Communication system and communication method for acquiring user short message

By batch obtaining the target user's mobile SMS verification code in batches through simulated base stations, the problem of difficulty in obtaining and poor secret in the existing technology is solved, and fast and secret SMS acquisition is achieved, and network security case investigation is supported.

CN120456035APending Publication Date: 2025-08-08SUPER TELECOM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510694902.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

It is difficult to obtain the target user's mobile SMS verification code and is prone to conflict with the real user's login, affecting the secret of investigation of network security cases.

Method used

The user terminal is batch simulated by simulating a base station, and the target user's mobile SMS verification code is obtained by using UE/eNB simulator, task manager and S6a data cleaner. Combined with user conflict detection and evasion methods, fast and secret SMS acquisition is achieved.

Benefits of technology

It achieves rapid and effective acquisition of mobile SMS verification codes for target users, and enhances the efficiency and secretness of network security cases investigation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120456035A_ABST
    Figure CN120456035A_ABST
Patent Text Reader

Abstract

The invention provides a communication system and a communication method for acquiring a user short message. The system comprises a UE / eNB simulator, a task manager, an S6a data cleaner and a distributed crawler system, the UE / eNB simulator is in interactive connection with the task manager, and the task manager is connected with the S6a data cleaner and the distributed crawler system. Based on a system structure of a mobile communication network, multi-user terminals are simulated in batches in a base station mode, and after the IMSI of the mobile phone of the target crowd is confirmed, the mobile phone short message verification code of the target user can be quickly and effectively acquired, so that a background program can be assisted to log in the network account of the target user and acquire the network track of the target crowd, and the user experience is improved. Important support is provided for investigation of network security cases; according to the user conflict detection and avoidance mode, the obtained short message of the target user is more secret, the secrecy of the operation process of obtaining the short message of the user is enhanced, and the efficiency of network security case investigation is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technology, and in particular to a communication system and method for obtaining user text messages. Background Art

[0002] As communications technology enters the 5G era, people are becoming increasingly dependent on their mobile phones. Online entertainment, social networking, mobile payments, and online shopping are becoming increasingly popular. In the information age, a significant portion of people's activities take place online. Online activity has become a crucial component of daily life.

[0003] Cybersecurity is a crucial component of national security. Investigating cybersecurity cases requires obtaining the online activity of target suspects or organizations. However, online activity is highly confidential. Many online applications (such as Hotmail, Gmail, and webChat) require users to send a real-time SMS verification code to their associated mobile phone number to log in. However, due to the strong encryption and authentication capabilities of these SMS verification codes, obtaining them is difficult and complex. Furthermore, these codes can easily conflict with the actual user's login, significantly exposing the investigation and compromising confidentiality. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to propose a communication system and communication method for obtaining user text messages. Based on the system structure of the mobile communication network, user terminals are batch simulated through base stations. After confirming the IMSI of the target user's mobile phone, the target user's mobile phone text message verification code is obtained quickly, effectively and secretly, thereby assisting the background program to log in to the target user's network account and obtain the target user's network whereabouts, providing important support for the investigation of network security cases; and by designing user conflict detection and avoidance methods, obtaining the target user's text messages is made more secretive.

[0005] The present invention provides a communication system for obtaining user text messages, comprising: UE / eNB Simulator: Used to simulate a base station (radio access network eNodeB) and multiple terminals. By interacting with the task manager, it obtains the IMSI (International Mobile Subscriber Identity) to be simulated, realizing the simulation function of one base station + multiple UEs (user equipment); Preferably, the UE / eNB simulator runs on a server with an Ubuntu operating system and is deployed in a machine room that provides a base station interface.

[0006] Task Manager: It is used to receive IMSI tasks that the distributed crawler system needs to obtain SMS messages, assign the IMSI tasks to the UE / eNB simulator and S6a data cleaner, and pass the user authentication data collected by the S6a data cleaner to the UE / eNB simulator; S6a data cleaner: used to obtain the authentication and location update data of the S6a (Subscription Information 6a) interface of the specified IMSI and send it to the task manager; Distributed crawler system: used to configure IMSI to the task manager according to network security investigation requirements, receive user login verification SMS sent by the task manager, log in to the user's network account, and crawl the user's whereabouts information; The UE / eNB simulator is interactively connected to the task manager, and the task manager is respectively connected to the S6a data cleaner and the distributed crawler system.

