Security protection system for 5G core network control plane data
By designing a security protection system for 5G core network control surface data, using simulation generation and verification, identity authentication and access control, data encryption and decryption, threat flow detection and analysis, and data visualization modules, the illegal utilization, tampering and replay attacks faced by 5G core network data is solved, and efficient threat detection and data privacy protection is achieved.
Patent Information
- Application Number
- CN202510165441.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-05-30
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
When facing illegal utilization, tampering and replay attacks, the existing technology is difficult to effectively detect and protect, resulting in threats to network security and stability.
A security protection system for 5G core network control plane data is designed, including signaling flow simulation generation and verification module, identity verification and access control module, data encryption and decryption module, threat flow detection and analysis module and data visualization module. Through simulation, real 5G signaling flow data can be generated, abnormal behavior can be captured, and the accuracy of threat flow detection is enhanced. Zero-knowledge proof and homomorphic encryption are used to ensure data privacy and security.
It realizes accurate threat detection and behavioral analysis of the control surface data of the 5G core network, enhances the security protection capabilities of the network, ensures data privacy and security, and provides an intelligent solution suitable for complex 5G network environments.
Smart Images

Figure CN120075798A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of security protection systems, and specifically to a security protection system for 5G core network control plane data. The present invention also provides a usage method for this system. Background Art
[0002] The mobile communication network is the cornerstone of China's informatization construction and the development of the digital economy, responsible for the management of communication services. Its security is crucial for the development of informatization construction and the digital economy. In recent years, with the rapid development of 5G technology, the complexity and data volume of the mobile communication network have increased significantly, and the core network control plane data has become an important target for network attacks. As the core data in the mobile communication network, the core network control plane data carries a large amount of user communication information and control instructions. Once the signaling network is attacked, it will not only lead to the leakage of personal privacy but may also indirectly cause large-scale network paralysis and service interruption. Lawbreakers illegally utilize signaling flow data through various means such as stealing, tampering, and replay, seriously threatening the security and stability of the communication network. For example, stealing signaling data can obtain users' sensitive information for identity theft and fraud; tampering with signaling data can forge or modify communication content, resulting in misleading operations; replay attacks can repeatedly send legitimate signals to disrupt the normal network communication process. With the popularization of 5G technology, these threats have become more complex and concealed, posing higher requirements for network security. Therefore, it is urgent to strengthen network security protection, solve data privacy protection in the 5G core network scenario, and establish a sound network security system.
[0003] Compared with the patent method of the publication number CN118013560B (a network data information security protection method based on blockchain technology), this method mainly solves the problems of data storage, transmission, and privacy protection in network security through blockchain technology, emphasizing decentralization, the security of smart contracts, and compliance supervision, etc. While the present invention focuses on the security protection of 5G network control plane data, especially in aspects such as signaling flow threat detection and behavior analysis. In response to the special requirements of the 5G network, the present invention designs a simulation generation and verification module for signaling flow, which enhances the accuracy of threat flow detection by simulating real 5G signaling flow data and capturing abnormal behaviors. Compared with the decentralized storage method of the blockchain method, this method is more focused on the security protection of 5G signaling flow, real-time detection, and response to network attacks. Summary of the Invention
[0004] The present invention aims to solve the above problems of the prior art. A security protection system for 5G core network control plane data is proposed. The technical solution of the present invention is as follows:
[0005] A security protection system for 5G core network control plane data, which includes a signaling flow simulation generation and verification module, an identity authentication and access control module, a data encryption and decryption module, a threat flow detection and analysis module, and a data visualization module. The signaling flow simulation generation and verification module is used to simulate and generate near-real normal 5G signaling flow data, signaling threat flow data, and data stream capture and analysis. The identity authentication and access control module is used for user identity verification to ensure that only users who have passed strict verification and authorization can access specific resources of this system, including identity registration, identity authentication, and access control. The data encryption and decryption module is used for data protection to ensure that sensitive information of the signaling data uploaded by users will not be leaked during transmission and storage. The threat flow detection and analysis module is used to implement the detection and analysis of signaling data, including data preprocessing, threat flow detection, behavior characteristics, and traceability map characterization. The data visualization module is used to visualize key data information, including real-time display of signaling flow data information, real-time display of network element information, real-time display of attack progress, and acquisition of real-time signaling data packets and signaling data information after the attack is completed. Among them, the interface interaction between the signaling flow simulation generation and verification module and the threat flow detection and analysis module uses the json data format to transfer signaling characteristics and threat rules to support the real-time analysis requirements of the threat detection and analysis module.
