Intranet login method and device, electronic equipment, storage medium and program product
By using a super SIM card for identity authentication and a security gateway in a dual-domain private network, the problem of the terminal access security control process being unable to close the loop is solved, user identity credibility and traffic traceability are realized, and network security and control capabilities are enhanced.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA MOBILE GRP BEIJING
- Filing Date
- 2024-09-18
- Publication Date
- 2026-08-04
AI Technical Summary
In existing dual-domain private network traffic offloading solutions, the security control process for terminal access cannot be closed-loop, and malicious computer software can not effectively prevent attacks on the internal network through the 5G private network.
By receiving the Super SIM card information from the terminal access request, an identity authentication system is built, and a trustworthy identity system is constructed. Combined with the Super SIM security gateway and firewall equipment, the system realizes legitimacy verification and address translation, ensuring the trustworthiness of the user's identity and avoiding address conflicts.
It improves the credibility of user identities and network security, enables real-name management of network traffic, ensures the traceability of each user's traffic, resolves address conflict issues, and enhances the network's security traceability and prevention capabilities.
Smart Images

Figure CN119109677B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network communication technology, and in particular to an intranet login method, device, electronic device, storage medium, and program product. Background Technology
[0002] Dual-domain private networks can provide enterprise users with a more convenient and secure channel to access the enterprise intranet and the Internet. However, building dual-domain private networks and traffic offloading solutions presents challenges in terms of security control for terminal access.
[0003] When a computer connects to a whitelisted mobile hotspot and directly accesses the production system on the intranet via a traffic splitting scheme based on DNN (Data Network Name) + ULCL (Uplink Classifier), malicious computer software may attack the intranet through the 5G private network. However, the 5G private network cannot provide the mobile phone number corresponding to the attack data packet, and the security control process cannot be closed. Summary of the Invention
[0004] This invention provides an intranet login method, device, electronic device, storage medium, and program product to address the shortcomings of existing dual-domain private network traffic splitting schemes, which fail to close the loop in the security control process for terminal access.
[0005] This invention provides an intranet login method, comprising:
[0006] The system receives a request from the first terminal to access the intranet via a hotspot connected to the second terminal. The second terminal accesses the intranet via a dual-domain private network and a traffic splitting method based on the uplink classifier ULCL.
[0007] Based on the Super SIM card information of the second terminal carried in the request, the identity of the second terminal is authenticated;
[0008] If the identity authentication is successful, a communication connection is established between the first terminal and the intranet, so that the first terminal can log in to the intranet.
[0009] According to the intranet login method provided by the present invention, establishing a communication connection between the first terminal and the intranet includes:
[0010] Based on the identity information of the first terminal carried in the request, the Super SIM security gateway performs a legality verification on the first terminal;
[0011] If the legitimacy verification passes, a communication connection is established between the first terminal and the intranet.
[0012] According to the intranet login method provided by the present invention, the method further includes:
[0013] The Super SIM security gateway records the access behavior logs of the first terminal and the second terminal.
[0014] According to the intranet login method provided by the present invention, the method further includes:
[0015] The firewall device translates the address distributed to the second terminal to ensure that the translated address is different from the internal network address; and,
[0016] Convert the addresses of the relevant core systems on the intranet to legitimate core network addresses.
[0017] According to the intranet login method provided by the present invention, the second terminal accesses the intranet through a dual-domain private network and a traffic splitting method based on the uplink classifier ULCL, specifically including:
[0018] When the Session Management Function (SMF) detects that the current location of the second terminal is within the campus intranet, it inserts the User Plane Function (UPF) into the user session.
[0019] The UPF (Uniform Traffic Flow Filter) matches the access traffic information of the second terminal with intranet traffic flow rules. If an intranet traffic flow rule is matched, the access traffic information is forwarded to the campus intranet; if no intranet traffic flow rule is matched, the access traffic information is forwarded to the Internet.
[0020] According to the intranet login method provided by the present invention, when the Session Management Function (SMF) detects that the current location of the second terminal is within the campus intranet, it inserts the User Plane Function (UPF) into the user session, including:
[0021] If the SMF detects that the current location of the second terminal is within the campus intranet and confirms that the second terminal is a terminal that has signed up for a dual-domain private network, it will insert the offloading UPF into the user session.
[0022] According to the intranet login method provided by the present invention, the traffic splitting UPF includes a primary anchor point UPF, an uplink classifier user plane function network element ULCL-UPF, and a secondary anchor point UPF;
[0023] The deployment modes of the split-point UPF include independent hardware deployment of the main anchor point UPF, or combined deployment of the ULCL-UPF and the auxiliary anchor point UPF.
[0024] The present invention also provides an intranet login device, comprising:
[0025] The request receiving unit is used to receive a request from the first terminal to access the intranet through a hotspot connected to the second terminal, wherein the second terminal accesses the intranet through a dual-domain private network and a traffic splitting method based on the uplink classifier ULCL.
[0026] An identity authentication unit is used to authenticate the second terminal based on the super SIM card information of the second terminal carried in the request;
[0027] A communication establishment unit is used to establish a communication connection between the first terminal and the intranet when the identity authentication is successful, so that the first terminal can log in to the intranet.
