Private network security communication method based on 5G LAN private network, core network and CPE

By introducing an authentication server into the core network of 5G LAN private network communication, identity authentication of client terminal devices is solved, the problem of security risks of 5G LAN private network communication is realized, the legality authentication and service access control of the device are realized, and communication security and user experience are improved.

CN119997012APending Publication Date: 2025-05-13COMBA TELECOM SYST CHINA LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411989413.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

Under the networking mode of 5G LAN private network communication, the downhill device of the client terminal device does not require authentication to access the 5G private network, which poses security risks and is prone to illegal attacks, affecting user communication and data security.

Method used

By introducing an authentication server into the UPF network element of the core network, using the N6 interface to communicate with the authentication server, identity authentication of the client terminal device is realized. The authentication message is determined through the UPF network element to determine whether the preset authentication packet release rule is met. If it is satisfied, it will be sent to the authentication server for identity authentication, and the authentication result will be feedback to update the service access control rule.

Benefits of technology

It has realized the addition of identity authentication and access control mechanisms in 5G LAN communication. Only devices authenticated through authentication servers can access services through UPF network elements to prevent illegal device access and overprivileged access, effectively ensuring the security of 5G LAN dedicated network communication, protecting user data security, and improving user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119997012A_ABST
    Figure CN119997012A_ABST
Patent Text Reader

Abstract

The invention relates to a private network security communication method based on a 5G LAN private network, a core network and a CPE, the method comprises the following steps: the method is applied to the core network, and in response to receiving an authentication message sent by the CPE, the core network judges whether the authentication message satisfies a preset authentication packet release rule, and the authentication message comprises identity information of a to-be-authenticated device; when the authentication message satisfies an authentication packet release rule, sending the authentication message to an authentication server so that the authentication server performs identity authentication on the to-be-authenticated device based on the authentication message and returns an authentication response message; feeding back the authentication response message to the CPE, and analyzing the authentication response message to obtain an authentication result; and adding the identity information of the to-be-authenticated device to a service access control rule to allow a data packet carrying the identity information to pass under the condition that the authentication result is that the authentication is passed. By adopting the scheme of the invention, an identity authentication and access control mechanism is added in 5G LAN communication, and the security of 5G LAN private network communication can be effectively ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of 5G communication technology, and in particular to a private network security communication method, core network and CPE based on a 5G LAN private network. Background Art

[0002] With the rapid development of 5G technology, the demand for higher bandwidth and lower latency in mobile communications and new applications in various vertical industries is also growing, and 5G local area network (LAN) communication mode has emerged. However, in the networking mode of 5G LAN private network communication, the devices under the customer premise equipment (CPE) can access the 5G private network without authentication, which poses a security risk and is easily attacked illegally, thus affecting user communication and data security. Summary of the invention

[0003] In order to solve the above technical problems or at least partially solve the above technical problems, the present disclosure provides a private network security communication method, core network and CPE based on a 5G LAN private network.

[0004] In a first aspect, the present disclosure provides a private network security communication method based on a 5G LAN private network, which is applied to a core network, wherein a UPF network element of the core network communicates with an authentication server through an N6 interface, and the method includes:

[0005] In response to receiving an authentication message sent by a customer terminal device CPE, determining whether the authentication message meets a preset authentication packet release rule, wherein the authentication message includes identity information of the device to be authenticated;

[0006] If the authentication message satisfies the authentication packet release rule, sending the authentication message to the authentication server, so that the authentication server performs identity authentication on the device to be authenticated based on the authentication message and returns an authentication response message;

[0007] In response to receiving the authentication response message, feeding back the authentication response message to the CPE, and parsing the authentication response message to obtain an authentication result;

[0008] When the authentication result is authentication passed, the identity information of the device to be authenticated is added to the service access control rule to allow the data packet carrying the identity information to pass.

[0009] In a second aspect, the present disclosure provides a private network security communication method based on a 5G LAN private network, which is applied to CPE, and the method includes:

[0010] Send an authentication message to the UPF network element of the core network, wherein the UPF network element sends the authentication message to the authentication server for identity authentication and receives an authentication response message returned by the authentication server if it is determined that the authentication message meets the authentication package release rule, and the authentication message includes the identity information of the device to be authenticated;

[0011] In response to receiving an authentication response message returned by the UPF network element, parsing the authentication response message to obtain an authentication result;

[0012] When the authentication result is authentication passed, the status of the device to be authenticated is updated to authentication passed.

[0013] In a third aspect, the present disclosure provides a core network, wherein a UPF network element of the core network communicates with an authentication server through an N6 interface, including:

[0014] A rule matching module, configured to determine whether a preset authentication packet release rule is satisfied in response to receiving an authentication message sent by a customer terminal device CPE, wherein the authentication message includes identity information of a device to be authenticated;

[0015] A first sending module, configured to send the authentication message to the authentication server if the authentication message satisfies the authentication packet release rule, so that the authentication server performs identity authentication on the device to be authenticated based on the authentication message and returns an authentication response message;

[0016] A second sending module is used for feeding back the authentication response message to the CPE in response to receiving the authentication response message;

[0017] A first parsing module, used for parsing the authentication response message to obtain an authentication result;

[0018] The rule adjustment module is used to add the identity information of the device to be authenticated to the service access control rule when the authentication result is authentication passed, so as to allow the data packet carrying the identity information to pass.