[0006] Furthermore, the signaling flow simulation generation and verification module integrates a 5G core network signaling storm simulation test platform, an open-source software Free5GC platform, a UERANSIM simulator, and a Kali attack system to build a complete signaling data set by combining the generation of normal signaling data and threat signaling data.
[0007] Furthermore, the signaling flow simulation generation and verification module includes a normal signaling flow simulation generation module, a threat signaling flow simulation generation module, and a data stream capture and analysis module. Among them,
[0008] The normal signaling flow simulation generation module is used to implement the simulation generation and testing of normal signaling flows. By using XPRO instruments to simulate and build the Free5GC platform, it simulates and generates real and reliable 5G signaling flow data, including the access process, authentication process, authorization process, and connection establishment process, and generates signaling flow data that complies with the 3GPP 5G standard.
[0009] The threat signaling flow simulation generation module is used to obtain threat signaling flow data. It can simulate various service combination processes by configuring XPRO instrument parameters to implement threat signaling behaviors and collect data; it can also use the Kali platform to simulate external attackers to initiate attacks on the core network to generate threat signaling flows; it can also be based on the openapi provided by the Free5GC environment. By deeply studying the communication mechanisms of each network element in the communication signaling network and analyzing the network element communication interfaces, and using the permission vulnerabilities between the internal interfaces of 5G communication, deduce the potential causes of logical threats, so as to discover control plane vulnerabilities and generate threat signaling flows.
[0010] The data flow capture and analysis module is used to capture the signaling data packets between the downloading users, base stations and the core network in real time and analyze the network traffic.
[0011] Furthermore, the authentication and access control module includes an identity registration module, an identity authentication module, and an access control permission module. Among them,
[0012] The identity registration module is used to implement the information management of user registration; it allows users to submit identity information for registration, encrypts the data during registration, converts the identity information provided by the user into a format suitable for storage on the Hyperledger Fabric consortium blockchain, and stores it on the chain through a smart contract to prevent information leakage.
[0013] The identity authentication module verifies the user's identity information and determines its legality. The user identity authentication mechanism based on the zero-knowledge proof algorithm is used to ensure that only verified users can access system resources, while protecting the user's privacy information from being leaked.
[0014] The access control permission module implements fine-grained access control to system resources according to the user's identity information and the permissions obtained during identity authentication, ensuring that only users who have passed identity authentication and been granted corresponding permissions can access specific resources; according to the results of identity authentication, decide whether the user has the permission to access specific resources.
[0015] Furthermore, the data encryption and decryption module implements the encryption and decryption operations of signaling data based on the data privacy protection model of the Paillier algorithm, including a data encryption module, a data decryption module, and a data upload and download module.
[0016] The encryption module is used to protect the privacy of signaling data. It implements data encryption operations through the Paillier algorithm, which is a public-key encryption algorithm based on homomorphic encryption and has additive homomorphicity. This enables encrypted data to perform addition operations without decryption, thus supporting privacy-preserving computing operations. Without exposing the content of the original data, the signaling data uploaded by users is encrypted, and the ciphertext data is uploaded to the blockchain network and stored in the chain code;
[0017] The decryption module is used to restore the encrypted signaling data and ensure that only authorized users can access it. Implementing the decryption function based on the Paillier algorithm ensures that the signaling data can be correctly restored during the download and decryption processes;
[0018] The data upload and download module supports secure signaling data upload and download operations, and can automatically encrypt the plaintext signaling data uploaded by authenticated users.