[0028] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement any of the intranet login methods described above.
[0029] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the intranet login method as described above.
[0030] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements any of the intranet login methods described above.
[0031] The intranet login method, apparatus, electronic device, storage medium, and program product provided by this invention authenticate the identity of a second terminal by carrying Super SIM card information in the intranet access request, thereby constructing a trusted identity system and improving the credibility and security of user identity. Furthermore, Super SIM identity authentication enables real-name management of network traffic, ensuring that each user's traffic can be authenticated and traced back to a specific user account, increasing the traceability of network security. Attached Figure Description
[0032] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0033] Figure 1 This is one of the flowcharts of the intranet login method provided by the present invention.
[0034] Figure 2 This is a diagram of the ULCL offloading network architecture provided by the present invention.
[0035] Figure 3 This is a schematic diagram of the city-level shared deployment mode provided by the present invention.
[0036] Figure 4 This is a schematic diagram of the park entry and deployment mode provided by the present invention.
[0037] Figure 5 This is a schematic diagram of the intranet login device provided by the present invention.
[0038] Figure 6 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation
[0039] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0040] The intranet within an industrial park presents unique ToB / ToC convergence requirements, necessitating a standardized solution: a dual-domain private network. Currently, in China, 5G ToB (i.e., 5G for enterprises) is characterized by mobile operators building separate ToB private networks, physically isolated from ToC networks. However, with the development of 5G, 5G private networks are gradually evolving from purely ToB networks to ToB / ToC converged private networks to address the issue of collaborative access between public and private networks. Based on common requirements such as 5G SA terminals simultaneously accessing both the intranet and the public network, and the need for SIM card and phone number changes, user and regional restrictions, and independent billing, 5G industry private networks require a standardized solution: a dual-domain private network, to support rapid industry upgrades.
[0041] Dual-domain private networks (DDNs) provide enterprise users with more convenient and secure access to the enterprise intranet and the internet. However, communication and interaction with the external internet leads to increased traffic. Therefore, it is necessary to optimize traffic management within the dual-domain DDN through traffic offloading to ensure network performance and reliability. Related technologies utilize a general / dedicated DNN+ULCL offloading scheme, a solution based on general or dedicated DNN and ULCL offloading technologies, used to achieve traffic offloading and targeted transmission for users.
[0042] Building a dual-domain private network and traffic offloading scheme presents challenges in security control for terminal access. When a computer connects to a whitelisted mobile hotspot and directly accesses the production system on the internal network via mobile DNN+ULCL offloading, malicious computer software may attempt to attack the internal network through the 5G private network. Since the 5G private network cannot identify the mobile phone number corresponding to the attack data packets, the security control process cannot be closed-loop.
[0043] To address the aforementioned issues, this invention proposes an intranet login method. In this method, the second terminal is authenticated using the Super SIM card information carried in the intranet access request. The mobile phone number is used as the unified account for authentication, constructing a trusted identity system and thereby improving the credibility and security of user identities. Furthermore, Super SIM identity authentication enables real-name management of network traffic, ensuring that each user's traffic can be authenticated and traced back to the specific user account, increasing the traceability of network security.
[0044] This invention can be applied to scenarios where access to the intranet via another terminal's hotspot is required, such as a computer accessing the intranet via a mobile hotspot. The executing entity of this method can be an electronic device such as a terminal device, computer, server, server cluster, or a specially designed intranet login device, or it can be an intranet login device installed in that electronic device, which can be implemented through software, hardware, or a combination of both.
[0045] In the description of the embodiments of the present invention, it should be understood that the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the stated features. In the description of the embodiments of the present invention, "multiple" means two or more, unless otherwise explicitly specified.
[0046] Figure 1 This is one of the flowcharts illustrating the intranet login method provided by the present invention, such as... Figure 1 As shown, the method includes the following steps:
[0047] Step 110: Receive a request from the first terminal to access the intranet through a hotspot connected to the second terminal. The second terminal accesses the intranet through a dual-domain private network and a traffic splitting method based on the uplink classifier ULCL.
[0048] Specifically, a dual-domain private network is a network architecture that allows user terminals to simultaneously access the internet and a corporate intranet (or campus intranet, government intranet, etc.) without changing their Subscriber Identity Module (SIM) card or phone number. ULCL-based traffic offloading is the key technology for achieving this functionality. It can offload data for services accessing the local area to the local area and data for internet access to the public network based on the characteristics of user service flows.
[0049] The first terminal can be a mobile phone, computer, or other device, and the second terminal can be a mobile phone. The first terminal connects to the hotspot of the second terminal via Wi-Fi or other wireless methods. Ensure that the hotspot settings of the second terminal allow the first terminal to access the network and that the relevant network parameters (such as SSID, password, etc.) are configured correctly.
[0050] The first terminal initiates an access request to the intranet through the second terminal's hotspot. This request is forwarded to the second terminal via Wi-Fi. According to ULCL's traffic routing policy, the second terminal forwards the intranet access request to the intranet server via the dual-domain private network and sends the response data back to the first terminal.