[0019] In a fourth aspect, the present disclosure provides a CPE, including:

[0020] The third sending module is used to send an authentication message to the UPF network element of the core network, wherein the UPF network element sends the authentication message to the authentication server for identity authentication and receives the authentication response message returned by the authentication server when judging that the authentication message meets the authentication package release rule, and the authentication message includes the identity information of the device to be authenticated;

[0021] A second parsing module is used for parsing the authentication response message to obtain the authentication result in response to receiving the authentication response message returned by the UPF network element;

[0022] The status update module is used to update the status of the device to be authenticated to authenticated if the authentication result is authentication passed.

[0023] In a fifth aspect, the present disclosure provides an electronic device comprising a processor and a memory; the processor is used to execute the private network security communication method based on the 5G LAN private network as described in the first aspect or the second aspect by calling a program or instruction stored in the memory.

[0024] In a sixth aspect, the present disclosure provides a computer-readable storage medium, in which computer execution instructions are stored. When the computer execution instructions are executed by a processor, the private network security communication method based on the 5G LAN private network as described in the first aspect or the second aspect is implemented.

[0025] In the seventh aspect, the present disclosure provides a computer program product, including a computer program, wherein when the computer program is executed by a processor, implements the private network security communication method based on the 5G LAN private network as described in the first aspect or the second aspect.

[0026] Compared with the prior art, the technical solution provided by the embodiments of the present disclosure has the following advantages:

[0027] In this solution, the UPF network element of the core network communicates with the authentication server through the N6 interface. The UPF network element responds to the authentication message sent by the customer terminal device CPE, determines whether the authentication message meets the preset authentication package release rules, and the authentication message includes the identity information of the device to be authenticated; if the authentication message meets the authentication package release rules, the authentication message is sent to the authentication server, so that the authentication server performs identity authentication on the device to be authenticated based on the authentication message and returns an authentication response message; in response to receiving the authentication response message, the authentication response message is fed back to the CPE, and the authentication response message is parsed to obtain the authentication result; if the authentication result is authentication passed, the identity information of the device to be authenticated is added to the service access control rule to allow the data packet carrying the identity information to pass. The scheme disclosed in this disclosure is adopted to realize the addition of identity authentication and access control mechanism in 5G LAN communication. Only devices that pass the identity authentication of the authentication server can access services through the UPF network element, preventing illegal devices from accessing the 5G LAN private network or performing unauthorized access, and can effectively ensure the security of 5G LAN private network communication, thereby protecting user data security and improving user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.

[0029] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0030] Figure 1 A schematic diagram of a 5G LAN dedicated network security communication framework of an exemplary embodiment of the present disclosure is shown;

[0031] Figure 2 A flowchart of a private network security communication method based on a 5G LAN private network provided for an exemplary embodiment of the present disclosure;

[0032] Figure 3 A flowchart of a private network secure communication method based on a 5G LAN private network provided for another exemplary embodiment of the present disclosure;

[0033] Figure 4 A schematic diagram of an identity authentication process of a CPE device according to an exemplary embodiment of the present disclosure is shown;

[0034] Figure 5 A schematic diagram showing an identity authentication process of a device connected to a CPE according to an exemplary embodiment of the present disclosure is shown;

[0035] Figure 6 A schematic diagram of service access control of a 5G LAN private network according to an exemplary embodiment of the present disclosure is shown;

[0036] Figure 7 A schematic diagram of the UPF network element structure of a core network provided in an embodiment of the present disclosure;

[0037] Figure 8 A schematic diagram of the structure of a CPE provided in one embodiment of the present disclosure. DETAILED DESCRIPTION

[0038] In order to more clearly understand the above-mentioned objectives, features and advantages of the present disclosure, the scheme of the present disclosure will be further described below. It should be noted that the embodiments of the present disclosure and the features in the embodiments can be combined with each other without conflict.

[0039] In the following description, many specific details are set forth to facilitate a full understanding of the present disclosure, but the present disclosure may also be implemented in other ways different from those described herein; it is obvious that the embodiments in the specification are only part of the embodiments of the present disclosure, rather than all of the embodiments.

[0040] The implementation of the embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.

[0041] Figure 1 A schematic diagram of a 5G LAN dedicated network security communication framework of an exemplary embodiment of the present disclosure is shown. The deployment process of the 5G LAN dedicated network is as follows: First, deploy a 5G dedicated core network. The core network includes a control plane network element, a unified data management function (UDM) network element, and a user plane function (UPF) network element. Ensure that the control plane network element supports wireless access of 5G LAN terminals, and the UPF network element supports data forwarding and parsing authentication messages of the 5G LAN. Then deploy a 5G base station to ensure that its wireless module is normal and that it communicates normally with the control plane and data plane of the 5G core network. When everything is ready, batch opening of Subscriber Identity Module (SIM) cards is performed on the UDM network element of the 5G core network, and different SIM cards are signed to different 5G virtual network groups (VN Group) according to network requirements and networking planning, such as Figure 1 As shown in the figure, there can be multiple CPEs in a 5G VN Group, and a CPE can be connected to at least one device. A CPE terminal that supports 5G LAN inserts a registered SIM card and initiates wireless access, and can access the 5G LAN private network wirelessly.