[0019] Furthermore, the threat flow detection and analysis module includes a data preprocessing module, a threat flow detection module, and a graph characterization module, where
[0020] The data preprocessing module is used to clean the signaling data and compress the data through dimensionality reduction techniques;
[0021] The threat flow detection module analyzes and detects the uploaded signaling data stream according to the algorithm model trained with real signaling threat flow data; the model training process includes parameter initialization, iterative optimization, and model evaluation; the goal of model training is to minimize the loss function;
[0022] The graph characterization module is used to characterize the association strength between threat methods and features, detect the threat types of the signaling data stream and analyze the behavior features, and display the complex data and threat associations in a visual way.
[0023] Furthermore, the data visualization module includes a real-time signaling flow data information display module, a network element information real-time display module, an attack process real-time display module, and a network element monitoring module, where,
[0024] The real-time signaling flow data information display module is used to display the captured signaling flow data information in real time, helping users quickly identify the network communication mode and timely discover signaling network threats;
[0025] The network element information real-time display module is used to display the basic information of network elements, including IP addresses, ports, connection status, and performance metrics, and provide detailed log information;
[0026] The attack process real-time display module is used to monitor the progress of attack activities in real time, display each stage of the attack using a progress bar, and automatically capture the signaling threat flow data packets generated during the attack after the attack ends;
[0027] The network element monitoring module is used to monitor the IP addresses and their statuses of all key network elements in the core network in real time, and respond to the abnormal status of network elements in real time.
[0028] Furthermore, the system architecture adopts a front-end and back-end separated B / S (Browser / Server) architecture design. Vue.js framework is selected for front-end development, and SpringBoot framework is used for back-end development. System users directly access the system through a browser, while the back-end server is responsible for providing necessary interfaces and algorithm services for the front-end. As the data storage layer, the database does not directly expose its interfaces to the outside.
[0029] The advantages and beneficial effects of the present invention are as follows:
[0030] 1. Novel functions: The security protection system for 5G core network control plane data proposed by the present invention not only realizes the simulation generation and verification of normal and threat signaling flows, but also designs an identity authentication and access control model based on zero-knowledge proof, a blockchain data privacy protection model based on homomorphic encryption, and a threat flow detection and analysis method. By providing a comprehensive signaling data privacy protection solution, it solves the problem of data privacy protection in the signaling network from the perspective of system practicability, and provides an intelligent solution for the data security and privacy protection of the signaling network.
[0031] 2. Openness and stability: The software system proposed by the present invention adopts a development mode of SpringBoot and Vue frameworks, both of which have the characteristics of openness and stability. It can accelerate the development and expansion of the system, and has the advantages of simple and convenient maintenance and upgrade, low cost, data security, real-time synchronization, etc.
[0032] 3. Easy maintainability: The software system of the present invention adopts a modular development mode with front-end and back-end separation, which makes it more convenient for later maintenance and requirement expansion, is more developer-friendly, and can easily add or modify functions.
[0033] 4. Security: The present invention adopts an identity authentication and access control model based on zero-knowledge proof. Users prove their identities without revealing any personal information, and obtain an identity token as a communication certificate for subsequent operations after passing the verification. This method provides a secure and privacy-friendly verification means for users, effectively protecting the security of user identity information.
[0034] 5. Authenticity: The experimental data set of the present invention consists of real signaling threat data from the existing network and threat flow data simulated by a highly simulated platform. The threat flow detection models are also trained with real signaling threat data. By simulating and testing the data in a real network environment, the system can provide highly reliable security analysis and verification results, with high application value and practicality.
