Access control method and device of communication terminal and storage medium
By obtaining the mobile trajectory information of the communication terminal and multi-dimensional identity authentication parameters, dynamically controlling its access to the communication network side, the problem of difficulty in adapting to dynamic changes and complex scenarios in the prior art is solved, and security and optimal resource allocation in the satellite communication environment are realized.
Patent Information
- Application Number
- CN202510263504.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-07-11
AI Technical Summary
The existing communication terminal access control technology is difficult to adapt to dynamically changing user needs and complex access scenarios, especially in unmanned areas and satellite communication environments, with limited resources and high costs, and the prior art is difficult to effectively manage the access of communication terminals.
By continuously obtaining the mobile trajectory information of the communication terminal and multi-dimensional identity authentication parameters, comprehensively assessing its legality and credibility, dynamically controlling its access to the communication network side, including whitelist management, priority scoring and abnormal behavior detection, to achieve accurate access control.
It has improved the legality identification ability in diversified access scenarios, ensured the security and efficient allocation of resources on the communication network side, ensured the service quality of high-priority users, and prevented illegal access and data forgery.
Smart Images

Figure CN120302374A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of wireless communication technologies, and in particular to an access control method, device, and storage medium for a communication terminal. Background Art
[0002] When performing wireless communication, a communication terminal needs to access the communication network side, and the communication network side provides services for the communication terminal. The communication network side will perform access control on the communication terminal, such as determining whether to allow the communication terminal to access, the duration of allowed access, etc., so as to achieve communication security guarantee, communication resource allocation, and communication billing, etc. In scenarios where the communication terminal is located in uninhabited areas, an airplane in flight, or a cruise ship in navigation, etc., the communication terminal generally can only choose to access the communication network side through a communication satellite, and the resources of the communication satellite are limited and the cost is high. At this time, it is more necessary to strictly manage the access of the communication terminal to ensure the reasonable allocation and use of communication resources.
[0003] Currently, the access control technology usually relies on the user subscription information of the communication terminal to perform authentication and other operations, and controls the access of the communication terminal according to the authentication result. However, the user subscription information is generally static information, and is often only applicable to conventional communication scenarios with good signals and sufficient communication resources in cities and towns, etc., and it is difficult to adapt to the dynamic user needs and complex access scenarios such as the diversification of the means of transportation carried by the communication terminal and the diversification of the location of the communication terminal. Summary of the Invention
[0004] Aiming at the technical problems that the current access control technology is difficult to adapt to dynamic user needs and complex access scenarios, etc., the purpose of the present invention is to provide an access control method, device, and storage medium for a communication terminal.
[0005] On the one hand, an embodiment of the present invention includes an access control method for a communication terminal, and the access control method for the communication terminal includes the following steps:
[0006] Continuously obtain the movement trajectory information of the first communication terminal;
[0007] Obtain the multi-dimensional identity authentication parameters of the first communication terminal; the multi-dimensional identity authentication parameters include multiple identity authentication sub-parameters;
[0008] Control the access of the first communication terminal to the communication network side according to the movement trajectory information and the multi-dimensional identity authentication parameters.
[0009] Further, the controlling the access of the first communication terminal to the communication network side according to the movement trajectory information and the multi-dimensional identity authentication parameters includes:
[0010] Obtain the first access request of the first communication terminal;
[0011] In response to the first access request, for each of the identity authentication sub-parameters in the multi-dimensional identity authentication parameters, obtain corresponding sub-ratings respectively;
[0012] Determine a credibility rating based on each of the sub-ratings;
[0013] When the credibility rating is greater than the rating threshold, accept the first communication terminal to access the communication network side; otherwise, reject the first communication terminal from accessing the communication network side.
[0014] Further, the controlling the access of the first communication terminal to the communication network side according to the mobile trajectory information and the multi-dimensional identity authentication parameters includes:
[0015] Perform a legality detection on the mobile trajectory information;
[0016] When the legality detection of the mobile trajectory information passes, add the first communication terminal to the whitelist;
[0017] When the legality detection of the mobile trajectory information fails, delete the first communication terminal from the whitelist;
[0018] Intermittently detect the whitelist;
[0019] When it is detected that the first communication terminal exists in the whitelist, maintain the access of the first communication terminal to the communication network side;
[0020] When it is detected that the first communication terminal does not exist in the whitelist, disconnect the access of the first communication terminal to the communication network side.
[0021] Further, the performing a legality detection on the mobile trajectory information includes:
[0022] Obtain the autocorrelation function of the mobile trajectory information;
[0023] Obtain the decay rate of the autocorrelation function;
[0024] When the decay rate is less than the speed threshold, determine that the legality detection of the mobile trajectory information passes; otherwise, determine that the legality detection of the mobile trajectory information fails.
[0025] Further, the access control method of the communication terminal further includes:
[0026] When accepting and maintaining the access of the first communication terminal to the communication network side, continuously obtain the network resource consumption information of the first communication terminal;
[0027] Generate a priority rating according to the network resource consumption information;
[0028] Adjust the service level of the first communication terminal on the communication network side according to the priority score.
[0029] Furthermore, the access control method for the communication terminal further includes:
[0030] Continuously obtain the connection behavior data of the first communication terminal;
[0031] Use the random forest algorithm to perform fine classification on the connection behavior data;
[0032] Identify the abnormal behavior of the first communication terminal according to the fine classification result;
[0033] When the abnormal behavior is identified, delete the first communication terminal from the whitelist.
[0034] Furthermore, the access control method for the communication terminal further includes:
[0035] Perform a legality detection on the connection behavior data according to the mobile trajectory information;
[0036] When the legality detection of the connection behavior data passes, add the first communication terminal to the whitelist;
[0037] When the legality detection of the connection behavior data fails, delete the first communication terminal from the whitelist.