[0051] Step 120: Authenticate the identity of the second terminal based on the Super SIM card information of the second terminal carried in the request.
[0052] Considering the possibility of malicious computer software attacking the internal network via the 5G private network in this scenario, and the fact that the 5G private network cannot provide the mobile phone number corresponding to the attack data packet, the security control process cannot be closed. Therefore, this implementation adds the Super SIM authentication function of the second terminal to achieve real-name management of network traffic, ensuring that each user's traffic can be authenticated and traced back to the specific user account, thereby increasing the traceability of network security.
[0053] Specifically, requests to access the intranet carry information related to the Super SIM card. This information may be transmitted through specific request headers, request parameters, or encryption tokens. The server or authentication system needs to parse the request to extract key information related to the Super SIM card. This may include, for example, the International Mobile Subscriber Identity (IMSI), the SIM card's serial number, public key certificate, and encryption key.
[0054] The server first queries the operator's authentication center (AuC) via the IMSI to verify the validity of the SIM card. The authentication center returns the authentication result, confirming the legitimacy of the SIM card.
[0055] If the request contains encrypted data or an encrypted token, the server will use the public or private key stored in the Super SIM card to decrypt or verify the encrypted data. Based on the decryption result or signature verification, the server determines whether the request originated from a legitimate Super SIM card.
[0056] If the system supports multi-factor authentication, in addition to SIM card information, other authentication factors (such as fingerprint recognition, facial recognition, PIN code, etc.) can be combined for identity verification.
[0057] Step 130: If the identity authentication is successful, establish a communication connection between the first terminal and the intranet so that the first terminal can log in to the intranet.
[0058] Specifically, if the Super SIM card information verification is successful, that is, if the identity authentication is successful, the server will allow the second terminal to access the corresponding network resources or perform specific operations. According to business needs, the server can allocate corresponding permissions and resources to the successfully authenticated terminal.
[0059] Because the first terminal establishes a communication connection between the first terminal and the intranet by connecting to the hotspot of the second terminal, the first terminal can log in to the intranet.
[0060] Understandably, if the Super SIM card information verification fails, i.e., identity authentication fails, the server will reject the access request from the second terminal and may return corresponding error messages. If necessary, authentication failure log information can be recorded for subsequent security audits and troubleshooting.
[0061] The method provided in this invention authenticates the second terminal by carrying Super SIM card information in the request to access the intranet, thereby constructing a trusted identity system and improving the credibility and security of user identities. Furthermore, Super SIM identity authentication enables real-name management of network traffic, ensuring that each user's traffic can be authenticated and traced back to a specific user account, increasing the traceability of network security.
[0062] Based on any of the above embodiments, step 130, establishing a communication connection between the first terminal and the intranet, includes:
[0063] Based on the identity information of the first terminal carried in the request, the Super SIM security gateway performs a legality verification on the first terminal;
[0064] If the legitimacy verification passes, a communication connection is established between the first terminal and the intranet.
[0065] Specifically, to further control access to hotspot sharing, this embodiment of the invention adds a super SIM security gateway between the 5G private network and the ToB enterprise network. By adding the super SIM security gateway to the network, comprehensive coverage of mobile phones and PCs in different network environments is achieved. This controls access to hotspot sharing and ensures the real-name authentication of network traffic.
[0066] The Super SIM security gateway first receives an access request from the first terminal. The gateway parses the identity information in the request, which may include the first terminal's MAC address, IP address, user account, digital certificate, or encryption token associated with the Super SIM card.
[0067] The legitimacy verification includes identity authentication, which is achieved through communication between the super gateway and the super SIM card of the second terminal to verify whether the first terminal is a legitimate device. Understandably, a communication connection between the first terminal and the intranet is established only if the legitimacy verification of the first terminal passes. That is, the first terminal can connect to the hotspot of the second terminal and access the intranet through the second terminal's hotspot.
[0068] The method provided in this invention uses a super SIM security gateway to control and manage hotspot sharing, restricting access by unauthorized devices and ensuring that only legitimate devices can access the intranet via mobile hotspot, thereby reducing security risks.
[0069] Based on any of the above embodiments, the method further includes:
[0070] The Super SIM security gateway records the access behavior logs of the first and second terminals.
[0071] Specifically, the devices and systems that need to be monitored to collect access behavior logs include the first and second terminals, as well as the network and security devices (such as routers, switches, firewalls, etc.) they are connected to.
[0072] Log data is collected from first and second terminals, as well as other critical devices and systems in the network, using both agentless and agent-based mechanisms. Agentless methods typically extract logs directly from network traffic, while agent-based methods require agent software to be installed on the devices to capture logs.
[0073] The collected log data is aggregated into the log management system of the Super SIM security gateway. This may involve data formatting and standardization to ensure that log data from different sources can be processed and analyzed uniformly on the same platform.
[0074] Furthermore, log processing and analysis can be performed. Aggregated log data can be cleaned to remove duplicate, invalid, or noisy data, improving data quality and accuracy. The cleaned log data can then be parsed to extract useful information such as access time, accessing IP address, accessed URL, request type, and return status code.
