Mobile communication network security monitoring method and device under non-cooperative condition
By introducing non-cooperating security monitoring methods and devices in mobile communication networks, including attachment process reset and air interface signal security monitoring, security risks and hidden dangers are solved for key industries, and efficient monitoring and alarming of the operational security of mobile communication networks is achieved. It is suitable for a variety of mobile communication systems and scenarios.
Patent Information
- Application Number
- CN202510676891.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-05-26
AI Technical Summary
When existing mobile communication networks are used in key industries, they rely on security configuration management with high level of administrators, which poses great security risks and hidden dangers. Traditional technologies require cooperation from multiple parties, and there are restrictions on use, making it difficult to achieve effective security monitoring in non-cooperation situations.
It provides a mobile communication network security monitoring method and device under non-cooperation conditions, including an attachment process reset method and an air interface signal security monitoring method. By adsorbing surrounding UE access, obtaining IMSI information, re-initiating the network access attachment process, and receiving wireless signals from the air interface, analyzing physical layer resources, analyzing packets and interaction processes, identifying whether the security enhancement mechanism is in effect, and alerting is issued if it is not effective as required.
It realizes the security control strategy of identifying the mobile communication network by collecting air-interface wireless signals without the cooperation of operator room and user data center administrators, and meets the high security needs of key industry applications. It is suitable for 3G, 4G, 5G cellular mobile communication systems and satellite Internet dedicated line scenarios.
Smart Images

Figure CN120224192A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and in particular, to a method and device for mobile communication network security monitoring in a non-cooperative scenario. Background Art
[0002] Since the cellular mobile communication system is the largest public infrastructure on land, there are currently three mainstream application modes for the mobile communication system in industrial applications, namely dedicated line mode, private network mode, and dedicated slice mode, as Figure 1a 、 Figure 1b shown.
[0003] Regardless of which application mode, the overall system security mechanism includes the mandatory and optional items of the 3GPP (3rd Generation Partnership Project) native security mechanism, the security enhancement mechanism of the dedicated network slice / secure private network, and the security enhancement mechanism of the industrial data network.
[0004] Analyzing from the overall security of the system, in addition to relying on design security and implementation security, it is also necessary to ensure operational security. It can be considered that for the mobile communication system for critical industrial applications, its design security and implementation security have been solidified in the technical state when the system is launched. Therefore, the overall security of the system mainly depends on operational security, which involves whether the mandatory and optional items of the 3GPP security mechanism, the security enhancement mechanism of the network slice / private network, and the security enhancement mechanism of the industrial data network are enabled as required.
[0005] The configuration management of these security mechanisms depends on the level of the administrator himself. When facing critical industrial applications, this kind of security mainly relies on the uncertainty and difference of the administrator's own level, and there are relatively large security risks and potential hazards. The traditional technical approach requires obtaining the mirror traffic of signaling and data through mirroring in the operator's computer room and the user data center computer room, which requires the cooperation of multiple parties and has limitations in use.
[0006] Therefore, there is an urgent need for a method and device for mobile communication network security monitoring in a non-cooperative scenario to provide security detection and continuous monitoring capabilities for the operation security of the mobile communication system for critical industrial applications, including mainstream application modes such as dedicated line mode, private network mode, and dedicated slice mode. Summary of the Invention
[0007] In view of the above problems, the present invention provides a method and device for mobile communication network security monitoring in a non-cooperative scenario.
[0008] The method for mobile communication network security monitoring in a non-cooperative scenario provided by the present invention includes an attachment process reset method and an air interface signal security monitoring method; The method for resetting the attachment process includes: adsorbing the access of surrounding UEs, obtaining the IMSI information of surrounding UEs, and triggering each UE to re-initiate the network access attachment process when releasing the UE; The method for monitoring the security of air interface signals includes: Receiving the downlink radio signal and uplink radio signal of surrounding UEs from the air interface, and parsing the downlink radio signal and uplink radio signal based on the IMSI information of the UE to obtain physical layer resources; Parsing the physical layer resources to obtain the message and interaction process; Analyzing the message and interaction process to identify whether the security enhancement mechanism takes effect. If a security enhancement mechanism that fails to take effect as required is detected, an alarm is issued.
[0009] In some embodiments, parsing the downlink radio signal and uplink radio signal based on the IMSI information of the UE to obtain physical layer resources includes: Segmenting according to the IMSI information of the UE, parsing the downlink radio signal and uplink radio signal, and obtaining the broadcast control channel message and common control channel message; Parsing the broadcast control channel message and common control channel message to obtain the physical layer resources.