[0038] Furthermore, the performing a legality detection on the connection behavior data according to the mobile trajectory information includes:
[0039] Obtain the first cross-correlation function of the connection behavior data and the mobile trajectory information;
[0040] Search for multiple second communication terminals from the whitelist;
[0041] Obtain the second cross-correlation function corresponding to each of the second communication terminals;
[0042] Perform a type comparison between the first cross-correlation function and each of the second cross-correlation functions;
[0043] When the type comparison is the same, determine that the legality detection of the connection behavior data passes;
[0044] When the type comparison is different, determine that the legality detection of the connection behavior data fails.
[0045] On the other hand, an embodiment of the present invention further includes a computer device, including a memory and a processor, where the memory is used to store at least one program, and the processor is used to load at least one program to execute the access control method for the communication terminal in the embodiment.
[0046] On the other hand, an embodiment of the present invention further includes a computer-readable storage medium storing a program executable by a processor, and the program executable by the processor is used to execute the access control method of the communication terminal in the embodiment when executed by the processor.
[0047] The beneficial effects of the present invention are as follows: For the access control method of the communication terminal in the embodiment, on the one hand, it controls the access of the first communication terminal to the communication network side according to the dynamically changing mobile trajectory information of the first communication terminal, which can adapt to dynamically changing and complex access scenarios. On the other hand, it controls the access of the first communication terminal to the communication network side according to the multi-dimensional identity authentication parameters of the first communication terminal. Since the multi-dimensional identity authentication parameters include identity authentication sub-parameters, the legitimacy of the first communication terminal can be identified from multiple aspects. By comprehensively using the mobile trajectory information and the multi-dimensional identity authentication parameters to control the access of the first communication terminal to the communication network side, the ability to identify the legitimacy of the communication terminal in diverse access scenarios can be improved, thereby ensuring the security of the communication network side and the efficient allocation of communication resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 It is a schematic flowchart of the access control method of the communication terminal in the embodiment.
[0049] Figure 2 It is a schematic diagram of the system architecture formed by the communication network side in the embodiment;
[0050] Figure 3 It is a schematic diagram of the steps of the access control method of the communication terminal executed by the communication network side in the embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0051] Term Explanation:
[0052] 1. UE (User Equipment): Also known as a communication terminal, it refers to a terminal device that connects to a communication system through a wireless network, such as a smart phone, a tablet computer, or an Internet of Things device.
[0053] 2. GPS module: A hardware component used to generate geographical location information, supporting device positioning and trajectory tracking.
[0054] 3. gNB (Next Generation Base Station): A base station in a 5G network, responsible for wireless communication with the UE and transmitting data information.
[0055] 4. AMF (Access and Mobility Management Function): Responsible for processing the registration, connection, and mobility management of the UE to ensure the normal access and handover of the device.
[0056] 5. UPF (User Plane Function): Responsible for data forwarding, resource allocation, and access control, and is a key component in the core network for processing user data.
[0057] 6. MSISDN (Mobile Subscriber Integrated Services Digital Network Number): The unique telephone number used to identify a mobile user, supporting user identity authentication and call record management.
[0058] 7. IMEI (International Mobile Equipment Identity): The number used to uniquely identify the device hardware, helping to track and authenticate the device.
[0059] 8. AUSF (Authentication Server Function): Responsible for user authentication and device authentication to ensure that only legitimate users can access the network.
[0060] 9. UDM (User Data Management): Stores user identity and authentication information and provides user data support for network components.
[0061] 10. PCF (Policy Control Function): Manages network resource allocation and service priorities according to preset policies to ensure efficient access control and load balancing.
[0062] 11. TLS (Transport Layer Security): An encryption protocol that protects data transmission security to ensure the confidentiality and integrity of data in the network.
[0063] 12. AES-256 (Advanced Encryption Standard - 256-bit): A high-strength data encryption standard widely used to protect sensitive information.
[0064] 13. Random Forest Algorithm: A machine learning algorithm used for anomaly detection and behavior analysis, improving the accuracy and stability of data analysis through a multi-decision tree structure.
[0065] 14. TAC (Location Area Code): The code that identifies a specific geographical area and is used for location management and user access area division.
[0066] 15. Access Timestamp: Records the time information when the device requests to access the network and is used for event tracking and duplicate request detection.
[0067] In this embodiment, the process of the access control method for the communication terminal is as Figure 1 shown. Referring to Figure 1 , the access control method for the communication terminal can be applied in a communication system including a first communication terminal and a communication network side. Among them, the first communication terminal is a specific communication terminal, and the communication network side includes network elements such as AMF, AUSF, UDM, PCF, and UPF.
[0068] In this embodiment, the communication network side forms a system architecture, and this system architecture is as Figure 2As shown, it includes an identity authentication module, a location management module, a priority management module, a data packet processing module, an access control module, and a security log module. The functions of each module are as follows:
[0069] Identity authentication module: This module is responsible for ensuring the legitimacy of the user's identity and performing security authentication on the access device through multiple authentication methods. It includes four sub-modules: device verification, biometric recognition, dynamic scoring, and failure handling. The device verification sub-module confirms the device identity based on identification information such as IMEI and MSISDN; the biometric recognition sub-module authenticates the user's identity using fingerprint or facial recognition; the dynamic scoring sub-module evaluates the user's access risk and assigns corresponding permissions; the failure handling sub-module records events and triggers an alarm when authentication fails.
[0070] Location management module: This module is responsible for obtaining and managing the geographical location of the user device to facilitate access control within the region. It includes three sub-modules: GPS positioning, area comparison, and movement monitoring. The GPS positioning sub-module obtains the user's geographical location information in real time through the GPS module of the UE device; the area comparison sub-module determines whether the user is in the permitted access area based on the TAC list; the movement monitoring sub-module monitors the change of the user's location in real time and adjusts the corresponding access policy.