[0075] Based on historical log data, normal access behavior models are established for both the first and second terminals. Then, by comparing actual access behavior with the model's predictions in real time, abnormal access behavior is detected. These abnormal behaviors may include unauthorized access, sensitive data leakage, and malware activity.
[0076] It can also conduct in-depth analysis of detected abnormal behaviors to determine the potential threat type, severity, and scope of impact. Furthermore, it utilizes threat intelligence databases and machine learning algorithms to improve the accuracy and efficiency of threat analysis.
[0077] The method provided in this invention records access behavior logs through a super SIM security gateway, including information such as the user's access time, access content, and access source. This allows for auditing and monitoring of access behavior, timely detection of abnormal behavior, and implementation of corresponding security measures.
[0078] Based on any of the above embodiments, the intranet login method further includes:
[0079] The firewall device translates the addresses distributed to the second terminal to ensure that the translated addresses are different from the internal network addresses; and,
[0080] Convert the addresses of relevant core systems on the intranet to legitimate addresses on the core network.
[0081] Specifically, when users use DNN+ULCL for traffic splitting, UPF will distribute IP addresses to users for accessing the ToB enterprise intranet. These distributed IP addresses may conflict with the ToB enterprise intranet. Furthermore, when dealing with numerous ToB enterprises, since the private IP address range is defined by the Internet Assigned Numbers Authority (IANA) and includes the following three address ranges: 10.0.0.0 to 10.255.255.255, 172.16.0.0 to 172.31.255.255, and 192.168.0.0 to 192.168.255.255, each enterprise intranet can use them freely, inevitably leading to situations where different enterprises use the same intranet address.
[0082] To avoid address conflicts between ULCL and the ToB enterprise intranet, the method provided in this embodiment adds a firewall device to the network. The firewall device can achieve one-to-one bidirectional address translation between user terminal addresses and ToB enterprise intranet addresses.
[0083] When a user attempts to access the enterprise intranet, the firewall device translates the address distributed to the user terminal by the UPF (User Protocol Adapter) into an address that does not conflict with the enterprise intranet. Simultaneously, the firewall device also translates the addresses of relevant core systems within the enterprise intranet into legitimate 5G private network addresses. This avoids address conflicts. By adding firewall devices and implementing address translation technology, normal communication between 5G private network user terminals and the ToB (Business-to-Business) enterprise intranet can be ensured, while resolving the issues caused by address conflicts. Such security measures effectively protect network security and guarantee user access to the enterprise intranet.
[0084] The method provided in this invention makes IP addresses unique through address translation, thereby avoiding conflicts that could lead to communication failures.
[0085] Based on any of the above embodiments, the second terminal accesses the intranet through a dual-domain private network and a traffic splitting method based on the uplink classifier ULCL, specifically including:
[0086] When the Session Management Function (SMF) detects that the current location of the second terminal is within the campus intranet, it inserts the User Plane Function (UPF) into the user session.
[0087] The UPF (Uniform Traffic Filtering) matches the access traffic information of the second terminal with intranet traffic shunting rules. If an intranet traffic shunting rule is matched, the access traffic information is forwarded to the campus intranet; if no intranet traffic shunting rule is matched, the access traffic information is forwarded to the Internet.
[0088] Specifically, mobile operators build separate ToB private networks, physically isolated from ToC networks, often using VPNs to achieve ToB and ToC converged private network development and solve the problem of public-to-public collaborative access. However, traditional intranet login methods via VPNs are prone to bandwidth congestion, lag, and VPN looping issues. There is also the risk of intranet production data being exposed to the public network via the VPN. Dual-domain private network technology requires a traffic offloading solution as a foundation, but existing offloading solutions lack authentication, which could lead to unauthorized users obtaining sensitive information or abusing network resources, thus posing security risks.
[0089] In this embodiment, legitimate users are identified on the network side, and network capabilities are used to allow "whitelisted" users to access the network legally. At the same time, intranet access traffic does not need to be exposed through the public network and is distributed locally to ensure intranet data security. Meanwhile, the overall solution is not limited by VPN bandwidth and the number of users, and maximizes the use of 5G advantages to achieve high-bandwidth and high-speed access.
[0090] This embodiment uses a ULCL-based traffic splitting method, employing a "whitelist" and legal access zone restrictions to ensure the security of intranet access services. The ULCL traffic splitting technical solution is as follows:
[0091] I. ULCL Main Process
[0092] 1. User Policy Subscription: The BOSS (Business and Operation Support System) defines a package name ABC, and the PCF (Point Coordination Function) configures a policy name ABC. When a user subscribes to this package, the BOSS sends the user's IMSI (International Mobile Subscriber Identity) and package name ABC to the PCF, and the PCF subscribes the user's IMSI to this ABC policy.
[0093] 2. PCF Policy Issuance: PCF issues policy names to the SMF (Session Management Function) unit through the N7 interface based on triggering conditions (such as the TAC of the wireless area, Tracking Area Code).