[0042] like Figure 1 As shown, compared with the traditional 5G LAN network, the security communication framework of the present invention adds an authentication server. The UPF network element communicates with the authentication server through the N6 interface and is deployed at the back end of the UPF network element, so that the authentication message can reach the authentication server through the UPF network element. The service address, user name, password and other information are configured in the authentication server in advance, and the identity information of the legal device is entered into the database of the authentication server, so that the authentication server can authenticate the device to verify whether the device is legal. In the UPF network element, session rules are created for CPE wireless access, which include authentication packet release rules to the service address of the authentication server, and only data packets with the destination address of the service address of the authentication server are allowed to pass. During the identity authentication, the UPF network element parses the message of the authentication result, and adds the identity information of the successfully authenticated device to the access control permission list, so that the authenticated device can access the service normally.

[0043] Figure 2 A flowchart of a private network security communication method based on a 5G LAN private network provided by an exemplary embodiment of the present disclosure is provided. The method can be applied to the core network provided by the embodiment of the present disclosure, and can be specifically applied to Figure 1 UPF network element in.

[0044] like Figure 2 As shown, the private network secure communication method based on the 5G LAN private network may include the following steps:

[0045] Step 101, in response to receiving an authentication message sent by a customer terminal device CPE, it is determined whether the authentication message meets a preset authentication packet release rule, and the authentication message includes identity information of the device to be authenticated.

[0046] In this embodiment, when the CPE or the device attached to the CPE needs to be authenticated, the CPE sends an authentication message to the UPF network element through the 5G base station. The authentication message carries the identity information of the device to be authenticated (CPE or the device attached to the CPE), where the identity information may include the Media Access Control (MAC) address of the device to be authenticated, and may also include the Internet Protocol (IP) address of the device to be authenticated as needed.

[0047] In an optional implementation of the present disclosure, when the UPF network element receives a service access request sent by the CPE, it can first detect whether the CPE is accessing the service for the first time. For example, the UPF network element can detect whether the service access control rule contains the identity information of the CPE. If not, it is considered that the CPE is accessing the service for the first time. For another example, when the CPE accesses the service for the first time, the service access request it sends can carry a first access identifier pre-agreed with the UPF network element. After receiving the service access request, the UPF network element parses the service access request to detect whether the request carries the first access identifier. If it does, it is considered that the CPE is accessing the service for the first time. Then, when the UPF detects that the CPE is accessing the service for the first time, it responds to the CPE with an authentication page so that the CPE initiates CPE identity authentication through the authentication page and sends an authentication message carrying the CPE's identity information to the UPF network element. It can be understood that the authentication page corresponds to the communication address (including IP address and port) of the authentication server, so that the destination address of the authentication message initiated by the authentication page is the communication address of the authentication server. Among them, CPE displays the authentication page. The user can follow the prompts of the authentication page and enter the login information (such as user name and password) configured by the authentication server through the authentication page to initiate identity authentication. The CPE generates an authentication message and sends it to the UPF network element. The authentication message can carry the input login information and the identity information of the CPE. The destination address of the authentication message is the communication address of the authentication server associated with the authentication page. In addition, the CPE can also save the login information entered by the user, the communication address of the authentication server, and other information for the identity authentication process of the downstream device.

[0048] In an optional implementation of the present disclosure, when a CPE that has completed identity authentication receives a service access request sent by a downstream device, it can detect whether the downstream device has completed authentication. If authentication has not been completed, identity authentication is initiated based on the identity information of the downstream device, combined with the login information of the authentication server saved when the CPE performs its own identity authentication and the communication address of the authentication server. A custom authentication message is composed and sent to the UPF network element. The authentication message carries the identity information of the downstream device and may also carry the login information of the authentication server.

[0049] In this embodiment, after the UPF network element receives the authentication message sent by the CPE, it can determine whether the authentication message meets the preset authentication packet release rule.

[0050] The authentication packet release rule is used to match data packets that can be released to the authentication server. If a data packet meets the authentication packet release rule, the data packet is considered to be a data packet for identity authentication and is released to the authentication server for identity authentication.

[0051] In this embodiment, after receiving the authentication message, the UPF network element matches it with the authentication package release rule. If the authentication package release rule is met, step 102 is executed; if the authentication package release rule is not met, the authentication message is discarded.

[0052] In an optional implementation of the present disclosure, the authentication packet release rule may allow the release of authentication packets carrying the communication address of the authentication server, wherein the communication address includes the IP address and port of the authentication server. Thus, after the UPF network element receives the authentication message, it can parse the authentication message, and by parsing the authentication message, the destination address of the authentication message can be obtained. Then, the destination address obtained by the analysis can be matched with the communication address of the authentication packet release rule. If the two are consistent, the match is successful, and it is determined that the authentication message meets the authentication packet release rule. As a result, only the authentication message whose destination address is the communication address of the authentication server can reach the authentication server through the UPF network element, which can effectively intercept data packets of illegal devices.

[0053] Step 102: When the authentication message satisfies the authentication package release rule, the authentication message is sent to the authentication server, so that the authentication server performs identity authentication on the authentication device based on the authentication message and returns an authentication response message.

[0054] The authentication server may be any server that can authenticate the legitimacy of the identity of the device. For example, the authentication server may be a server with a Remote Authentication Dial-In User Service (RADIUS) authentication server installed.

