User location privacy protection method for virtual operator in satellite internet field
By deploying PLPS servers in satellite Internet communications, modifying and encrypting user location information, the problem of Full MVNO user location privacy exposure is solved, and the location privacy protection of sensitive users is achieved without affecting the 5G network functions.
Patent Information
- Application Number
- CN202410024331.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-08
- Publication Date
- 2025-07-08
AI Technical Summary
In satellite Internet communication, the identity and location information of Full MVNO users are easily mastered by the AMF on the MNO core network side, and there are security risks of exposure to the privacy of sensitive users' locations.
Deploy the privacy location protection server PLPS between the base station and the AMF. By modifying and encrypting the user's real location information, providing virtual location information, disassembly the one-to-one correspondence between user identity and location, and establishing a secure tunnel for encrypted communication.
It effectively protects the location privacy of sensitive users, avoids AMF tracking the user's real location and mobile trajectory, ensures the normal operation of 5G network functions, and does not affect the original network architecture.
Smart Images

Figure CN120282131A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of satellite communication, and particularly relates to a method for protecting the user location privacy of virtual operators in the field of satellite Internet. Background Art
[0002] According to the satellite Internet development plan, the satellite Internet communication system adopts the ground 5G technology system. 5G base stations are deployed on the satellite, and a complete 5G core network is deployed on the ground side, and inter-satellite networking conditions are available. Users access the satellite Internet through satellite terminals via the on-satellite base stations.
[0003] MVNO is a concept that emerged during the mobile telecommunications operation. It is a new type of operator that emerged based on the separation of the network and services in mobile telecommunications operation. MVNO does not use its own infrastructure to provide connections, but rents infrastructure from mobile network operators to provide more competitive mobile connection plans. Except for lacking its own wireless network, the network implementation of Full MVNO is basically the same as that of mobile network operators.
[0004] According to the existing 5G mobile network technology system specifications, the identity identification and location information of users under the jurisdiction of Full MVNO are always mastered by the AMF network element on the core network side of the MNO when the users access the satellite Internet. There are great security risks for the exposure of sensitive information such as the identity and location of sensitive users when using satellite Internet communication services. Summary of the Invention
[0005] In view of the above analysis, the present invention aims to provide a method for protecting the user location privacy of virtual operators in the field of satellite Internet, and a Privacy Location Protection Server (PLPS) is deployed between the base station and the AMF to solve the problem of security risks existing in the use of satellite Internet communication services by sensitive users in the prior art.
[0006] The method of the present invention specifically includes:
[0007] When the user terminal actively initiates a service request to the base station, the following steps are included:
[0008] The base station forwards the user's service request to the PLPS;
[0009] The PLPS modifies the real location information of the user terminal in the service request to obtain virtual location information for the user terminal judged to be in a sensitive area, and encrypts the real location information and sends both to the AMF;
[0010] The AMF sends the encrypted real location information to the SMF, and the SMF judges whether it is necessary to update the UPF based on the decrypted real location information and feeds back updated context information to the AMF;
[0011] The AMF sends the received service information to the base station via the PLPS, and the base station forwards it to the user terminal.
[0012] Furthermore, a secure tunnel is established between the PLPS and the SMF, and the real location information is encrypted based on the key negotiated through the secure tunnel.
[0013] Furthermore, the PLPS modifies the real location information of the terminal user sent by the base station to obtain virtual location information, including that the PLPS modifies the real location information of the terminal user sent by the base station to the information of any non-confidential location within the RA area where the user terminal is located, to obtain the virtual location information.
[0014] Furthermore, the management scope of the PLPS for the user terminal is consistent with the scope of the AMF Region where the user terminal is located.
