A Mobile Terminal Secure Access Authentication Method for 5G Standalone Private Networks

By adding UIF network elements to the 5G core network and using NFC technology to read employee card information, the problem of "loopback" of secure access authentication of mobile terminal devices in 5G independent private network is solved, convenient and secure terminal access is achieved, and management process is simplified.

CN119743758BActive Publication Date: 2025-06-17POWERCHINA BEIJING ENG CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411402341.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-09
Publication Date
2025-06-17
Estimated Expiration
2044-10-09

AI Technical Summary

Technical Problem

In 5G independent private network, there is a problem of "loopback" in the secure access authentication of mobile terminal devices, resulting in cumbersome access process and uncontrollable security.

Method used

A new user identity function (UIF) network element is added to the 5G core network, and the user identity information in the employee's employee card is read on the mobile terminal device through NFC, and the UIF of the 5G core network is uniformly stored and managed, thereby realizing secure access authentication for mobile terminal devices.

Benefits of technology

Through the UIF network element, the user identity is managed uniformly, multiple application app login processes are avoided, convenient and secure login access of mobile terminal devices is realized, the use and management process is simplified, and network security is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119743758B_ABST
    Figure CN119743758B_ABST
Patent Text Reader

Abstract

The present invention provides a mobile terminal secure access authentication method for a 5G standalone private network, which includes the following steps: constructing a 5G standalone private network architecture, including a 5G core network, a zero-trust gateway, an MDM server, and an enterprise intranet application server; in the 5G core network, adding a UIF network element, and the UIF network element is configured to maintain an employee information database; at the same time, each employee within the enterprise has an employee work card storing their own user identity information. By adding a UIF network element to the core network in the present invention, storing user identity information in the UIF of the 5G core network, and uniformly distributing user identity information to the zero-trust client and the enterprise internal App application through the 5G core network, it effectively avoids the problem of multiple App login processes, ensures the login security of mobile terminal devices, and at the same time enables users to log in and access without feeling, greatly simplifying the usage and management processes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of mobile terminal security control, and particularly relates to a mobile terminal secure access authentication method for a 5G standalone private network. Background Art

[0002] In some scenarios with high requirements for network security, deploying a 5G standalone private network is a promising and recognized wireless communication network solution. A 5G standalone private network refers to an independent mobile communication network composed of a company's self-deployed network infrastructure such as 5G base stations and 5G core networks. It has no direct connection with the mobile communication networks deployed by operators such as China Mobile, China Unicom, and China Telecom. It is a network independently built and managed by users, and the equipment assets such as base stations and core networks involved belong to the company rather than the operator.

[0003] Compared with the existing virtual private networks based on slicing technology and the hybrid private networks based on the sinking of the User Plane Function (UPF) and Mobile Edge Computing (MEC) technology of operators, the 5G standalone private network has the characteristics of high independence and high controllability. All data of the company (including user data and business data) belongs to the company, is isolated from the operator's public communication network, and the coverage area is also limited to the area where the company deploys base stations, rather than a large-scale national coverage.

[0004] In the wireless network scenario of a 5G standalone private network, controlling mobile terminal devices and performing access control on end-users are the most common security requirements of companies. The Mobile Device Management (MDM) system and the zero-trust system are the mainstream technical solutions to address the above requirements.

[0005] In the prior art, when the MDM system and the zero-trust system are applied to a 5G standalone private network with high security requirements, the problem of "loopback" in the secure access authentication of mobile terminal devices will occur, which is explained as follows:

[0006] Taking a tablet computer Pad as an example of a mobile terminal device, its working process is as follows:

[0007] 1) The mobile terminal device Pad is powered on and connected to the 5G standalone private network;

[0008] 2) The mobile terminal device Pad logs in to the zero-trust client App and accesses the zero-trust gateway for identity authentication and verification. After the authentication is passed, a secure transmission channel is established between the Pad and the zero-trust gateway;

[0009] 3) Based on the secure transmission channel in step 2, the zero-trust client App in the Pad accesses the MDM server for authentication and configures the corresponding mobile terminal permissions;

[0010] 4) The Pad user completes their own business through the user interface of the zero-trust client App.