[0055] In this embodiment, when the UPF network element determines that the received authentication message meets the authentication package release rule, the authentication message is released, and the authentication message is transmitted to the authentication server through the N6 interface. The authentication server performs identity authentication on the device to be authenticated based on the authentication message, and returns an authentication response message to the UPF network element according to the authentication result. After receiving the authentication message, the authentication server can parse the authentication message to obtain the identity information of the device to be authenticated, and compare the identity information with the identity information of the legal device pre-entered in the database of the authentication server. If the identity information consistent with the identity information of the device to be authenticated is compared from the database, it is determined that the device to be authenticated is authenticated, and an authentication response message of authentication is returned to the UPF network element, and the authentication response message may carry the identity information of the device to be authenticated; if the identity information consistent with the identity information of the device to be authenticated is not compared from the database, it is determined that the device to be authenticated is not authenticated, and an authentication response message of authentication failure is returned to the UPF network element. When the authentication fails, the authentication response message may or may not carry the identity information of the device that failed to pass the authentication. When the authentication message carries the login information of the authentication server, the login information can also be compared with the login information pre-configured in the authentication server to see if they are consistent. When the login information is successfully compared and the identity information is also successfully compared, it is determined that the authentication of the device to be authenticated is successful.

[0056] Step 103: In response to receiving the authentication response message, the authentication response message is fed back to the CPE, and the authentication response message is parsed to obtain the authentication result.

[0057] In this embodiment, after receiving the authentication response message, the UPF network element feeds back the authentication response message to the CPE to inform the CPE of the authentication result; and the UPF network element also parses the authentication response message to obtain the authentication result, and then dynamically adjusts the service access control rules according to the authentication result.

[0058] Step 104: When the authentication result is authentication passed, the identity information of the device to be authenticated is added to the service access control rule to allow the data packet carrying the identity information to pass.

[0059] Among them, the service access control rules are used to match data packets that are allowed to access the network for service access. When the data packet carries the identity information in the service access control rules, the data packet is allowed to pass through the UPF network element and can access the data in the data network (DN) at the back end of the UPF network element. It can also provide end-to-end communication services with other CPEs and downstream devices in the same virtual group.

[0060] In this embodiment, if the UPF network element parses the authentication response message and obtains the authentication result of passing the authentication, the UPF network element adds the identity information of the device to be authenticated to the service access control rules, so that the data packets carrying its own identity information subsequently sent by the device to be authenticated can pass through the UPF network element and can communicate normally within the 5G LAN private network. By adding the identity information of the authenticated device to the service access control rules, it is possible to effectively intercept the service access of illegal devices, avoid unauthorized access by illegal devices, and protect user data security.

[0061] In the private network security communication method based on the 5G LAN private network of the embodiment of the present disclosure, the UPF network element of the core network communicates with the authentication server through the N6 interface, and the UPF network element responds to the authentication message sent by the customer terminal device CPE, and determines whether the authentication message meets the preset authentication package release rule, and the authentication message includes the identity information of the device to be authenticated; if the authentication message meets the authentication package release rule, the authentication message is sent to the authentication server, so that the authentication server performs identity authentication on the device to be authenticated based on the authentication message and returns an authentication response message; in response to receiving the authentication response message, the authentication response message is fed back to the CPE, and the authentication response message is parsed to obtain the authentication result; if the authentication result is authentication passed, the identity information of the device to be authenticated is added to the service access control rule to allow the data packet carrying the identity information to pass. The scheme of the present disclosure is adopted to realize the addition of identity authentication and access control mechanism in 5G LAN communication, and only the device that passes the identity authentication of the authentication server can access the service through the UPF network element, which prevents illegal devices from accessing the 5G LAN private network or performing unauthorized access, and can effectively ensure the security of 5G LAN private network communication, thereby protecting user data security and improving user experience.

[0062] In an optional implementation of the present disclosure, for authenticated devices, the service access frequency of these devices can also be monitored. If the UPF network element does not receive the service data of a certain authenticated device within a period of time, the identity information of the device is deleted from the service access control rules, and the next time the service access is to be performed, identity authentication needs to be performed again to further ensure data security. Thus, in this embodiment, the UPF network element can also obtain the access time of the authenticated device's most recent service access. For example, the UPF network element can record the time when the service data of the authenticated device is received as the access time of the device each time the service data of the authenticated device is received, and query the access time of the most recent service access of each authenticated device according to the preset period. Then, the UPF network element can compare the obtained access time with the current time. When the time difference between the access time and the current time is greater than the preset duration, the identity information of the authenticated device associated with the access time whose time difference with the current time is greater than the preset duration is deleted from the service access control rules. As a result, the authenticated device that has not performed service access for more than the preset duration cannot match the service access control rules, and thus cannot perform service access, and needs to perform identity authentication again, which helps to ensure the secure communication of the 5G LAN private network and the security of user data.

[0063] In an optional implementation of the present disclosure, during the authentication process, a pre-agreed private protocol is used between the CPE, the authentication server, and the UPF network element to package and parse messages. The private protocol is a custom protocol pre-agreed by the CPE, the authentication server, and the UPF network element, which can agree on the packaging method of the authentication message (for example, the parameters stored in each field in the authentication message), the processing method of the parameters of each field in the authentication message (for example, the parameters of the identity information field are processed in a non-plaintext manner such as encryption, reversing the order, adding obfuscated characters, etc.), the parsing method of the authentication message, and the packaging method and parsing method of the authentication response message. Thus, when performing identity authentication, the CPE uses the packaging method of the authentication message agreed in the private protocol to package and generate the authentication message. After the UPF network element receives the authentication message, if it is determined that the authentication message meets the authentication package release rule, the authentication message is released to the authentication server, and the UPF network element does not need to parse the authentication message. After receiving the authentication message, the authentication server parses the authentication message in accordance with the parsing method of the authentication message agreed upon in the private protocol to obtain the information carried in the authentication message, and performs identity authentication based on the parsed information. After the authentication is completed, the authentication response message is packaged in accordance with the packaging method of the authentication response message agreed upon in the private protocol to generate an authentication response message and return it to the UPF network element. After receiving the authentication response message, the UPF network element sends the authentication response message to the CPE, and parses the authentication response message in accordance with the parsing method of the authentication response message agreed upon in the private protocol to obtain the authentication result. After receiving the authentication response message, the CPE also parses the authentication response message in accordance with the parsing method of the authentication response message agreed upon in the private protocol to obtain the authentication result.