[0010] In some embodiments, it is necessary to determine whether the IMSI information of the UE can be obtained: If it is found that the IMSI information of the UE cannot be obtained, the method for resetting the attachment process is triggered, so that the UE re-initiates the network access attachment process from the initial attachment; If the IMSI information of the UE can be obtained, proceed.
[0011] In some embodiments, it is necessary to judge the obtained physical layer resources: If it is found that the obtained physical layer resources are incomplete and insufficient for parsing, the method for resetting the attachment process is triggered, so that the UE re-initiates the network access attachment process from the initial attachment; If the obtained physical layer resources are complete, proceed.
[0012] In some embodiments, parsing the physical layer resources to obtain the message and interaction process includes: Parsing the physical layer resources to obtain the dedicated control channel message and dedicated service channel message; Through the dedicated control channel message, parsing out the L3 layer RRC signaling message interaction process and the high layer NAS signaling message interaction process; Through the dedicated service channel message, parsing out the air interface user plane data message and the high layer IP data message.
[0013] In some embodiments, analyzing the message and interaction process to identify whether the security enhancement mechanism is effective includes: Analyze the L3 layer RRC signaling messages and interaction processes, air interface user plane data messages, and high-layer NAS signaling messages and interaction processes of each UE to identify whether the 3GPP security mechanism is effective and whether the security enhancement mechanism of the network slice and / or private network is effective.
[0014] In some embodiments, analyzing the message and interaction process to identify whether the security enhancement mechanism is effective includes: Analyze the high-layer IP data messages of each UE to identify whether the security enhancement mechanism of the user data network is effective.
[0015] In some embodiments, when performing the air interface signal security monitoring method, initially, trigger the attachment process reset method to cause the current surrounding UEs to re-initiate the network access attachment process.
[0016] In a second aspect, the present invention provides a mobile communication network security monitoring device in a non-cooperative situation, including: A mobile base station unit for attracting surrounding UEs to access, obtaining the IMSI information of the surrounding UEs, and triggering each UE to re-initiate the network access attachment process when releasing the UE; A radio frequency receiving unit for receiving the downlink radio signals and uplink radio signals of the surrounding UEs from the air interface, and parsing the downlink radio signals and uplink radio signals based on the IMSI information of the UE to obtain physical layer resources; A protocol parsing unit for parsing the physical layer resources to obtain messages and interaction processes; A security analysis unit for analyzing the messages and interaction processes to identify whether the security enhancement mechanism is effective, and if a security enhancement mechanism that fails to take effect as required is detected, an alarm is issued.
[0017] In some embodiments, the device is applied to 5G mobile communication networks, 4G mobile communication networks, 3G mobile communication networks, and / or satellite Internet dedicated lines.
[0018] In summary, due to the adoption of the above technical solutions, the beneficial effects of the present invention are: 1. The present invention can identify information such as control strategies of the 3GPP security mechanism, network slice / security private network security enhancement mechanism, user data network security enhancement mechanism, etc. by collecting air interface radio signals without the cooperation of the operator's computer room and the user data center administrator, so as to realize the monitoring ability of the operation security of the mobile communication network for key industry applications and meet the high security requirements of key industry applications.
[0019] 2. The present invention can be applied to 3G, 4G, 5G cellular mobile communication systems and satellite Internet dedicated line scenarios. Description of the Drawings
[0020] Figure 1a It is a schematic diagram of the application scenario of the mobile communication system for the dedicated line mode.
[0021] Figure 1b It is a schematic diagram of the application scenario of the mobile communication system for the private network mode / dedicated slice mode.
[0022] Figure 2 It is a flowchart of the attachment process reset method in a mobile communication network security monitoring method provided in an embodiment of the present invention under non - cooperative circumstances.
[0023] Figure 3 It is a flowchart of the air interface signal security monitoring method in a mobile communication network security monitoring method provided in an embodiment of the present invention under non - cooperative circumstances.
[0024] Figure 4 It is a schematic diagram of an air interface signal security monitoring device and its application in a mobile communication network security monitoring method provided in an embodiment of the present invention under non - cooperative circumstances.
[0025] Figure 5 It is a schematic diagram of the application of a mobile communication network security monitoring device provided in an embodiment of the present invention in a 5G mobile communication network.
