environment. For example, when a 4 / 5G user initiates the network registration process, the access management network element (AMF / MME) receives information reported by the user terminal (UE) and user subscription information returned from the user database. During the normal registration process, this invention embeds a legality detection process for the user terminal's device identification information into the existing business process. This legality detection obtains relevant information and makes judgments, primarily comparing the IMEI terminal information carried by the registered user terminal with a pre-entered list / database of unauthorized terminal device identifiers. This automatically intercepts unauthorized terminals during normal UE network registration. The method can determine terminal legality without modifying the normal registration process for obtaining subscription information, simply by adding a legality detection module and pre-configured unauthorized terminal data. This invention does not require adding new network elements, reducing network implementation complexity and investment. It only enhances the logical function of existing network elements, leveraging the existing registration business process and using additional instructions to determine terminal legality. This, in turn, affects the access management network element's ability to permanently restrict terminal access, thereby reducing the possibility of users being defrauded and improving overall network security.
[0066] As an optional embodiment, the method further includes:
[0067] Receive device identification information of unauthorized terminals sent by the business operation support system;
[0068] The device identification information of illegal terminals sent by the business operation support system is written into a pre-established illegal terminal device identification list database.
[0069] It should be noted that, in this embodiment of the invention, the BOSS system (Business Operation Support System) is a controllable means to record the IMEI / PEI information of illegal terminals such as fraudulent devices (5G systems use PEI (Permanent Device Identifier) to identify user terminals UE) that are required by the operator to restrict network access through security into the UDR in real time via the SOAP interface protocol, and construct an illegal terminal device identifier list / table in the UDR. The daily maintenance and update of information can be achieved through registration and deletion steps.
[0070] For example, the operator marks this batch of IMEI information as illegal terminal information and enters it into the illegal terminal device identification list database / table of the user data UDM / UDR network element through BOSS.
[0071] Further, step S12: The step of performing a legality check on the device identification information of the user terminal based on the illegal terminal device identifier list database and obtaining the detection result specifically includes:
[0072] Based on the device identification information of the user terminal, a query is performed on the illegal terminal device identification list database, and a timer of a set duration is started simultaneously.
[0073] When no matching device identifier information is found in the illegal terminal device identifier list database, or when no matching device identifier information is found in the illegal terminal device identifier list database within a set time period, the detection result is that the user terminal is a legitimate user terminal.
[0074] When a device identifier matching the device identifier information of the user terminal is found in the illegal terminal device identifier list database, the detection result is that the user terminal is an illegal user terminal.
[0075] Further, step S13: sending the reading result of reading the user subscription information to the access management network element based on the detection result specifically includes:
[0076] If the detection result indicates that the user terminal is a legitimate user terminal, then the result of successfully reading the user's subscription information and the read user subscription information will be sent to the access management network element.
[0077] If the detection result indicates that the user terminal is an illegal user terminal, then the result of failure to read the user's subscription information will be sent to the access management network element.
[0078] See Figures 2-3 , Figure 2 This is a schematic diagram illustrating the legality detection interaction of a method for intercepting unauthorized terminal access to the network provided in an embodiment of the present invention. Figure 3 This is another legality detection interaction diagram of a method for intercepting unauthorized terminal access to the network provided in an embodiment of the present invention. In this embodiment of the present invention, as... Figure 2As shown, when a user terminal (UE) sends a network registration request in a 4G / 5G network, the access management network element sends the request to the user data management network element, triggering a legality detection process. This legality detection process can be co-located with the user data management network element, with a built-in detection counter (initial value can be set to N, numerical or time-based). Together with the UDM / UDR, it completes service registration and issuance via NRF (NF repository function), and then interacts with the AMF. Illegal terminal data can be written in real-time through the BOSS system, thus completing the interaction between the UDR and BOSS; or it can interact with the MME via DRA (Dynamic Resource Allocation / Scheduling). The interaction logic between the legality detection module and the internal illegal terminal list / database query and the access management network element is as follows: Figure 3 As shown, based on the key IMEI information in the multi-dimensional information input in the user registration request, the legitimacy is judged by querying the IMEI status of the already entered list of illegal terminals. If it meets the legitimacy judgment logic, a feedback of network access rejection is sent to the access management network element, and the user registration fails. If it is a status outside the legitimacy judgment logic or the detection timeout occurs, a notification of network access permission is sent to the access management network element, and the normal registration process is carried out.