[0071] Priority management module: This module is used to dynamically adjust network resource allocation according to the user's priority to ensure that high-priority users can obtain resources first. It includes three sub-modules: priority evaluation, resource allocation, and bandwidth control. The priority evaluation sub-module evaluates the priority based on the user identity, service type, and historical behavior; the resource allocation sub-module dynamically allocates bandwidth according to the user priority and network load; the bandwidth control sub-module adjusts the bandwidth allocation according to the user's real-time needs to ensure that high-priority users can use network resources first.
[0072] Data packet processing module: This module is responsible for screening, deduplicating, formatting, and time-stamping the received data packets to ensure the integrity and consistency of the data. It includes three sub-modules: deduplication filtering, data screening, and time-stamping. The deduplication filtering sub-module removes duplicate data packets through identifiers; the data screening sub-module screens valid data according to predefined rules; the time-stamping sub-module stamps the data packets with timestamps to ensure the timeliness of the data.
[0073] Access control module: This module controls the user's access rights to the network based on the user's identity, location, and priority. It includes three sub-modules: whitelist management, permission check, and access decision-making. The whitelist management sub-module ensures that only legitimate users can access by dynamically updating the whitelist; the permission check sub-module performs access permission checks according to the user priority and resource availability; the access decision-making sub-module makes a decision on whether to allow access based on the comprehensive evaluation results.
[0074] Security Log Module: This module is used to record and analyze abnormal events during the access process to ensure system security. It includes three sub-modules: record storage, anomaly detection, and log analysis. The record storage sub-module stores all user access events; the anomaly detection sub-module monitors abnormal behaviors in real time, such as illegal access or attack attempts; the log analysis sub-module analyzes the stored logs, generates security reports, and provides improvement suggestions.
[0075] Refer to Figure 3 , the access control method for a communication terminal includes the following steps:
[0076] S1. Continuously obtain the mobile trajectory information of the first communication terminal;
[0077] S2. Obtain the multi-dimensional identity authentication parameters of the first communication terminal;
[0078] S3. Control the access of the first communication terminal to the communication network side according to the mobile trajectory information and the multi-dimensional identity authentication parameters.
[0079] It can be performed by Figure 1 the communication network side in
[0080] In step S1, refer to Figure 1 , when the first communication terminal hopes to access the communication network side to receive communication services provided by the communication network side, the first communication terminal can continuously send mobile trajectory information to the communication network side.
[0081] Specifically, refer to Figure 1 , the first communication terminal generates geographical location information in the form of longitude and latitude coordinates through its own GPS module, and records call details and traffic consumption data. These data are sent to the nearest gNB in real time through a wireless channel; when the gNB receives the data packet, it attaches the access time and signal strength information and forwards it to the AMF. The AMF can obtain the mobile trajectory information according to the geographical location information and the corresponding time. The mobile trajectory information represents the geographical location of the first communication terminal at each moment when it moves with the user or the vehicle.
[0082] In step S2, refer to Figure 1When the first communication terminal attempts to access the communication network side for the first time, the first communication terminal can send multi-dimensional identity authentication parameters to the gNB. The multi-dimensional identity authentication parameters include multiple identity authentication sub-parameters, which can specifically be the MSISDN, device fingerprint, and biometric authentication data, etc. Among them, the MSISDN is extracted from the SIM card of the user device to ensure the uniqueness of the user identity; the device fingerprint is dynamically generated based on the hardware serial number, operating system version, and device network adapter information, with strong device uniqueness characteristics; the biometric authentication data is obtained from the device side through fingerprint scanning, face recognition, or iris scanning, etc., and is sent after being encrypted locally. After receiving these data, the gNB attaches the IMEI of a device and the access timestamp to form a complete data packet. The attached IMEI ensures that the data of each device can be uniquely traced, while the timestamp is used to track the exact initiation time of the request to prevent data packet replay attacks. The generated data packet is end-to-end encrypted through the AES-256 encryption algorithm, and the encrypted data packet is transmitted to the AMF through a TLS encrypted channel.
[0083] In step S3, the communication network side can control the access of the first communication terminal to the communication network side according to the mobile trajectory information obtained in step S1 and the multi-dimensional identity authentication parameters obtained in step S2, such as determining to accept the access of the first communication terminal to the communication network side, or rejecting the access of the first communication terminal to the communication network side, or disconnecting the connection between the first communication terminal and the communication network side.
[0084] For example, referring to Figure 1 , when performing step S3, for the mobile trajectory information obtained in step S1, after the AMF receives the data from the gNB, it forwards the mobile trajectory information to the UPF to screen the data packets, identify and delete duplicate data records; the device identifier and timestamp are used as the basis for uniqueness determination during this process. The UPF standardizes the format of the screened data packets. According to the predefined data format, the location field adopts a standardized geographical coordinate format, while the call record field needs to include the complete call time and duration information to avoid processing errors caused by inconsistent data formats. The UPF verifies whether the mobile trajectory of the first communication terminal conforms to the actual geographical and time change logic by analyzing the geographical coordinates generated by the GPS module in the mobile trajectory information and the recorded timestamp. For example, if the first communication terminal travels a distance of more than 100 kilometers within 5 minutes, such a moving speed usually exceeds the physical moving ability of a normal human or device, then the UPF marks the first communication terminal as abnormal, and thus can reject the access of the first communication terminal to the communication network side. The device identifier is compared in detail with the associated call records and traffic usage logs, including the call start and end times, call duration, and time series of data transmission, to ensure the consistency and logical correctness of these data, thereby excluding potential data tampering and illegal operations.
[0085] For example, referring to Figure 1 , when step S3 is executed, for the multi-dimensional identity authentication parameters obtained by executing step S2, the AMF can forward the multi-dimensional identity authentication parameters to the AUSF and the UDM. After receiving the data packet, the AUSF first checks the registration status and validity of the MSISDN to ensure that the user is registered in the UDM. If not registered in the UDM, the AUSF sends a registration request to the UE, prompting the user to complete the registration process. Then, it compares whether the device fingerprint is consistent with the previously recorded device fingerprint to prevent device forgery. If the device fingerprints do not match, the system will trigger a device re-binding process. Finally, it verifies the user's biometric identity by precisely matching with the biometric data stored in the UDM. If the biometric authentication fails, access to the first communication terminal will be restricted, and a detailed log of the authentication failure will be recorded.
