Terminal access control method, electronic equipment and storage medium
By receiving and decrypting the encrypted SIB1 message sent by the base station, acquiring cell information and making access requests, the problem of poor security in the access control method in the prior art is solved, and a more secure and strict access control of the 5G terminal is achieved.
Patent Information
- Application Number
- CN202311524516.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-15
- Publication Date
- 2025-05-27
AI Technical Summary
There are security loopholes in the access control method of the existing 5G network. The fake base station can induce 5G terminal access through forged digital certificates, resulting in security accidents.
By receiving the encrypted SIB1 message sent by the base station, decrypting it based on the preset encryption information, obtaining cell information, and initiating an access request to the base station based on the information to ensure the security of terminal access.
This method uses confidentiality technology to process the key information of the terminal accessing the base station to confidentially ensure that the terminal without the security decryption ability cannot access the base station with the security encryption ability, and at the same time ensure that the terminal with the security decryption ability cannot access the base station without the security encryption ability, thereby improving the security of the access control.
Smart Images

Figure CN120050751A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and in particular, to an access control method, an electronic device, and a storage medium for a terminal. Background Art
[0002] With the continuous acceleration of the commercial deployment rhythm of the fifth-generation mobile communication technology (5G), a large number of 5G terminals are connected to the 5G network.
[0003] Currently, the access control for 5G terminals in the 5G network is mainly completed through the mutual authentication between the terminal and the network. However, such an access control method has certain security vulnerabilities. For example, a fake base station can induce a 5G terminal through a forged digital certificate, causing the 5G terminal to be attracted to the fake base station, resulting in security incidents. The security of the access control method in the prior art is relatively poor.
[0004] Therefore, there is an urgent need for an access control method to more securely and strictly manage critical 5G terminals. Summary of the Invention
[0005] This application provides an access control method, an electronic device, and a storage medium for a terminal, so as to at least solve the problem of relatively poor security of the access control method in the related art.
[0006] In a first aspect, this application provides an access control method for a terminal, which is applied to the terminal. The method includes:
[0007] Receiving an encrypted SIB1 message sent by a base station;
[0008] Decrypting the encrypted SIB1 message based on preset encryption information to obtain a decryption result;
[0009] Initiating a selection of a cell to the base station based on the cell information in the decryption result to determine a target access cell, so that the terminal accesses the target access cell.
[0010] In a second aspect, this application provides an access control method for a terminal, which is applied to a base station. The method includes:
[0011] Encrypting an SIB1 message based on preset encryption information to obtain an encrypted SIB1 message, where the SIB1 message includes cell information corresponding to the base station;
[0012] Sending the encrypted SIB1 message to a terminal within the signal range of the base station.
[0013] In a third aspect, the present application provides an electronic device, including: at least one communication interface; at least one bus connected to the at least one communication interface; at least one processor connected to the at least one bus; and at least one memory connected to the at least one bus, wherein the processor is configured to be capable of executing the method described in the first aspect or the method described in the second aspect of the present application above.
[0014] In a fourth aspect, the present application further provides a computer storage medium storing computer-executable instructions for executing the method described in the first aspect or the method described in the second aspect of the present application above.
[0015] In the method provided by the embodiments of the present application, when the terminal accesses the base station, it decrypts the encrypted SIB1 message encrypted by the base station, and obtains the cell information for the terminal to access the base station based on the decryption result, so that the terminal accesses the base station corresponding to the cell information. Through the technical solution provided by the present application, when the terminal accesses the base station, the key information for the terminal to access the base station is encrypted through confidentiality technology, ensuring that terminals without secure decryption capabilities cannot access base stations with secure encryption capabilities, and at the same time ensuring that terminals with secure decryption capabilities cannot access base stations without secure encryption capabilities, thereby solving the problem of poor security of the access control method in the related art. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The accompanying drawings here are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present invention, and are used together with the specification to explain the principles of the present invention.
[0017] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for describing the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.
[0018] One or more embodiments are exemplarily illustrated by the pictures in the corresponding accompanying drawings. These exemplary illustrations do not limit the embodiments. Elements with the same reference numerals in the drawings are represented as similar elements, unless otherwise stated, and the drawings in the figures do not constitute a proportional limitation.