[0015] Furthermore, when the user terminal powers on and registers, it includes:
[0016] After the base station selects the AMF, it sends an INITIAL UE MESSAGE to the PLPS directly connected to the AMF, which includes the real location information of the user terminal;
[0017] The PLPS generates a PLPS-AMF-UE-NGAP-ID for the user terminal to determine the corresponding relationship with the user terminal, and sends the INITIAL UE MESSAGE and the PLPS-AMF-UE-NGAP-ID to the AMF; the AMF sends a Registration Accept to the PLPS, which carries the corresponding RA, GUTI of the user terminal and the generated AMF-PLPS-NGAP-ID;
[0018] The PLPS records the real location information, the corresponding RA and GUTI of the user terminal, and sends a RegistrationAccept message to the base station.
[0019] Furthermore, in the Xn handover scenario, the protection process for the real location information of the user terminal includes:
[0020] After the source base station determines the handover, the target base station sends an N2 path handover request to the PLPS;
[0021] The PLPS modifies the real location information of the user terminal to obtain virtual location information and encrypts the real location information, and then sends them both to the target AMF;
[0022] The source AMF sends an Nsmf_PDUSession_UpdateSMContext request and the encrypted real location information to the SMF;
[0023] The SMF updates the UPF based on the decrypted real location information and sends an Nsmf_PDUSession_UpdateSMContextResponse to the source AMF, including the N3 tunnel information provided to the UPF of the target base station;
[0024] The source AMF sends an N2 path switch request confirmation message to the target base station, including the N3 tunnel information provided to the UPF of the target base station.
[0025] Furthermore, the SMF updating the UPF based on the decrypted real location information includes: the SMF determines whether the user is outside the LADN based on the decrypted real location information, and determines whether to select a new UPF according to the decrypted real location information.
[0026] Furthermore, in the N2 handover scenario, the protection process for the real location information of the user terminal includes:
[0027] The PLPS modifies the real target base station ID to obtain a virtual target base station ID based on the handover request information of the source base station, encrypts it and sends it to the target AMF, and the PLPS sends the virtual location information and the encrypted real location information to the target AMF;
[0028] The target AMF sends an Nsmf_PDUSession_UpdateSMContext request, the encrypted real target base station ID, and the encrypted real location information to the SMF based on the virtual target base station ID;
[0029] The SMF updates the UPF based on the decrypted real target base station ID and real location information and sends an Nsmf_PDUSession_UpdateSMContext response to the target AMF;
[0030] The target AMF sends a handover request to the target base station through the PLPS; the target base station replies with a handover request confirmation to the target TMF through the PLPS.
[0031] Furthermore, the modifying the real target base station ID to obtain a virtual target base station ID includes: modifying the real target base station to any other base station within the service range of the serving AMF to obtain the virtual target base station ID.
[0032] Furthermore, when the user terminal performs mobility registration:
[0033] The source base station routes the MRU received from the user terminal to the PLPS;
[0034] After the PLPS modifies the real location information of the user terminal to virtual location information based on the MRU, it routes the MRU to the target AMF;
[0035] The source AMF sends the terminal context to the target AMF through the PLPS;
[0036] The target AMF receives the terminal subscription data and sends an MRU Accept to the PLPS;
[0037] The PLPS updates the RA and GUTI of the end user and sends them to the end user via the source base station.
[0038] The present invention can at least achieve one of the following beneficial effects:
[0039] By using the Privacy Location Protection Server (PLPS), the one-to-one correspondence between the user identity and the user location is disassembled, making it impossible for the AMF on the MNO side to track the real location where the user identity is at this moment, and avoiding the security risk problem caused by the exposure of the real location information and the real movement trajectory of sensitive users when using satellite Internet communication services.
[0040] While realizing the hiding of the user's real location from the AMF through the PLPS, providing virtual location information within the RA range to the AMF, and providing the real location information of the user to the SMF, enabling network elements such as the AMF and the SMF to normally complete all service functions including paging, that is, realizing user privacy protection without affecting the function of the AMF.
[0041] By directly adding interface N21 between the PLPS and the base station and interface N22 between the PLPS and the AMF respectively, and enhancing the privacy protection of the location, the N2 interface function between the base station and the AMF in the original 5G protocol is realized, and there is no other impact on the 5G network architecture except for realizing the protection of user location privacy.