[0079] As an optional embodiment, after sending the result of failure to read user subscription information to the access management network element if the detection result indicates that the user terminal is an illegal user terminal, the method further includes:
[0080] The system checks whether a registered user exists in the illegal terminal device identifier list database that corresponds to the device identifier information of the user terminal.
[0081] If a corresponding registered user exists, the device identification information of the user terminal is associated with the corresponding registered user, and a deregistration notification is sent to the access management network element; wherein, the deregistration notification includes the registered user corresponding to the device identification information of the user terminal, and is used to instruct the access management network element to interrupt the network connection of the corresponding registered user;
[0082] If no corresponding registered user exists, the device identification information of the user terminal will be updated to the illegal terminal device identification list database.
[0083] It is worth noting that by adding the device identification information of unauthorized user terminals to the unauthorized terminal device identification list, these devices can be prevented from connecting to the network in the future; by terminating the network connection of unauthorized user terminals, legitimate users can be protected from fraud and network attacks, and network performance and reliability can be improved.
[0084] Please see Figure 4 , Figure 4 This is another flowchart of a method for intercepting unauthorized terminal access to the network provided in an embodiment of the present invention. The method for intercepting unauthorized terminal access to the network is applied to an access management network element and includes:
[0085] S21: Receive network registration request information initiated by the user terminal;
[0086] S23: Send the network access registration request information to the user data management network element; wherein, the network access registration request information is used to instruct the user data management network element to perform a legality check on the user terminal according to the illegal terminal device identifier list database;
[0087] S23: Receive the reading result of the user subscription information sent by the user data management network element, and determine whether the user terminal is allowed to access the network based on the reading result.
[0088] Specifically, step S23: receiving the reading result of the user subscription information sent by the user data management network element, and determining whether the user terminal is allowed to access the network based on the reading result, specifically includes:
[0089] If the system receives a successful read result of the user's subscription information and the read user subscription information, then the user terminal is allowed to access the network and proceed with the normal registration process.
[0090] If a result indicating failure to read user subscription information is received, the user terminal will be denied network access and registration will fail.
[0091] In an optional embodiment, the method for intercepting unauthorized terminals from accessing the network further includes:
[0092] The system receives a deregistration notification sent by the user data management network element; wherein the deregistration notification includes the registered user corresponding to the device identification information of the user terminal.
[0093] Based on the notification to disconnect from registration, the network connection of the corresponding registered user is interrupted.
[0094] It should be noted that the working principle of the method for intercepting illegal terminal access to the network described in the embodiments of the present invention can refer to the working principle of the method for intercepting illegal terminal access to the network described in the above embodiments, and the technical effect achieved is the same as that of the method for intercepting illegal terminal access to the network described in the above embodiments, and will not be repeated here.
[0095] See Figure 5 , Figure 5 This is an overall interactive schematic diagram of a method for intercepting unauthorized terminals from accessing the network, provided by an embodiment of the present invention; the embodiment of the present invention takes the legality detection of fraudulent terminals as an example, such as... Figure 5As shown, 1-1, 1-2, 1-3, 3-1, and 3-2 are normal registration process messages. In this embodiment of the invention, three additional messages are added, namely messages 2-1, 2-2, and 2-3, which are embedded in the normal registration process to perform legality checks on fraudulent terminals. Through messages 3-1 and 3-2, the associated records are synchronized with the fraudulent IMEI and multiple IMSI relationships.
[0096] The result constructed by the legality detection and judgment module includes two parts. First, it detects whether the IMEI of the UE accessing the device belongs to the list of fraudulent terminals. Then, it returns a result code to the UDM based on the judgment. The UDM then determines whether to return the subscription data to the access management network element (AMF / MME) based on the result code, so as to further determine whether to allow the terminal to register or whether it is restricted from accessing the network.
[0097] If the condition matches the predefined logic, the terminal is identified as a fraudulent terminal. The detection and judgment module then returns a NOT_ALLOW code indicating that access is not permitted. This information is then compared with the subscription information using an AND logic, ultimately leading to a failure to obtain the subscription data and feedback to the access management network element (AMF / MME). The access management network element automatically implements a network access prohibition command for terminals with illegal IMEIs. Simultaneously, the detection and judgment module associates and records the IMSI number carried by the IMEI during this registration, and synchronizes this data to the fraudulent terminal list database of the UDR for use by security agencies, etc., and further allows for the identification of new fraudulent terminal IMEIs through the illegal IMSI.