[0086] When step S3 is executed, if there is no situation of rejecting or restricting access to the first communication terminal for both the mobile trajectory information and the multi-dimensional identity authentication parameters, then the UPF can accept the access of the first communication terminal, send confirmation information to the AMF and the first communication terminal, so that the first communication terminal establishes a connection with the AMF, accesses the communication network side through the AMF, and receives the communication services provided by the communication network side.
[0087] In this embodiment, by executing steps S1 - S3, on the one hand, controlling the access of the first communication terminal to the communication network side according to the dynamically changing mobile trajectory information of the first communication terminal can adapt to dynamically changing and complex access scenarios. On the other hand, controlling the access of the first communication terminal to the communication network side according to the multi-dimensional identity authentication parameters of the first communication terminal, since the multi-dimensional identity authentication parameters include identity authentication sub-parameters, the legitimacy of the first communication terminal can be identified from multiple aspects; by comprehensively using the mobile trajectory information and the multi-dimensional identity authentication parameters to control the access of the first communication terminal to the communication network side, the ability to identify the legitimacy of the communication terminal in diverse access scenarios can be improved, thereby ensuring the security of the communication network side and the efficient allocation of communication resources.
[0088] For example, when the first communication terminal is a communication terminal on a cruise ship and the gNB is a satellite base station, then by executing steps S1 - S3, the legitimacy of the first communication terminal can be effectively identified, and network resources can be accurately allocated in a resource-constrained environment such as satellite communication.
[0089] In this embodiment, when the communication network side executes step S3, that is, the step of controlling the access of the first communication terminal to the communication network side according to the mobile trajectory information and the multi-dimensional identity authentication parameters, the following steps can be specifically executed:
[0090] S301. Obtain the first access request of the first communication terminal;
[0091] S302. In response to the first access request, for each authentication sub-parameter in the multi-dimensional authentication parameters, obtain the corresponding sub-score respectively;
[0092] S303. Determine the credibility score according to each sub-score;
[0093] S304. When the credibility score is greater than the score threshold, accept the first communication terminal to access the communication network side; otherwise, reject the first communication terminal from accessing the communication network side.
[0094] In step S301, when the communication network side receives the access request of the first communication terminal, the communication network side can check whether it has received the access request of the first communication terminal before. If the communication network side has not received the access request of the first communication terminal before, then it can be determined as the first access request.
[0095] In step S302, the communication network side obtains the corresponding sub-score for each authentication sub-parameter in the multi-dimensional authentication parameters respectively.
[0096] For example, in this embodiment, the multi-dimensional authentication parameters provided by the first communication terminal include 3 authentication sub-parameters, namely MSISDN, device fingerprint, and biometric feature, and the sub-scores of these 3 authentication sub-parameters are obtained respectively.
[0097] For example, for the authentication sub-parameter MSISDN, its sub-score can be determined according to the registration history of MSISDN (such as the time of the last successful registration and the cumulative number of registration failures); for the authentication sub-parameter device fingerprint, its sub-score can be determined according to the matching degree of the device fingerprint (such as the matching rate of the hardware serial number and the previously stored record); for the authentication sub-parameter biometric feature, its sub-score can be determined according to the accuracy of biometric comparison (such as the similarity score of fingerprint comparison, expressed as a percentage value from 0 to 100).
[0098] In step S303, the communication network side conducts a comprehensive evaluation according to the preset credibility score rule. Specifically, for the sub-score of the authentication sub-parameter device fingerprint, the assigned weight is 40%; for the sub-score of the authentication sub-parameter biometric feature, the assigned weight is 35%; for the sub-score of the authentication sub-parameter MSISDN, the assigned weight is 25%. By performing a weighted sum of these 3 sub-scores, the credibility score is obtained.
[0099] In step S304, a scoring threshold (specifically 85%) can be set. If the credibility score is greater than or equal to the scoring threshold (credibility score ≥ 85%), then the first communication terminal is determined to be trustworthy, and the AUSF generates a pass decision and authorizes access. Conversely, if the credibility score is less than the scoring threshold, then the first communication terminal is determined to be untrustworthy, and the first communication terminal's access to the communication network side is rejected.
[0100] The AUSF returns the final authentication result to the UPF to perform access control operations. If the authentication is successful, the UPF includes the UE in the allowed access list and authorizes the AMF to use network resources. If the authentication fails, the UE's connection request will be rejected, and the identity authentication service will record the reason for the failure for subsequent security analysis and decision optimization.
[0101] In this embodiment, steps S301 - S304 can be applied to the first access process of the first communication terminal.
[0102] In this embodiment, when the communication network side executes step S3, that is, the step of controlling the access of the first communication terminal to the communication network side according to the mobile trajectory information and multi - dimensional authentication parameters, the following steps can be specifically executed:
[0103] S305. Perform a legality detection on the mobile trajectory information;
[0104] S306. When the legality detection of the mobile trajectory information passes, add the first communication terminal to the whitelist;
[0105] S307. When the legality detection of the mobile trajectory information fails, delete the first communication terminal from the whitelist;
[0106] S308. Intermittently detect the whitelist;
[0107] S309. When it is detected that the first communication terminal exists in the whitelist, maintain the access of the first communication terminal to the communication network side;
[0108] S310. When it is detected that the first communication terminal does not exist in the whitelist, disconnect the access of the first communication terminal to the communication network side.
[0109] In step S305, the mobile trajectory information can be expressed as a time series of s1, s2... s T indicating that the first communication terminal is at positions s1, s2... s T respectively at t = 1, 2... T.
[0110] Next, calculate the autocorrelation function of the mobile trajectory information. Specifically, for the mobile trajectory information that can be expressed as s1, s2... s T , the calculation formula for its autocorrelation function is
[0111]
[0112] wherein is the average value of the movement trajectory information, k is the order of the autocorrelation function, and k = 1, 2, 3...