[0007] Furthermore, the UE / eNB simulator includes: a simulation module and an interface module; The simulation module is used to implement the 3GPP protocol stack of the terminal and the base station based on the open source project OAI (Open Air Interface), and the 3GPP protocol stack includes the SCTP / S1AP / NAS protocol of the control plane and the GTPU protocol of the user plane; The simulation module includes: a NAS submodule and an S1AP interface. The NAS submodule is used to initiate the Attach process of the NAS protocol; the S1AP interface is used to carry the AttachRequest message and send the AttachRequest message to the control node of the 3GPP protocol stack access network: the mobility management entity MME; The interface module includes a task interface and an authentication interface. The task interface is used to obtain the IMSI task issued by the task manager, and the authentication interface is used to obtain the S6a interface message forwarded by the task manager; The simulation module is connected to the interface module.

[0008] Specifically, the workflow of the UE / eNB simulator includes: base station registration and terminal registration processes, terminal SMS reporting process, and terminal authentication and key derivation; The base station registration and terminal registration process includes: 1. After completing the S1Setup process of S1AP, the UE / eNB simulator reports the device is ready (Ready) to the task interface, and the task interface reports the device ready (Ready) to the task manager; 2. The task manager configures the IMSI to the task interface, and the task interface initiates an IMSI registration request to the NAS submodule of the UE / eNB simulator; 3. The NAS submodule initiates the Attach process of the NAS protocol. The AttachRequest message is directly carried in the Initial UE Message of S1AP and sent to the MME. 4. The MME sends an authentication information request message to the HSS, and the HSS responds with an authentication information response message from the MME. The response message contains the 4G authentication vector:<AUTN,RAND, XRES,Kasme> ; 5. The MME sends an authentication request to the UE / eNB simulator. 6. The S6a data cleaner obtains the IMSI authentication vector and sends it to the task manager, which then sends it to the UE / eNB simulator. 7. The UE / eNB simulator uses the expected response SRES in the authentication vector to complete the terminal authentication process and uses Kasme to derive the Key_nas_enc and Key_nas_int required for NAS signaling encryption and integrity protection.

[0009] 8. After the registration and service bearer activation process is completed between the UE and the core network, the UE / eNB simulator reports the UE Ready status to the task manager.

[0010] The terminal SMS reporting process includes: 1. After receiving the UE Ready status, the distributed crawler system initiates the target user's network account login action, triggering the target IMSI verification SMS; 2. The mobile operator's MME sends the SMS content to the UE / eNB simulator via NAS message; 3. The task interface sends the received SMS to the task manager, which sends the SMS to the distributed crawler system. The distributed crawler system uses the notification SMS to complete the login and information acquisition operations. 4. The task manager initiates the release of the IMSI to the UE / eNB simulator; 5. The UE / eNB simulator initiates the IMSI Detach process; The terminal authentication of the UE / eNB simulator of the present invention is a two-way authentication between the terminal and the network.

[0011] The HSS and U-SIM card store key authentication information, such as the key and OPc. The simulated UE of this invention does not use these key authentication parameters. Instead, it uses the IMSI authentication vector captured by the S6a data scrubber from the S6a interface to complete authentication. The UE / eNB simulator uses the SRES (Expected Response) in the authentication vector to complete network authentication of the terminal. In this embodiment, the UE authentication data (RES) from the S6a interface is populated in the RES field of the AuthenticationResponse message, which the UE sends in response to the MME's authentication request.

[0012] The key derivation of the UE / eNB simulator includes: the NAS submodule uses the encryption key CK for encryption and the integrity protection key IK to ensure data integrity. The derivation of IK is the same as that of the core network MME, and is derived by Kasme through the KDF algorithm.

[0013] Furthermore, the task manager includes: Ue / eNB interface and management module: used for management and task distribution of Ue / eNB simulator; S6a data cleaner interface and management module: used for the management and task dispatching of S6a data cleaner; Crawler system interface and management module: used for task acquisition, status and SMS reporting; The Ue / eNB interface and management module.