[0098] If the logic is not met or the detection times out, the state is either outside the fraud terminal list or something else. The timeout detection is to ensure the impact on device and service performance when the detection fails. A reasonable detection time counter can be set. If the terminal is not on the fraud terminal list or the timeout occurs, the detection module returns the correct code ALLOW, the registration process is bypassed, and the normal registration process is completed by connecting to the management network element.
[0099] For a more intuitive description of the judgment logic, please refer to Table 2, which is an explanation of the legality judgment logic of a method for intercepting illegal terminal access to the network.
[0100] Table 2 Explanation of Legality Judgment Logic
[0101]
[0102] Combining the judgment logic in Table 2 above and Figure 5 The interactive diagram shown is provided below for reference to more clearly describe the technical solutions provided in the embodiments of the present invention:
[0103] Example 1: When a user UE initiates a registration service based on a 4G or 5G base station, the access management network element AMF / MME sends the registration request to UDM. After obtaining the subscription information, UDM triggers the detection and judgment module processing flow. The detection and judgment module uses the IMEI data of this registration to query the UDR for relevant fraudulent terminal list IMEI status data, and starts the detection timer simultaneously. If it is confirmed to be a fraudulent terminal list status (see Table 1, serial number 1), UDM directly returns a registration failure to the access management network element AMF / MME based on the result code NOT_ALLOW.
[0104] Example 2: When a user UE initiates a registration service based on a 4G or 5G base station, the access management network element AMF / MME sends the registration request to the UDM. After obtaining the subscription information, the UDM triggers the detection and judgment module processing flow. The detection and judgment module uses the IMEI data of this registration to query the UDR for relevant fraudulent terminal list IMEI status data, and simultaneously starts the detection timer. If it is confirmed that it is a non-fraudulent terminal status (see Serial No. 2 in Table 1), the UDM directly returns the registration and subscription information success message to the access management network element AMF / MME based on the result code ALLOW.
[0105] Example 3: When a user UE initiates a registration service based on a 4G or 5G base station, the access management network element AMF / MME sends the registration request to the UDM. After obtaining the subscription information, the UDM triggers the detection and judgment module processing flow. This module uses the IMEI data of this registration to query the UDR for relevant fraudulent terminal list database IMEI status data, and simultaneously starts the detection timer. If the TIME countdown is 0 (see Table 1, Serial No. 3), the detection stops and the result code ALLOW is returned directly. Based on the result code ALLOW, the UDM directly returns the registration and subscription information success message to the access management network element AMF / MME.
[0106] In this embodiment of the invention, the method for updating the list of illegal terminals is implemented based on BOSS controllable means, and can also safely add and delete the IMEI status information of fraudulent terminals.
[0107] See Figures 6-7 , Figure 6 This is a schematic diagram illustrating the registration process of a method for intercepting unauthorized terminals from accessing the network, provided in an embodiment of the present invention. Figure 7 This is a schematic diagram illustrating the process of deleting an illegal terminal list in a method for intercepting illegal terminal access to the network, provided by an embodiment of the present invention. Figure 6As shown, adding illegal terminals such as those involved in IMEI fraud can also immediately kick users offline. Message 1 / 2: When registering illegal terminals, the IMEIs of the registration list are sent to the UDR via the BOSS system. The UDR then sends a notification to the UDM regarding the registration of illegal terminals such as those involved in IMEI fraud. Message 3 / 4: The UDM queries the user information corresponding to the IMEI in the UDR. The query result includes the IMEI, registration information, IMSI (International Mobile Subscriber Identity), and MME / AMF Address (Mobility Management Entity and Access and Mobility Management Function Address). Based on the queried registration information, the UDM sends a deregistration notification message to the access management network element. Message 5 / 6: The access management network element AMF / MME receives the deregistration notification and kicks the user offline. Message 7 / 8: After receiving the deregistration confirmation result from the access management network element, the UDM updates the current status of the user's IMEI to "fraud list confirmed status". Message 9 / 10: After updating, the UDM sends a registration confirmation notification to the UDR, which then sends the confirmed registration list to the BOSS system, completing the registration of the newly added fraudulent terminals.