[0064] In this embodiment, a pre-agreed private protocol is used between the CPE, the authentication server and the UPF network element to package and parse messages during the authentication process. Compared with the use of a general standard protocol, the use of a customized private protocol can effectively reduce the probability of the message being cracked and has better security.

[0065] Corresponding to the above embodiments, the present disclosure also provides a private network security communication method based on a 5G LAN private network, which is applied to CPE.

[0066] Figure 3 A flowchart of a private network security communication method based on a 5G LAN private network provided by another exemplary embodiment of the present disclosure, which can be applied to Figure 1 The CPE in is executed by the CPE provided by the embodiment of the present disclosure.

[0067] like Figure 3 As shown, the private network secure communication method based on the 5G LAN private network may include the following steps:

[0068] Step 201, sending an authentication message to the UPF network element of the core network, wherein the UPF network element sends the authentication message to the authentication server for identity authentication and receives an authentication response message returned by the authentication server when determining that the authentication message meets the authentication package release rule, and the authentication message includes the identity information of the device to be authenticated.

[0069] In this embodiment, when the CPE or a device attached to the CPE needs to perform identity authentication, an authentication message is sent to the UPF network element of the core network.

[0070] In an optional implementation of the present disclosure, the CPE sends a service access request to the UPF network element. After receiving the service access request, the UPF network element first detects whether the CPE is accessing the service for the first time. If so, it redirects to the authentication page and returns the authentication page to the CPE. The authentication page corresponds to the communication address of the authentication server. For example, the UPF network element can detect whether the service access control rule contains the identity information of the CPE. If not, it is considered that the CPE is accessing the service for the first time. For another example, when the CPE accesses the service for the first time, the service access request it sends can carry a first access identifier pre-agreed with the UPF network element. After receiving the service access request, the UPF network element parses the service access request to detect whether the request carries the first access identifier. If so, it is considered that the CPE is accessing the service for the first time. After receiving the authentication page returned by the UPF network element, the CPE can display the authentication page, and the user enters the login information of the authentication server through the authentication page according to the prompts of the authentication page. After the user completes the input, the CPE obtains the login information, and generates an authentication message based on the obtained login information and the identity information of the CPE and sends it to the UPF network element, where the CPE is the device to be authenticated. The login information may include a user name and password, and the identity information may include the MAC address of the CPE, and may also include the IP address of the CPE as required. The CPE can also record the login information entered by the user and the communication address of the authentication server for the identity authentication process of the downstream device.

[0071] In an optional implementation of the present disclosure, when the CPE receives a service access request sent by a downstream device, in response to receiving the service access request sent by the downstream device, it detects whether its own status is authenticated; if it detects that its own status is not authenticated, it discards the data packet of the service access request. In the case of detecting that its own status is authenticated, it further detects whether the status of the downstream device is authenticated; if the status of the downstream device that sends the service access request is authenticated, the service access request is sent to the UPF network element for matching the service access control rules. If it is detected that the status of the downstream device is not authenticated, the downstream device is a device to be authenticated, and an authentication message is generated based on the identity information of the downstream device and sent to the UPF network element, wherein the identity information of the downstream device includes the IP address and MAC address of the downstream device. It should be noted that although the authentication message carries the IP address of the downstream device, in order to avoid the situation where the dynamic change of the IP address affects the authentication result and causes the legitimate device to fail to authenticate, the authentication server may not verify the IP address when performing identity authentication, but only verify the MAC address of the downstream device.

[0072] In this embodiment, after the UPF network element receives the authentication message sent by the CPE, it determines whether the authentication message satisfies the authentication package release rules. If so, the authentication message is released to the authentication server. After receiving the authentication message, the authentication server performs identity authentication based on the authentication message and returns an authentication response message to the UPF network element. After receiving the authentication response message, the UPF network element not only parses the authentication response message to obtain the authentication result, but also returns the authentication response message to the CPE.

[0073] Step 202: In response to receiving the authentication response message returned by the UPF network element, parse the authentication response message to obtain the authentication result.

[0074] Step 203: When the authentication result is authentication passed, the status of the device to be authenticated is updated to authentication passed.

[0075] In this embodiment, after the CPE receives the authentication response message returned by the UPF network element, it parses the authentication response message and obtains the authentication result of the device to be authenticated. If the authentication result is passed, the status of the device to be authenticated is updated to passed. The authenticated device can initiate service access to the UPF network element, and the device that has not passed the authentication needs to be authenticated first.

[0076] It should be noted that, for the parts of the CPE, UPF and authentication server not described in detail in this embodiment, please refer to the relevant description in the previous embodiments. To avoid repetition, they will not be repeated here.