[0019] Figure 1 It is a flowchart of a method for controlling access of a terminal applied to a terminal provided by an embodiment of the present application.
[0020] Figure 2 It is a flowchart of a method for controlling access of a terminal applied to a base station provided by an embodiment of the present application.
[0021] Figure 3 Schematic diagram of the encryption key update process in an access control method for a terminal provided in an embodiment of the present application.
[0022] Figure 4 Interaction diagram between a terminal and a base station in an access control method for a terminal provided in an embodiment of the present application.
[0023] Figure 5 Interaction diagram between a secure terminal and a base station during the movement process in an access control method for a terminal provided in an embodiment of the present application.
[0024] Figure 6 Interaction diagram between a non-secure terminal and a base station during the movement process in an access control method for a terminal provided in an embodiment of the present application.
[0025] Figure 7 Schematic diagram of the structure of an access control device for a terminal applied to a terminal provided in an embodiment of the present application.
[0026] Figure 8 Schematic diagram of the structure of an access control device for a terminal applied to a base station provided in an embodiment of the present application.
[0027] Figure 9 Schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Detailed implementation manners
[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0029] The following disclosure provides many different embodiments or examples for implementing different structures of the present invention. To simplify the disclosure of the present invention, components and settings of specific examples are described below. Of course, they are only examples and are not intended to limit the present invention. In addition, the present invention may repeat reference numerals and / or letters in different examples. This repetition is for the purpose of simplification and clarity, and does not itself indicate the relationship between the various embodiments and / or settings discussed.
[0030] To solve the problem of poor security in the access control method in the related art, the present application provides an access control method for a terminal, which can provide more secure access control for the terminal and the base station.
[0031] Refer to Figure 1, an embodiment of the present application provides an access control method for a terminal, which is applied to the terminal. The method includes:
[0032] S101: Receive the encrypted SIB1 message sent by the base station;
[0033] Specifically, when the terminal is in the initial access after power-on or during the moving process, it needs to parse the SI (Service Indication message, system message) to obtain the cell information of the base station to be accessed, so as to select the target cell to camp on and the base station to be accessed during the later access process. The SIB1 (System Information Block 1) message in the SI is crucial. The SIB1 message is a special system information block in the 5G wireless communication system, which is used to broadcast the most basic system configuration and network parameters to the terminal. It contains key information required for the terminal to connect to the base station, such as cell selection information, cell ID, frequency band information, system bandwidth, physical cell identification code, etc.
[0034] In a feasible embodiment of the present application, when the terminal is within the signal range of the base station, it receives the encrypted SIB1 message broadcast by the base station. Among them, the encrypted SIB1 message is the message obtained by the base station encrypting the SIB1 message. The encrypted SIBI message can be displayed in the format of the SIBI message to facilitate the terminal to receive the encrypted SIBI message.
[0035] S102: Decrypt the encrypted SIB1 message based on the preset encryption information to obtain a decryption result;
[0036] In a feasible embodiment of the present application, decrypting the encrypted SIB1 message based on the decryption key in the preset encryption information specifically includes:
[0037] Decrypt the encrypted SIB1 message based on the preset encryption information to obtain the SIB1 message;
[0038] Identify the key message in the SIB1 message based on the preset identification rule;
[0039] Decrypt the key message with the decryption key in the preset encryption information to obtain the decryption result.
[0040] Specifically, the key messages are included in the SIB1 message. The key messages provide important information for the terminal to access the base station, which can help the terminal perform system selection, cell communication, and communication parameter configuration. The key messages include cell AccessRelated Info (cell access related information), Scheduling Info (scheduling information), and so on. Since the key messages are several specific fields in the SIB1 message, the process of identifying the key messages is the process of searching for specific fields. After the terminal obtains the SIB1 message corresponding to the encrypted SIB1 message sent by the base station, the terminal identifies the key messages in the SIB1 message based on the preset identification rules.
[0041] It can be understood that, based on the encrypted SIB1 message being the message encrypted by the base station, the key messages are also encrypted messages. Therefore, after the terminal identifies the key messages, it cannot directly parse the information contained in the key messages and cannot configure the access process of the terminal to access the base station based on the key messages. Based on the above understanding, the decryption result obtained by decrypting the key messages is a message in plaintext, and the decryption result can be correctly identified by the terminal. At the same time, the terminal can parse the information contained in the decryption result, so as to complete the configuration of the access process according to the parsed information.