[0108] like Figure 7 As shown, if a terminal's IMEI is mistakenly included in the fraudulent terminal list, it can be corrected by deletion. Message 1 / 2: When it is necessary to delete an illegal terminal from the list, the IMEI to be deleted is sent to the UDR through the BOSS system. Then, the UDR sends a notification to the UDM to delete the illegal terminals such as those with fraudulent IMEIs. Message 3 / 4: The UDM queries the user information corresponding to the IMEI in the UDR. The query result includes the IMEI, registration information, IMSI (International Mobile Subscriber Identity), and MME / AMF Address (Mobility Management Entity and Access and Mobility Management Function Address). Message 5 / 6: The UDM updates the information in the IMEI fraudulent terminal list database to the UDR based on the queried registration information. After the UDR updates, it sends an update confirmation to the UDM. After receiving the update confirmation, the UDM returns a list registration confirmation notification. Message 7 / 8: After receiving the list registration confirmation notification, the UDR sends the deleted list to the BOSS system, completing the deletion of the fraudulent terminal list registration.
[0109] See Figure 8 , Figure 8 This is a structural block diagram of a device for intercepting unauthorized terminal access to the network, provided by an embodiment of the present invention. It is applied to a user data management network element and includes:
[0110] The network access registration request information receiving module 31 is used to receive network access registration request information of user terminals sent by the access management network element, and read the device identification information and user subscription information of the user terminals according to the network access registration request information;
[0111] The legality detection module 32 is used to perform legality detection on the device identification information of the user terminal according to the illegal terminal device identification list database, and obtain the detection result;
[0112] The user subscription information reading result sending module 33 is used to send the reading result of reading the user subscription information to the access management network element according to the detection result. The reading result is used to indicate whether the access management network element allows the user terminal to access the network.
[0113] In an optional embodiment, the device further includes a device identification information writing module for an illegal terminal, the device identification information writing module for the illegal terminal specifically comprising:
[0114] The illegal terminal device identification information receiving unit is used to receive the illegal terminal device identification information sent by the business operation support system;
[0115] The illegal terminal device identification information writing unit is used to write the illegal terminal device identification information sent by the business operation support system into a pre-established illegal terminal device identification list database.
[0116] In a preferred embodiment, the legality detection module 32 specifically includes:
[0117] The device identification information query unit is used to query the illegal terminal device identification list database based on the device identification information of the user terminal, and at the same time start a timer of a set duration.
[0118] The first detection unit is used to obtain a detection result that the user terminal is a legitimate user terminal when no device identification information matching the device identification information of the user terminal is found in the illegal terminal device identification list database, or when no device identification information matching the device identification information of the user terminal is found in the illegal terminal device identification list database within a set time period.
[0119] The second detection unit is used to obtain a detection result that the user terminal is an illegal user terminal when it finds that there is device identification information in the illegal terminal device identification list database that matches the device identification information of the user terminal.
[0120] In a preferred embodiment, the user subscription information reading result sending module 33 specifically includes:
[0121] The first information sending unit is configured to send the result of successfully reading the user's subscription information and the read user subscription information to the access management network element if the detection result indicates that the user terminal is a legitimate user terminal.
[0122] The second information sending unit is used to send the result of failure to read user subscription information to the access management network element if the detection result indicates that the user terminal is an illegal user terminal.
[0123] In an optional embodiment, the device for intercepting illegal terminal access to the network further includes:
[0124] The module for sending registration requests includes:
[0125] The registered user query unit is used to query whether there is a registered user in the illegal terminal device identifier list database that corresponds to the device identifier information of the user terminal;
[0126] A deregistration notification unit is configured to, if a corresponding registered user exists, associate the device identification information of the user terminal with the corresponding registered user and send a deregistration notification to the access management network element; wherein, the deregistration notification includes the registered user corresponding to the device identification information of the user terminal, and is used to instruct the access management network element to interrupt the network connection of the corresponding registered user;
[0127] The device identification information update unit is used to update the device identification information of the user terminal to the illegal terminal device identification list database if there is no corresponding registered user.
[0128] It should be noted that the working process of each module in the device for intercepting illegal terminal access to the network described in the embodiments of the present invention can refer to the working process of the method for intercepting illegal terminal access to the network described in the above embodiments, and the technical effect achieved is the same as that of the method for intercepting illegal terminal access to the network described in the above embodiments, and will not be repeated here.
[0129] See Figure 9 , Figure 9 This is a structural block diagram of a device for intercepting unauthorized terminal access to the network, provided by an embodiment of the present invention. The device is applied to an access management network element and includes:
[0130] The network access registration request information receiving module 41 is used to receive network access registration request information initiated by the user terminal;
[0131] The network access registration request information sending module 42 is used to send the network access registration request information to the user data management network element; wherein, the network access registration request information is used to instruct the user data management network element to perform a legality check on the user terminal according to the illegal terminal device identifier list database;
[0132] The user subscription information reading result receiving module 43 is used to receive the reading result of the user subscription information sent by the user data management network element, and to determine whether the user terminal is allowed to access the network based on the reading result.