[0026] Figure 6 It is a schematic diagram of the application of a mobile communication network security monitoring device provided in an embodiment of the present invention in a 4G mobile communication network.
[0027] Figure 7 It is a schematic diagram of the application of a mobile communication network security monitoring device provided in an embodiment of the present invention in a 3G mobile communication network.
[0028] Figure 8 It is a schematic diagram of the application of a mobile communication network security monitoring device provided in an embodiment of the present invention in a satellite Internet dedicated line.
[0029] Definitions in the drawings: AAA (Authentication, Authorization, and Accounting); LNS (LonWorks Network Service); VPN (Virtual Private Network); UDM (Unified Data Management); PGW (PDN GateWay); PDN (Public Data Network); UPF (User Plane Function); GGSN (Gateway GPRS Supporting Node); GPRS (General Packet Radio Service). Detailed implementation manners
[0030] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. The components of the embodiments of the present invention described and illustrated herein generally may be arranged and designed in a variety of different configurations.
[0031] Therefore, the detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0032] An embodiment of the present invention provides a method for monitoring the security of a mobile communication network in a non-cooperative situation, including an attachment process reset method and an air interface signal security monitoring method.
[0033] As Figure 2 shown, the attachment process reset method includes the following steps: S101. The device starts and attracts the surrounding UEs (User Equipment) to access. Among them, the device interferes with and shields the signals of normal surrounding base stations by transmitting high-power signals, forcing all or specified surrounding UEs to interrupt the communication with normal base stations; S102. After attracting and accessing all or specified surrounding UEs, obtain the IMSI information (International Mobile Subscriber Identity) of the surrounding UEs; S103. In the AKA (Authentication and Key Agreement) process of the surrounding UEs for network access authentication, trigger each UE to re-initiate the network access attachment process when releasing the UE.
[0034] As shown in Figure 3 , the air interface signal security monitoring method includes the following steps: S201. Initially, trigger the attachment process reset method to cause the current surrounding UEs to re-initiate the network access attachment process; S202. Receive the downlink radio signal and uplink radio signal of the surrounding UEs from the air interface, and parse the downlink radio signal and uplink radio signal based on the IMSI information of the UEs to obtain physical layer resources; specifically: S202-1. Segment according to the IMSI information of the UEs, parse the downlink radio signal and uplink radio signal, and obtain the broadcast control channel message and the common control channel message; among them, it is necessary to determine whether the IMSI information of the UEs can be obtained: If it is found that the IMSI information of the UEs cannot be obtained, trigger the attachment process reset method to cause the UE to re-initiate the network access attachment process from the initial attachment; If the IMSI information of the UEs can be obtained, continue; S202-2. Parse the broadcast control channel message and the common control channel message to obtain the physical layer resources, including physical layer resources such as time and frequency. Among them, it is necessary to judge the obtained physical layer resources: If it is found that the obtained physical layer resources are incomplete and insufficient for parsing, trigger the attachment process reset method to cause the UE to re-initiate the network access attachment process from the initial attachment; If the obtained physical layer resources are complete, continue; S203. Parse the physical layer resources to obtain the message and the interaction process; specifically: S203-1. Parse the physical layer resources to obtain the dedicated control channel message and the dedicated service channel message: S203-2. Through the dedicated control channel message, parse the L3 layer RRC (Radio Resource Control) signaling message interaction process and the high-layer NAS (Non Access Stratum) signaling message interaction process; S203-3. Through the dedicated service channel message, parse the air interface user plane data message and the high-layer IP (Internet Protocol) data message.
[0035] S204. Analyze the message and the interaction process to identify whether the security enhancement mechanism takes effect. If a security enhancement mechanism that does not take effect as required is detected, an alarm is generated. Specifically: S204-1. Analyze the L3 layer RRC signaling messages and interaction processes, air interface user plane data messages, and high-layer NAS signaling messages and interaction processes of each UE, identify whether the 3GPP security mechanism is effective, and whether the security enhancement mechanism for network slices and / or private networks is effective; S204-2. Analyze the high-layer IP data messages of each UE to identify whether the security enhancement mechanism for the user data network is effective; S204-3. If a security enhancement mechanism that fails to take effect as required is detected, or there is an attack threat, issue an alarm (to the security management system).