[0035] 6. The ingenuity of the present invention lies in that the signaling flow simulation generation and verification module realizes the simulation and verification of normal and threat signaling flows, accurately identifying potential threats; the zero-knowledge proof and homomorphic encryption models provide enhanced authentication and data privacy protection, effectively solving the data privacy and security problems in 5G networks; the threat flow detection and analysis method combines real and simulated data, improving the accuracy and reliability of detection. Through these innovations, while ensuring the system security and privacy protection, the present invention also provides an efficient and intelligent solution, with high practical value and application prospects. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 It is a schematic diagram of the system function module framework provided by the preferred embodiment of the present invention;
[0037] Figure 2 It is a schematic diagram of the system architecture of the present invention;
[0038] Figure 3 It is a diagram of the signaling flow simulation generation and verification module of the present invention;
[0039] Figure 4 It is a diagram of the authentication and access control module of the present invention;
[0040] Figure 5 It is a schematic diagram of the data encryption and decryption module process of the present invention;
[0041] Figure 6 It is a schematic diagram of the threat flow detection and analysis module process of the present invention;
[0042] Figure 7 It is a schematic diagram of the data visualization module process of the present invention;
[0043] Figure 8 It is a diagram of the operation result of the threat signaling flow simulation generation (DDOS attack on the AMF network element) of the present invention
[0044] Figure 9 It is a diagram of the identity registration page of the present invention;
[0045] Figure 10 It is a diagram of the data encryption page of the present invention;
[0046] Figure 11 It is a diagram of the data decryption authentication page of the present invention;
[0047] Figure 12 This is the threat flow detection page diagram of the present invention;
[0048] Figure 13 This is the visualization page of the behavior graph of the present invention;
[0049] Figure 14 This is the accuracy performance graph of the signaling threat flow detection model of the present invention;
[0050] Figure 15 This is the request-response time performance graph of the data privacy protection model of the present invention;
[0051] Figure 16 This is the throughput performance graph of the data privacy protection model of the present invention. Detailed implementation manners
[0052] Next, the technical solutions in the embodiments of the present invention will be clearly and detailedly described in conjunction with the accompanying drawings in the embodiments of the present invention. The described embodiments are only a part of the embodiments of the present invention.
[0053] The technical solution for the present invention to solve the above technical problems is:
[0054] Embodiment 1
[0055] This embodiment provides a security protection system for 5G core network control plane data. The system is based on a front-end and back-end separated B / S architecture. The system runs under the Win10 system, uses Tomcat as the application server, uses Mysql and Redis as the database servers. Mysql stores a large amount of fixed data, Redis stores common data and user authentication information, and uses blockchain technology to store important data. It uses the Springboot server framework of JAVA (JDK1.8), the Axios library to implement front-end and back-end data interaction, uses Vue.js as the front-end framework, combines the Element UI component library and the vue-element-admin solution to quickly build a page application. Signaling flow data is simulated and generated through the 5G core network signaling storm simulation test platform (XPRO instrument), Free5GC, UERANSIM and Kali platforms. Hyperledger Fabric provides distributed storage and smart contract execution to ensure data privacy and fine-grained access control. Login access is performed through the http / https protocol to manage the security protection system for 5G core network control plane data.
[0056] As Figure 2As shown in the figure, in the security protection system architecture for the control plane data of the 5G core network, the display layer includes Vue.js, H5 / CSS3 / JS, Element UI, and Echarts. The interaction layer includes Vuex, Vue-router, Axios, and JSON. The service layer includes Spring Boot, Spring Security, and WebSocket. The data storage layer includes Mysql and Redis. The algorithms include the authentication algorithm based on zero-knowledge proof and the data privacy protection algorithm based on homomorphic encryption.
[0057] The following is a detailed explanation of some of the above arrangements:
[0058] 1) Spring Boot technology framework
[0059] Spring Boot is an open-source framework developed by the Pivotal team. It simplifies the application development of the Spring framework through convention over configuration and out-of-the-box features, reduces the initial configuration work, and improves development efficiency. It automatically configures common Spring components and third-party libraries and provides a complete set of monitoring and management tools, enabling developers to focus on business logic and quickly build production-level applications.
[0060] 2) Vue.js front-end technology framework
[0061] Vue.js is a progressive framework designed specifically for building data-driven web interfaces. Its core goal is to achieve reactive data binding and modular view components through a simplified API. Vue.js can be easily integrated with other libraries or existing projects. When combined with single-file components and various libraries in the Vue ecosystem, Vue.js can also efficiently drive complex single-page applications.