[0133] In a preferred embodiment, the user subscription information reading result receiving module 43 specifically includes:
[0134] The first registration judgment unit is used to allow the user terminal to access the network and proceed with the normal registration process if it receives the result of successfully reading the user's contract information and the read user's contract information.
[0135] The second registration judgment unit is used to refuse the user terminal's access to the network and register it if it receives a result indicating that reading the user's contract information failed.
[0136] In an optional embodiment, the device for intercepting illegal terminal access to the network further includes:
[0137] The module for receiving registration notifications specifically includes:
[0138] A deregistration notification receiving unit is configured to receive a deregistration notification sent by the user data management network element; wherein the deregistration notification includes the registered user corresponding to the device identification information of the user terminal;
[0139] The network interruption unit is used to interrupt the network connection of the corresponding registered user according to the deregistration notification.
[0140] It should be noted that the working process of each module in the device for intercepting illegal terminal access to the network described in the embodiments of the present invention can refer to the working process of the method for intercepting illegal terminal access to the network described in the above embodiments, and the technical effect achieved is the same as that of the method for intercepting illegal terminal access to the network described in the above embodiments, and will not be repeated here.
[0141] See Figure 10 , Figure 10 This is a structural block diagram of a device for intercepting unauthorized terminal access to the network provided in an embodiment of the present invention. The device includes a processor 51, a memory 52, and a computer program stored in the memory 52 and executable on the processor 51. When the processor 51 executes the computer program, it implements the steps in the method embodiment for intercepting unauthorized terminal access to the network described in the above embodiment, such as steps S11-S13 or steps S21-S23.
[0142] For example, the computer program can be divided into one or more modules / units, which are stored in the memory 52 and executed by the processor 51 to complete the present invention. The one or more modules / units can be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the device for intercepting illegal terminal access to the network.
[0143] The device for intercepting unauthorized terminal access to the network may include, but is not limited to, processor 51 and memory 52. Those skilled in the art will understand that the schematic diagram is merely an example of a device for intercepting unauthorized terminal access to the network and does not constitute a limitation on the device. It may include more or fewer components than illustrated, or combine certain components, or use different components. For example, the device for intercepting unauthorized terminal access to the network may also include input / output devices, network access devices, buses, etc.
[0144] The processor 51 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor. The processor 51 is the control center of the device for intercepting illegal terminal access to the network, connecting various parts of the device through various interfaces and lines.
[0145] The memory 52 can be used to store the computer programs and / or modules. The processor 51 implements various functions of the device for intercepting illegal terminal access by running or executing the computer programs and / or modules stored in the memory 52 and calling the data stored in the memory 52. The memory 52 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory 52 may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0146] Wherein, if the modules / units integrated in the device for intercepting illegal terminal access to the network are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when the computer program is executed by the processor 51, it can implement the steps of the above method embodiments. Wherein, the computer program includes computer program code, which can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.
[0147] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.
[0148] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A method for intercepting unauthorized terminals from accessing the network, characterized in that, Applied to user data management network elements, including: Receive network access registration request information from a user terminal sent by an access management network element, and read the device identification information and user subscription information of the user terminal based on the network access registration request information; Based on the illegal terminal device identifier list database, the legality of the device identifier information of the user terminal is checked to obtain the detection result; Based on the detection results, a read result of reading the user's subscription information is sent to the access management network element. The read result is used to indicate whether the access management network element allows the user terminal to access the network.
2. The method for intercepting unauthorized terminal access to the network as described in claim 1, characterized in that, Also includes: Receive device identification information of unauthorized terminals sent by the business operation support system; The device identification information of illegal terminals sent by the business operation support system is written into a pre-established illegal terminal device identification list database.
3. The method for intercepting unauthorized terminal access to the network as described in claim 2, characterized in that, The step of performing a legality check on the device identification information of the user terminal based on the illegal terminal device identification list database and obtaining the detection result specifically includes: Based on the device identification information of the user terminal, a query is performed on the illegal terminal device identification list database, and a timer of a set duration is started simultaneously. When no matching device identifier information is found in the illegal terminal device identifier list database, or when no matching device identifier information is found in the illegal terminal device identifier list database within a set time period, the detection result is that the user terminal is a legitimate user terminal. When a device identifier matching the device identifier information of the user terminal is found in the illegal terminal device identifier list database, the detection result is that the user terminal is an illegal user terminal.