[0077] In the private network security communication method based on the 5G LAN private network of the embodiment of the present disclosure, the CPE sends an authentication message to the UPF network element of the core network, wherein the UPF network element sends the authentication message to the authentication server for identity authentication and receives the authentication response message returned by the authentication server when judging that the authentication message meets the authentication packet release rule, and the authentication message includes the identity information of the device to be authenticated; in response to receiving the authentication response message returned by the UPF network element, the authentication response message is parsed to obtain the authentication result; when the authentication result is authentication passed, the status of the device to be authenticated is updated to authentication passed. The scheme of the present disclosure is adopted to realize the addition of identity authentication and access control mechanism in 5G LAN communication, and only the device that has passed the identity authentication of the authentication server can access the service through the UPF network element, preventing illegal devices from accessing the 5G LAN private network or performing unauthorized access, and can effectively ensure the security of 5G LAN private network communication, thereby protecting user data security and improving user experience.

[0078] Figure 4 A schematic diagram of the identity authentication process of a CPE device according to an exemplary embodiment of the present disclosure is shown. Figure 4 As shown, the CPE wirelessly accesses the base station, the base station interacts with the control plane network element to complete registration, authentication and integrity protection, the control plane network element interacts with the UPF network element to establish a session, and the CPE completes access to the UPF network element. After the CPE accesses the 5G LAN private network through wireless, it will be redirected to the authentication page by the UPF network element when accessing the service for the first time. The user enters the correct username and password on the authentication page as prompted to initiate identity authentication, and generates a custom authentication message. The authentication message carries the username and password configured by the authentication server and the MAC address of the CPE device, and records the username, password and authentication server address. The customized authentication message reaches the UPF network element of the core network through the 5G base station. The UPF network element matches the authentication packet release rules. If the match is successful, it will be released to the authentication server. After receiving the authentication message, the authentication server parses the data and verifies the username, password and MAC address, and returns the authentication response message according to the verification result. After receiving the authentication response message, the UPF network element forwards it to the CPE and parses the authentication response message to obtain the authentication result. If the authentication result is authentication passed, the service access control rules are dynamically modified, and the MAC address of the CPE is added to the service access control rules to allow data packets using the MAC address to pass. After receiving the authentication response message, the CPE parses it to obtain the authentication result. If the authentication result is authentication passed, it updates its own status to authenticated.

[0079] Figure 5 A schematic diagram of the identity authentication process of a CPE downstream device according to an exemplary embodiment of the present disclosure is shown. Figure 5As shown, the downstream device is connected to the CPE, the CPE assigns an IP address to the downstream device, and the downstream device initiates service access. If the CPE itself has not completed identity authentication, the data packet of the service access is discarded. If the CPE that has completed identity authentication finds that the downstream device has not completed identity authentication, the CPE automatically generates an authentication message to initiate an identity authentication request to the authentication server. The authentication message carries the previously saved user name, password, and MAC address and IP address of the downstream device. The authentication message passes through the 5G base station to the UPF network element of the core network. After receiving the authentication message, the UPF network element matches the authentication packet release rule. If the match passes, it is released to the authentication server. After receiving the authentication message, the authentication server parses the data and verifies the user name, password, and MAC address. According to the verification result, the authentication response message is returned. After receiving the authentication response message, the UPF network element forwards it to the CPE and parses the authentication response message to obtain the authentication result. If the authentication result is authentication passed, the service access control rule is dynamically modified, and the MAC address and IP address of the downstream device are added to the service access control rule, allowing the data packet using the MAC address and the IP address carried in the authentication message to pass. After receiving the authentication response message, the CPE parses it to obtain the authentication result. If the authentication result is authentication passed, the status of the downstream device is updated to authentication passed.

[0080] Figure 6 A schematic diagram of service access control of a 5G LAN private network according to an exemplary embodiment of the present disclosure is shown. Figure 6 As shown, the CPE and downstream devices that have passed the identity authentication using the solution disclosed in the present invention can access public network resources in the 5G LAN private network. Terminal devices in the same 5G virtual group can communicate with each other, while terminal devices in different 5G virtual groups are isolated by UPF network elements and cannot access each other.

[0081] In summary, compared with the existing 5G LAN private network communication networking mode in which CPE devices can access the 5G private network without authentication, the solution of adding a custom identity authentication and access control mechanism provided by the present disclosure has the following advantages:

[0082] (1) A new authentication server is added to authenticate the legitimacy of the device. The MAC address that uniquely identifies the legitimate device is entered into the authentication server's database. Interactive authentication is performed through a custom authentication protocol. Only legitimate downstream devices can pass identity authentication, thus preventing unauthorized downstream devices from accessing the network.

[0083] (2) The UPF network element parses the authentication response message from the authentication server through a custom authentication protocol. When the authentication is successful, the service access control rules are automatically updated. There is no need for external access control devices such as firewalls, which reduces hardware and maintenance costs.

[0084] (3) Downstream devices access the 5G LAN private network through a wireless network. Only after identity authentication is passed on the authentication server can they access services. This prevents illegal downstream devices from accessing the network and ensures secure communication and user data security of the 5G LAN private network.

[0085] (4) The authentication method disclosed in the present invention has good versatility and is also suitable for other similar products.

[0086] In order to implement the above embodiments, the present disclosure also provides a core network.

[0087] Figure 7 A schematic diagram of the UPF network element structure of the core network provided in an embodiment of the present disclosure, wherein the UPF network element communicates with the authentication server via the N6 interface, such as Figure 7 As shown, the UPF network element 50 of the core network may include: a rule matching module 510, a first sending module 520, a second sending module 530, a first parsing module 540 and a rule adjustment module 550.