[0042] In a feasible embodiment of the present application, the preset identification rules can be a created key message field table. The key message field table contains a large number of specific fields corresponding to the key messages. By searching all the fields contained in the SIB1 message through the key message field table, the fields contained in the key message field table in the SIB1 message are found, so as to identify the key messages in the SIB1 message.
[0043] Specifically, the preset encryption information can be stored in the terminal in the form of software, for example, stored in the storage module of the terminal in the form of an APP, a program field, or a software program. After the terminal receives the encrypted SIB1 message sent by the base station, it decrypts the encrypted SIB1 message using the preset encryption information to obtain the SIB1 message. After using the preset identification rules to identify the key messages in the SIB1 message, it decrypts the key messages using the decryption key in the preset encryption information to generate a decryption result. At the same time, the preset identification rules are set to accurately identify the key messages to ensure information security.
[0044] In a feasible embodiment of the present application, the decryption key in the preset encryption information is used to decrypt the encrypted SIB1 message. The decryption method of the decryption key corresponds to the encryption method of the base station. The decryption methods of the decryption key include decryption algorithms such as the SM4 algorithm and the ZUC algorithm.
[0045] In a feasible embodiment of the present application, if the preset encryption information is stored in the terminal in the form of software, when the user replaces or modifies the preset encryption information, it is necessary to re-enter the new preset encryption information, which is very inconvenient for the user to operate.
[0046] In another feasible embodiment of the present application, the preset encryption information is stored in the first security card built into the terminal, that is, the first security card is a built-in hardware device, for example, stored in the PCIE card, SIM card, TF card or USB card built into the terminal. By storing the preset encryption information in the first security card built into the terminal, when the user modifies or replaces the preset encryption information, the first security card can be replaced with a security card storing the new preset encryption information, which is convenient for the user to operate.
[0047] Based on the above embodiment of storing the preset encryption information in the first security card built into the terminal, in a feasible embodiment of the present application, decrypting the key message based on the decryption key in the preset encryption information to generate a decryption result, specifically including:
[0048] Generating a decryption request and sending the decryption request to the first security card built into the terminal;
[0049] Receiving the decryption key returned by the first security card;
[0050] Decrypting the key message with the decryption key to generate a decryption result.
[0051] Specifically, when the terminal receives the encrypted SIB1 message sent by the base station, it triggers the decryption process of the encrypted SIB1 message.
[0052] In a feasible embodiment of the present application, the terminal generates a decryption request in response to the event of receiving the encrypted SIB1 message and sends the decryption request to the first security card built into the terminal. The decryption request contains the request information for requesting data, and the request information indicates the specific content of the data requested by the terminal from the first security card. In this embodiment, the specific content of the data requested by the terminal from the first security card is the decryption key; after receiving the decryption request sent by the terminal, the first security card searches for the corresponding specific data according to the request information in the decryption request, obtains the decryption key, and after completing the search for the decryption key, the first security card returns the decryption key to the terminal; after receiving the decryption key returned by the first security card, the terminal decrypts the key message in the identified SIB1 message with the decryption key, thereby generating a decryption result.
[0053] In a feasible embodiment of the present application, after the terminal receives the SIB1 message sent by the base station, it further includes a process of updating the decryption key. The updating process specifically includes:
[0054] Identify the extended message in the SIB1 message based on the preset recognition rules;
[0055] Obtain the key update random number included in the extended message based on the update identifier in the extended message, and update the decryption key according to the key update random number.
[0056] Specifically, the SIB1 message also contains an extended message, which provides additional extended functions or configurations for the terminal to access the base station. After the terminal receives the encrypted SIB1 message, it identifies the extended message included in the SIB1 message corresponding to the encrypted SIB1 message. When it is recognized that the extended message contains an update identifier, the key update random number is obtained from the extended message, and the decryption key is updated according to the key update random number; when the update identifier is not recognized, the existing decryption key is continued to be used.