[0011] As can be seen from the above process, the prerequisite for a Pad user to access the MDM server is that a secure transmission channel between themselves and the zero-trust gateway has been established. However, the prerequisite for establishing a secure transmission channel with the zero-trust gateway is that the zero-trust client App has been installed on the Pad, and the zero-trust client App establishes a secure transmission channel with the zero-trust gateway. However, installing the zero-trust client App on the Pad requires the Pad to first access the MDM server, and the MDM server centrally pushes and installs the zero-trust client App, which constitutes the "loopback" problem of terminal access.

[0012] Regarding this problem, the existing solutions are as follows:

[0013] (1) Temporarily open the ports and application installation permissions of the Pad, and manually install the zero-trust client App on the Pad by the staff. Then, establish a secure transmission channel to access the MDM server. After access, the MDM server closes the corresponding permissions and ports of the Pad.

[0014] (2) The zero-trust client App is deeply integrated with the mobile terminal device operating system and comes pre-installed as a system-preinstalled App when the Pad leaves the factory.

[0015] It is not difficult to see that the above solutions have the following problems:

[0016] 1) For the scenario of deploying a large number of Pads online, the method of temporarily opening permissions and manually installing the zero-trust client App is too cumbersome, with a large workload, prone to errors, and does not meet the conditions for large-scale promotion and use;

[0017] 2) The method of temporarily opening permissions and installing the zero-trust client App has uncontrollable security, and there are problems such as the Pad being installed with malicious software and malicious files being deposited; in addition, due to the high requirements of enterprises for network security, it is usually not allowed to open permissions for manual installation at the management system level, and temporarily opening ports and permissions is also non-compliant at the management system level;

[0018] 3) Pre-installing the App in the mobile terminal device operating system increases the complexity of the operating system;

[0019] 4) In the Pad work process, there are three sets of user systems for 5G private network user authentication, zero-trust system user authentication, and MDM system user authentication. The user systems are not unified, increasing the enterprise's management cost and management difficulty. Summary of the Invention

[0020] Aiming at the defects existing in the prior art, the present invention provides a mobile terminal secure access authentication method for a 5G standalone private network, which can effectively solve the above problems.

[0021] The technical solution adopted by the present invention is as follows:

[0022] The present invention provides a mobile terminal secure access authentication method for a 5G standalone private network, including the following steps:

[0023] Step S1, construct a 5G standalone private network architecture; the 5G standalone private network architecture includes a 5G core network, a zero-trust gateway, an MDM server, and an enterprise intranet application server; the 5G core network is connected to the MDM server and the enterprise intranet application server respectively through the zero-trust gateway;

[0024] Step S2, add a UIF network element in the 5G core network; the UIF network element is a user identity function network element; the UIF network element configures and maintains an employee information database; all user identity information of employees within the enterprise is stored in the employee information database. At the same time, each employee within the enterprise has an employee work card storing his own user identity information;

[0025] Step S3, when a certain mobile terminal device is powered on, the mobile terminal device establishes a communication link with the 5G core network to enable the mobile terminal device to access the 5G core network;

[0026] Step S4, the mobile terminal device reads the user identity information in the employee work card and sends a user identity authentication request to the UIF network element of the 5G core network, and the user identity information is carried in the request;

[0027] Step S5, the UIF network element performs user identity authentication on the received user identity information, and judges whether the received user identity information is in the employee information database. If it is, the authentication passes and step S6 is executed; if not, the authentication fails and an alarm prompt message is directly fed back to the mobile terminal device;

[0028] Step S6, the UIF network element forwards the user identity information to the zero-trust gateway, and the zero-trust gateway performs identity authentication on the user identity information. If the authentication passes, a PDU Session session connection is established between the mobile terminal device and the zero-trust gateway. Also, since the zero-trust gateway and the MDM server are communicatively connected, the mobile terminal device and the MDM server are communicatively connected;

[0029] Step S7: The MDM server verifies whether the zero-trust client App and the enterprise internal application App are installed on the mobile terminal device according to the pre-configured policy; if not, the MDM server sends the zero-trust client App and the enterprise internal application App to the mobile terminal device, and controls the mobile terminal device to install and run the zero-trust client App and the enterprise internal application App, and keeps the zero-trust client App and the enterprise internal application App in the logged-in state on the MDM server;

