A Mobile Communication Network Security Monitoring Method and Device in a Non-Cooperative Situation

By resetting the attachment process and analyzing the air interface signal without the need for the cooperation of the operator's room, the security uncertainty of mobile communication systems in key industry applications is solved, and the security monitoring capabilities of 3G, 4G, 5G and satellite Internet dedicated lines are achieved.

CN120224192BActive Publication Date: 2025-08-05NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510676891.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-08-05
Estimated Expiration
2045-05-26

AI Technical Summary

Technical Problem

In mobile communication systems for key industry applications, the existing technology relies on the level of operators and user data center administrators to configure and manage security mechanisms, which poses security uncertainty and risks. Traditional monitoring methods require cooperation from multiple parties, limiting the security detection and monitoring capabilities in non-cooperation scenarios.

Method used

It provides a non-cooperative mobile communication network security monitoring method, which can absorb surrounding UE access, obtain IMSI information, reset the attachment process, analyze the air interface signal, identify whether the security enhancement mechanism is in effect, and monitor without the need for the cooperation of the operator's room, including the attachment process reset and air interface signal security monitoring.

Benefits of technology

It realizes security enhancement mechanisms for 3GPP, network slice/dedicated network and security monitoring of user data networks, meets the high security needs of key industry applications, and is suitable for 3G, 4G, 5G cellular mobile communication systems and satellite Internet dedicated lines, improving the system operation security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120224192B_ABST
    Figure CN120224192B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of communication technology, and provides a method and device for monitoring mobile communication network security under non-cooperative conditions. The method comprises: attracting surrounding UE access, obtaining the IMSI information of the surrounding UEs, and triggering each UE to re-initiate the network attachment process when releasing the UE; receiving downlink wireless signals and uplink wireless signals from the surrounding UEs from the air interface, and parsing the downlink wireless signals and uplink wireless signals based on the UE's IMSI information to obtain physical layer resources; parsing the physical layer resources to obtain messages and interaction processes; analyzing the messages and interaction processes to identify whether a security enhancement mechanism is effective, and issuing an alarm if a security enhancement mechanism is detected that is not effective as required. The present invention can achieve security enhancement mechanism monitoring capabilities by collecting air interface wireless signals without the need for cooperation from the operator's computer room or the user's data center administrator, thereby meeting the high security requirements of key industry applications.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technology, and in particular to a method and device for monitoring mobile communication network security under non-cooperative conditions. Background Art

[0002] Since the cellular mobile communication system is the largest public infrastructure on land, there are currently three mainstream application modes for mobile communication systems for industry applications, namely dedicated line mode, dedicated network mode and dedicated slice mode, such as Figure 1a 、 Figure 1b shown.

[0003] Regardless of the application mode, the overall system security mechanism includes the mandatory and optional 3GPP (3rd Generation Partnership Project) native security mechanisms, security enhancement mechanisms for dedicated network slices / secure private networks, and security enhancement mechanisms for industry data networks.

[0004] From the perspective of overall system security, in addition to relying on design and implementation security, operational security must also be ensured. It can be argued that the design and implementation security of mobile communication systems for critical industry applications are already solidified in their technical state when the systems are launched. Therefore, overall system security primarily depends on operational security, which involves ensuring that mandatory and optional 3GPP security mechanisms, security enhancement mechanisms for network slicing / private networks, and security enhancement mechanisms for industry data networks are enabled as required.

[0005] The configuration and management of these security mechanisms relies heavily on the administrator's own skills. When applied to critical industries, this security relies primarily on the uncertainty and variability of human skills, posing significant security risks and potential security vulnerabilities. Traditional technical approaches, however, require mirroring signaling and data traffic in both the operator's computer room and the user's data center, requiring collaboration from multiple parties and imposing limitations.

[0006] Therefore, there is an urgent need for a security monitoring method and device for mobile communication networks in non-cooperative situations, which can provide mobile communication systems for key industry applications, including mainstream application modes such as dedicated line mode, private network mode, and dedicated slicing mode, with security detection and continuous monitoring capabilities for their operation security. Summary of the Invention

[0007] In view of the above problems, the present invention provides a method and apparatus for monitoring mobile communication network security under non-cooperative conditions.