[0036] The embodiment of the present invention also discloses a mobile communication network security monitoring device in a non-cooperative scenario to support the above-mentioned mobile communication network security monitoring method in a non-cooperative scenario. This device is deployed in a place where mobile communication radio signals can be received, such as Figure 4 As shown, the device includes: A mobile base station unit for attracting surrounding UEs to access, obtaining the IMSI information of surrounding UEs, and triggering each UE to re-initiate the network access attachment process when releasing the UE; A radio frequency receiving unit for receiving the downlink radio signals and uplink radio signals of surrounding UEs from the air interface, and parsing the downlink radio signals and uplink radio signals based on the IMSI information of the UE to obtain physical layer resources; A protocol parsing unit for parsing the physical layer resources to obtain messages and interaction processes; A security analysis unit for analyzing the messages and interaction processes, identifying whether the security enhancement mechanism is effective, and issuing an alarm if a security enhancement mechanism that fails to take effect as required is detected.
[0037] The working principles of the above units in the device can refer to the descriptions in the method of the foregoing embodiments and will not be elaborated here.
[0038] The following are some embodiments of the above-mentioned mobile communication network security monitoring method and device in a non-cooperative scenario.
[0039] Embodiment 1 In the case of a 5G mobile communication network, applying the above-mentioned mobile communication network security monitoring method and device in a non-cooperative scenario, the relevant functional entities include: 5G terminals, 5G base stations, 5G networks, security enhancement devices, and security monitoring devices, such as Figure 5 As shown.
[0040] The mobile communication network security monitoring in the non-cooperative scenario includes the following steps: S1. First, trigger the attachment process reset method to cause all current surrounding UEs to re-initiate the network access attachment process; S2. Receive the downlink radio signals and uplink radio signals of all surrounding UEs.
[0041] S3. Split according to the IMSI information of the UE, analyze the downlink radio signal and the uplink radio signal, and obtain the broadcast control channel message and the common control channel message.
[0042] S4. According to the signal analysis of the cell search and random access process for the broadcast control channel message and the common control channel message, obtain the physical layer resources, including physical layer resources such as time, frequency, and space.
[0043] S5. Continue to analyze the physical layer resources to obtain the dedicated control channel message and the dedicated service channel message.
[0044] S6. Through the dedicated control channel message, analyze the L3 layer RRC signaling message interaction process and the high-layer NAS signaling message interaction process.
[0045] S7. Through the dedicated service channel message, analyze the radio interface user plane data message and the high-layer IP data message.
[0046] S8. Analyze the L3 layer RRC signaling messages and interaction processes, radio interface user plane data messages, and high-layer NAS signaling messages and interaction processes of each UE to identify whether the 3GPP security mechanism is effective and whether the security enhancement mechanism of the network slice and / or private network is effective; S9. Analyze the high-layer IP data messages of each UE to identify whether the security enhancement mechanism of the user data network is effective.
[0047] S10. If a security enhancement mechanism that fails to take effect as required is detected, or there is an attack threat, an alarm is sent to the security management system.
[0048] Embodiment 2 In the case of a 4G mobile communication network, applying the above-mentioned mobile communication network security monitoring method and device in a non-cooperative situation, the relevant functional entities include: 4G terminals, 4G base stations, 4G networks, security enhancement devices, and security monitoring devices, as Figure 6 shown.
[0049] The specific steps include: The mobile communication network security monitoring in the non-cooperative situation includes the following steps: S1. First trigger the attachment process reset method to cause all current surrounding UEs to re-initiate the network attachment process; S2. Receive the downlink radio signals and uplink radio signals of all surrounding UEs.
[0050] S3. Split according to the IMSI information of the UE, analyze the downlink radio signal and the uplink radio signal, and obtain the broadcast control channel message and the common control channel message.
[0051] S4. Parse the broadcast control channel messages and common control channel messages according to the signal analysis of the cell search and random access procedures to obtain physical layer resources, including physical layer resources such as time, frequency, and space.
[0052] S5. Continue to parse the physical layer resources to obtain dedicated control channel messages and dedicated service channel messages.
[0053] S6. Through the dedicated control channel messages, parse the L3 layer RRC signaling message interaction process and the high layer NAS signaling message interaction process.
[0054] S7. Through the dedicated service channel messages, parse the radio interface user plane data messages and the high layer IP data messages.
[0055] S8. Analyze the L3 layer RRC signaling messages and interaction processes, radio interface user plane data messages, and high layer NAS signaling messages and interaction processes of each UE to identify whether the 3GPP security mechanism is effective and whether the security enhancement mechanism of the network slice and / or private network is effective; S9. Analyze the high layer IP data messages of each UE to identify whether the security enhancement mechanism of the user data network is effective.