[0030] Step S8: The mobile terminal device accesses the enterprise intranet application server through the installed and running enterprise internal application App, thereby establishing a session connection between the mobile terminal device and the enterprise intranet application server;

[0031] Step S9: When the enterprise internal application App on the mobile terminal device is clicked to log out, the PDU Session session connection between the mobile terminal device and the zero-trust gateway and the session connection between the mobile terminal device and the enterprise intranet application server are terminated, so that the enterprise internal application App logs out.

[0032] Preferably, in step S7, after the mobile terminal device installs and runs the zero-trust client App, the MDM server controls the mobile terminal device through the PDU Session session connection.

[0033] Preferably, the MDM server controls the mobile terminal device through the PDU Session session connection, specifically including:

[0034] The MDM server performs device full-life cycle management, application full-life cycle management, and document full-life cycle management on the mobile terminal device according to the pre-set management and control policies:

[0035] 1) Device full-life cycle management: Manage the network access, permission management, and remote control related functions of the mobile terminal device;

[0036] 2) Application full-life cycle management: Manage the installation, running, and uninstallation of applications in the mobile terminal device;

[0037] 3) Document full-life cycle management: The MDM server uniformly pushes files to the mobile terminal device, or deletes files in the mobile terminal device.

[0038] Preferably, the zero-trust client App running on the mobile terminal device detects the operating environment of the mobile terminal device, obtains security threat information, and reports it to the MDM server through the PDU Session session connection; the MDM server generates an access control policy based on the security threat information and distributes it to the zero-trust gateway, and the zero-trust gateway performs access control according to the access control policy.

[0039] Preferably, in step S7, the MDM server distributes the zero-trust client App and the enterprise internal application App to the mobile terminal device, specifically as follows:

[0040] The MDM server pushes the zero-trust client App and the enterprise internal application App to the mobile terminal device in reverse based on the routing table established by the mobile terminal device for communication with it.

[0041] Preferably, step S8 is specifically as follows:

[0042] The mobile terminal device installs and runs the enterprise internal application App; then, it triggers the UIF network element to actively send the user identity information to the enterprise intranet application server; the enterprise intranet application server authenticates the user identity information; if the authentication passes, the mobile terminal device automatically logs in to the enterprise intranet application server through the user identity information, so that the mobile terminal device can directly access the enterprise intranet application server.

[0043] Preferably, step S9 is specifically as follows:

[0044] Step S9.1, when the enterprise internal application App is clicked to log out, it triggers a request to send the corresponding user identity information to log out to the enterprise intranet application server;

[0045] Step S9.2, when the enterprise intranet application server receives the logout request carrying the user identity information, it actively triggers a request to send a request to release the session link of the user corresponding to the user identity information to the UIF network element;

[0046] Step S9.3, after the UIF network element receives the request, it performs the following two operations:

[0047] Operation 1: The UIF network element actively sends a signaling of the user session link release response to the enterprise intranet application server to end the session link between the user of the mobile terminal device and the enterprise intranet application server;

[0048] Operation 2: The UIF network element actively sends a request for the user to log out of the zero-trust gateway to the zero-trust gateway; after receiving the request, the zero-trust gateway ends the PDU Session session connection established between the mobile terminal device and the zero-trust gateway, and completes the user's logout of the zero-trust gateway.

[0049] Step S9.4. Thus, the mobile terminal device completes the operation of logging out.