[0062] 3) Redis database
[0063] Redis is short for Remote Dictionary Server, that is, a remote dictionary server, which is an open-source in-memory data structure storage system. It supports various data structures such as strings, hashes, lists, sets, and sorted sets, and can persist the data structures in memory to disk. Redis has two major advantages: First, it improves data access speed and system performance; second, it improves development efficiency and simplifies application development work by providing support for various data structures and flexible operations. Redis also has built-in replication, Lua scripting, LRU-driven events, transactions, and high-availability support, making it a powerful database solution.
[0064] 4) 5G core network signaling storm simulation test platform - XPRO
[0065] The XPRO instrument is an advanced evaluation tool. With a high-performance 5G core network simulation tester as the core, it focuses on the performance and stability analysis of the core network part of the 5G network. The platform can accurately simulate the signaling processes in the 5G core network, realizing the simulation of the main signaling network elements AMF, SMF, AUSF, UDM, NSSF, NRF, PCF, and AF in the 5GC, as well as the interface protocols between each network element. It can reproduce the network behaviors in the real world and provide a real scenario for testing. The platform has the ability to generate a large amount of signaling data streams in a short time and can simulate extreme situations such as network attacks, equipment failures, or threat traffic.
[0066] 5) Free5GC Platform
[0067] Free5GC is an open-source software for the 5G core network based on 3GPP standards, and it supports 5G SA and NSA. Free5GC provides a series of core network nodes such as AMF, SMF, UPF, UDM, etc., realizing various functions of the control plane and user plane of the 5G core network. At the same time, the provided Web GUI can be used to manage and monitor the network.
[0068] 6) hyperledger Fabric Consortium Chain
[0069] Hyperledger Fabric is an open-source blockchain platform designed for enterprise-level applications. It provides a flexible and scalable architecture that allows organizations to build and run permissioned blockchain networks. Relying on its unique distributed ledger technology DLT, it ensures the integrity and consistency of data. When building a modular blockchain system, Hyperledger Fabric can bring enterprise-level security guarantees and high-performance operations.
[0070] The advantages of the security protection system architecture for the 5G core network control plane data are summarized as follows:
[0071] 1) System platform performance improvement: This system is based on the SpringBoot and Vue.js frameworks, both of which have the characteristics of openness and stability, accelerating the development and expansion of the system. It has the advantages of simple and convenient maintenance and upgrade, low cost, data security, and real-time synchronization.
[0072] 2) Using the Vue.js framework and the Element UI component library: It improves the compatibility of the WEB side and the friendliness of the user interface interaction, speeds up the development speed of the front-end page, and ensures the consistency and professionalism of the interface.
[0073] 3) Use the Axios technology framework: Provide a standardized and extensible communication channel protocol, applicable to both browser and Node.js platforms. The Axios library offers a series of advanced features such as request and response interceptors and JSON data processing, thus enhancing the efficiency and stability of front-end and back-end data communication.
[0074] 4) Validity of signaling data: Combine simulation instruments with the 5GC core network to simulate the signaling process in the 5G network, generate near-real signaling data streams, and the generated signaling threat data shows high destructiveness after verification. It can be used to test and verify the correctness and stability of network devices, providing a comprehensive signaling data set for security analysis.
[0075] 5) Use the Hyperledger Fabric consortium blockchain technology: Ensure data privacy and security, achieve distributed storage of data and execution of smart contracts, and provide a mechanism for data privacy protection through the concepts of channels and private data sets, ensuring that only authorized participants can access specific data.
[0076] 6) Diversified database design: Adopt MySQL database, Redis cache, and blockchain database to achieve the storage and management of different types of data. MySQL is responsible for storing fixed and large amounts of data, Redis is used to store frequently used data and user authentication information, and blockchain technology ensures the immutability and security of important data.