[0057] S103: Initiate the selection of a cell to the base station based on the cell information in the decryption result, determine the target cell, so that the terminal accesses the target cell;
[0058] Specifically, the decryption result is obtained by the terminal decrypting the key message in the SIB1 message corresponding to the encrypted SIB1 message. The decryption result contains the key information for the terminal to access the base station, which specifically includes cell information that can be correctly recognized by the terminal. After the terminal obtains the cell information from the decryption result, it determines the target cell based on the cell information, and thus applies to the base station that sent the encrypted SIB1 message for access. After the base station completes the authentication of the terminal's identity, an access process with the terminal is established, and the terminal accesses the base station based on the established access process.
[0059] It can be understood that before the encrypted SIB1 message is decrypted, the terminal cannot correctly recognize the key message in the encrypted SIB1 message, so it cannot provide the key message to determine the cell information of the base station, resulting in the inability to access the base station. In the technical solution provided in this application, the decryption of the encrypted SIB1 message by the terminal is a necessary step. When the terminal receives an unencrypted SIB1 message, it will also execute the decryption step of the encrypted SIB1 message. Decrypting the SIB1 message on the basis that the SIB1 message is not encrypted will obtain incorrect data, so that the terminal cannot access the base station either.
[0060] Through the technical solution provided by the above embodiments, a secure terminal with decryption capabilities can only access a secure base station with encryption capabilities, and cannot access an insecure base station without encryption capabilities, thereby improving the security of the access control method for the terminal to access the base station.
[0061] In a possible implementation scenario, some industries and parks have strict access scope and security control over terminals. They can only access the network within the specified area and cannot access the network when leaving the designated area. Through the technical solution provided by the above embodiments of the present application, security card base stations with encryption capabilities are deployed in areas such as parks and factory areas. Ordinary terminals entering this area cannot access the network because they do not have decryption capabilities. Only security terminals with security cards and decryption capabilities can access the network. Once a security terminal with decryption capabilities needs to leave the area, it only needs to remove the security card set on the security terminal with decryption capabilities and convert the security terminal with decryption capabilities into an ordinary terminal, then the purpose of area control can be achieved, thereby enhancing the information control ability of key areas.
[0062] Referring to Figure 2 , an access control method for a terminal is provided in an embodiment of the present application, which is applied to a base station. The method includes:
[0063] S201: Encrypt the SIB1 message based on preset encryption information to obtain an encrypted SIB1 message. The SIB1 message contains cell information corresponding to the base station;
[0064] Specifically, the SIB1 message is generated by the base station and contains cell information corresponding to the base station. After generating the SIB1 message, the base station encrypts the SIB1 message based on preset encryption information to generate an encrypted SIB1 message.
[0065] In a feasible embodiment of the present application, encrypting the SIB1 original message based on preset encryption information to generate an encrypted SIB1 message specifically includes:
[0066] Identifying key messages in the SIB1 message based on a preset identification rule;
[0067] Encrypting the key messages using the encryption key in the preset encryption information to obtain an encryption result;
[0068] Obtaining the encrypted SIB1 message according to the encryption result.
[0069] Specifically, after generating the SIB1 message, the base station identifies the key messages contained in the SIB1 message based on a preset identification rule. The key messages are used to provide key information for terminals within the signal range of the base station to access the base station. The base station encrypts the key messages based on the encryption key in the preset encryption information. The preset encryption information can be directly stored in the storage medium of the base station in the form of software or stored on a second security card built into the base station. The encryption key can specifically encrypt the key messages through encryption algorithms such as the SM4 algorithm and the ZUC algorithm.
[0070] It should be noted that the encryption key of the base station corresponds to the decryption key of the terminal. Under the same configuration, the encryption key and the decryption key appear in pairs, and the same confidentiality technology is used to encrypt or decrypt the key message.
[0071] Based on the above embodiment of storing the preset encryption information in the second security card built in the base station, in a feasible embodiment of the present application, encrypting the key message based on the encryption key in the preset encryption information to generate an encryption result specifically includes:
[0072] Generating an encryption request and sending the encryption request to the second security card built in the base station;
[0073] Receiving the encryption key returned by the second security card;
[0074] Encrypting the key message with the encryption key to generate an encryption result.