[0050] A mobile terminal secure access authentication method for a 5G independent private network provided by the present invention has the following advantages:

[0051] By adding a UIF network element to the core network in the present invention, obtaining the user identity stored in the enterprise employee's work card through NFC on mobile terminal devices such as pads, storing the user identity information in the UIF of the 5G core network, and uniformly distributing the user identity information to the zero-trust client and the enterprise internal App application by the 5G core network, it effectively avoids the problem of multiple App login processes, ensures the login security of the mobile terminal device, and at the same time enables the user to log in and access without feeling, greatly simplifying the usage and management processes. Description of the Drawings

[0052] Figure 1 It is a flowchart of a mobile terminal secure access authentication method for a 5G independent private network provided by the present invention;

[0053] Figure 2 It is an architecture diagram of a mobile terminal secure access authentication method for a 5G independent private network provided by the present invention. Detailed Embodiments

[0054] In order to make the technical problems, technical solutions and beneficial effects solved by the present invention clearer, the present invention will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0055] The present invention proposes a mobile terminal secure access authentication method for a 5G independent private network. This method innovatively proposes to add a User Identity Function (UIF) network element to the 5G private network to dock with the NFC work card, unify the enterprise user identity system and meet the security requirements for mobile terminal access and authentication, and has the advantages of easy operation and scalability.

[0056] Refer to Figures 1 to 2 , the present invention provides a mobile terminal secure access authentication method for a 5G independent private network, including the following steps:

[0057] Step S1, construct a 5G standalone private network architecture; the 5G standalone private network architecture includes a 5G core network, a zero-trust gateway, an MDM server, and an enterprise intranet application server; the 5G core network is connected to the MDM server and the enterprise intranet application server respectively through the zero-trust gateway;

[0058] Step S2, add a UIF network element in the 5G core network; the UIF network element is a user identity function network element; the UIF network element configures and maintains an employee information database; the employee information database stores the user identity information of all employees within the enterprise. At the same time, each employee within the enterprise has an employee work card storing their own user identity information;

[0059] Step S3, when a certain mobile terminal device is powered on, the mobile terminal device establishes a communication link with the 5G core network, enabling the mobile terminal device to access the 5G core network;

[0060] Specifically, after an enterprise employee obtains a mobile terminal device, they power it on to complete the two-way authentication of the 5G network, and successfully register and access the 5G core network.

[0061] Step S4, the mobile terminal device reads the user identity information in the employee work card and sends a user identity authentication request to the UIF network element of the 5G core network, and the user identity information is carried in the request;

[0062] In practical applications, NFC communication is carried out between the employee work card and the mobile terminal device, and the mobile terminal device reads the user identity information (department, name, etc.). More specifically, the security module of the operating system of the mobile terminal device initiates the access process of the UIF, and sends the read user identity information (department, name, etc.) to the UIF network element of the 5G core network through the 5G network, thereby triggering the user identity authentication process. For example, the security module of the operating system of the mobile terminal device initiates a User Identity Conformation Request to the UIF network element based on the Https protocol, and the user identity information is carried in the signaling.

[0063] Step S5, the UIF network element authenticates the received user identity information, determines whether the received user identity information is in the employee information database. If it is, the authentication passes, and it is legal employee information, and step S6 is executed; if not, the authentication fails, and an alarm prompt message is directly fed back to the mobile terminal device, indicating that an illegal user has accessed;

[0064] Step S6, the UIF network element forwards the user identity information to the zero-trust gateway; for example, the UIF network element forwards the user identity information to the zero-trust gateway through the UPF N6 interface;

[0065] The zero-trust gateway authenticates the user identity information. If the authentication is passed, the PDU Session session data of the user is allowed to be sent to the zero-trust gateway through the UPF, and then the mobile terminal device can establish a communication connection with the MDM server. Therefore, a PDU Session session connection is established between the mobile terminal device and the zero-trust gateway. Since the zero-trust gateway is communicatively connected to the MDM server, the mobile terminal device and the MDM server are communicatively connected.

[0066] Step S7: The MDM server checks, according to the pre-configured policy, whether the zero-trust client App and the enterprise internal application App are installed on the mobile terminal device. If not, the MDM server sends the zero-trust client App and the enterprise internal application App to the mobile terminal device, controls the mobile terminal device to install and run the zero-trust client App and the enterprise internal application App, and keeps the zero-trust client App and the enterprise internal application App in the logged-in state on the MDM server.

[0067] In this step, when the MDM server checks, according to the pre-configured policy, whether the zero-trust client App and the enterprise internal application App are installed on the mobile terminal device, if the zero-trust client App is not installed but the enterprise internal application App is installed, only the zero-trust client App needs to be sent to the mobile terminal device.