[0088] The rule matching module 510 is used to determine whether the authentication message meets the preset authentication packet release rule in response to receiving the authentication message sent by the customer terminal equipment CPE, and the authentication message includes the identity information of the device to be authenticated;

[0089] The first sending module 520 is used to send the authentication message to the authentication server when the authentication message meets the authentication packet release rule, so that the authentication server performs identity authentication on the authentication device based on the authentication message and returns an authentication response message;

[0090] The second sending module 530 is configured to feed back the authentication response message to the CPE in response to receiving the authentication response message;

[0091] A first parsing module 540, configured to parse the authentication response message to obtain an authentication result;

[0092] The rule adjustment module 550 is used to add the identity information of the device to be authenticated to the service access control rule when the authentication result is authentication passed, so as to allow the data packet carrying the identity information to pass.

[0093] Optionally, the authentication packet release rule is that the authentication packet carrying the communication address of the authentication server is allowed to be released; the rule matching module 510 is further used to:

[0094] Parsing the authentication message to obtain the destination address of the authentication message;

[0095] Check whether the destination address is consistent with the communication address;

[0096] When the destination address is consistent with the communication address, it is determined that the authentication message meets the authentication packet release rule.

[0097] Optionally, the UPF network element 50 of the core network further includes:

[0098] A first detection module, configured to detect whether the CPE is accessing the service for the first time in response to receiving a service access request sent by the CPE;

[0099] The page redirection module is used to respond to the CPE with an authentication page when it is detected that the CPE is accessing the service for the first time, so that the CPE initiates CPE identity authentication through the authentication page and sends an authentication message carrying the CPE's identity information to the UPF network element.

[0100] Optionally, the UPF network element 50 of the core network further includes:

[0101] A time acquisition module is used to obtain the time of the last service access performed by the authenticated device;

[0102] The rule adjustment module 550 is further configured to delete the identity information of the authenticated device from the service access control rule when the time difference between the access time and the current time is greater than a preset time period.

[0103] Optionally, during the authentication process, a pre-agreed private protocol is used between the CPE, the authentication server and the UPF network element to package and parse messages.

[0104] The core network provided in the embodiment of the present disclosure can execute the private network security communication method based on the 5G LAN private network applied to the core network provided in the embodiment of the present disclosure, and has the corresponding functional modules and beneficial effects of the execution method. The contents not described in detail in the embodiment of the device of the present disclosure can refer to the description in any method embodiment of the present disclosure.

[0105] In order to implement the above embodiments, the present disclosure also provides a CPE.

[0106] Figure 8 A schematic diagram of the structure of a CPE provided in an embodiment of the present disclosure is shown in FIG. Figure 8 As shown, the CPE 60 may include: a third sending module 610 , a second parsing module 620 and a status updating module 630 .

[0107] Among them, the third sending module 610 is used to send an authentication message to the UPF network element of the core network, wherein the UPF network element sends the authentication message to the authentication server for identity authentication and receives the authentication response message returned by the authentication server when it is determined that the authentication message meets the authentication package release rule, and the authentication message includes the identity information of the device to be authenticated;

[0108] The second parsing module 620 is used to parse the authentication response message to obtain the authentication result in response to receiving the authentication response message returned by the UPF network element;

[0109] The status update module 630 is used to update the status of the device to be authenticated to authenticated if the authentication result is authentication passed.

[0110] Optionally, the third sending module 610 is further configured to:

[0111] Send service access request to UPF network element;

[0112] In response to receiving an authentication page sent by the UPF network element, obtaining the login information of the authentication server entered by the user through the authentication page, wherein the authentication page is a response made by the UPF network element after receiving the service access request and detecting that the CPE is accessing the service for the first time;

[0113] An authentication message is generated based on the login information and the identity information of the CPE and sent to the UPF network element.

[0114] Optionally, the third sending module 610 is further configured to:

[0115] In response to receiving a service access request sent by a downstream device, detecting whether its own status is authenticated;

[0116] When the device's own status is detected as authenticated, the device detects whether the status of the downstream device is authenticated;

[0117] When it is detected that the status of the downstream device is not authenticated, an authentication message is generated based on the identity information of the downstream device and sent to the UPF network element.

[0118] The CPE provided in the embodiment of the present disclosure can execute the private network security communication method based on the 5GLAN private network applied to the CPE provided in the embodiment of the present disclosure, and has the corresponding functional modules and beneficial effects of the execution method. The contents not fully described in the embodiment of the device of the present disclosure can refer to the description in any method embodiment of the present disclosure.

[0119] An embodiment of the present disclosure also provides an electronic device, including a processor and a memory; the processor calls the program or instructions stored in the memory to execute the steps of each embodiment of the private network security communication method based on the 5G LAN private network as described in the above embodiments. To avoid repeated description, they will not be repeated here.

[0120] The embodiments of the present disclosure also provide a computer-readable storage medium, which stores computer execution instructions. When the computer execution instructions are executed by a processor, the steps of each embodiment of the private network security communication method based on the 5GLAN private network as described in the aforementioned embodiments are implemented. To avoid repeated description, they are not repeated here.

[0121] The embodiments of the present disclosure also provide a computer program product, including a computer program. When the computer program is executed by a processor, the steps of each embodiment of the private network security communication method based on the 5G LAN private network as described in the aforementioned embodiments are implemented. To avoid repeated description, they are not repeated here.