[0042] Other features and advantages of the present invention will be described in the following specification, and some advantages can be made obvious from the specification, or understood by implementing the present invention. The objectives and other advantages of the present invention can be realized and obtained from the content specifically pointed out in the specification, the claims, and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] The drawings are only for the purpose of illustrating specific embodiments and are not considered to be a limitation of the present invention. Throughout the drawings, the same reference signs denote the same components;
[0044] Figure 1 It is a schematic diagram of the basic architecture of the location privacy protection system side of the present invention;
[0045] Figure 2 It is a flow chart of the user terminal network access registration of the present invention;
[0046] Figure 3 It is a flow chart of location protection in the case where the user terminal actively initiates a service of the present invention;
[0047] Figure 4 This is the location protection flowchart of the present invention based on the Xn handover scenario;
[0048] Figure 5 This is the location protection flowchart of the present invention based on the N2 handover scenario;
[0049] Figure 6 This is the schematic diagram of the location protection process for the user midshield mobility registration of the present invention. Detailed implementation manners
[0050] The following will specifically describe the preferred embodiments of the present invention in conjunction with the accompanying drawings and Table 1 of terms. The accompanying drawings and Table 1 of terms form a part of this application and are used together with the embodiments of the present invention to explain the principle of the present invention, rather than to limit the scope of the present invention.
[0051] Table 1 Comparison table of the meanings of professional terms
[0052]
[0053]
[0054] A specific embodiment of the present invention discloses a method for protecting the location privacy of users of a virtual operator, which is used to hide the sensitive location information of a user terminal from the AMF, realize the protection of sensitive user location privacy information, and solve the problem of potential safety hazards existing in the existing satellite Internet communication service mode for sensitive users.
[0055] It should be noted that sensitive users refer to users who may be monitored, tracked or attacked by the enemy, and sensitive locations refer to location information that needs to be kept confidential. Since sensitive users often move in sensitive location areas, it is necessary to protect the user location privacy. When the real location information of the user terminal is sensitive location information, the method of the present invention realizes hiding the current real location information of the user terminal from the AMF, so that the AMF cannot determine the real location information and activity track of the user.
[0056] The method of the present invention is based on the network architecture of the existing satellite Internet 5G system, and a Privacy Location Protection Server (PLPS) is added on the MNO side, which is deployed between the base station and the AMF, as Figure 1 shown.
[0057] Furthermore, the management scope of the PLPS for the user terminal is consistent with the AMF Region scope where the user terminal is located.
[0058] Furthermore, an interface N21 is added between the PLPS and the base station gNB, and an interface N22 is added between the PLPS and the AMF. Among them, N21 realizes the N2 interface function between the original base station and the AMF, and N22 also realizes the function of hiding the user's real location from the AMF and providing a virtual location on the basis of the N2 interface function between the original base station and the AMF.
[0059] Furthermore, let the user's location include space loc1 and loc2: where loc1 represents a sensitive area, that is, the location information that the user terminal needs to keep secret; loc2 represents a non-important area, that is, the location information that the user terminal does not need to keep secret. When the user terminal is at loc1, the user's location needs to be hidden, and the sensitive location information of the user is modified to any location within loc2 that does not need to be kept secret to obtain virtual location information. It should be noted that the ranges of loc1 and loc2 are preset ranges, and the range information of loc1 and loc2 is pre-stored in the PLPS (while the AMF does not know it) for judging whether the user terminal's location is in a sensitive area or a non-important area.
[0060] It should be noted that in the present invention, the PLPS provides non-discriminatory protection for the user identity. When the user terminal is located in the sensitive area loc1, only the location field in the NGAP protocol is processed to disrupt the corresponding relationship between the user terminal identity and the real location information, while the user identity still uses the GUTI assigned by the AMF and the SUCI field held by the user. The solution of the present invention does not add / modify the configuration content of the user terminal's location privacy protection policy, has no requirements for the number and geographical location of the terminals, has no requirements for the mobility of the terminals, and except for adding the function of hiding the real location information within the scope of the original system's mobility management responsibilities, there is no change to the mobility management mechanism. Without changing the existing 5G communication mechanism, the problem of security risks is solved.