[0077] The functions of the security protection system for 5G core network control plane data are generally described as follows:
[0078] Such as Figure 1As shown in the figure, the security protection system for 5G core network control plane data includes: a signaling flow simulation generation and verification module, an identity authentication and access control module, a data encryption and decryption module, a threat flow detection and analysis module, and a data visualization module. Among them, the signaling flow simulation generation and verification module is used to simulate and generate 5G signaling flow data close to the real situation, including a normal signaling flow simulation generation module, a threat signaling flow simulation generation module, and a data flow capture and analysis module; the identity authentication and access control module is used to authenticate and authorize access users, including an identity registration module, an identity authentication module, and an access control permission module; the data encryption and decryption module is used to encrypt and decrypt data without exposing the original signaling data, including a data encryption module, a data decryption module, and a data upload and download module; the threat flow detection and analysis module is used to detect the types of threats and analyze the behavior characteristics of the signaling data flow, including a data preprocessing module, a threat flow detection module, and a graph characterization module; the data visualization module is used to present complex signaling data flows and network element status information to users in a graphical manner, including a real-time display module for signaling flow data information, a real-time display module for network element information, a real-time display module for the attack process, and a network element monitoring module.
[0079] 1. Signaling flow simulation generation and verification module
[0080] 1) Normal signaling flow simulation generation module: It can either simulate and generate data in a 5G environment by configuring corresponding network elements and signaling loads using an XPRO instrument according to the real environment; or simulate the core network by building a Free5GC platform, build a UERANSIM to simulate network terminals and base stations, and make the three interconnected through certain configurations to simulate the interactions between UEs, gNBs, and core network elements, so as to realize various signaling processes in the simulated 5G network and generate normal signaling flow data.
[0081] 2) Threat signaling flow simulation generation module: Generate threat signaling flow data through three methods: constructing a signaling storm service model and traffic trigger using an XPRO instrument, simulating DDoS attack behaviors on the core network by external attackers based on Free5GC and Kali attack systems, and taking advantage of the permission vulnerabilities between internal interfaces of 5G communications based on the openapi of the Free5GC environment.
[0082] 3) Data flow capture and analysis module: Real-time capture and analyze signaling data flows, such as protocol types, packet contents, and timestamps.
[0083] 2. Identity authentication and access control module
[0084] 1) Identity registration module: Allow users to submit identity information for registration, and encrypt user data during registration and store it in the blockchain to prevent information leakage;
[0085] 2) Authentication module: Based on zero-knowledge proof algorithm to verify the user's identity, ensuring that only verified users can access system resources while protecting the user's privacy information from being leaked;
[0086] 3) Access control permission module: Assign identity tokens to users based on the results of authentication, and verify the user's permissions according to the tokens, ensuring that only authorized users can perform corresponding operations.
[0087] 3. Data encryption and decryption module;
[0088] 1) Data encryption module: Without exposing the content of the original data, encrypt the key information uploaded by users based on the Paillier homomorphic encryption privacy algorithm, and support users to select specific data attributes for encryption to meet the privacy protection needs of different users and different scenarios of the signaling network;
[0089] 2) Data decryption module: Based on user authorization verification, restore the ciphertext data to the original plaintext. If the user password is incorrect, the user will be blocked from performing subsequent file upload and decryption operations;
[0090] 3) Data upload and download module: Support users to upload plaintext data and encrypt it, or upload encrypted data for decryption. At the same time, it also supports users to download and access the original signaling data or backup and store encrypted data.
[0091] 4. Threat flow detection and analysis module
[0092] 1) Data preprocessing module: Used to clean the signaling data, including handling missing values, infinite values, duplicate data, performing dataset balancing processing, compressing the data through dimensionality reduction technology, and removing constant features, etc.;
[0093] 2) Threat flow detection module: Analyze and detect the uploaded signaling data stream based on multiple algorithm models trained by the real signaling threat dataset, and visually display the types of threat flows contained in the signaling flow in a visual form;
[0094] 3) Atlas characterization module: Based on the correlation analysis between threat methods and statistical features, reflect the correlation between threats and features through a weight system, construct a behavioral feature atlas for analyzing the correlation between complex data and threats; construct a traceability atlas based on the time node information of each stage of the threat for tracing the source of the threat and locating the attacker;
[0095] 5. Data visualization module
[0096] 1) Real-time Signaling Flow Data Information Display Module: It shows the captured signaling flow data and the data flow in the network in real time, including the sender, receiver of data packets, and protocol types, etc.;
[0097] 2) Network Element Information Real-time Display Module: It displays the detailed log information of network elements in real time and supports switching network elements for viewing; users can view the operation records of network elements through this module, switch to view the logs of different network elements to locate problems;
[0098] 3) Attack Process Real-time Display Module: It monitors the progress of attack activities in real time. It can simulate various network attack scenarios by executing attacks and display the real-time attack progress and automatically download the data stream files captured during the attack to the local;
[0099] 4) Network Element Monitoring Module: It shows the current status of all network elements in the core network. When an attack is executed, the network element monitoring module will update the status of the attacked network elements in real time and display the impact of the attack.