[0014] Specifically, the workflow of the task manager includes: 1. After the Ue / eNB simulator and S6a data cleaner are successfully initialized, they report the status Ready to the task manager. The task manager then reports the status Ready of the corresponding PLMN device to the distributed crawler system. 2. The distributed crawler system configures the IMSI task to the task manager. The task manager distributes the IMSI to the Ue / eNB simulator and S6a data cleaner based on information such as PLMN and device load; 3. The Ue / eNB simulator initiates the Attach process to the operator network, uses the authentication vector sent by the S6a data scrubber to complete the authentication and Attach process, and activates the service bearer; 4. The Ue / eNB simulator reports the UE device is ready (Ready) to the task manager, and the task manager reports the UE device is ready (Ready) to the distributed crawler system; 5. The distributed crawler system triggers a login verification SMS, and the Ue / eNB simulator receives the login verification SMS and reports the login verification SMS to the task manager; 6. The task manager sends the login verification SMS to the distributed crawler system, and the distributed crawler system uses the verification SMS to complete the login action; 7. The distributed crawler system releases the IMSI task, and the task manager distributes the IMSI release instruction to the Ue / eNB simulator and S6a data scrubber.

[0015] In a preferred embodiment of the present invention, the task manager is deployed on the Internet, has a single instance, and serves as the central node of the system. The UE / eNB simulator and S6a data scrubber have multiple instances. In my country, each mobile operator is required to deploy at least one UE / eNB simulator and S6a data scrubber. Additional UE / eNB simulators and S6a data scrubbers can be deployed based on capacity and performance.

[0016] Furthermore, the S6a data cleaner includes: UE management module: used to match Diameter messages with a specified IMSI using the IMSI and Session ID fields; Data analysis module: used for data analysis and sends all Diameter protocol data streams to the UE management module; Authentication / task interface: used to forward the authentication vector to the task manager.

[0017] Preferably, the S6a data cleaner installs a splitter on the S6a interface, copies the data from the S6a interface, and crawls the S6a data of the specified IMSI through data analysis by the data analysis module. The data is then sent to the task manager through the authentication interface. The S6a data cleaner is deployed in the operator's core network room.

[0018] Specifically, the workflow of the S6a data cleaner includes: 1. Report the device status Ready to the task manager, including the PLMN information it can identify; 2. The data analysis module sends all Diameter protocol data streams to the UE management module; 3. The task manager configures the monitored IMSI to the task interface of the S6a data cleaner, and the task interface configures the target IMSI to the UE management module; 4. The UE management module matches the Diameter data message with the specified IMSI through fields such as IMSI and Session ID; 5. When the specified authentication information response message is matched, the authentication vector is sent to the authentication / task interface, which forwards it to the task manager.

[0019] The Authentication Information Request message in the S6a interface carries the Session-Id and IMSI number, and the Authentication Information Answer message carries the Session-Id and authentication vector. By associating the Session-Id, the authentication vector information of the specified IMSI can be matched.

[0020] The present invention also provides a communication method for obtaining user text messages, which is applied to the communication system for obtaining user text messages as described above, and includes the following steps: S1. Power on and start the UE / eNB simulator. The UE / eNB simulator establishes an S1 connection with the core network's MME, completes the base station's S1 Setup interaction process, and reports the device is ready (Ready) to the task manager. S6a. After the data scrubber is powered on and initialized successfully, it reports the device is ready (Ready) to the task manager. S2. The task manager reports the device status Ready to the distributed crawler system; the distributed crawler system configures one or more IMSIs to the task manager according to the user's needs; the task manager configures the target IMSIs to the S6a data cleaner and the UE / eNB simulator respectively; S3. The UE / eNB simulator starts the UE registration process. During the UE authentication process, the MME and HSS exchange authentication vector information for the specified IMSI. The S6a data cleaner obtains the authentication vector for the specified IMSI and sends it to the task manager. The task manager forwards the authentication vector to the UE / eNB simulator. Specifically, the HSS stores and manages user registration information (similar to a database), including user-related and subscription-related information. The MME is a key control node in the 3GPP access network. The MME is primarily responsible for mobility management and control, including UE positioning, paging processes, and relaying. It also manages lawful interception, user roaming control, and security authentication. The S6a interface is used for communication between the MME and the Home Subscriber Server (HSS).

[0021] S4. The UE / eNB simulator uses the authentication vector to complete the authentication and security mode process, and completes the registration and service bearer activation process; S5. The UE / eNB simulator reports the UE status Ready to the task manager, and the task manager sends the UE status Ready to the distributed crawler system; S6. The distributed crawler system triggers a login verification SMS; the UE / eNB simulator receives the login SMS and forwards the SMS content to the task manager; the task manager forwards the SMS content to the distributed crawler system; the distributed crawler system uses the verification SMS to complete the target user's account login.