[0008] The present invention provides a method for monitoring mobile communication network security in a non-cooperative situation, including an attachment process resetting method and an air interface signal security monitoring method;

[0009] The attachment process resetting method includes: attracting surrounding UEs to access, obtaining IMSI information of surrounding UEs, and triggering each UE to re-initiate the network attachment process when releasing the UE;

[0010] The air interface signal security monitoring method includes:

[0011] Receive downlink and uplink wireless signals from surrounding UEs through the air interface, and parse the downlink and uplink wireless signals based on the UE's IMSI information to obtain physical layer resources;

[0012] Parse physical layer resources to obtain messages and interaction processes;

[0013] Analyze messages and interaction processes to identify whether the security enhancement mechanism is effective. If it is detected that the security enhancement mechanism is not effective as required, an alarm will be issued.

[0014] In some embodiments, the parsing of downlink wireless signals and uplink wireless signals based on the IMSI information of the UE to obtain physical layer resources includes:

[0015] Segment the downlink and uplink wireless signals according to the UE's IMSI information to obtain broadcast control channel messages and common control channel messages;

[0016] Parse broadcast control channel messages and common control channel messages to obtain physical layer resources.

[0017] In some embodiments, it is necessary to determine whether the UE's IMSI information can be obtained:

[0018] If the UE's IMSI information is not obtained, the attach process reset method is triggered, so that the UE re-initiates the network attach process from the initial attach;

[0019] If the UE's IMSI information can be obtained, continue.

[0020] In some embodiments, it is necessary to determine the acquired physical layer resources:

[0021] If it is found that the acquired physical layer resources are incomplete and insufficient for parsing, the attach process reset method is triggered, so that the UE re-initiates the network attach process from the initial attach;

[0022] If the acquired physical layer resources are complete, continue.

[0023] In some embodiments, the parsing of physical layer resources to obtain messages and interaction processes includes:

[0024] Parse the physical layer resources to obtain dedicated control channel messages and dedicated service channel messages;

[0025] Through dedicated control channel messages, the interaction process of L3 layer RRC signaling messages and high-layer NAS signaling message interaction process are analyzed;

[0026] Through the dedicated service channel message, the air interface user plane data message and the high-level IP data message are parsed.

[0027] In some embodiments, analyzing the message and interaction process to identify whether the security enhancement mechanism is effective includes:

[0028] Analyze the L3 layer RRC signaling messages and interaction processes, air interface user plane data messages, and high-level NAS signaling messages and interaction processes of each UE to identify whether the 3GPP security mechanism is effective and whether the security enhancement mechanism of the network slice and / or private network is effective.

[0029] In some embodiments, analyzing the message and interaction process to identify whether the security enhancement mechanism is effective includes:

[0030] Analyze the high-level IP data packets of each UE to identify whether the security enhancement mechanism of the user data network is effective.

[0031] In some embodiments, when executing the air interface signal security monitoring method, initially, an attachment process resetting method is triggered first, so that the current surrounding UEs re-initiate the network attachment process.

[0032] In a second aspect, the present invention provides a mobile communication network security monitoring device in a non-cooperative situation, comprising:

[0033] The mobile base station unit is used to attract surrounding UEs to access, obtain the IMSI information of surrounding UEs, and trigger each UE to re-initiate the network attachment process when releasing the UE;

[0034] The radio frequency receiving unit is used to receive downlink and uplink radio signals from surrounding UEs through the air interface, and parse the downlink and uplink radio signals based on the UE's IMSI information to obtain physical layer resources;

[0035] Protocol parsing unit, used to parse physical layer resources to obtain messages and interaction processes;

[0036] The security analysis unit is used to analyze messages and interaction processes to identify whether the security enhancement mechanism is effective. If it is detected that the security enhancement mechanism is not effective as required, an alarm will be issued.

[0037] In some embodiments, the device is applied to a 5G mobile communication network, a 4G mobile communication network, a 3G mobile communication network and / or a satellite Internet dedicated line.

[0038] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are:

[0039] 1. The present invention can identify control policies such as 3GPP security mechanisms, network slicing / secure private network security enhancement mechanisms, and user data network security enhancement mechanisms by collecting air interface wireless signals without the need for cooperation from operator computer rooms or user data center administrators. This allows for monitoring the operational security of mobile communication networks for key industry applications, meeting the high security requirements of key industry applications.

[0040] 2. The present invention can be applied to 3G, 4G, and 5G cellular mobile communication systems and dedicated line scenarios of satellite Internet. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] Figure 1a Schematic diagram of application scenarios for dedicated line mode in mobile communication systems.

[0042] Figure 1b Schematic diagram of application scenarios for private network mode / dedicated slicing mode in mobile communication systems.