[0061] Furthermore, when the user terminal actively initiates a service request to the base station, the following steps are included:
[0062] The base station forwards the user's service request to the PLPS;
[0063] The PLPS modifies the real location information of the user terminal in the service request to obtain virtual location information for the user terminal judged to be in the sensitive area, and encrypts the real location information and sends it to the AMF; among them, the virtual location information is the information of any location in the RA area where the user terminal is located except the real location information;
[0064] The AMF sends the encrypted real location information to the SMF. The SMF determines whether to update the UPF based on the decrypted real location information and feeds back the updated context information to the AMF. To enable the SMF to decrypt the encrypted real location information, a secure tunnel is established between the PLPS and the SMF, and a shared key is negotiated through the secure tunnel for encrypting and decrypting the real location information by both the PLPS and the SMF.
[0065] The AMF sends and receives service information to the base station through the PLPS, and the base station forwards it to the user terminal.
[0066] In this embodiment, by using the Privacy Location Protection Server (PLPS), the one-to-one correspondence between the user identity and the user location is disassembled, making it impossible for the AMF on the MNO side to track the real location where the user identity is at this moment, and avoiding the security risks to the security of sensitive information such as the identity and location of sensitive users when using satellite Internet communication services.
[0067] It should be noted that according to the management items of the AMF in the existing satellite Internet user location management, the management of the terminal by the AMF includes: location change, time zone change, access type change, registration status change, connection status change, UE connection loss, and UE reachability status change, etc. Therefore, the AMF is a network element with an important role in the satellite Internet mobile communication system. All important location information of the user and the user's identification information are matched and stored one by one inside the AMF, constantly grasping information such as the location change of the user. This design also reflects the important principle of user mobility management in the mobile system. If the real location information of the user is directly hidden from the AMF, most service functions in the mobile system, including paging, cannot be carried out normally. Therefore, in this embodiment, while hiding the real location of the user from the AMF, virtual location information of the user is provided to the AMF, which can protect the user privacy without affecting the AMF function.
[0068] A specific embodiment of the present invention discloses a method for protecting the user location privacy of a virtual operator in the field of satellite Internet.
[0069] Among them, the location protection process when the user terminal powers on and registers (as Figure 2 shown) specifically includes:
[0070] 1. The UE (user terminal) sends a Registration Request signaling to the base station gNB, protecting the user's SUPI / GUTI / PEI and the last accessed TAI in the Dedicate NAS-Message to help the AMF generate a registration area for the UE;
[0071] 2. The base station selects an AMF based on the SUPI / GUTI / etc.
[0072] 3. After the base station selects an AMF, it sends an INITIAL UE MESSAGE to the PLPS directly connected to the AMF, which includes information such as the real location information of the user terminal, the RAN-UE-NGAP-ID, and the terminal TAI, etc.; the PLPS records the user terminal identity and real location information, and generates a PLPS-AMF-UE-NGAP-ID for the user terminal to determine the corresponding relationship with the user terminal.
[0073] 4. The PLPS sends the original NAS information, i.e., the INITIAL UE MESSAGE and the PLPS-AMF-UE-NGAP-ID, to the AMF through the NGAP protocol.
[0074] 5. The AMF initiates an authentication process to the AUSF.
[0075] 6. The UDM verifies the user terminal identity and performs subsequent authentication processes.
[0076] 7. The AMF starts the NGAP-related security process. The 5G-AN stores the security context and confirms it to the AMF.
[0077] 8. The AMF notifies the user terminal UE to establish a context through NGAP. The AMF sends a Registration Accept to the PLPS, which carries the corresponding RA, GUTI of the user terminal, and the generated AMF-PLPS-NGAP-ID; the PLPS records the real location information, the corresponding RA, and GUTI of the user terminal.