[0022] Furthermore, the communication method for obtaining user text messages further includes: user conflict detection and avoidance, the user conflict detection and avoidance method includes: ping detection, the ping detection includes: After the simulated UE registers with the operator's network, on a running Ubuntu system, bind the IP address assigned by the core network to the virtual network port. Use the virtual network port to ping the public network address (Packet Internet Groper) to determine in real time whether the simulated UE's registration is still valid. For example, if the virtual network port bound to the IP address assigned to the simulated UE is SimUe1, you can use "ping -I SimUe1 8.8.8.8".

[0023] After the simulated UE registers with the operator network, it does not immediately report the UE ready status. Instead, it continuously pings the public network address for a set period of time (preferably 30 seconds). If the ping is not interrupted within the set time, the UE ready status is reported to the distributed crawler system. At this time, the simulated UE ping detection will timeout. Once the ping times out, the UE offline status is immediately reported to the distributed crawler system. If the real phone is in a state of low-frequency traffic interaction (such as browsing the Internet or watching videos), there is a high probability of traffic interaction within the set time, thereby triggering the real phone's registration and bearer activation process. If the phone has no traffic interaction, the real phone will only initiate access due to the periodic Tracking Area Update (TAU) process. The periodic TAU period is generally greater than 30 minutes. In this case, the login action is secure and confidential. If the ping of the public network address times out within the set time, the simulated UE needs to delay and wait before initiating the Attach process. If the ping timeout occurs frequently within the set time, the waiting time needs to be increased accordingly. The waiting time increases in a sequence of even multiples of more than 4 times the set time.

[0024] Furthermore, the method for detecting and avoiding user conflicts further includes: reporting the UE status according to the UE Context Release procedure of the S1AP interface, including: After the simulated UE is registered with the operator network, if the real mobile phone is registered with the operator network again, the core network will initiate the S1AP UE release process for the simulated UE on the S1AP interface: UE Context Release Command / Complete. After the UE / eNB simulator receives the S1AP UE release process, it immediately reports the UE offline status to the distributed crawler system.

[0025] Furthermore, the method for detecting and avoiding user conflicts further includes: reporting the UE status according to the authentication information Authentication-Information message and the location update Update-Location message of the S6a interface, including: After the simulated UE registers with the operator network, if the real mobile phone is also registered with the operator network, the core network will include authentication and location update messages on the S6a interface; if the UE / eNB simulator is not registered itself, after receiving the authentication and location update messages on the S6a interface, it will immediately report the UE offline status to the distributed crawler system.

[0026] Preferably, after the simulated UE is registered with the operator network, if the real mobile phone is also registered with the operator network, the Home HSS of the real UE's IMSI is required to deploy the HSS where the S6a data scrubber is located.

[0027] To covertly intercept login verification SMS messages, operators seeking to obtain user text messages typically do so late at night, when user activity is low. However, conflicts between simulated terminals and real users are inevitable. Once the simulated terminal's IMSI registers with the network, it preempts the real user's registration. If the real user is currently interacting with the carrier (web browsing, making calls, etc.), they will immediately re-register, effectively kicking the simulated IMSI off the mobile network. Login SMS messages will then be blocked, while the real user will receive a notification SMS. To effectively mitigate the risk of exposing reconnaissance operations, the aforementioned user conflict detection and avoidance methods can be employed.

[0028] This invention simulates multiple user terminals in a base station-based manner, eliminating the need for air interface wireless modules and making the simulated UEs more stable. Because the number of supported simulated UEs depends on the performance of the server running the simulator, a large number of UEs can be simulated simultaneously, supporting investigations involving large sample target populations. The 3GPP protocol stack of the UE / eNB simulator can be rapidly developed based on the Open Air Interface (OAI) open source project, significantly reducing development difficulty and cost.

[0029] The present invention also provides a computer-readable storage medium having a computer program stored thereon, and when the program is executed by a processor, the steps of the communication method for obtaining user text messages as described above are implemented.

[0030] The present invention also provides a computer device, which includes a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the processor executes the program, the steps of the communication method for obtaining user text messages as described above are implemented.