[0043] Figure 2 The present invention provides a flowchart of a method for resetting an attachment process in a method for monitoring mobile communication network security under non-cooperative conditions.

[0044] Figure 3 The present invention provides a flowchart of a method for monitoring air interface signal security in a method for monitoring mobile communication network security under non-cooperative conditions.

[0045] Figure 4 A schematic diagram of an air interface signal security monitoring device and its application in a mobile communication network security monitoring method under non-cooperative conditions provided by an embodiment of the present invention.

[0046] Figure 5 A schematic diagram of an application of a mobile communication network security monitoring device in a 5G mobile communication network under non-cooperative conditions provided by an embodiment of the present invention.

[0047] Figure 6 A schematic diagram of an embodiment of the present invention providing an apparatus for monitoring mobile communication network security in a non-cooperative manner and applying it to a 4G mobile communication network.

[0048] Figure 7 A schematic diagram of an application of a mobile communication network security monitoring device in a 3G mobile communication network under non-cooperative conditions provided by an embodiment of the present invention.

[0049] Figure 8A schematic diagram of an embodiment of the present invention providing an embodiment of a mobile communication network security monitoring device applied to a satellite Internet dedicated line under non-cooperative conditions.

[0050] Definitions in the accompanying drawings:

[0051] AAA (Authentication, Authorization, and Accounting);

[0052] LNS (LonWorks Network Service, network operating system);

[0053] VPN (Virtual Private Network);

[0054] UDM (Unified Data Management);

[0055] PGW (PDN GateWay, PDN Gateway);

[0056] PDN (Public Data Network);

[0057] UPF (User Plane Function);

[0058] GGSN (Gateway GPRS Supporting Node);

[0059] GPRS (General Packet Radio Service). DETAILED DESCRIPTION

[0060] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.

[0061] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention as claimed, but rather merely represents selected embodiments of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort are intended to fall within the scope of protection of the present invention.

[0062] The embodiment of the present invention provides a method for monitoring the security of a mobile communication network in a non-cooperative situation, including an attachment process resetting method and an air interface signal security monitoring method.

[0063] like Figure 2 As shown, the attachment process reset method includes the following steps:

[0064] S101: The device starts up and attracts nearby UEs (User Equipment) to access the device. The device transmits high-power signals to interfere with and shield the signals of normal base stations, forcing all or specified UEs to interrupt communication with normal base stations.

[0065] S102: After all or a specified UE is adsorbed and connected, the IMSI information (International Mobile Subscriber Identity) of the surrounding UE is obtained;

[0066] S103: The surrounding UEs complete the network authentication AKA (Authentication and Key Agreement) process, and when the UE is released, each UE is triggered to re-initiate the network attachment process.

[0067] like Figure 3 As shown, the air interface signal security monitoring method includes the following steps:

[0068] S201. Initially, trigger the attach process reset method so that the surrounding UEs re-initiate the network attach process.

[0069] S202. Receive downlink and uplink wireless signals from surrounding UEs through an air interface, and parse the downlink and uplink wireless signals based on the UE's IMSI information to obtain physical layer resources. Specifically:

[0070] S202-1. Segment the downlink and uplink wireless signals according to the UE's IMSI information, and obtain broadcast control channel messages and common control channel messages. It is necessary to determine whether the UE's IMSI information can be obtained.

[0071] If the UE's IMSI information is not obtained, the attach process reset method is triggered, so that the UE re-initiates the network attach process from the initial attach;

[0072] If the UE's IMSI information can be obtained, continue;

[0073] S202-2, parse the broadcast control channel message and the common control channel message to obtain physical layer resources, including time, frequency and other physical layer resources. It is necessary to judge the obtained physical layer resources:

[0074] If it is found that the acquired physical layer resources are incomplete and insufficient for parsing, the attach process reset method is triggered, so that the UE re-initiates the network attach process from the initial attach;

[0075] If the acquired physical layer resources are complete, continue;

[0076] S203. Analyze physical layer resources to obtain messages and interaction processes; specifically:

[0077] S203-1. Analyze physical layer resources to obtain dedicated control channel messages and dedicated service channel messages:

[0078] S203-2. Analyze the L3 layer RRC (Radio Resource Control) signaling message interaction process and the higher layer NAS (Non Access Stratum) signaling message interaction process through the dedicated control channel message.

[0079] S203-3. Analyze the dedicated service channel message to obtain the air interface user plane data message and the high-level IP (Internet Protocol) data message.