[0094] 3. SMF Policy Configuration: An SMF policy contains two pieces of information: one is when the policy is executed, such as the TAC determination based on the wireless area, and the other is the content of the policy to be executed.
[0095] 4. SMF Policy Execution and Insertion of Split UPF: When the user's location changes and the SMF detects that the user has entered a TAC that meets the trigger conditions, it executes a split policy that matches the policy name and inserts the split UPF into the user session. The split UPF performs user traffic splitting operations based on information such as the network name (DNN) carried by the terminal, the radio tracking area identifier (TAI), and the network access identifier (DNAI) bound to the policy name.
[0096] 5. Traffic splitting UPF policy configuration: The traffic splitting UPF determines the specific traffic splitting action based on the configuration information of the policy name. For example, internal network IPs / domains are split to the campus internal network, and the remaining traffic is sent to the main anchor point (responsible for forwarding public network traffic, i.e., ordinary large network 2CUPF).
[0097] 6. UPF forwarding of internal network traffic: When a user enters an internal network IP / domain name to access internal network services while a UPF is inserted, the data packet is sent to the UPF. The UPF identifies the internal network service flow according to the local configured traffic filtering rules. If it matches the internal network traffic distribution rules, it sends the traffic to the campus through the local N6 port of the UPF.
[0098] 7. UPF forwarding public network traffic: If the data packet does not match the internal network traffic splitting rules, the splitting UPF will send the traffic to the main anchor UPF in the core data center through the N9 interface between it and the main anchor point, and then forward the traffic to the Internet through the N6 interface of the main anchor point.
[0099] The ULCL process, through policy management and traffic routing, enables users to distribute their traffic to different networks (internal or public networks), thereby meeting users' access needs for different network resources. It provides flexible traffic control and management while ensuring network security and performance.
[0100] The UPF (User Plane Function) is a key component in 5G networks, responsible for handling data transmission and distribution. ULCL offloading is a traffic processing technology performed on the UPF. Figure 2This is a diagram of the ULCL offloading network architecture provided by the present invention, such as... Figure 2 As shown, the offloading UPF includes the main anchor UPF, the uplink classifier user plane function network element ULCL-UPF, and the secondary anchor UPF.
[0101] Among them, the primary anchor point UPF is the UPF that assigns the user plane IP to the UE when the UE is activated, and it is also the session anchor point for the UE to access the Internet.
[0102] ULCL-UPF: The full name is Uplink Classifier-UPF. ULCL-UPF is a data processing node that splits uplink business data and aggregates the split downlink data.
[0103] Auxiliary anchor point UPF: is the PDU session anchor point when the UE accesses the local network.
[0104] The trigger conditions for ULCL and secondary anchor insertion include: whether the user's location is within the park (required) and whether the user has signed up for a park package (optional).
[0105] Based on the above triggering conditions, two ULCL shunt technology solutions can be adopted:
[0106] 1) Location-based: Based on the user's location, traffic that meets the criteria is routed and processed accordingly.
[0107] 2) Location-based + Subscription-based: In addition to considering the user's location, it is also necessary to confirm whether the user has subscribed to a specific campus package, and thus perform traffic splitting based on these two conditions. That is, if the SMF detects that the current location of the second terminal is within the campus intranet and confirms that the second terminal is a terminal that has subscribed to a dual-domain private network, it will insert the traffic splitting UPF into the user session, thereby achieving traffic splitting.
[0108] The deployment modes of the offloading UPF include independent hardware deployment of the main anchor UPF, or combined deployment of ULCL-UPF and secondary anchor UPF.
[0109] 1) Independent Hardware Deployment of the Primary Anchor UPF: In this deployment mode, the primary anchor UPF is an independent hardware device that is deployed and operated separately. The primary anchor UPF is responsible for handling user data traffic, including assigning user plane IPs upon user activation and serving as the session anchor for users accessing the Internet. This deployment mode provides flexibility and independence, making it suitable for high-demand scenarios, such as those with high requirements for processing power and performance.
[0110] 2) Co-located ULCL-UPF and Auxiliary Anchor Point UPF: In this deployment mode, the ULCL-UPF and the auxiliary anchor point UPF are deployed together on the same hardware device. The ULCL-UPF is responsible for offloading uplink traffic data and aggregating downlink data, while the auxiliary anchor point UPF serves as the PDU (Packet Data Unit) session anchor point when the UE (User Equipment) accesses the local network. This deployment mode can save equipment costs and space, and provide higher equipment utilization. It is suitable for scenarios with limited resources or where efficient equipment utilization is required.
[0111] In the mode of co-deploying hardware of ULCL-UPF and auxiliary anchor point UPF, it can include city-level shared deployment and park-entry deployment.