[0068] In this step, after the mobile terminal device installs and runs the zero-trust client App, the MDM server controls the mobile terminal device through the PDU Session session connection, which specifically includes:

[0069] The MDM server performs device full-life cycle management, application full-life cycle management, and document full-life cycle management on the mobile terminal device according to the pre-set management policies:

[0070] 1) Device full-life cycle management: Manage the network access, permission management, and remote control related functions of the mobile terminal device.

[0071] 2) Application full-life cycle management: Manage the installation, running, and uninstallation of applications in the mobile terminal device.

[0072] 3) Document full-life cycle management: The MDM server uniformly pushes files to the mobile terminal device or deletes files in the mobile terminal device.

[0073] In this step, the zero-trust client App running on the mobile terminal device has the following functions: detecting the running environment of the mobile terminal device, obtaining security threat information, and reporting it to the MDM server through the PDU Session session connection; the MDM server generates an access control policy based on the security threat information and distributes it to the zero-trust gateway, and the zero-trust gateway performs access control according to the access control policy.

[0074] In this step, the MDM server distributes the zero-trust client App and the enterprise internal application App to the mobile terminal device, specifically: the MDM server pushes the zero-trust client App and the enterprise internal application App to the mobile terminal device in reverse based on the routing table established by the mobile terminal device for communication with it.

[0075] In step S8, the mobile terminal device accesses the enterprise intranet application server through the installed and running enterprise internal application App, thereby establishing a session connection between the mobile terminal device and the enterprise intranet application server;

[0076] Step S8 is specifically as follows:

[0077] The mobile terminal device installs and runs the enterprise internal application App; then, it triggers the UIF network element to actively send the user identity information to the enterprise intranet application server; the enterprise intranet application server performs identity authentication on the user identity information; if the authentication passes, the mobile terminal device automatically logs in to the enterprise intranet application server through the user identity information, so that the mobile terminal device can directly access the enterprise intranet application server.

[0078] Step S9, user logout mechanism:

[0079] When the enterprise internal application App on the mobile terminal device is clicked to log out, the PDU Session session connection between the mobile terminal device and the zero-trust gateway and the session connection between the mobile terminal device and the enterprise intranet application server are terminated, so that the enterprise internal application App logs out.

[0080] Step S9 is specifically as follows:

[0081] In step S9.1, when the enterprise internal application App is clicked to log out, it triggers a request to send the corresponding user identity information to the enterprise intranet application server to log out;

[0082] Step S9.2, when the enterprise intranet application server receives the logout request carrying the user identity information, it actively triggers to send a request to the UIF network element to release the session link of the user corresponding to the user identity information, namely: User Identity Conformation Release Request;

[0083] Step S9.3: After receiving the request, the UIF network element performs the following two operations:

[0084] Operation 1: The UIF network element actively sends a signaling of a user session link release response, namely, User Identity Conformation Release Response, to the enterprise intranet application server to terminate the session link between the user of the mobile terminal device and the enterprise intranet application server;

[0085] Operation 2: The UIF network element actively sends a request for the user to log out of the zero trust gateway, namely, a User Identity Conformation log out Request, to the zero trust gateway; after receiving the request, the zero trust gateway sends a User Identity Conformation log out Response, ends the PDU Session connection established between the mobile terminal device and the zero trust gateway, and completes the user's logout of the zero trust gateway;

[0086] Step S9.4, at this point, the mobile terminal device completes the logout operation.

[0087] When the next user swipes his work card to log in again, steps S3-S9 are repeated.

[0088] The present invention proposes a mobile terminal secure access authentication method for a 5G independent private network, which has the following characteristics:

[0089] (1) A new user identity function UIF network element is added to the 5G core network. With user identity as the trust basis and UIF as the trust anchor point, two channels, "mobile terminal device-UIF" and "UIF-zero trust", are opened up to solve the "loop" problem of mobile terminal device access.

[0090] Specifically, the present invention adds a new network element, the user identity function (UIF), in the core network of the enterprise's 5G independent private network to complete the user identity system management of the independent network, unify the original zero-trust system's identity system and the MDM system's identity system into the UIF, and combine the enterprise user's NFC work card to complete the access control of mobile terminal devices in the 5G independent private network.