[0080] S204: Analyze the message and interaction process to identify whether the security enhancement mechanism is effective. If the security enhancement mechanism is not effective as required, an alarm is issued. Specifically:

[0081] S204-1. Analyze the L3 RRC signaling messages and interaction processes, air interface user plane data messages, and high-layer NAS signaling messages and interaction processes of each UE to identify whether the 3GPP security mechanism is effective and whether the security enhancement mechanism of the network slice and / or private network is effective;

[0082] S204-2. Analyze the high-layer IP data packets of each UE to identify whether the security enhancement mechanism of the user data network is effective;

[0083] S204-3. If it is detected that the security enhancement mechanism has not taken effect as required, or there is an attack threat, an alarm will be issued (to the security management system).

[0084] The embodiment of the present invention also discloses a mobile communication network security monitoring device under non-cooperative conditions to support the above-mentioned mobile communication network security monitoring method under non-cooperative conditions. The device is deployed in a place where mobile communication wireless signals can be received, such as Figure 4As shown, the device includes:

[0085] The mobile base station unit is used to attract surrounding UEs to access, obtain the IMSI information of surrounding UEs, and trigger each UE to re-initiate the network attachment process when releasing the UE;

[0086] The radio frequency receiving unit is used to receive downlink and uplink radio signals from surrounding UEs through the air interface, and parse the downlink and uplink radio signals based on the UE's IMSI information to obtain physical layer resources;

[0087] Protocol parsing unit, used to parse physical layer resources to obtain messages and interaction processes;

[0088] The security analysis unit is used to analyze messages and interaction processes to identify whether the security enhancement mechanism is effective. If it is detected that the security enhancement mechanism is not effective as required, an alarm will be issued.

[0089] The working principle of each unit in the above device can be referred to the description in the above embodiment method, and will not be repeated here.

[0090] The following are some embodiments of the method and apparatus for monitoring mobile communication network security in the non-cooperative situation.

[0091] Example 1

[0092] In the case of a 5G mobile communication network, the above-mentioned non-cooperative mobile communication network security monitoring method and device are applied, and the relevant functional entities include: a 5G terminal, a 5G base station, a 5G network, a security enhancement device, and a security monitoring device, such as Figure 5 shown.

[0093] The mobile communication network security monitoring under non-cooperative conditions includes the following steps:

[0094] S1. First, trigger the attach process reset method to enable all UEs in the surrounding area to re-initiate the network attach process;

[0095] S2. Receive downlink and uplink wireless signals from all surrounding UEs.

[0096] S3. Segment the downlink wireless signal and the uplink wireless signal according to the UE's IMSI information, and obtain the broadcast control channel message and the common control channel message.

[0097] S4. Analyze the signals of the broadcast control channel message and the common control channel message according to the cell search and random access process to obtain physical layer resources, including time, frequency, space and other physical layer resources.

[0098] S5. Continue parsing the physical layer resources to obtain a dedicated control channel message and a dedicated service channel message.

[0099] S6. Analyze the L3 layer RRC signaling message interaction process and the high-layer NAS signaling message interaction process through the dedicated control channel message.

[0100] S7. parse the air interface user plane data message and the high-layer IP data message through the dedicated service channel message.

[0101] S8. Analyze the L3 RRC signaling messages and interaction processes, air interface user plane data messages, and high-layer NAS signaling messages and interaction processes of each UE to identify whether the 3GPP security mechanism is effective and whether the security enhancement mechanism of the network slice and / or private network is effective;

[0102] S9. Analyze the high-level IP data packets of each UE to identify whether the security enhancement mechanism of the user data network is effective.

[0103] S10. If it is detected that the security enhancement mechanism has not taken effect as required, or there is an attack threat, an alarm will be sent to the security management system.

[0104] Example 2

[0105] In the case of a 4G mobile communication network, the above-mentioned method and apparatus for monitoring mobile communication network security in a non-cooperative situation are applied, and the relevant functional entities include: a 4G terminal, a 4G base station, a 4G network, a security enhancement device, and a security monitoring device, such as Figure 6 shown.

[0106] The specific steps include:

[0107] The mobile communication network security monitoring under non-cooperative conditions includes the following steps:

[0108] S1. First, trigger the attach process reset method to enable all UEs in the surrounding area to re-initiate the network attach process;

[0109] S2. Receive downlink and uplink wireless signals from all surrounding UEs.