[0112] Figure 3 This is a schematic diagram of the city-wide shared deployment mode provided by the present invention. In this mode, when a 5G user terminal is powered on, the primary anchor point UPF assigns an IP address to the terminal, the user completes activation, establishes a session, and can access the Internet. When the user terminal is in a specific location, it reports its location information to the PCF. After receiving the location information, the PCF issues a traffic splitting policy to the SMF according to a pre-set strategy. Upon receiving the traffic splitting policy, the SMF selects the ULCL-UPF and the secondary anchor point UPF based on the policy and inserts them into the session. The ULCL, based on the destination IP or DNS information, splits traffic that needs to access the local intranet to the secondary anchor point UPF, while traffic that needs to access the enterprise intranet is split through N9 to the primary anchor point UPF for processing, thereby accessing the Internet.
[0113] This deployment method and process allows for the routing of specific service traffic to secondary anchor UPFs for local intranet access, while other service traffic is routed to primary anchor UPFs for public network access, based on user location information. This deployment model improves network resource utilization efficiency, meets users' access needs for different networks, and ensures network performance and security. Furthermore, resource sharing and rational deployment can reduce equipment costs and optimize network architecture.
[0114] Figure 4 This is a schematic diagram of the park entry deployment mode provided by the present invention. In the park entry deployment mode, two park users are configured on the PCF to trigger ULCL to insert a specified area (TAI list) into the user session and the binding relationship between the park user's signed service package and the predefined rule names profile-A and profile-B.
[0115] Configure the binding relationships of profile-A, profile-B and DNAI-A, DNAI-B on the SMF respectively. The SMF selects a secondary anchor point and ULCL UPF based on DNN (Data Network Name) + DNAI (Network Access Identifier) + TAI (Radio Tracking Area Identifier) from the user profile configuration and inserts them into the user session (the secondary anchor point is selected based on DNN + DNAI + TAI, and the secondary anchor point and ULCL are set together).
[0116] The secondary anchor point UPF assigns different VPNs (Virtual Private Networks) based on different DNAIs. For example, DNAI-A corresponds to VPN-A, and DNAI-B corresponds to VPN-B. VPN isolation between different campuses is achieved through the N6 port of the secondary anchor point.
[0117] The above configuration enables ULCL traffic splitting for users in different campuses. Based on user attributes such as TAI, service package, and DNAI, the SMF selects appropriate secondary anchor points and ULCL-UPFs to insert into the user session. The secondary anchor point UPF then assigns a corresponding VPN for isolation based on the DNAI. This ensures network isolation and data security between users in different campuses. This campus deployment solution is suitable for scenarios where multiple campuses are hosted by the same network operator. It supports the specific network access needs of users in different campuses and achieves the goals of optimizing network resource utilization and data isolation.
[0118] The intranet login method provided by this invention, through the construction of a ToB / ToC converged dual-domain private network solution and traffic offloading based on ULCL, identifies legitimate users on the network side, adds an authentication step, and utilizes network capabilities to allow "whitelisted" users to access the network legitimately, ensuring security and applicability to more access scenarios. Intranet access traffic does not need to be exposed through the public network and is offloaded locally, ensuring intranet data security. At the same time, the overall solution is not limited by VPN bandwidth and the number of users, maximizing the use of 5G advantages to achieve high-bandwidth, high-speed access. Furthermore, by adding firewall devices in the network to translate addresses and resolve address conflicts, intranet access security control is improved, solving the address conflict problem and enabling all private network users to access simultaneously, making the solution more complete and its applicability more widespread and comprehensive. Specifically, it includes the following advantages:
[0119] 1. Enhanced Experience: 5G enables continuous indoor and outdoor coverage without dead zones, offers greater capacity, stronger anti-interference capabilities, and better mobility, providing a better user experience.
[0120] 2. Managed Operations and Maintenance: The operator centrally operates the private network, eliminating the need for the park to build its own operations and maintenance platform and team. Operator-grade network operations and maintenance ensures rapid response to network failures.
[0121] 3. Seamless Traffic Distribution: Users can access both the public and private networks simultaneously, enabling the convenience of using a single SIM card for multiple purposes. The network handles traffic distribution, requiring no user awareness or manual switching.
[0122] 4. Controllable Location: The operator identifies the user's location and grants access based on the school's requirements, ensuring data security. This restricts access to private network resources to devices only within legally designated areas.
[0123] 5. Independent Billing: Public network traffic and private network traffic are billed independently, making traffic package customization more flexible and personalized.
[0124] 6. Enhanced Security: The dual-domain private network solution provides higher security by using whitelists and authorized access zones to ensure that only authorized devices or users can access internal resources. This helps prevent security threats such as unauthorized access, malicious attacks, and data breaches.
[0125] The method provided by this invention can be applied to 5G ToBToC converged service scenarios:
[0126] 1) Government Private Network: 5G private networks can replace mobile network VPNs, providing a secure channel for government agencies to conduct office work and data transmission.
[0127] 2) Campus Network: 5G private network can replace WLAN, providing more stable and faster campus network coverage, while also supplementing outdoor network coverage.
[0128] 3) Police Network: The 5G private network can inherit the 4G industry gateway, providing police departments with more efficient and secure communication and data transmission.
[0129] 4) Industrial field network: 5G private network can realize the isolation of production, office and life flows, and provide network services that meet the needs of industrial field.