[0100] The systems, devices, modules or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions.
[0101] It should also be noted that the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitations, the element defined by the statement "including one..." does not exclude the existence of other identical elements in the process, method, commodity or device including the said element.
[0102] These above embodiments should be understood as only for illustrating the present invention and not for limiting the protection scope of the present invention. After reading the content recorded in the present invention, those skilled in the art can make various changes or modifications to the present invention, and these equivalent changes and modifications also fall within the scope defined by the claims of the present invention.
Claims
1. A security protection system for 5G core network control plane data, characterized in that: It includes a signaling flow simulation generation and verification module, an identity authentication and access control module, a data encryption and decryption module, a threat flow detection and analysis module and a data visualization module. The signaling flow simulation generation and verification module is used to simulate and generate normal 5G signaling flow data, signaling threat flow data and data flow capture and analysis that are close to the real thing; the identity authentication and access control module is used to verify the user's identity to ensure that only users who have been strictly verified and authorized can access specific resources of this system, including identity registration, identity authentication, and access control; the data encryption and decryption module is used for data protection to ensure that sensitive information of the signaling data uploaded by the user is not transmitted and stored The threat flow detection and analysis module is used to realize the detection and analysis of signaling data, including data preprocessing, threat flow detection, behavior characteristics and traceability map characterization; the data visualization module is used to visualize key data information, including real-time display of signaling flow data information, real-time display of network element information, real-time display of attack progress, and real-time signaling data packets and signaling data information acquisition after the attack is completed; wherein, the interface interaction between the signaling flow simulation generation and verification module and the threat flow detection and analysis module adopts the json data format to transmit the signaling characteristics and threat rules to support the real-time analysis requirements of the threat detection and analysis module.
2. A security protection system for 5G core network control plane data according to claim 1, characterized in that: The signaling flow simulation generation and verification module integrates the 5G core network signaling storm simulation test platform, the open source software Free5GC platform, the UERANSIM simulator and the Kali attack system, and constructs a complete signaling data set by generating normal signaling data and combining it with threat signaling data.
3. A security protection system for 5G core network control plane data according to claim 1 or 2, characterized in that: The signaling flow simulation generation and verification module includes a normal signaling flow simulation generation module, a threat signaling flow simulation generation module and a data flow capture and analysis module; wherein, The normal signaling flow simulation generation module is used to realize the simulation generation and testing of normal signaling flow. It uses XPRO instrument simulation and builds Free5GC platform to simulate and generate real and reliable 5G signaling flow data, including access process, authentication process, authorization process, and connection establishment process, to generate signaling flow data that complies with 3GPP 5G standards. The threat signaling flow simulation generation module is used to obtain threat signaling flow data. It can simulate various business combination processes by configuring XPRO instrument parameters to realize threat signaling behavior and collect data; it can also use the Kali platform to simulate external attackers to launch attacks on the core network to generate threat signaling flows; it can also be based on the openapi provided by the Free5GC environment, through in-depth research on the communication mechanism of each network element of the communication signaling network and analysis of the network element communication interface, and use the permission loopholes between the internal interfaces of 5G communication to deduce potential logical threat causes, thereby discovering control plane loopholes to generate threat signaling flows; The data flow capture and analysis module is used to capture and download signaling data packets between users, base stations and core networks in real time and analyze network traffic.