4. The method for intercepting unauthorized terminal access to the network as described in claim 3, characterized in that, The step of sending the read result of reading the user subscription information to the access management network element based on the detection result specifically includes: If the detection result indicates that the user terminal is a legitimate user terminal, then the result of successfully reading the user's subscription information and the read user subscription information will be sent to the access management network element. If the detection result indicates that the user terminal is an illegal user terminal, then the result of failure to read the user's subscription information will be sent to the access management network element.
5. The method for intercepting unauthorized terminal access to the network as described in claim 4, characterized in that, If the detection result indicates that the user terminal is an illegal user terminal, after sending the result of failure to read user subscription information to the access management network element, the method further includes: The system checks whether a registered user exists in the illegal terminal device identifier list database that corresponds to the device identifier information of the user terminal. If a corresponding registered user exists, the device identification information of the user terminal is associated with the corresponding registered user, and a deregistration notification is sent to the access management network element; wherein, the deregistration notification includes the registered user corresponding to the device identification information of the user terminal, and is used to instruct the access management network element to interrupt the network connection of the corresponding registered user; If no corresponding registered user exists, the device identification information of the user terminal will be updated to the illegal terminal device identification list database.
6. A method for intercepting unauthorized terminals from accessing the network, characterized in that, Applied to access management network elements, including: Receive network registration request information initiated by user terminals; The network access registration request information is sent to the user data management network element; wherein, the network access registration request information is used to instruct the user data management network element to perform a legality check on the user terminal according to the illegal terminal device identifier list database; The system receives the reading result of the user subscription information sent by the user data management network element, and determines whether the user terminal is allowed to access the network based on the reading result.
7. The method for intercepting unauthorized terminal access to the network as described in claim 6, characterized in that, The process of receiving the user subscription information sent by the user data management network element and determining whether the user terminal is allowed to access the network based on the reading result specifically includes: If the system receives a successful read result of the user's subscription information and the read user subscription information, then the user terminal is allowed to access the network and proceed with the normal registration process. If a result indicating failure to read user subscription information is received, the user terminal will be denied network access and registration will fail.
8. The method for intercepting unauthorized terminal access to the network as described in claim 6, characterized in that, Also includes: The system receives a deregistration notification sent by the user data management network element; wherein the deregistration notification includes the registered user corresponding to the device identification information of the user terminal. Based on the notification to disconnect from registration, the network connection of the corresponding registered user is interrupted.
9. A device for intercepting unauthorized terminal access to the network, characterized in that, Applied to user data management network elements, including: The network access registration request information receiving module is used to receive network access registration request information of user terminals sent by the access management network element, and read the device identification information and user subscription information of the user terminals according to the network access registration request information; The legitimacy detection module is used to perform legitimacy detection on the device identification information of the user terminal based on the illegal terminal device identification list database, and obtain the detection result; The user subscription information reading result sending module is used to send the reading result of the user subscription information to the access management network element according to the detection result. The reading result is used to indicate whether the access management network element allows the user terminal to access the network.
10. A device for intercepting unauthorized terminal access to the network, characterized in that, Applied to access management network elements, including: The network access registration request information receiving module is used to receive network access registration request information initiated by user terminals; The network access registration request information sending module is used to send the network access registration request information to the user data management network element; wherein, the network access registration request information is used to instruct the user data management network element to perform a legality check on the user terminal according to the illegal terminal device identifier list database; The user subscription information reading result receiving module is used to receive the user subscription information reading result sent by the user data management network element, and determine whether the user terminal is allowed to access the network based on the reading result.
11. A device for intercepting unauthorized terminals from accessing the network, characterized in that, include: A processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements the method for intercepting unauthorized terminal access to the network as described in any one of claims 1 to 5, or the method for intercepting unauthorized terminal access to the network as described in any one of claims 6 to 8.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the method for intercepting illegal terminal access to the network as described in any one of claims 1 to 5, or the method for intercepting illegal terminal access to the network as described in any one of claims 6 to 8.
13. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the method for intercepting illegal terminal access to the network as described in any one of claims 1 to 5, or the method for intercepting illegal terminal access to the network as described in any one of claims 6 to 8.