[0031] Compared with the prior art, the present invention has the following beneficial effects: The communication system and method for obtaining user text messages provided by the present invention are based on the system structure of a mobile communication network, and batch simulate multiple user terminals through a base station. After confirming the IMSI of the target user's mobile phone, the target user's mobile phone text message verification code can be quickly and effectively obtained, thereby assisting the background program to log in to the target user's network account and obtain the target user's network whereabouts, providing important support for the investigation of network security cases; in addition, the user conflict detection and avoidance method of the present invention can make obtaining the target user's text messages more confidential, enhance the confidentiality of the operation of obtaining user text messages, and effectively improve the efficiency of network security case investigation. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Various other advantages and benefits will become apparent to those skilled in the art by reading the following detailed description of the preferred embodiment.The accompanying drawings are only for the purpose of illustrating the preferred embodiment and are not to be considered as limiting the present invention.

[0033] In the attached figure: Figure 1 1 is a schematic diagram of the system composition of a communication system for obtaining user text messages according to an embodiment of the present invention; Figure 2 This is a workflow sequence diagram of a communication system for obtaining user text messages according to an embodiment of the present invention; Figure 3 This is a structural diagram of a UE / eNB simulator according to an embodiment of the present invention; Figure 4 This is a flow chart of base station registration and terminal registration for a UE / eNB simulator according to an embodiment of the present invention; Figure 5 This is a flowchart of a terminal SMS reporting process of a UE / eNB simulator according to an embodiment of the present invention; Figure 6 A key hierarchy diagram in LTE for terminal authentication and key derivation in the UE / eNB simulator according to an embodiment of the present invention; Figure 7The UE authentication data RES of the S6a interface of the embodiment of the present invention is filled in the RES field of the Authentication Response message in which the UE responds to the MME authentication; Figure 8 This is a structural diagram of the S6a data cleaner according to an embodiment of the present invention; Figure 9 This is a workflow diagram of the S6a data cleaner according to an embodiment of the present invention; Figure 10 This is a screenshot of the page of the Authentication-Information Request message sent by the MME to the HSS in an embodiment of the present invention; Figure 11 This is a screenshot of the authentication information matching (Authentication-InformationAnswer) message sent by the HSS to the MME in accordance with an embodiment of the present invention. Figure 12 A task manager and a global network topology diagram according to an embodiment of the present invention; Figure 13 A flowchart of a task manager according to an embodiment of the present invention; Figure 14 This is a flow chart of a communication method for obtaining user text messages according to the present invention; Figure 15 Schematic diagram of the structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0034] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, like numbers in different figures represent like or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all possible embodiments consistent with the present disclosure. Rather, they are merely examples of devices and products consistent with certain aspects of the present disclosure, as detailed in the appended claims.

[0035] The terms used in this disclosure are for the purpose of describing specific embodiments only and are not intended to limit the disclosure. As used in this disclosure and the appended claims, the singular forms "a," "an," "the," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0036] It should be understood that although the terms first, second, third, etc. may be used in this disclosure to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of this disclosure, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining."

[0037] The embodiments of the present invention are described in further detail below.

[0038] The embodiment of the present invention provides a communication system for obtaining user text messages, such as Figure 1 Shown, including: UE / eNB Simulator: Used to simulate a base station (radio access network eNodeB) and multiple terminals. By interacting with the task manager, it obtains the IMSI (International Mobile Subscriber Identity) to be simulated, realizing the simulation function of one base station + multiple UEs (user equipment); In this embodiment, the UE / eNB simulator runs on a server running the Ubuntu operating system and is deployed in a computer room that provides a base station interface.

[0039] Task Manager: It is used to receive IMSI tasks that the distributed crawler system needs to obtain SMS messages, assign the IMSI tasks to the UE / eNB simulator and S6a data cleaner, and pass the user authentication data collected by the S6a data cleaner to the UE / eNB simulator; S6a data cleaner: used to obtain the authentication and location update data of the S6a interface of the specified IMSI and send it to the task manager; Distributed crawler system: used to configure IMSI to the task manager according to network security investigation requirements, receive user login verification SMS sent by the task manager, log in to the user's network account, and crawl the user's whereabouts information; The UE / eNB simulator is interactively connected to the task manager, and the task manager is respectively connected to the S6a data cleaner and the distributed crawler system.