[0075] Specifically, the encryption request is similar to the decryption request and contains request information for requesting data, and the request information indicates the specific content of the data requested by the base station from the second security card. In response to the event of generating the SIB1 message, the base station generates an encryption request and sends the encryption request to the second security card built in the base station; after receiving the encryption request, the second security card looks up the encryption key according to the request information in the encryption request and returns the encryption key to the base station.
[0076] In a feasible embodiment of the present application, before encrypting the key message with the encryption key in the preset encryption information to generate an encryption result, it further includes:
[0077] Judging whether the encryption key meets the update trigger condition;
[0078] When the update trigger condition is met, the base station obtains a key update random number and updates the encryption key according to the key update random number;
[0079] Specifically, the update trigger condition may include an event update trigger condition or a time update trigger condition. Referring to Figure 3 , in a feasible embodiment of the present application, when any one of the event update trigger condition and the time update trigger condition is met, the update of the encryption key is triggered; when neither the event update trigger condition nor the time update trigger condition is met, the encryption key is not updated.
[0080] In a feasible embodiment of the present application, the encryption key is updated when the event update trigger condition is met. For example, a technician issues a key update instruction to the base station, and the base station responds to the key update instruction to meet the event update trigger condition. In another feasible embodiment of the present application, the encryption key is updated when the time update trigger condition is met. For example, a technician pre-sets the update period to 3 days, and the base station times while working. When it reaches the 3rd day, the time update trigger condition is met.
[0081] In a feasible embodiment of the present application, when the update trigger condition is not met, the encryption key is not updated.
[0082] In a feasible embodiment of the present application, when the update trigger condition is met, obtaining the encrypted SIB1 message according to the encryption result specifically includes:
[0083] Obtain the key update random number and the update identifier;
[0084] Configure the extended message in the SIB1 message according to the key update random number and the update identifier configuration;
[0085] Obtain the encrypted SIB1 message according to the encryption result and the extended message after completion of configuration.
[0086] Specifically, the update identifier is used to indicate that the terminal receiving the encrypted SIB1 message sent by the base station updates the decryption key, and the key update random number is used to update the encryption key.
[0087] The SIB1 message contains key messages, extended messages, and some related information fields. When the update trigger condition is met, first configure the extended message according to the key update random number and the update identifier, and then combine the extended message after completion of configuration with the encrypted key message to obtain the encrypted SIB1 message.
[0088] When the update trigger condition is not met, directly combine the encryption result and the extended message to configure the SIB1 message as the encrypted SIB1 message.
[0089] S202: Send the encrypted SIB1 message to the terminals within the signal range of the base station.
[0090] It can be understood that a secure base station with encryption capabilities only broadcasts the encrypted SIB1 message encrypted by the base station. When a terminal within the signal range of the base station receives the encrypted SIB1 message, only a secure terminal with decryption capabilities can correctly decrypt the key message in the encrypted SIB1 message to obtain the cell information corresponding to the base station.
[0091] Through the technical solution provided by the above embodiments, the secure base station with encryption capabilities only allows secure terminals with decryption capabilities to access, thereby completing the access control of the terminals. At the same time, since the encrypted SIB1 message sent by the secure base station with encryption capabilities is an encrypted message, even if it is obtained by other devices during the broadcast process of the encrypted SIB1 message, other devices cannot decrypt the encrypted SIB1 message, thus ensuring the information security of the base station.
[0092] In a possible implementation scenario, to prevent a terminal from accessing a fake base station, based on the technical solution provided by this application, the base station needs to encrypt the SIB1 message, and the terminal needs to decrypt the SIB1 message. If there is a fake base station in the area and it broadcasts the SIB1 message, since the fake base station does not have the corresponding encryption process to encrypt the SIB1 message to obtain the encrypted SIB1 message, the broadcast SIB1 message is in plain text. After receiving this message, the terminal cannot obtain the correct information after decrypting the message sent by the fake base station because it has the decryption ability for the encrypted SIB1 message, so that the terminal cannot access the fake base station, thereby preventing the terminal from accessing the fake base station.