[0078] 9. Send a Registration Accept message to the base station.
[0079] 10. The base station establishes a security mode with the user terminal through an RRC message.
[0080] 11. The user terminal notifies the AMF through NAS's Registration Complete that the registration process has been completed on the user terminal UE side.
[0081] It should be noted that PLPS does not hide the real location information of the user terminal during the user terminal startup registration phase, because AMF needs to generate LADN and RA based on the real location information, otherwise registration is not possible. AMF can only know the real location information of the user when the user terminal is powered on and registered, and in the subsequent user terminal initiating service requests, Xn switching, N2 switching and mobile registration scenarios, the method of the present invention hides the real location information of the user terminal from AMF for user terminals entering sensitive areas, so that AMF cannot obtain the real movement trajectory of the user terminal, thereby realizing the privacy protection of the user terminal.
[0082] Furthermore, when the user terminal actively initiates a service request to the base station (such as Figure 3 The location protection process (as shown) includes:
[0083] 1. The user terminal sends a Service Request message to the gNB. When the user terminal wants to reactivate the PDU session, the UE provides a list of PDU sessions to be activated, including parameters such as 5G-S-TMSI and AN parameters.
[0084] 2. The gNB selects AMF according to GUTI / 5G-S-TMSI or TAI, and sends service request information and N21 Message to the PLPS directly connected to the AMF, including the real location information of the UE, that is, the cell information where the UE resides; the N21 Message implements the N2 Message;
[0085] 3.PLPS authenticates the real location information RL of the user terminal in the service request. If the location information is considered as sensitive location information, it is modified to obtain virtual location information at any location within the RA area where the user terminal is located. The real location information RL is encrypted with the shared key with SMF and attached to the N22 Message. The modified NAS information and N22Message are sent to AMF. The shared key is obtained based on the secure tunnel negotiation.
[0086] It should be noted that if the real location information of the user terminal is not sensitive location information, PLPS does not process the real location information and directly forwards the service request to AMF. The subsequent processes are carried out according to the corresponding processes in the existing 5G protocol. PLPS only performs the forwarding function in each interaction process.
[0087] 4.AMF verifies the integrity of the NAS information. If there is no integrity protection, the security context establishment process between AMF and UE is triggered;
[0088] 5. The AMF carries the RL information encrypted by PLPS in the Nsmf_PDUSession_UpdateSMContext message and sends this message to the SMF to request an update of the PDU session context;
[0089] 6. The SMF determines whether to update the UPF based on the decrypted RL information. If an update is needed, operations such as adding an I-UPF or adding a PSA are initiated; and the SMF feeds back the updated context information Nsmf_PDUSession_UpdateSMContextResponse to the AMF;
[0090] 7. The AMF sends the received service information Service Accept to PLPS via the N22 interface;
[0091] 8. PLPS forwards Service Accept to the base station, and the base station performs corresponding processing;
[0092] 9. The base station sends the Service Accept message to the user terminal and performs RRC connection reconfiguration with the user terminal;
[0093] 10. For the subsequent information flow process and content of the information sent from the gNB to the AMF, the AMF to the SMF, and the SMF to the PCF and UPF, they are consistent with the 3GPP description. PLPS only performs forwarding and does not modify any information, so it will not be elaborated here.