[0130] Separation of production, office, and living resources
[0131] Common needs: 1) In scenarios such as government, large enterprises, hospitals, and campuses, there is a widespread need for ToC terminals to access both the enterprise intranet and the Internet simultaneously;
[0132] 2) ToC terminal users can access the enterprise intranet and the Internet using 5G terminals without changing their SIM cards or phone numbers;
[0133] 3) Access to the enterprise intranet is billed separately, based on intranet traffic costs, while access to the public network is billed separately based on the public network costs.
[0134] With the expansion of 5G private network services, various sub-sectors such as education, government affairs, culture and tourism, healthcare, large enterprises, and police have generally put forward the demand for ToBToC dual-domain private networks. This means that the ToBToC dual-domain network model provides services to 5G public users based on 5G private networks, which strengthens user stickiness, enhances service value, and helps to expand the scale of 5G users and revenue.
[0135] Three types of demand scenarios:
[0136] 1) Fixed users access private network services locally, such as in a campus scenario: students access the campus network within the school area.
[0137] 2) Fixed users accessing private network services from other locations, such as government service scenarios: public officials accessing the government network while on business trips.
[0138] 3) Non-fixed users accessing private network services locally, such as in cultural tourism scenarios: non-fixed tourists accessing the intranet in scenic areas.
[0139] Three basic needs
[0140] 1) Public users can access enterprise intranets and the Internet using personal 5G terminals without changing their SIM cards or phone numbers; 2) Campuses, government agencies, large enterprises, hospitals, police departments, cultural and tourism enterprises, and other customers have a widespread need for isolated access to internal and external networks; 3) Access to the enterprise intranet is billed separately and paid by ToB customers, while access to the public network is paid by ToC users themselves.
[0141] Three basic principles
[0142] 1) 5G dual-domain private network services will not affect the existing services used by ToC users; 2) Solutions that do not limit terminal types or have special requirements for terminals will not be considered; 3) The construction pace will be local area first and then wide area, with private network users accessing the local area first and then the wide area.
[0143] The intranet login device provided by the present invention is described below. The intranet login device described below and the intranet login method described above can be referred to in correspondence.
[0144] Figure 5 This is a schematic diagram of the intranet login device provided by the present invention, as shown below. Figure 5 As shown, an intranet login device is provided, comprising:
[0145] The request receiving unit 510 is used to receive a request from the first terminal to access the intranet through a hotspot connected to the second terminal, wherein the second terminal accesses the intranet through a dual-domain private network and a traffic splitting method based on the uplink classifier ULCL.
[0146] The identity authentication unit 520 is used to authenticate the second terminal based on the super SIM card information of the second terminal carried in the request;
[0147] The communication establishment unit 530 is used to establish a communication connection between the first terminal and the intranet when the identity authentication is successful, so that the first terminal can log in to the intranet.
[0148] The device provided in this invention authenticates the second terminal by using the Super SIM card information carried in the request to access the intranet, thereby constructing a trusted identity system and improving the credibility and security of user identities. Furthermore, Super SIM identity authentication enables real-name management of network traffic, ensuring that each user's traffic can be authenticated and traced back to a specific user account, increasing the traceability of network security.
[0149] Based on any of the above embodiments, the communication establishment unit is further configured to:
[0150] Based on the identity information of the first terminal carried in the request, the Super SIM security gateway performs a legality verification on the first terminal;
[0151] If the legitimacy verification passes, a communication connection is established between the first terminal and the intranet.
[0152] Based on any of the above embodiments, a log recording unit is further included, for:
[0153] The Super SIM security gateway records the access behavior logs of the first terminal and the second terminal.
[0154] Based on any of the above embodiments, an address translation unit is further included, for:
[0155] The firewall device translates the address distributed to the second terminal to ensure that the translated address is different from the internal network address; and,
[0156] Convert the addresses of the relevant core systems on the intranet to legitimate core network addresses.
[0157] Based on any of the above embodiments, a shunt unit is further included, for:
[0158] When the Session Management Function (SMF) detects that the current location of the second terminal is within the campus intranet, it inserts the User Plane Function (UPF) into the user session.
[0159] The UPF (Uniform Traffic Flow Filter) matches the access traffic information of the second terminal with intranet traffic flow rules. If an intranet traffic flow rule is matched, the access traffic information is forwarded to the campus intranet; if no intranet traffic flow rule is matched, the access traffic information is forwarded to the Internet.
[0160] Based on any of the above embodiments, the shunt unit is further configured to:
[0161] If the SMF detects that the current location of the second terminal is within the campus intranet and confirms that the second terminal is a terminal that has signed up for a dual-domain private network, it will insert the offloading UPF into the user session.
[0162] Based on any of the above embodiments, the traffic splitting UPF includes a primary anchor UPF, an uplink classifier user plane function network element ULCL-UPF, and a secondary anchor UPF;
[0163] The deployment modes of the split-point UPF include independent hardware deployment of the main anchor point UPF, or combined deployment of the ULCL-UPF and the auxiliary anchor point UPF.