[0056] S10. If a security enhancement mechanism that fails to take effect as required is detected, or there is an attack threat, an alarm is sent to the security management system.
[0057] Embodiment 3 In the case of a 3G mobile communication network, applying the above-mentioned mobile communication network security monitoring method and device in a non-cooperative situation, the relevant functional entities include: 3G terminals, 3G base stations, 3G networks, security enhancement devices, and security monitoring devices, as Figure 7 shown.
[0058] The mobile communication network security monitoring in the non-cooperative situation includes the following steps: S1. First, trigger the attachment process reset method to cause all current surrounding UEs to re-initiate the network attachment process; S2. Receive the downlink radio signals and uplink radio signals of all surrounding UEs.
[0059] S3. Segment according to the IMSI information of the UE, parse the downlink radio signals and uplink radio signals, and obtain broadcast control channel messages and common control channel messages.
[0060] S4. Parse the broadcast control channel messages and common control channel messages according to the signal analysis of the cell search and random access procedures to obtain physical layer resources, including physical layer resources such as time, frequency, and space.
[0061] S5. Continue to parse the physical layer resources to obtain dedicated control channel messages and dedicated service channel messages.
[0062] S6. Parse the L3 layer RRC signaling message interaction process and the high-layer NAS signaling message interaction process through the dedicated control channel message.
[0063] S7. Parse the radio interface user plane data message and the high-layer IP data message through the dedicated service channel message.
[0064] S8. Analyze the L3 layer RRC signaling messages and interaction processes, radio interface user plane data messages, and high-layer NAS signaling messages and interaction processes of each UE, and identify whether the 3GPP security mechanism is effective and whether the security enhancement mechanism of the network slice and / or private network is effective. S9. Analyze the high-layer IP data messages of each UE and identify whether the security enhancement mechanism of the user data network is effective.
[0065] S10. If a security enhancement mechanism that fails to take effect as required is detected, or there is an attack threat, an alarm is sent to the security management system.
[0066] Embodiment 4 In the case of a satellite Internet dedicated line, the above-mentioned security monitoring method and device for a mobile communication network in a non-cooperative situation are applied. The relevant functional entities include: a satellite Internet terminal, a satellite, a gateway station, a 5G core network, a security enhancement device, and a security monitoring device, as Figure 8 shown.
[0067] The security monitoring of the mobile communication network in the non-cooperative situation includes the following steps: S1. First, trigger the attachment process reset method to make all current surrounding UEs re-initiate the network access attachment process. S2. Receive the downlink radio signals and uplink radio signals of all surrounding UEs.
[0068] S3. Segment according to the IMSI information of the UE, and parse the downlink radio signal and the uplink radio signal to obtain the broadcast control channel message and the common control channel message.
[0069] S4. According to the signal parsing of the broadcast control channel message and the common control channel message in the cell search and random access process, obtain the physical layer resources, including physical layer resources such as time, frequency, and space.
[0070] S5. Continue to parse the physical layer resources to obtain the dedicated control channel message and the dedicated service channel message.
[0071] S6. Parse the L3 layer RRC signaling message interaction process and the high-layer NAS signaling message interaction process through the dedicated control channel message.
[0072] S7. Parse the radio interface user plane data packet and the high-layer IP data packet through the dedicated service channel message.
[0073] S8. Analyze the L3 layer RRC signaling packets and interaction processes, radio interface user plane data packets, and high-layer NAS signaling packets and interaction processes of each UE to identify whether the 3GPP security mechanism is effective and whether the security enhancement mechanism of the network slice and / or private network is effective. S9. Analyze the high-layer IP data packets of each UE to identify whether the security enhancement mechanism of the user data network is effective.
[0074] S10. If a security enhancement mechanism that fails to take effect as required is detected, or there is an attack threat, an alarm is sent to the security management system.
[0075] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for security monitoring of a mobile communication network in a non - cooperative situation, characterized in that It includes an attachment process reset method and an air interface signal security monitoring method; The attachment process reset method includes: attracting surrounding UEs to access, obtaining the IMSI information of the surrounding UEs, and triggering each UE to re-initiate the network access attachment process when releasing the UE; The air interface signal security monitoring method includes: Receiving the downlink radio signal and uplink radio signal of the surrounding UEs from the air interface, and parsing the downlink radio signal and uplink radio signal based on the IMSI information of the UE to obtain the physical layer resources; Parsing the physical layer resources to obtain the message and the interaction process; Analyzing the message and the interaction process to identify whether the security enhancement mechanism takes effect. If a security enhancement mechanism that fails to take effect as required is detected, an alarm is issued.