[0094] Furthermore, in the Xn handover scenario, the protection process for the real location information of the user terminal (as Figure 4 shown) includes:
[0095] 1. After the source base station S-gNB determines the handover, the target base station T-gNB sends an N2 path handover request to PLPS to notify the core network that the user terminal has moved to the new target cell. The content of the path handover request includes the user terminal location information, etc.;
[0096] 2. PLPS authenticates the real location information based on the received path handover request. For the user terminal with real location information being sensitive location information, its real location information is modified to any location within the AMF service area where the target base station is located to obtain virtual location information; and the real location information is encrypted and appended to the path request message and then sent to the target AMF; it should be noted that for the case where the real location information of the user terminal is not sensitive location information, PLPS does not process the real location information and directly forwards the service request to the AMF. The subsequent processes are all carried out according to the corresponding processes in the existing 5G protocol. PLPS only performs the forwarding function in each interaction process;
[0097] 3. The source AMF sends the Nsmf_PDUSession_UpdateSMContext request and the encrypted real location information to the SMF, notifying each SMF corresponding to the relatively replaced PDU session.
[0098] 4. The SMF determines whether the user is outside the LADN based on the decrypted real location information, determines whether to update the UPF according to the decrypted real location information, and provides the N3 tunnel information to the UPF of the corresponding target base station.
[0099] 5. The SMF replies to the source AMF with the Nsmf_PDUSession_UpdateSMContextResponse, including the N3 tunnel information provided to the UPF of the target base station.
[0100] 6. The UPF sends one or more "end markers" to the source base station. The source base station deletes the old path according to the end markers and forwards them to the target base station to facilitate the reordering of downlink data.
[0101] 7. The source AMF sends the N2 path switch request confirmation information to the target base station, including the N3 tunnel information provided to the UPF of the target base station; PLPS does not perform any operation here.
[0102] 8. The target base station notifies the source base station that the handover is completed, and the source base station releases the relevant resources.
[0103] Furthermore, when there is no Xn signaling interface between the source base station and the target base station, N2 handover is required. Based on N2 handover, it is divided into two phases: the preparation phase and the execution phase.
[0104] Specifically, in the N2 handover scenario, the preparation phase includes the following steps (as Figure 5 shown):
[0105] 1. The source base station decides to trigger an N2 handover and sends a handover request to the PLPS, including information such as the target base station ID. When the PLPS determines that the target base station is within the sensitive area, it modifies the real target base station to any other base station within the service range of the corresponding AMF based on the handover request information of the source base station to obtain the virtual target base station ID; for the case where the target base station is in a non-critical area, the PLPS does not perform any processing and directly forwards the handover request to the AMF, and the subsequent process follows the existing 5G corresponding process.
[0106] 2. The PLPS sends the virtual location information and the encrypted real location information to the target AMF; the target AMF determines whether this AMF, i.e., the source AMF, continues to serve based on the virtual target base station ID. If it exceeds the service range, an AMF selection is performed to select a suitable target AMF.
[0107] 3. The source AMF sends the information of the Create UE Context request to the target AMF; this step is optional and follows the process in the original 5G protocol;
[0108] 4. The target AMF sends an Nsmf_PDUSession_UpdateSMContext request, the encrypted real target base station ID, and the encrypted real location information to the SMF, notifying each SMF corresponding to the replaced PDU session. After decryption by the SMF, it determines whether the current UPF can continue to serve the target base station based on the real target base station ID and the real location information, and whether a new I-UPF needs to be added;
[0109] 5. If an I-UPF needs to be added, the SMF interacts with the PSA and the T-UPF for N4 session modification information;
[0110] 6. The SMF sends an Nsmf_PDUSession_UpdateSMContext response to the target AMF;
[0111] 7. When the target AMF has received responses from all SMFs or cannot wait, the target AMF sends a handover request to the PLPS, and the PLPS forwards the handover request to the T-gNB, including the PDU session information to be handed over; the target AMF can allocate a valid 5G-GUTI and a target TAI for the UE in the AMF;
[0112] 8. The target base station replies to the handover request confirmation to the target TMF through the PLPS, including the N3 tunnel information for each PDU session;
[0113] 9. The target AMF forwards the PDU session information received from the target base station to each SMF;
[0114] 10. The SMF replies with a PDU session response to the target AMF;
[0115] 11. The target AMF replies with a Create UE Context request response to the source AMF, and the preparation phase is completed.