[0164] Figure 6 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 6 As shown, the electronic device may include a processor 610, a communications interface 620, a memory 630, and a communication bus 640, wherein the processor 610, communications interface 620, and memory 630 communicate with each other via the communication bus 640. The processor 610 can call logical instructions in the memory 630 to execute an intranet login method. This method includes: receiving a request from a first terminal to access the intranet via a hotspot connected to a second terminal; the second terminal accessing the intranet via a dual-domain private network and a traffic splitting method based on an uplink classifier ULCL; authenticating the second terminal based on the super SIM card information of the second terminal carried in the request; and, if the authentication is successful, establishing a communication connection between the first terminal and the intranet to enable the first terminal to log in to the intranet.
[0165] Furthermore, the logical instructions in the aforementioned memory 630 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0166] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the intranet login method provided by the above methods. The method includes: receiving a request from a first terminal to access the intranet through a hotspot connected to a second terminal, wherein the second terminal accesses the intranet through a dual-domain private network and a traffic splitting method based on an uplink classifier ULCL; authenticating the second terminal based on the super SIM card information of the second terminal carried in the request; and establishing a communication connection between the first terminal and the intranet if the authentication is successful, so that the first terminal can log in to the intranet.
[0167] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the intranet login method provided by the above methods. The method includes: receiving a request from a first terminal to access the intranet via a hotspot connected to a second terminal, wherein the second terminal accesses the intranet via a dual-domain private network and a traffic splitting method based on an uplink classifier ULCL; authenticating the second terminal based on the super SIM card information of the second terminal carried in the request; and, if the authentication is successful, establishing a communication connection between the first terminal and the intranet to enable the first terminal to log in to the intranet.
[0168] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0169] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0170] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. An intranet login method characterized by, include: The system receives a request from the first terminal to access the intranet via a hotspot connected to the second terminal. The second terminal accesses the intranet via a dual-domain private network and a traffic splitting method based on the uplink classifier ULCL. Based on the Super SIM card information of the second terminal carried in the request, the identity of the second terminal is authenticated; If the identity authentication is successful, a communication connection is established between the first terminal and the intranet, so that the first terminal can log in to the intranet; The establishment of the communication connection between the first terminal and the intranet includes: the Super SIM security gateway performing a legitimacy verification on the first terminal based on the identity information of the first terminal carried in the request; If the legitimacy verification passes, a communication connection is established between the first terminal and the intranet.
2. The intranet login method according to claim 1, characterized by, The method further includes: The Super SIM security gateway records the access behavior logs of the first terminal and the second terminal.
3. The intranet login method of claim 1, wherein, The method further includes: The firewall device translates the address distributed to the second terminal to ensure that the translated address is different from the internal network address; and, Convert the addresses of the relevant core systems on the intranet to legitimate core network addresses.
4. The intranet login method of claim 1, wherein, The second terminal accesses the intranet through a dual-domain private network and a traffic splitting method based on the uplink classifier ULCL, specifically including: When the Session Management Function (SMF) detects that the current location of the second terminal is within the campus intranet, it inserts the User Plane Function (UPF) into the user session. The UPF (Uniform Traffic Flow Filter) matches the access traffic information of the second terminal with intranet traffic flow rules. If an intranet traffic flow rule is matched, the access traffic information is forwarded to the campus intranet; if no intranet traffic flow rule is matched, the access traffic information is forwarded to the Internet.
5. The intranet login method of claim 4, wherein, When the Session Management Function (SMF) detects that the second terminal's current location is within the campus intranet, it inserts the User Plane Function (UPF) into the user session, including: If the SMF detects that the current location of the second terminal is within the campus intranet and confirms that the second terminal is a terminal that has signed up for a dual-domain private network, it will insert the offloading UPF into the user session.
6. The intranet login method of claim 4, wherein, The offloading UPF includes a primary anchor point UPF, an uplink classifier user plane function network element ULCL-UPF, and a secondary anchor point UPF. The deployment modes of the split-point UPF include independent hardware deployment of the main anchor point UPF, or combined deployment of the ULCL-UPF and the auxiliary anchor point UPF.
7. An intranet login apparatus characterized by comprising: include: The request receiving unit is used to receive a request from the first terminal to access the intranet through a hotspot connected to the second terminal, wherein the second terminal accesses the intranet through a dual-domain private network and a traffic splitting method based on the uplink classifier ULCL. An identity authentication unit is used to authenticate the second terminal based on the super SIM card information of the second terminal carried in the request; A communication establishment unit is used to establish a communication connection between the first terminal and the intranet when the identity authentication is successful, so that the first terminal can log in to the intranet; The establishment of the communication connection between the first terminal and the intranet includes: the Super SIM security gateway performing a legitimacy verification on the first terminal based on the identity information of the first terminal carried in the request; If the legitimacy verification passes, a communication connection is established between the first terminal and the intranet.
8. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the intranet login method as described in any one of claims 1 to 6. 9.A non-transitory computer-readable storage medium having stored thereon a computer program, characterized in that, When the computer program is executed by the processor, it implements the intranet login method as described in any one of claims 1 to 6.
10. A computer program product comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the intranet login method as described in any one of claims 1 to 6.