[0122] It should be noted that, in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0123] The above description is only a specific embodiment of the present disclosure, so that those skilled in the art can understand or implement the present disclosure. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure will not be limited to the embodiments described herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.

[0124] In addition, although each operation is described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details are included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination mode.

[0125] Although the subject matter has been described in language specific to structural features and / or methodological logical actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. On the contrary, the specific features and actions described above are merely example forms of implementing the claims.

Claims

1. A private network security communication method based on a 5G LAN private network, characterized in that: Applied to a core network, a UPF network element of the core network communicates with an authentication server via an N6 interface, and the method comprises: In response to receiving an authentication message sent by a customer terminal device CPE, determining whether the authentication message meets a preset authentication packet release rule, wherein the authentication message includes identity information of the device to be authenticated; If the authentication message satisfies the authentication packet release rule, sending the authentication message to the authentication server, so that the authentication server performs identity authentication on the device to be authenticated based on the authentication message and returns an authentication response message; In response to receiving the authentication response message, feeding back the authentication response message to the CPE, and parsing the authentication response message to obtain an authentication result; When the authentication result is authentication passed, the identity information of the device to be authenticated is added to the service access control rule to allow the data packet carrying the identity information to pass.

2. The method according to claim 1, characterized in that The authentication packet release rule is that the authentication packet carrying the communication address of the authentication server is allowed to be released; The determining whether the authentication message satisfies a preset authentication packet release rule includes: Parsing the authentication message to obtain a destination address of the authentication message; Match whether the destination address is consistent with the communication address; When the destination address is consistent with the communication address, it is determined that the authentication message satisfies the authentication packet release rule.

3. The method according to claim 1, characterized in that The method further comprises: In response to receiving a service access request sent by the CPE, detecting whether the CPE is accessing a service for the first time; When it is detected that the CPE is accessing the service for the first time, an authentication page is responded to the CPE so that the CPE initiates CPE identity authentication through the authentication page and sends an authentication message carrying the identity information of the CPE to the UPF network element.

4. The method according to claim 1, characterized in that: The method further comprises: Get the time of the last service access by the authenticated device; When the time difference between the access time and the current time is greater than a preset time period, the identity information of the authenticated device is deleted from the service access control rule.

5. The method according to any one of claims 1 to 4, characterized in that: During the authentication process, the CPE, the authentication server and the UPF network element use a pre-agreed private protocol to package and parse messages.

6. A private network security communication method based on a 5G LAN private network, characterized in that: Applied to CPE, the method comprises: Send an authentication message to the UPF network element of the core network, wherein the UPF network element sends the authentication message to the authentication server for identity authentication and receives an authentication response message returned by the authentication server if it is determined that the authentication message meets the authentication package release rule, and the authentication message includes the identity information of the device to be authenticated; In response to receiving an authentication response message returned by the UPF network element, parsing the authentication response message to obtain an authentication result; When the authentication result is authentication passed, the status of the device to be authenticated is updated to authentication passed.

7. The method according to claim 6, characterized in that The sending of the authentication message to the UPF network element comprises: Sending a service access request to the UPF network element; In response to receiving an authentication page sent by the UPF network element, obtaining login information of the authentication server entered by the user through the authentication page, wherein the authentication page is a response made by the UPF network element after receiving the service access request and detecting that the CPE is accessing the service for the first time; The authentication message is generated based on the login information and the identity information of the CPE and sent to the UPF network element.

8. The method according to claim 6, characterized in that The sending of the authentication message to the UPF network element comprises: In response to receiving a service access request sent by a downstream device, detecting whether its own status is authenticated; When detecting that the state of the device itself is authenticated, detecting whether the state of the downstream device is authenticated; When it is detected that the status of the downstream device is not authenticated, the authentication message is generated based on the identity information of the downstream device and sent to the UPF network element.

9. A core network, characterized in that: The UPF network element of the core network communicates with the authentication server through the N6 interface, including: A rule matching module, configured to determine whether a preset authentication packet release rule is satisfied in response to receiving an authentication message sent by a customer terminal device CPE, wherein the authentication message includes identity information of a device to be authenticated; A first sending module, configured to send the authentication message to the authentication server if the authentication message satisfies the authentication packet release rule, so that the authentication server performs identity authentication on the device to be authenticated based on the authentication message and returns an authentication response message; A second sending module is used for feeding back the authentication response message to the CPE in response to receiving the authentication response message; A first parsing module, used for parsing the authentication response message to obtain an authentication result; The rule adjustment module is used to add the identity information of the device to be authenticated to the service access control rule when the authentication result is authentication passed, so as to allow the data packet carrying the identity information to pass.

10. A CPE, characterized in that: include: The third sending module is used to send an authentication message to the UPF network element of the core network, wherein the UPF network element sends the authentication message to the authentication server for identity authentication and receives the authentication response message returned by the authentication server when judging that the authentication message meets the authentication package release rule, and the authentication message includes the identity information of the device to be authenticated; A second parsing module is used for parsing the authentication response message to obtain the authentication result in response to receiving the authentication response message returned by the UPF network element; The status update module is used to update the status of the device to be authenticated to authenticated if the authentication result is authentication passed.

11. An electronic device, characterized in that: including a processor and a memory; The processor is used to execute the private network security communication method based on the 5G LAN private network as described in any one of claims 1-8 by calling the program or instruction stored in the memory.

12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer execution instructions, and when the computer execution instructions are executed by the processor, the private network security communication method based on the 5GLAN private network as described in any one of claims 1 to 8 is implemented.