[0116] Furthermore, the execution phase is consistent with the execution phase process in the original 5G protocol. The PLPS is responsible for forwarding all information from the base station to the AMF and does not require special processing, so it is not elaborated here.
[0117] Furthermore, the base station broadcasts the TA identifier in each cell, and the user terminal compares this information with one or more TAs previously stored as part of the designated RA. If the broadcast tracking area is not part of the allocated RA, the user terminal initiates a mobile registration process to the network to notify that the user terminal is now in a different location.
[0118] Specifically, the location protection process in the mobility registration scenario (as shown in Figure 6 ) includes the following steps:
[0119] 1. When the user terminal reselects a cell and finds that the broadcast TA ID is not in any TA list of its RA, the terminal initiates a Mobile Registration Update (MRU) process to the network;
[0120] 2. The source base station routes the MRU received from the user terminal to the PLPS;
[0121] 3. Based on the MRU, the PLPS authenticates the real location information of the user terminal. If the location information is regarded as sensitive location information, it is modified to location information outside the RA of the user terminal to obtain virtual location information, and the MRU is routed to the target AMF; if the location information is non-sensitive location information, the PLPS directly routes the MRU to the target AMF, and the subsequent process is the same as the relevant process of the existing 5G protocol;
[0122] 4. The source AMF receives the MRU message and checks whether the context of the terminal is available. If it is not available, the AMF checks the temporary identity (5G-GUTI) of the terminal to determine which AMF has retained the context of the terminal. After determination, the AMF sends a request back to the old AMF to inquire about the terminal context;
[0123] 5. The source AMF sends the terminal context to the target AMF through the PLPS;
[0124] 6. The target AMF receives the terminal context from the source AMF, notifies the UDM that the terminal context has been moved to the target AMF by registering itself with the UDM, sends a subscription notification to the UDM, tells the target AMF when the UDM deletes the source AMF, and obtains the subscribed data of the terminal from the UDM; the target AMF sends an MRU Accept to the PLPS;
[0125] 7. The UDM deletes the terminal context in the source AMF;
[0126] 8. The UDM confirms the target AMF and inserts new subscribed data in the target AMF;
[0127] 9. The PLPS updates the RA and GUTI of the terminal user and sends them to the terminal user through the source base station.
[0128] This embodiment discloses a method for protecting the user location privacy of virtual network operators. While hiding the real location of the user from the AMF through PLPS, virtual location information within the RA range is provided to the AMF, and the real location information of the user is provided to the SMF, enabling network elements such as the AMF and SMF to normally complete all service functions including paging. That is, without affecting the function of the AMF, the corresponding relationship between the real-time real location and identity of sensitive users is hidden from the AMF, achieving user privacy protection. In this embodiment method, interfaces N21 and N22 are directly added between the PLPS and the base station and the AMF respectively to implement the N2 interface function between the base station and the AMF in the original 5G protocol, without causing other impacts on the 5G network architecture except for enhancing the protection of user location privacy.
[0129] It should be noted that the above embodiments are based on the same inventive concept, and for the parts not repeatedly described, reference can be made to each other.
[0130] As described above, the above are only the preferred specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention.
Claims
1. A method for protecting the user location privacy of virtual network operators in the field of satellite Internet, characterized in that, Deploy a Privacy Location Protection Server (PLPS) between the base station and the AMF; When the user terminal actively initiates a service request to the base station, the following steps are included: The base station forwards the user's service request to the PLPS; The PLPS modifies the real location information of the user terminal in the service request for the user terminal judged to be in the sensitive area to obtain virtual location information, and encrypts the real location information and then sends both to the AMF; The AMF sends the encrypted real location information to the SMF. The SMF judges whether the UPF needs to be updated based on the decrypted real location information and feeds back the updated context information to the AMF; The AMF sends a receive service message to the base station through the PLPS, and the base station forwards it to the user terminal.
2. The user location privacy protection method according to claim 1, wherein Establish a secure tunnel between the PLPS and the SMF, and encrypt the real location information based on the key negotiated by the secure tunnel.