[0093] Figure 4 This is the interaction timing diagram between the terminal and the base station in an access control method for a terminal provided by this application. Refer to Figure 4 , in a feasible embodiment of this application, the specific interaction process between the base station and the terminal includes:
[0094] S401: The base station generates an SIB1 message;
[0095] S402: The base station sends the SIB1 message to the second security card built in the base station;
[0096] S403: The second security card encrypts the SIB1 message with a pre-set encryption key to generate an encrypted SIB1 message;
[0097] S404: The second security card returns the encrypted SIB1 message to the base station;
[0098] S405: The base station broadcasts the encrypted SIB1 message;
[0099] S406: After receiving the encrypted SIB1 message, the terminal sends the encrypted SIB1 message to the first security card built in the terminal;
[0100] S407: The first security card decrypts the encrypted SIB1 message with a pre-set decryption key to obtain the SIB1 message;
[0101] S408: The first security card returns the SIB1 message to the terminal;
[0102] S409: The terminal initiates an access procedure to the base station according to the SIB1 message.
[0103] Through the technical solution provided by the embodiments of the present application, during the interaction between the terminal and the base station, the messages transmitted between the terminal and the base station are all encrypted messages, and the recognizable plaintext messages are all processed inside the terminal or the base station, thereby preventing the information leakage between the terminal and the base station.
[0104] Refer to Figure 5 , in a possible implementation scenario of the present application, a secure card terminal with a first secure card having decryption capabilities is in a mobile state, moving from a secure card S-gNB (Source-gNB, source-side base station) with a second secure card having encryption capabilities to a non-secure card T-gNB (Target-gNB, target base station) without a second secure card and without encryption capabilities.
[0105] In the case where the source-side base station of the secure card and the target base station of the non-secure card are not configured with neighboring cells, the secure card terminal accesses the source-side base station of the secure card based on the access control method provided in the above embodiments; during the movement of the secure card terminal, a strong signal of the non-secure card target base station is detected, and the signal strength of the non-secure card target base station has reached the base station handover threshold. At this time, the secure card terminal attempts to access the non-secure card target base station; the secure card terminal receives the SIB1 message broadcast by the non-secure card target base station. Since the non-secure card target base station does not have an encryption function, the SIB1 message broadcast by the non-secure card target base station is an unencrypted message; the secure card terminal decrypts the SIB1 message broadcast by the non-secure card target base station. Since the SIB1 message is not encrypted, the secure card terminal cannot correctly complete the decryption of the SIB1 message, and thus cannot correctly obtain the cell information of the non-secure card target base station; the secure card terminal fails to switch from the source-side base station of the secure card to the non-secure card target base station.
[0106] In the case where the source-side base station of the secure card and the target base station of the non-secure card are not configured with neighboring cells, the secure card terminal will first directly access the non-secure card target base station; the secure card terminal receives the SIB1 message broadcast by the non-secure card target base station. Since the non-secure card target base station does not have an encryption function, the SIB1 message broadcast by the non-secure card target base station is an unencrypted message; the secure card terminal decrypts the SIB1 message broadcast by the non-secure card target base station. Since the SIB1 message is not encrypted, the secure card terminal cannot correctly complete the decryption of the SIB1 message, and thus cannot correctly identify the cell information of the non-secure card target base station; the non-secure card target base station releases the access of the secure card terminal.
[0107] Refer to Figure 6, in a possible implementation scenario of this application, a non-secure card terminal without the decryption ability of the first security card is in a moving state, moving from a non-secure card source-side base station without the encryption ability of the second security card to a secure card target base station with the encryption ability of the second security card.
[0108] When the non-secure card source-side base station and the non-secure card target base station are configured with neighboring cells, the non-secure card terminal normally accesses the non-secure card source-side base station; during the movement of the non-secure card terminal, a strong signal of the secure card target base station is detected, and the signal strength of the secure card target base station has reached the base station handover threshold. At this time, the non-secure card terminal attempts to access the secure card target base station; the non-secure card terminal receives the SIB1 message broadcast by the secure card target base station. Since the secure card target base station has an encryption function, the SIB1 message broadcast by the secure card target base station is an encrypted message; the non-secure card terminal identifies the SIB1 message broadcast by the secure card target base station. Since the non-secure card terminal does not have the decryption ability, it is also unable to correctly device the cell information included in the SIB1 message broadcast by the secure card target base station; the non-secure card terminal fails to switch from the non-secure card source-side base station to the secure card target base station.