2. The method for monitoring the security of a mobile communication network in a non-cooperative situation according to claim 1, wherein The parsing of the downlink radio signal and uplink radio signal based on the IMSI information of the UE to obtain the physical layer resources includes: Segmenting according to the IMSI information of the UE, parsing the downlink radio signal and uplink radio signal, and obtaining the broadcast control channel message and the common control channel message; Parsing the broadcast control channel message and the common control channel message to obtain the physical layer resources.
3. The method for monitoring the security of a mobile communication network in a non - cooperative scenario according to claim 2, wherein It is necessary to determine whether the IMSI information of the UE can be obtained: If it is found that the IMSI information of the UE cannot be obtained, the attachment process reset method is triggered, so that the UE re-initiates the network access attachment process from the initial attachment; If the IMSI information of the UE can be obtained, continue.
4. The method for monitoring the security of a mobile communication network in a non - cooperative situation according to claim 2, wherein It is necessary to judge the obtained physical layer resources: If it is found that the obtained physical layer resources are incomplete and insufficient for parsing, the attachment process reset method is triggered, so that the UE re-initiates the network access attachment process from the initial attachment; If the obtained physical layer resources are complete, continue.
5. The method for monitoring the security of a mobile communication network in a non - cooperative situation according to claim 1, wherein, The parsing of the physical layer resources to obtain the message and the interaction process includes: Parsing the physical layer resources to obtain the dedicated control channel message and the dedicated service channel message; Through the dedicated control channel message, parsing out the L3 layer RRC signaling message interaction process and the high layer NAS signaling message interaction process; Through the dedicated service channel message, parsing out the air interface user plane data message and the high layer IP data message.
6. The method for monitoring the security of a mobile communication network in a non-cooperative situation according to claim 5, wherein The analysis of the message and the interaction process to identify whether the security enhancement mechanism takes effect includes: Analyzing the L3 layer RRC signaling message and interaction process, the air interface user plane data message, and the high layer NAS signaling message and interaction process of each UE to identify whether the 3GPP security mechanism takes effect, and whether the security enhancement mechanism of the network slice and / or private network takes effect.
7. The method for monitoring the security of a mobile communication network in a non-cooperative situation according to claim 5, wherein The analysis of the message and the interaction process to identify whether the security enhancement mechanism takes effect includes: Analyzing the high layer IP data message of each UE to identify whether the security enhancement mechanism of the user data network takes effect.
8. The method for monitoring the security of a mobile communication network in a non - cooperative situation according to claim 1, characterized in that, When executing the air interface signal security monitoring method, initially, the attachment process reset method is triggered first, so that the current surrounding UEs re-initiate the network access attachment process.
9. A mobile communication network security monitoring device in a non-cooperative situation, characterized in that, It includes: A mobile base station unit, which is used to attract surrounding UEs to access, obtain the IMSI information of the surrounding UEs, and trigger each UE to re-initiate the network access attachment process when releasing the UE; The radio frequency receiving unit is used to receive the downlink radio signals and uplink radio signals of surrounding UEs from the air interface, and parse the downlink radio signals and uplink radio signals based on the IMSI information of the UEs to obtain physical layer resources; The protocol parsing unit is used to parse the physical layer resources to obtain the messages and interaction processes; The security analysis unit is used to analyze the messages and interaction processes, identify whether the security enhancement mechanism takes effect, and issue an alarm if a security enhancement mechanism that fails to take effect as required is detected.
10. The non-cooperative mobile communication network security monitoring device according to claim 9, characterized in that, The device is applied to 5G mobile communication networks, 4G mobile communication networks, 3G mobile communication networks, and / or satellite Internet dedicated lines.
Citation Information
Patent Citations
Method for interworking between networks in wireless communication system and apparatus therefor
CN109155949A
A method for realizing an IMSI (International Mobile Subscriber Identity) change function in an SIM (Subscriber Identity Module) card
CN109842877A
Method and device for obtaining UE security capabilities
CN111316233A
Wireless telecommunications network
CN116058007A
Scheduling indication method
CN118337841A