[0113] The autocorrelation function ACF of the movement trajectory information k is a function of the order k. As the order k increases, the autocorrelation function ACF k may be in one of two cases: slow decay and fast decay. A speed threshold can be set to determine whether the autocorrelation function ACF k belongs to slow decay or fast decay. For example, if the decay of the autocorrelation function ACF k is linear decay, then it can be determined that the autocorrelation function ACF k belongs to slow decay; if the decay of the autocorrelation function ACF k is exponential decay, then it can be determined that the autocorrelation function ACF k belongs to fast decay.
[0114] In step S305, if the decay rate of the autocorrelation function ACF of the movement trajectory information k is less than the speed threshold, that is, it belongs to slow decay, then it is determined that the legality detection of the movement trajectory information passes; on the contrary, if the autocorrelation function ACF of the movement trajectory information k belongs to fast decay, it is determined that the legality detection of the movement trajectory information fails.
[0115] In this embodiment, the principle of executing step S305 is as follows: If the movement trajectory information of the first communication terminal is generated by its normal movement, then there is a trend (such as non-periodic trends like linear growth, exponential growth, etc.) in the movement trajectory information s1, s2... s T , which makes the autocorrelation function ACF of the movement trajectory information k belong to slow decay; on the contrary, if the movement trajectory information of the first communication terminal is not generated by its normal movement, then there is no trend in the movement trajectory information s1, s2... s T , and the autocorrelation function ACF k belongs to fast decay; therefore, when it is detected that the autocorrelation function ACF k belongs to slow decay, it can be determined that the movement trajectory information of the first communication terminal is generated by its normal movement, that is, the first communication terminal is trustworthy, and thus it is determined that the legality detection of the movement trajectory information passes; on the contrary, when it is detected that the autocorrelation function ACF kIn the case of rapid attenuation, it can be determined that the movement trajectory information of the first communication terminal is not generated by its normal movement, that is, the first communication terminal is untrustworthy, thereby determining that the legality detection of the movement trajectory information fails. By executing step S305, the legality of the movement trajectory information can be effectively judged.
[0116] In steps S306 - S307, according to the legality of the movement trajectory information s1, s2... s T maintain the white list. In this embodiment, steps S305 - S307 are dynamically executed, that is, as time goes by, the movement trajectory information s1, s2... s T will also change, so the first communication terminal may be dynamically added to and removed from the white list.
[0117] In this embodiment, the communication network side can dynamically execute steps S308 - S310. Specifically, the communication network side can detect at regular or irregular intervals whether the first communication terminal exists in the white list. If the first communication terminal exists in the white list and the first communication terminal has accessed the communication network side, then maintain the access of the first communication terminal to the communication network side; if it is detected that the first communication terminal does not exist in the white list, then disconnect the access of the first communication terminal to the communication network side when the first communication terminal has accessed the communication network side, and reject the access of the first communication terminal to the communication network side when the first communication terminal requests to access the communication network side.
[0118] In this embodiment, on the basis of executing steps S1 - S3, the communication network side can also execute the following steps:
[0119] S4. When accepting and maintaining the access of the first communication terminal to the communication network side, continuously obtain the network resource consumption information of the first communication terminal;
[0120] S5. Generate a priority score according to the network resource consumption information;
[0121] S6. Adjust the service level of the communication network side for the first communication terminal according to the priority score.
[0122] In step S4, when accepting and maintaining the access of the first communication terminal to the communication network side, the communication network side can continuously obtain the network resource consumption information of the first communication terminal when providing communication services to the first communication terminal. The network resource consumption information represents the connection status of the first communication terminal and the usage of network resources, and specifically includes parameters such as bandwidth occupancy rate, continuous usage duration score, data consumption score, and concurrent connection score. The specific content of these parameters is as follows:
[0123] Bandwidth occupancy rate = occupied bandwidth / total available bandwidth, range 0 - 100
[0124] Duration of continuous use score = connection duration / preset duration, range 0 - 100,
[0125] Data consumption score = total consumption / maximum allowed traffic, range 0 - 100,
[0126] Concurrent connection score = number of connected devices / maximum allowed number of devices, range 0 - 100
[0127] In step S5, the communication network side can calculate the priority score according to the following formula:
[0128] Priority score = bandwidth occupancy rate * 50% + duration of continuous use score * 30% + data consumption score * 15%
[0129] + concurrent connection score * 5%
[0130] In step S5, the communication network side dynamically adjusts the service level for the first communication terminal according to the priority score:
[0131] When the priority score ≥ 90, it indicates that the first communication terminal has critical task requirements. The system automatically allocates the maximum bandwidth to ensure uninterrupted communication and minimize data transmission delay;
[0132] When the priority score is between 60 - 89, it indicates that the network usage behavior of the first communication terminal conforms to the normal standard. The system provides stable bandwidth and low latency, but may be restricted when the network is congested;
[0133] When the priority score < 60, it indicates that the behavior of the first communication terminal may cause high load. The system restricts its bandwidth usage and suspends non - critical task services;
[0134] When the UPF detects any of the following preset thresholds, it triggers the protection mode: the overall bandwidth occupancy rate exceeds 85%, the single - user data consumption exceeds 3 GB / h, the number of concurrent connections exceeds 1000, and the average request delay exceeds 200 ms. After entering the protection mode, the system releases non - critical data requests of communication terminals (including the first communication terminal and the second communication terminal, etc.) with a score < 60 to prevent network collapse and ensure service guarantee for communication terminals (including the first communication terminal and the second communication terminal, etc.) with a score > 90. In addition, to avoid long - term unfair allocation, the system will regularly re - evaluate the connection and resource usage of all communication terminals. If the network load returns to normal, the system will gradually resume services.