[0091] Specifically, by adding a UIF network element to the core network, obtaining the user identity stored in the enterprise employee's work card in a mobile terminal device such as a Pad through NFC, storing the user identity information in the UIF of the 5G core network, and uniformly distributing the user identity information to the zero-trust client and the enterprise internal App application through the 5G core network, the problem of multiple application App login processes is effectively avoided. While ensuring the login security of the mobile terminal device, seamless login access for users can be achieved, greatly simplifying the usage and management processes.

[0092] (2) By performing lightweight transformation and customization on the operating system of the mobile terminal device, the establishment of the "mobile terminal device - UIF" channel is completed. Without pre-installing a third-party App, employees can complete identity authentication and verification safely and reliably by swiping their work cards, thereby opening up the zero-trust channel and establishing a network path for business operations.

[0093] The present invention proposes a mobile terminal security access authentication method for a 5G independent private network, which has the following effects:

[0094] (1) The solution proposed by the present invention can provide a convenient and secure 5G private network terminal access solution for enterprises and enterprise employees, and solve the "loopback" problem of user access. From the perspective of convenience, after an enterprise deploys a 5G independent private network, employees only need to swipe their work cards to trigger various security control measures and business access logics with one key, which enables employees in the factory to perform business operations in a safe and controllable environment without mastering complex security knowledge; from the perspective of security, the solution proposed by the present invention has security features such as zero-trust dynamic access control, and at the same time has the security features of a mobile terminal device management and control system, providing strong security protection for enterprises using 5G private networks.

[0095] (2) The solution proposed by the present invention has good security itself. The UIF is a newly added network element to the core network and is protected by the closed nature of the 5G private network control plane. The threshold and cost for external personnel of the core network to attack the UIF are very high, and the security of the UIF itself is strongly guaranteed. In addition, since the operating systems of mobile terminal devices such as Pads have been customized and transformed, the risk of malicious personnel attempting to purchase conventional devices on the market to access the enterprise network is also avoided.

[0096] (3) The solution proposed by the present invention has good scalability. From the perspective of 5G private network equipment providers, the UIF is an internal network element of the 5G private network, and the equipment providers have strong transformation capabilities for the UIF. When an enterprise purchases and deploys a 5G independent private network, the equipment providers can flexibly dock according to the deployment information of the enterprise's zero-trust gateway and MDM server, with small and controllable workload. In addition, the above docking is transparent and seamless for enterprises and their employees, providing a good user experience.

[0097] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.

Claims

1. A mobile terminal secure access authentication method for 5G independent private network, characterized in that: The following steps are involved: Step S1, constructing a 5G independent private network architecture; the 5G independent private network architecture includes a 5G core network, a zero-trust gateway, an MDM server, and an enterprise intranet application server; the 5G core network is connected to the MDM server and the enterprise intranet application server respectively through the zero-trust gateway; Step S2, in the 5G core network, adding a UIF network element; the UIF network element is a user identity function network element; the UIF network element configures and maintains an employee information database; the employee information database stores the user identity information of all employees within the enterprise, and at the same time, each employee within the enterprise has an employee card storing his or her own user identity information; Step S3, when a certain mobile terminal device is turned on, the mobile terminal device establishes a communication link with the 5G core network, so that the mobile terminal device is connected to the 5G core network; Step S4, the mobile terminal device reads the user identity information in the employee work card, and sends a request for user identity authentication to the UIF network element of the 5G core network, where the request carries the user identity information; Step S5, the UIF network element performs user identity authentication on the received user identity information, and determines whether the received user identity information is in the employee information database. If so, the authentication is passed, and step S6 is executed; if not, the authentication fails, and an alarm prompt information is directly fed back to the mobile terminal device; Step S6, the UIF network element forwards the user identity information to the zero-trust gateway, and the zero-trust gateway performs identity authentication on the user identity information. If the authentication is successful, a PDU Session connection is established between the mobile terminal device and the zero-trust gateway. Since the zero-trust gateway and the MDM server are in communication connection, the mobile terminal device and the MDM server are in communication connection; Step S7, the MDM server verifies whether the mobile terminal device has the zero-trust client App and the enterprise internal application App installed according to the pre-configured policy; If not, the MDM server sends the zero-trust client App and the enterprise internal application App to the mobile terminal device, controls the mobile terminal device to install and run the zero-trust client App and the enterprise internal application App, and keeps the zero-trust client App and the enterprise internal application App logged in on the MDM server; Step S8, the mobile terminal device accesses the enterprise intranet application server by installing and running the enterprise internal application App, thereby establishing a session connection between the mobile terminal device and the enterprise intranet application server; Step S9, when the enterprise internal application App of the mobile terminal device is clicked to log out, the PDU Session session connection between the mobile terminal device and the zero trust gateway, as well as the session connection between the mobile terminal device and the enterprise intranet application server are terminated, thereby logging out of the enterprise internal application App.