4. A security protection system for 5G core network control plane data according to claim 1, characterized in that: The identity authentication and access control module includes an identity registration module, an identity authentication module, and an access control authority module, wherein: The identity registration module is used to implement information management of user registration; it allows users to submit identity information for registration, encrypts the data during registration, and converts the identity information provided by the user into a format suitable for storage on the Hyperledger Fabric consortium chain, and stores it on the chain through smart contracts to prevent information leakage; The identity authentication module verifies the user's identity information and determines its legitimacy. The user identity authentication mechanism based on the zero-knowledge proof algorithm is used to ensure that only verified users can access system resources, while protecting the user's privacy information from being leaked; The access control permission module implements fine-grained access control on system resources based on the user's identity information and the permissions obtained during identity authentication, ensuring that only users who have passed identity authentication and are granted corresponding permissions can access specific resources; based on the results of identity authentication, it determines whether the user has permission to access specific resources.
5. A security protection system for 5G core network control plane data according to claim 1, characterized in that: The data encryption and decryption module implements encryption and decryption operations on signaling data based on the data privacy protection model of the Paillier algorithm, and includes a data encryption module, a data decryption module, and a data upload and download module. The encryption module is used to protect the privacy of signaling data. The data encryption operation is implemented through the Paillier algorithm. The Paillier algorithm is a public key encryption algorithm based on homomorphic encryption and has additive homomorphism. The encrypted data can be added without decryption, thereby supporting privacy-protected computing operations. Without exposing the original data content, the signaling data uploaded by the user is encrypted, and the ciphertext data is uploaded to the blockchain network and stored in the chain code. The decryption module is used to restore the encrypted signaling data and ensure that only authorized users can access it. The decryption function is implemented based on the Paillier algorithm to ensure that the signaling data can be correctly restored during the download and decryption process; The data upload and download module supports secure signaling data upload and download operations, and can automatically encrypt plaintext signaling data uploaded by authenticated users.
6. A security protection system for 5G core network control plane data according to claim 1, characterized in that: The threat flow detection and analysis module includes a data preprocessing module, a threat flow detection module, and a graph characterization module. The data preprocessing module is used to clean the signaling data and compress the data through dimensionality reduction technology; The threat flow detection module analyzes and detects the uploaded signaling data flow according to the algorithm model trained by the real signaling threat flow data; The model training process includes parameter initialization, iterative optimization and model evaluation; the goal of model training is to minimize the loss function; The graph characterization module is used to characterize the strength of association between threat methods and features, detect threat types and analyze behavioral features of signaling data flows, and present complex data and threat associations in a visual manner.
7. A security protection system for 5G core network control plane data according to claim 1, characterized in that: The data visualization module includes a signaling flow data information real-time display module, a network element information real-time display module, an attack process real-time display module, and a network element monitoring module, wherein: The signaling flow data information real-time display module is used to display the captured signaling flow data information in real time, helping users to quickly identify network communication modes and timely discover signaling network threats; The network element information real-time display module is used to display the basic information of the network element, including IP address, port, connection status and performance indicators, and provide detailed log information; The attack process real-time display module is used to monitor the progress of the attack activity in real time, using a progress bar to display each stage of the attack, and automatically capture the signaling threat flow data packets generated during the attack after the attack is completed; The network element monitoring module is used to monitor the IP addresses and status of all key network elements in the core network in real time, and respond to abnormal status of network elements in real time.
8. A security protection system for 5G core network control plane data according to claim 1, characterized in that: The system architecture adopts the B / S (Browser / Server) architecture design with front-end and back-end separation. The front-end development uses the Vue.js framework, and the back-end development uses the SpringBoot framework. System users directly access the system through the browser, while the back-end server is responsible for providing the necessary interface and algorithm services for the front-end. The database is the data storage layer, and its interface is not directly open to the outside world.
Citation Information
Patent Citations
A network data information security protection method based on blockchain technology
CN118013560B
Mobile network honeypot system for 5G independent networking
CN113114692A
5G signaling storm vulnerability analysis method based on Petri network
CN116866921A