[0110] S3. Segment the downlink wireless signal and the uplink wireless signal according to the UE's IMSI information, and obtain the broadcast control channel message and the common control channel message.

[0111] S4. Analyze the signals of the broadcast control channel message and the common control channel message according to the cell search and random access process to obtain physical layer resources, including time, frequency, space and other physical layer resources.

[0112] S5. Continue parsing the physical layer resources to obtain a dedicated control channel message and a dedicated service channel message.

[0113] S6. Analyze the L3 layer RRC signaling message interaction process and the high-layer NAS signaling message interaction process through the dedicated control channel message.

[0114] S7. parse the air interface user plane data message and the high-layer IP data message through the dedicated service channel message.

[0115] S8. Analyze the L3 RRC signaling messages and interaction processes, air interface user plane data messages, and high-layer NAS signaling messages and interaction processes of each UE to identify whether the 3GPP security mechanism is effective and whether the security enhancement mechanism of the network slice and / or private network is effective;

[0116] S9. Analyze the high-level IP data packets of each UE to identify whether the security enhancement mechanism of the user data network is effective.

[0117] S10. If it is detected that the security enhancement mechanism has not taken effect as required, or there is an attack threat, an alarm will be sent to the security management system.

[0118] Example 3

[0119] In the case of a 3G mobile communication network, the above-mentioned method and apparatus for monitoring mobile communication network security in a non-cooperative situation are applied, and the relevant functional entities include: a 3G terminal, a 3G base station, a 3G network, a security enhancement device, and a security monitoring device, such as Figure 7 shown.

[0120] The mobile communication network security monitoring under non-cooperative conditions includes the following steps:

[0121] S1. First, trigger the attach process reset method to enable all UEs in the surrounding area to re-initiate the network attach process;

[0122] S2. Receive downlink and uplink wireless signals from all surrounding UEs.

[0123] S3. Segment the downlink wireless signal and the uplink wireless signal according to the UE's IMSI information, and obtain the broadcast control channel message and the common control channel message.

[0124] S4. Analyze the signals of the broadcast control channel message and the common control channel message according to the cell search and random access process to obtain physical layer resources, including time, frequency, space and other physical layer resources.

[0125] S5. Continue parsing the physical layer resources to obtain a dedicated control channel message and a dedicated service channel message.

[0126] S6. Analyze the L3 layer RRC signaling message interaction process and the high-layer NAS signaling message interaction process through the dedicated control channel message.

[0127] S7. parse the air interface user plane data message and the high-layer IP data message through the dedicated service channel message.

[0128] S8. Analyze the L3 RRC signaling messages and interaction processes, air interface user plane data messages, and high-layer NAS signaling messages and interaction processes of each UE to identify whether the 3GPP security mechanism is effective and whether the security enhancement mechanism of the network slice and / or private network is effective;

[0129] S9. Analyze the high-level IP data packets of each UE to identify whether the security enhancement mechanism of the user data network is effective.

[0130] S10. If it is detected that the security enhancement mechanism has not taken effect as required, or there is an attack threat, an alarm will be sent to the security management system.

[0131] Example 4

[0132] In the case of satellite Internet dedicated lines, the above-mentioned mobile communication network security monitoring method and device in the non-cooperative situation are applied, and the relevant functional entities include: satellite Internet terminals, satellites, information gateways, 5G core networks, security enhancement equipment, and security monitoring equipment, such as Figure 8 shown.

[0133] The mobile communication network security monitoring under non-cooperative conditions includes the following steps:

[0134] S1. First, trigger the attach process reset method to enable all UEs in the surrounding area to re-initiate the network attach process;

[0135] S2. Receive downlink and uplink wireless signals from all surrounding UEs.

[0136] S3. Segment the downlink wireless signal and the uplink wireless signal according to the UE's IMSI information, and obtain the broadcast control channel message and the common control channel message.

[0137] S4. Analyze the signals of the broadcast control channel message and the common control channel message according to the cell search and random access process to obtain physical layer resources, including time, frequency, space and other physical layer resources.

[0138] S5. Continue parsing the physical layer resources to obtain a dedicated control channel message and a dedicated service channel message.

[0139] S6. Analyze the L3 layer RRC signaling message interaction process and the high-layer NAS signaling message interaction process through the dedicated control channel message.

[0140] S7. parse the air interface user plane data message and the high-layer IP data message through the dedicated service channel message.