2. A mobile terminal secure access authentication method for 5G independent private network according to claim 1, characterized in that: In step S7, the mobile terminal device installs and runs the zero-trust client App, and then the MDM server manages and controls the mobile terminal device through the PDU Session connection.

3. A method for secure access authentication of a mobile terminal for a 5G independent private network according to claim 2, characterized in that: The MDM server manages and controls the mobile terminal device through the PDU Session connection, specifically including: The MDM server performs device lifecycle management, application lifecycle management, and document lifecycle management on the mobile terminal device according to the preset management and control policies: 1) Equipment life cycle management: manage the network access, permission management, and remote control related functions of the mobile terminal device; 2) Application life cycle management: managing the installation, operation and uninstallation of applications in the mobile terminal device; 3) Document life cycle management: The MDM server uniformly pushes files to the mobile terminal device, or deletes files in the mobile terminal device.

4. A method for secure access authentication of a mobile terminal for a 5G independent private network according to claim 2, characterized in that: The zero-trust client App running on the mobile terminal device detects the operating environment of the mobile terminal device, obtains security threat information, and reports it to the MDM server through the PDU Session connection; the MDM server generates an access control policy based on the security threat information, and sends it to the zero-trust gateway, which performs access control according to the access control policy.

5. A method for secure access authentication of a mobile terminal for a 5G independent private network according to claim 1, characterized in that: In step S7, the MDM server sends the zero-trust client App and the enterprise internal application App to the mobile terminal device, specifically: The MDM server pushes the zero-trust client App and the enterprise internal application App to the mobile terminal device based on the routing table in which the mobile terminal device establishes a communication connection with the MDM server.

6. A method for secure access authentication of a mobile terminal for a 5G independent private network according to claim 1, characterized in that: Step S8 is specifically as follows: The mobile terminal device installs and runs the enterprise internal application App; then, the UIF network element is triggered to actively send the user identity information to the enterprise intranet application server; the enterprise intranet application server performs identity authentication on the user identity information; If the authentication is successful, the mobile terminal device automatically logs in to the enterprise intranet application server through the user identity information, so that the mobile terminal device directly accesses the enterprise intranet application server.

7. A mobile terminal secure access authentication method for 5G independent private network according to claim 1, characterized in that: Step S9 is specifically as follows: Step S9.1, when the enterprise internal application App is clicked to log out, a request for logging out of the corresponding user identity information is sent to the enterprise intranet application server; Step S9.2, when the enterprise intranet application server receives the logout request carrying the user identity information, it actively triggers to send a request to the UIF network element to release the session link of the user corresponding to the user identity information; Step S9.3: After receiving the request, the UIF network element performs the following two operations: Operation 1: The UIF network element actively sends a user session link release response signaling to the enterprise intranet application server to terminate the session link between the user of the mobile terminal device and the enterprise intranet application server; Operation 2: The UIF network element actively sends a request for the user to log out of the zero trust gateway to the zero trust gateway; After receiving the request, the zero-trust gateway terminates the PDU Session connection established between the mobile terminal device and the zero-trust gateway, and completes the user logging out of the zero-trust gateway; Step S9.4, at this point, the mobile terminal device completes the logout operation.

Citation Information

Patent Citations

  • Network security protection system for power system cloud service

    CN115665734A

  • Remote office access method and system based on zero trust

    CN116032533A