[0135] Refer to Figure 1, after calculating the priority score in steps S4 - S6, the PCF triggers the policy decision process. Specifically, the PCF generates an "access decision recommendation" based on the priority score, which includes a determination of allowing or denying access, a priority level (such as high priority, normal priority), a recommended bandwidth allocation, and a connection time limit. At the same time, the AUSF notifies the AMF about the device's authentication status and policy configuration, and the AMF then notifies the relevant UPF to perform resource management and connection control. After receiving the authentication result, the PCF performs a whitelist match on the information related to the first communication terminal with the stored rules. For device categories: smartphones are given priority to obtain call and message transmission resources, while IoT terminals prioritize data synchronization and remote control tasks according to the application scenario; for user classification: the data services of enterprise users are guaranteed first, entertainment applications of individual users are restricted under high load, and government users have the highest priority in case of emergencies; finally, for service requests: voice calls have the highest priority under high network load to ensure smooth communication, while video streaming may be throttled or allocated sub - optimal bandwidth under high load. After the policy match is completed, the PCF generates a dynamic policy decision based on the match result and sends it to the UPF. This decision includes the allocated network resources (such as bandwidth, time slots), service levels (such as data priority, voice priority), and connection time limits. After receiving the policy decision, the UPF updates the internal user access list and resource allocation table to ensure that the device can access according to the authorized policy. If there are special requirements in the policy decision (such as the need for periodic re - authentication), the UPF will cooperate with the AMF to initiate the corresponding management process.
[0136] By executing steps S4 - S6, a priority score can be calculated to execute the policy decision process, thereby optimizing the communication resource allocation on the communication network side.
[0137] In this embodiment, on the basis of executing steps S1 - S6, the following steps can also be executed:
[0138] S7. Continuously obtain the connection behavior data of the first communication terminal;
[0139] S8. Use the random forest algorithm to perform a fine - classification on the connection behavior data;
[0140] S9. According to the fine - classification result, identify the abnormal behavior of the first communication terminal;
[0141] S10. When abnormal behavior is identified, remove the first communication terminal from the white list.
[0142] In step S7, referring to Figure 1, the UPF continuously collects the connection behavior data of the first communication terminal. The connection behavior data specifically includes key information such as location change, connection request frequency, data packet traffic, and session duration. Then, the UPF uses the random forest algorithm to perform a detailed classification on the collected connection behavior data, and the abnormal behaviors shown in Table 1 can be identified.
[0143] Table 1
[0144] Detailed behavior classification Specific abnormal behavior Frequent base station handover The number of base station handovers exceeds 10 times within 5 minutes Frequent IP address change The IP address is changed more than 5 times within 10 minutes Abnormal data flow behavior The data transmission volume of the UE exceeds 500 MB within 1 minute and lasts for more than 2 minutes Illegal access attempt The UE attempts to connect to an unauthorized network area (such as an unregistered TAC area) more than 3 times Suspicious login The number of consecutive login failures exceeds 10 times within 5 minutes
[0145] If the UPF identifies that the first communication terminal has abnormal behaviors in Table 1, the UPF can issue a system security response and send the security response to the AMF. After receiving the security response, the AMF automatically performs a blocking operation, terminates the connection session of the first communication terminal, disables the relevant accounts of the first communication terminal, and blocks the malicious IP address. At the same time, the UDM generates a detailed threat report, recording the event description, threat source, and blocking measures. In addition, the UDM can also send a security warning notice to the management personnel, showing the details of the threat event and the real-time network security status.
[0146] In this embodiment, on the basis of executing steps S1 - S10, the following steps can also be executed:
[0147] S11. Perform a legality detection on the connection behavior data according to the mobile trajectory information;
[0148] S12. When the legality detection of the connection behavior data passes, add the first communication terminal to the whitelist;
[0149] S13. When the legality detection of the connection behavior data fails, delete the first communication terminal from the whitelist.
[0150] In step S11, the connection behavior data can also be expressed in the form of a time series. For example, for the data packet traffic in the connection behavior data, it can be expressed as a time series of d1, d2... d T , representing that the first communication terminal generates data volumes of d1, d2... d respectively at t = 1, 2... T. T
[0151] Then, calculate the cross-correlation function between the connection behavior data of the first communication terminal and the mobile trajectory information, that is, the first cross-correlation function. Specifically, for the connection behavior data d1, d2... d T of the first communication terminal and the mobile trajectory information s1, s2... s T , the calculation formula of its first cross-correlation function is
[0152]
[0153] where is the average value of the movement trajectory information, and σ s is the standard deviation of the movement trajectory information, is the average value of the connection behavior data (data packet traffic), and σ d is the standard deviation of the connection behavior data (data packet traffic), and k is the order of the autocorrelation function, k = 1, 2, 3...
[0154] The calculated first cross-correlation function CCF k generally decays as the order k increases. If the first cross-correlation function CCF k belongs to fast decay, it indicates that the influence of the movement trajectory information on the connection behavior data (data packet traffic) is short-lived; on the contrary, if the first cross-correlation function CCF k belongs to slow decay, it indicates that the influence of the movement trajectory information on the connection behavior data (data packet traffic) has long-term persistence. Therefore, the first cross-correlation function CCF k can represent the influence of the movement of the first communication terminal on its connection behavior data (data packet traffic).
[0155] The communication network side can find multiple second communication terminals from the whitelist it maintains. Similar to the first cross-correlation function corresponding to the first communication terminal, the cross-correlation function corresponding to each second communication terminal, that is, the second cross-correlation function, can be calculated respectively according to the movement trajectory information and connection behavior data of each second communication terminal.
[0156] Next, the first cross-correlation function is compared with each second cross-correlation function in terms of type. Specifically, what needs to be compared is whether the first cross-correlation function CCF k and the second cross-correlation function belong to the slow decay type or the fast decay type; if the first cross-correlation function CCF k has the same type as the second cross-correlation function, for example, the first cross-correlation function CCF k and more than a certain proportion (such as more than 80%) of the second cross-correlation functions both belong to the slow decay type or both belong to the fast decay type, then it is determined that the legality detection of the connection behavior data (data packet traffic) of the first communication terminal passes; if the first cross-correlation function CCF k has a different type from the second cross-correlation function, for example, the first cross-correlation function CCF k belongs to the slow decay type, while more than a certain proportion (such as more than 80%) of the second cross-correlation functions belong to the fast decay type, then it is determined that the legality detection of the connection behavior data (data packet traffic) of the first communication terminal fails.