3. The user location privacy protection method according to claim 2, wherein The PLPS modifies the real location information of the terminal user sent by the base station to obtain virtual location information, including that the PLPS modifies the real location information of the terminal user sent by the base station to the information of any non-confidential location within the RA area where the user terminal is located, to obtain virtual location information.
4. The user privacy location protection method according to claim 3, wherein The management scope of the PLPS for the user terminal is consistent with the scope of the AMF Region where the user terminal is located.
5. The user privacy location protection method according to claim 4, wherein, When the user terminal powers on and registers, it includes: After the base station selects the AMF, it sends an INITIAL UE MESSAGE directly connected to the PLPS of the AMF, which includes the real location information of the user terminal; The PLPS generates a PLPS-AMF-UE-NGAP-ID for the user terminal to determine the corresponding relationship with the user terminal, and sends the INITIAL UE MESSAGE and the PLPS-AMF-UE-NGAP-ID to the AMF; The AMF sends a Registration Accept to the PLPS, which carries the corresponding RA, GUTI of the user terminal and the generated AMF-PLPS-NGAP-ID; The PLPS records the real location information, the corresponding RA and GUTI of the user terminal, and sends a RegistrationAccept message to the base station.
6. The user privacy location protection method according to claim 5, wherein In the Xn handover scenario, the protection process for the real location information of the user terminal includes: After the source base station determines the handover, the target base station sends an N2 path handover request to the PLPS; The PLPS modifies the real location information of the user terminal to obtain virtual location information and encrypts the real location information and then sends both to the target AMF; The source AMF sends an Nsmf_PDUSession_UpdateSMContext request and the encrypted real location information to the SMF; The SMF updates the UPF based on the decrypted real location information and sends an Nsmf_PDUSession_UpdateSMContextResponse to the source AMF, including the N3 tunnel information provided to the UPF of the target base station; The source AMF sends an N2 path handover request confirmation message to the target base station, including the N3 tunnel information provided to the UPF of the target base station.
7. The user privacy location protection method according to claim 6, wherein The SMF updates the UPF based on the decrypted real location information, including: the SMF determines whether the user is outside the LADN based on the decrypted real location information, and determines whether to select a new UPF according to the decrypted real location information.
8. The user privacy location protection method according to claim 5, wherein In the N2 handover scenario, the protection process for the real location information of the user terminal includes: The PLPS modifies the real target base station ID to obtain a virtual target base station ID based on the handover request information of the source base station, encrypts it, and sends it to the target AMF. The PLPS sends the virtual location information and the encrypted real location information to the target AMF; The target AMF sends an Nsmf_PDUSession_UpdateSMContext request, the encrypted real target base station ID, and the encrypted real location information to the SMF based on the virtual target base station ID; The SMF updates the UPF based on the decrypted real target base station ID and real location information, and sends an Nsmf_PDUSession_UpdateSMContext response to the target AMF; The target AMF sends a handover request to the target base station through the PLPS; the target base station replies to the handover request confirmation to the target TMF through the PLPS.
9. The user privacy location protection method according to claim 8, characterized in that, The modification of the real target base station ID to obtain a virtual target base station ID includes: modifying the real target base station to any other base station within the service range of the AMF where it is located to obtain the virtual target base station ID.
10. The user privacy location protection method according to claim 5, characterized in that, When the user terminal performs mobility registration: The source base station routes the MRU received from the user terminal to the PLPS; After the PLPS modifies the real location information of the user terminal to virtual location information based on the MRU, it routes the MRU to the target AMF; The source AMF sends the terminal context to the target AMF through the PLPS; The target AMF receives the terminal subscription data and sends an MRU Accept to the PLPS; The PLPS updates the RA and GUTI of the terminal user and sends them to the terminal user through the source base station.
Citation Information
Cited By
Communication method, communication device and communication system
CN121357499A
A communication method, a communication device, and a communication system
CN121357499B