[0109] When the non-secure card source-side base station and the secure card target base station are configured with neighboring cells, the secure card terminal will first directly access the secure card target base station; the non-secure card terminal receives the SIB1 message broadcast by the secure card target base station. Since the secure card target base station has an encryption ability, the SIB1 message broadcast by the secure card target base station is an encrypted message; the non-secure card terminal decrypts the SIB1 message broadcast by the secure card target base station. Since the non-secure card terminal does not have the decryption ability, the non-secure card terminal cannot correctly complete the decryption of the SIB1 message, and thus cannot correctly identify the cell information of the secure card target base station; the secure card target base station releases the access of the non-secure card terminal.
[0110] Corresponding to the above method embodiments, the embodiments of this application also provide an access control device for a terminal, which is applied to the terminal, as Figure 7 shown. The device may include: a receiving module 701, a decryption module 702, and an access module 703.
[0111] The receiving module 701 is configured to receive the encrypted SIB1 message sent by the base station;
[0112] The decryption module 702 is configured to decrypt the encrypted SIB1 message based on preset encryption information to obtain a decryption result;
[0113] The access module 703 is configured to initiate a cell selection to the base station based on the cell information in the decryption result, determine a target access cell, so that the terminal accesses the target access cell.
[0114] In a possible implementation, the decryption module 702 includes:
[0115] A first decryption unit, configured to decrypt the encrypted SIB1 message based on preset encryption information to obtain the SIB1 message;
[0116] A second decryption unit, configured to decrypt the SIB1 message to obtain a decryption result.
[0117] In a possible implementation, the second decryption unit includes:
[0118] An identification subunit, configured to identify critical messages in the SIB1 message based on preset identification rules;
[0119] A decryption subunit, configured to decrypt the critical messages using the decryption key in the preset encryption information to obtain a decryption result.
[0120] In a possible implementation, the apparatus may further include:
[0121] An identification module, configured to identify extended messages in the SIB1 message based on preset identification rules;
[0122] An update module, configured to obtain a key update random number included in the extended message based on an update identifier in the extended message, and update the decryption key according to the key update random number.
[0123] Corresponding to the above method embodiment, an access control apparatus for a terminal provided in an embodiment of the present application is applied to a base station. As Figure 8 shown, the apparatus may include: an encryption module 801 and a sending module 802.
[0124] The encryption module 801 is configured to encrypt the SIB1 message based on preset encryption information to obtain an encrypted SIB1 message, where the SIB1 message includes cell information corresponding to the base station;
[0125] The sending module 802 is configured to send the encrypted SIB1 message to a terminal within the signal range of the base station.
[0126] In a possible implementation, the encryption module 801 includes:
[0127] An identification unit, configured to identify critical messages in the SIB1 message based on preset identification rules;
[0128] An encryption unit, configured to encrypt the critical messages using the encryption key in the preset encryption information to obtain an encryption result;
[0129] A generation unit, configured to obtain the encrypted SIB1 message according to the encryption result.
[0130] In a possible implementation, the encryption module 801 includes:
[0131] A judgment unit, configured to judge whether an encryption key meets an update trigger condition;
[0132] An update unit, configured to obtain a key update random number and update the encryption key according to the key update random number when the update trigger condition is met.
[0133] In a possible implementation, the generation unit includes:
[0134] An obtaining subunit, configured to obtain a key update random number and an update identifier when the update trigger condition is met;
[0135] A configuration subunit, configured to configure an extended message in the SIB1 message according to the key update random number and the update identifier;
[0136] A generation subunit, configured to obtain an encrypted SIB1 message according to the encryption result and the extended message after configuration.
[0137] As Figure 9 shown, an embodiment of the present application provides an electronic device, including a processor 901, a communication interface 902, a memory 903, and a communication bus 904. Among them, the processor 901, the communication interface 902, and the memory 903 complete communication with each other through the communication bus 904.
[0138] The memory 903 is used for storing a computer program;
[0139] In an embodiment of the present application, when the processor 901 executes the program stored on the memory 903, it implements an access control method for a terminal provided in any one of the foregoing method embodiments.