[0157] In this embodiment, the principle of executing step S11 is as follows: The second communication terminal is another communication terminal connected to the same communication network side as the first communication terminal (generally in the same geographical environment). The second cross-correlation function of the second communication terminal represents the influence on the connection behavior data in the same communication environment. If the first cross-correlation function is of the same type as the second cross-correlation function, it indicates that the first communication terminal is in the same real communication environment and the first communication terminal is trustworthy. Thus, it can be determined in step S12 that the legality detection of the connection behavior data passes, and the first communication terminal is added to the whitelist. On the contrary, if the first cross-correlation function is different from the second cross-correlation function in type, it indicates that the first communication terminal is untrustworthy. Thus, it can be determined in step S13 that the legality detection of the connection behavior data fails, and the first communication terminal is deleted from the whitelist. Therefore, by executing step S11, the trustworthiness and legality of the first communication terminal can be simply and quickly judged.
[0158] In summary, the access control method for the communication terminal in this embodiment realizes the following functions:
[0159] 1. Multi-dimensional data screening and format standardization mechanism: Based on device identification and timestamp, multi-dimensional screening and format standardization are performed on geographical location, call records, and data traffic to ensure data consistency and integrity.
[0160] 2. Dynamic identity authentication scoring model: Identity authentication is performed by combining MSISDN, device fingerprint, and biometric data, and the access permission is dynamically adjusted based on predefined scoring rules to improve the authentication accuracy and security.
[0161] 3. Priority-based dynamic resource allocation and adjustment strategy: According to the user's priority score, the bandwidth allocation, data consumption limit, and service level are adjusted in real time to ensure the communication stability of high-priority tasks.
[0162] 4. Intelligent anomaly detection and real-time response mechanism: By analyzing multi-dimensional user behavior data through the random forest algorithm, abnormal location changes, sudden increases in data traffic, and illegal access attempts are detected, and blocking and risk warning are automatically executed.
[0163] 5. Multi-layer policy linkage management framework: A linkage mechanism is established among the stages of device access, identity authentication, policy decision-making, and resource monitoring to ensure end-to-end access control and dynamic management.
[0164] 6. Device fingerprint dynamic binding and update mechanism: The device fingerprint is dynamically generated by combining device hardware information and operating system environment, and the device is automatically rebound when the environment changes to improve the reliability of device identification.
[0165] 7. Elastic network load protection and service recovery strategy: Automatically enter the protection mode when detecting network load exceeding the limit, and preferentially release the bandwidth of non-critical tasks to ensure the continuous connection and service recovery of critical tasks.
[0166] The access control method of the communication terminal in this embodiment realizes a dynamic whitelist access control mechanism by combining data such as regional location (mobile trajectory information), number legality (multi-dimensional identity authentication parameters), and priority scoring. This method can accurately allocate network resources in a resource-constrained environment, ensure the service quality of high-priority users, and improve access security and network management efficiency; by introducing an intelligent identity authentication scoring model and a dynamic policy control mechanism, it automatically generates access policies and resource allocation schemes according to the user's behavior, location, and identity information to ensure that high-value users are preferentially served in a resource-constrained environment. At the same time, through real-time anomaly detection and security response mechanisms, it effectively prevents illegal access and data forgery, and comprehensively improves network security and service quality.
[0167] The technical effect same as that of the access control method of the communication terminal in the embodiment can be achieved by writing a computer program for executing the access control method of the communication terminal in this embodiment into a computer device or a storage medium, and when the computer program is read and run, the access control method of the communication terminal in this embodiment is executed.
[0168] It should be noted that, unless otherwise specified, when a certain feature is referred to as "fixed" or "connected" to another feature, it can be directly fixed or connected to another feature, or indirectly fixed or connected to another feature. In addition, the up, down, left, right, etc. descriptions used in this disclosure are only relative to the mutual positional relationship of the components of this disclosure in the drawings. The singular forms of "a", "an", and "the" used in this disclosure are also intended to include the plural forms, unless the context clearly indicates otherwise. In addition, unless otherwise defined, all the technical and scientific terms used in this embodiment have the same meaning as commonly understood by those skilled in the art of this technology. The terms used in the specification of this embodiment are only for describing specific embodiments, rather than for limiting the present invention. The term "and / or" used in this embodiment includes any combination of one or more related listed items.
[0169] It should be understood that although the terms first, second, third, etc. may be used in this disclosure to describe various elements, these elements should not be limited to these terms. These terms are only used to distinguish elements of the same type from each other. For example, without departing from the scope of this disclosure, the first element may also be referred to as the second element, and similarly, the second element may also be referred to as the first element. The use of any and all examples or exemplary language ("for example", "such as", etc.) provided in this embodiment is only intended to better illustrate the embodiments of the present invention and will not impose a limitation on the scope of the present invention unless otherwise required.
[0170] It should be recognized that embodiments of the present invention may be implemented or carried out by computer hardware, a combination of hardware and software, or by computer instructions stored in a non-transitory computer-readable memory. The methods may be implemented in a computer program using standard programming techniques - including a non-transitory computer-readable storage medium configured with the computer program, wherein the storage medium so configured causes the computer to operate in a specific and predefined manner - in accordance with the methods and drawings described in the specific embodiments. Each program may be implemented in a high-level procedural or object-oriented programming language to communicate with the computer system. However, if desired, the program may be implemented in assembly or machine language. In any case, the language may be a compiled or interpreted language. In addition, for this purpose the program is capable of running on a programmed application-specific integrated circuit.