[0141] S8. Analyze the L3 RRC signaling messages and interaction processes, air interface user plane data messages, and high-layer NAS signaling messages and interaction processes of each UE to identify whether the 3GPP security mechanism is effective and whether the security enhancement mechanism of the network slice and / or private network is effective;

[0142] S9. Analyze the high-level IP data packets of each UE to identify whether the security enhancement mechanism of the user data network is effective.

[0143] S10. If it is detected that the security enhancement mechanism has not taken effect as required, or there is an attack threat, an alarm will be sent to the security management system.

[0144] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.

Claims

1. A method for monitoring mobile communication network security in a non-cooperative situation, characterized in that: Including attachment process reset method and air interface signal security monitoring method; The attachment process resetting method includes: attracting surrounding UEs to access, obtaining IMSI information of surrounding UEs, and triggering each UE to re-initiate the network attachment process when releasing the UE; The air interface signal security monitoring method includes: Receive downlink and uplink wireless signals from surrounding UEs through the air interface, and parse the downlink and uplink wireless signals based on the UE's IMSI information to obtain physical layer resources; Parse physical layer resources to obtain messages and interaction processes; Analyze messages and interaction processes to identify whether security enhancement mechanisms are effective. If security enhancement mechanisms are not effective as required, an alarm is issued. The step of parsing downlink wireless signals and uplink wireless signals based on the UE's IMSI information to obtain physical layer resources includes: Segment the downlink and uplink radio signals based on the UE's IMSI information, parse the signals, and obtain broadcast control channel messages and common control channel messages. The process then determines whether the UE's IMSI information can be obtained. If the UE's IMSI information cannot be obtained, the attach process reset method is triggered, causing the UE to re-initiate the network attach process from the initial attach. If the UE's IMSI information can be obtained, the process continues. Parse broadcast control channel messages and common control channel messages to obtain physical layer resources. The obtained physical layer resources need to be judged. If the obtained physical layer resources are found to be incomplete and insufficient for parsing, the attach process reset method is triggered, causing the UE to re-initiate the network attach process from the initial attach. If the obtained physical layer resources are complete, the process continues. The process of parsing physical layer resources, obtaining messages and interaction includes: Parse the physical layer resources to obtain dedicated control channel messages and dedicated service channel messages; Through dedicated control channel messages, the interaction process of L3 layer RRC signaling messages and high-layer NAS signaling message interaction process are analyzed; Parse the air interface user plane data packets and high-layer IP data packets through dedicated service channel messages; The analysis of messages and interaction processes to identify whether the security enhancement mechanism is effective includes: Analyze each UE's L3 RRC signaling messages and interaction processes, air interface user plane data messages, and high-layer NAS signaling messages and interaction processes to identify whether the 3GPP security mechanism is effective and whether the security enhancement mechanism of the network slice and / or private network is effective; Analyze the high-level IP data packets of each UE to identify whether the security enhancement mechanism of the user data network is effective.

2. The method for monitoring mobile communication network security in a non-cooperative situation according to claim 1, characterized in that: When executing the air interface signal security monitoring method, initially, the attach process resetting method is triggered first, so that the current surrounding UEs re-initiate the network attach process.

3. A mobile communication network security monitoring device under non-cooperative conditions, characterized in that: Used to execute the method for monitoring mobile communication network security in a non-cooperative situation as claimed in claim 1 or 2, The mobile communication network security monitoring device in the non-cooperative situation includes: The mobile base station unit is used to attract surrounding UEs to access, obtain the IMSI information of surrounding UEs, and trigger each UE to re-initiate the network attachment process when releasing the UE; The radio frequency receiving unit is used to receive downlink and uplink radio signals from surrounding UEs through the air interface, and parse the downlink and uplink radio signals based on the UE's IMSI information to obtain physical layer resources; Protocol parsing unit, used to parse physical layer resources to obtain messages and interaction processes; The security analysis unit is used to analyze messages and interaction processes to identify whether the security enhancement mechanism is effective. If it is detected that the security enhancement mechanism is not effective as required, an alarm will be issued.

4. The mobile communication network security monitoring device in non-cooperative situation according to claim 3, characterized in that: The device is applied to 5G mobile communication networks, 4G mobile communication networks, 3G mobile communication networks and / or satellite Internet dedicated lines.

Citation Information

Patent Citations

  • Method for interworking between networks in wireless communication system and apparatus therefor

    CN109155949A

  • A method for realizing an IMSI (International Mobile Subscriber Identity) change function in an SIM (Subscriber Identity Module) card

    CN109842877A