[0140] Through the electronic device provided in the embodiment of the present application, it is possible to execute an access control method for a terminal provided in any one of the foregoing method embodiments, so that when the terminal accesses the base station, key information for the terminal to access the base station is encrypted through confidentiality technology, ensuring that a terminal without security decryption capabilities cannot access a base station with security encryption capabilities, and at the same time ensuring that a terminal with security decryption capabilities cannot access a base station without security encryption capabilities, so as to solve the problem of poor security of the access control method in the related art.
[0141] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the steps of an access control method for a terminal provided in any one of the foregoing method embodiments.
[0142] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0143] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solution, in essence, or the part that contributes to the related technology can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0144] It should be understood that the terms used herein are only for the purpose of describing specific example embodiments and are not intended to be limiting. Unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" as used herein may also include the plural forms. The terms "include", "comprise", "contain", and "have" are inclusive and thus specify the presence of the stated features, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, steps, operations, elements, components, and / or combinations thereof. The method steps, processes, and operations described herein are not to be construed as necessarily requiring them to be performed in the particular order described or illustrated, unless the order of execution is explicitly stated. It should also be understood that additional or alternative steps may be used.
[0145] The above description is only the specific embodiments of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features claimed herein.
Claims
1. An access control method for a terminal, characterized in that, applied to the terminal, the method includes: receiving an encrypted SIB1 message sent by a base station; decrypting the encrypted SIB1 message based on preset encryption information to obtain a decryption result; initiating a selection of a cell to the base station based on the cell information in the decryption result to determine a target access cell, so that the terminal accesses the target access cell.
2. The method according to claim 1, characterized in that, decrypting the encrypted SIB1 message based on preset encryption information to obtain a decryption result, including: decrypting the encrypted SIB1 message based on the preset encryption information to obtain an SIB1 message; decrypting the SIB1 message to obtain the decryption result.
3. The method according to claim 2, characterized in that, decrypting the SIB1 message to obtain the decryption result, including: identifying key messages in the SIB1 message based on a preset identification rule; decrypting the key messages using a decryption key in the preset encryption information to obtain the decryption result.
4. The method according to claim 1, characterized in that, after receiving the encrypted SIB1 message sent by the base station, it further includes: identifying extended messages in the SIB1 message based on a preset identification rule; obtaining a key update random number included in the extended message based on an update identifier in the extended message, and updating the decryption key according to the key update random number.
5. An access control method for a terminal, characterized in that, applied to a base station, the method includes: encrypting an SIB1 message based on preset encryption information to obtain an encrypted SIB1 message, where the SIB1 message includes cell information corresponding to the base station; sending the encrypted SIB1 message to a terminal within the signal range of the base station.
6. The method according to claim 5, characterized in that, encrypting the SIB1 message based on preset encryption information to obtain an encrypted SIB1 message, including: identifying key messages in the SIB1 message based on a preset identification rule; encrypting the key messages using an encryption key in the preset encryption information to obtain an encryption result; obtaining the encrypted SIB1 message according to the encryption result.
7. The method according to claim 6, characterized in that, before encrypting the key messages using the encryption key in the preset encryption information to generate an encryption result, it further includes: judging whether the encryption key meets an update trigger condition; when the update trigger condition is met, obtaining a key update random number, and updating the encryption key according to the key update random number.
8. The method according to claim 7, characterized in that, obtaining the encrypted SIB1 message according to the encryption result, including: when the update trigger condition is met, obtaining the key update random number and an update identifier; configuring extended messages in the SIB1 message according to the key update random number and the update identifier configuration; The encrypted SIB1 message is obtained based on the encryption result and the extended message after the configuration is completed.
9. An electronic device, characterized in that, comprising: at least one communication interface; at least one bus connected to the at least one communication interface; at least one processor connected to the at least one bus; at least one memory connected to the at least one bus, wherein the processor is configured to be capable of implementing any one of the methods recited in claims 1-4 or any one of the methods recited in claims 5-8.
10. A computer storage medium, characterized in that, stores computer-executable instructions for executing any one of the methods recited in claims 1-4 or any one of the methods recited in claims 5-8.