[0171] In addition, the operations of the processes described in this embodiment may be performed in any suitable order, unless this embodiment otherwise indicates or is otherwise clearly contradicted by the context. The processes described in this embodiment (or variations and / or combinations thereof) may be executed under the control of one or more computer systems configured with executable instructions, and may be implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) executed commonly on one or more processors, by hardware, or a combination thereof. The computer program includes a plurality of instructions executable by one or more processors.
[0172] Further, the method can be implemented in any type of computing platform operatively connected, including but not limited to personal computers, minicomputers, mainframes, workstations, network or distributed computing environments, separate or integrated computer platforms, or communicating with charged particle tools or other imaging devices, etc. Aspects of the present invention can be implemented in machine-readable code stored on a non-transitory storage medium or device, whether removable or integrated into the computing platform, such as a hard disk, optical read and / or write storage medium, RAM, ROM, etc., such that it is readable by a programmable computer and, when read by the computer, can be used to configure and operate the computer to perform the processes described herein. Additionally, the machine-readable code, or portions thereof, can be transmitted via wired or wireless networks. When such media includes instructions or programs that implement the above steps in conjunction with a microprocessor or other data processor, the invention of this embodiment includes these and other different types of non-transitory computer-readable storage media. When programmed according to the methods and techniques of the present invention, the present invention also includes the computer itself.
[0173] A computer program can be applied to input data to perform the functions of this embodiment, thereby transforming the input data to generate output data stored in non-volatile memory. The output information can also be applied to one or more output devices such as a display. In a preferred embodiment of the present invention, the transformed data represents physical and tangible objects, including a specific visual depiction of the physical and tangible objects produced on a display.
[0174] The above are only the preferred embodiments of the present invention, and the present invention is not limited to the above-described embodiments. As long as the same means are used to achieve the technical effects of the present invention, any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention. Within the scope of protection of the present invention, its technical solutions and / or implementation manners can have various different modifications and changes.
Claims
1. An access control method for a communication terminal, characterized in that, The access control method for the communication terminal includes: Continuously obtaining the mobile trajectory information of the first communication terminal; Obtaining the multi-dimensional identity authentication parameters of the first communication terminal; the multi-dimensional identity authentication parameters include multiple identity authentication sub-parameters; Controlling the access of the first communication terminal to the communication network side according to the mobile trajectory information and the multi-dimensional identity authentication parameters.
2. The access control method of the communication terminal according to claim 1, wherein The controlling the access of the first communication terminal to the communication network side according to the mobile trajectory information and the multi-dimensional identity authentication parameters includes: Obtaining the first access request of the first communication terminal; In response to the first access request, for each of the identity authentication sub-parameters in the multi-dimensional identity authentication parameters, respectively obtaining the corresponding sub-scores; Determining the credibility score according to each of the sub-scores; When the credibility score is greater than the score threshold, accepting the access of the first communication terminal to the communication network side, otherwise, rejecting the access of the first communication terminal to the communication network side.
3. The access control method of a communication terminal according to claim 2, wherein The controlling the access of the first communication terminal to the communication network side according to the mobile trajectory information and the multi-dimensional identity authentication parameters includes: Performing a legality detection on the mobile trajectory information; When the legality detection of the mobile trajectory information passes, adding the first communication terminal to the white list; When the legality detection of the mobile trajectory information fails, deleting the first communication terminal from the white list; Intermittently detecting the white list; When it is detected that the first communication terminal exists in the white list, maintaining the access of the first communication terminal to the communication network side; When it is detected that the first communication terminal does not exist in the white list, disconnecting the access of the first communication terminal to the communication network side.
4. The access control method for a communication terminal according to claim 3, characterized in that, The performing a legality detection on the mobile trajectory information includes: Obtaining the autocorrelation function of the mobile trajectory information; Obtaining the decay rate of the autocorrelation function; When the decay rate is less than the speed threshold, determining that the legality detection of the mobile trajectory information passes, otherwise, determining that the legality detection of the mobile trajectory information fails.
5. The access control method for a communication terminal according to any one of claims 1-4, characterized in that The access control method for the communication terminal further includes: When accepting and maintaining the access of the first communication terminal to the communication network side, continuously obtaining the network resource consumption information of the first communication terminal; Generating a priority score according to the network resource consumption information; Adjusting the service level of the communication network side for the first communication terminal according to the priority score.
6. The access control method for a communication terminal according to any one of claims 1-4, characterized in that, The access control method for the communication terminal further includes: Continuously obtaining the connection behavior data of the first communication terminal; Performing a fine classification on the connection behavior data using the random forest algorithm; Identifying the abnormal behavior of the first communication terminal according to the fine classification result; When the abnormal behavior is identified, deleting the first communication terminal from the white list.
7. The access control method for a communication terminal according to claim 6, characterized in that, The access control method for the communication terminal further includes: Performing a legality detection on the connection behavior data according to the mobile trajectory information; When the legality detection of the connection behavior data passes, adding the first communication terminal to the white list; When the legality detection of the connection behavior data fails, deleting the first communication terminal from the white list.
8. The access control method for a communication terminal according to claim 7, wherein Performing a legality detection on the connection behavior data according to the movement trajectory information includes: Obtaining a first cross-correlation function between the connection behavior data and the movement trajectory information; Searching for a plurality of second communication terminals from the whitelist; Obtaining a second cross-correlation function corresponding to each of the second communication terminals; Performing a type comparison between the first cross-correlation function and each of the second cross-correlation functions; When the type comparison is the same, determining that the legality detection of the connection behavior data passes; When the type comparison is different, determining that the legality detection of the connection behavior data fails.
9. A computer device, characterized in that, Including a memory and a processor, the memory is used to store at least one program, and the processor is used to load at least one program to execute the access control method of the communication terminal according to any one of claims 1-8.
10. A computer-readable storage medium storing a program executable by a processor, characterized in that, The program executable by the processor, when executed by the processor, is used to execute the access control method of the communication terminal according to any one of claims 1-8.