[0040] like Figure 3 As shown, the UE / eNB simulator includes: a simulation module and an interface module; The simulation module is used to implement the 3GPP protocol stack of the terminal and the base station based on the open source project OAI, and the 3GPP protocol stack includes the SCTP / S1AP / NAS protocol of the control plane and the GTPU protocol of the user plane; The simulation module includes: a NAS submodule and an S1AP interface. The NAS submodule is used to initiate the Attach process of the NAS protocol; the S1AP interface is used to carry the AttachRequest message and send the AttachRequest message to the control node of the 3GPP protocol stack access network: the mobility management entity MME; The interface module includes a task interface and an authentication interface. The task interface is used to obtain the IMSI task issued by the task manager, and the authentication interface is used to obtain the S6a interface message forwarded by the task manager; The simulation module is connected to the interface module.

[0041] The workflow of the UE / eNB simulator includes: base station registration and terminal registration process, terminal SMS reporting process, and terminal authentication and key derivation; Among them, the base station registration and terminal registration process (such as Figure 4 shown) include: 1. After completing the S1Setup process of S1AP, the UE / eNB simulator reports the device is ready (Ready) to the task interface, and the task interface reports the device ready (Ready) to the task manager; 2. The task manager configures the IMSI to the task interface, and the task interface initiates an IMSI registration request to the NAS submodule of the UE / eNB simulator; 3. The NAS submodule initiates the Attach process of the NAS protocol. The AttachRequest message is directly carried in the Initial UE Message of S1AP and sent to the MME. 4. The MME sends an authentication information request message to the HSS, and the HSS responds with an authentication information response message from the MME. The response message contains the 4G authentication vector:<AUTN,RAND, XRES,Kasme> ; 5. The MME sends an authentication request to the UE / eNB simulator. 6. The S6a data cleaner obtains the IMSI authentication vector and sends it to the task manager, which then sends it to the UE / eNB simulator. 7. The UE / eNB simulator uses the expected response SRES in the authentication vector to complete the terminal authentication process and uses Kasme to derive the Key_nas_enc and Key_nas_int required for NAS signaling encryption and integrity protection.

[0042] 8. After the registration and service bearer activation process is completed between the UE and the core network, the UE / eNB simulator reports the UE Ready status to the task manager.

[0043] The terminal SMS reporting process (such as Figure 5 shown) include: 1. After receiving the UE Ready status, the distributed crawler system initiates the target user's network account login action, triggering the target IMSI verification SMS; 2. The mobile operator's MME sends the SMS content to the UE / eNB simulator via NAS message; 3. The task interface sends the received SMS to the task manager, which sends the SMS to the distributed crawler system. The distributed crawler system uses the notification SMS to complete the login and information acquisition operations. 4. The task manager initiates the release of the IMSI to the UE / eNB simulator; 5. The UE / eNB simulator initiates the IMSI Detach process; The terminal authentication of the UE / eNB simulator of this embodiment is a two-way authentication between the terminal and the network. The key hierarchy in LTE of one embodiment of the present invention is as follows: Figure 6 As shown. The simulated UE uses the IMSI authentication vector captured by the S6a data cleaner from the S6a interface to complete the authentication. The UE / eNB simulator uses the SRES (expected response) in the authentication vector to complete the network authentication of the terminal. In this embodiment, the UE authentication data RES (resource) of the S6a interface is filled in the RES field of the Authentication Response message of the UE's response to the MME authentication, as shown Figure 7 shown.

[0044] The NAS submodule of the UE / eNB simulator uses the encryption key CK for encryption and the integrity protection key IK to ensure data integrity. The IK is derived by Kasme through the KDF algorithm.

[0045] The task manager includes: Ue / eNB interface and management module: used for management and task distribution of Ue / eNB simulator; S6a data cleaner interface and management module: used for the management and task dispatching of S6a data cleaner; Crawler system interface and management module: used for task acquisition, status and SMS reporting; The Ue / eNB interface and management module.

[0046] The workflow of the task manager (such as Figure 13 shown) include: 1. After the Ue / eNB simulator and S6a data cleaner are successfully initialized, they report the status Ready to the task manager. The task manager then reports the status Ready of the corresponding PLMN device to the distributed crawler system. 2. The distributed crawler system configures the IMSI task to the task manager. The task manager distributes the IMSI to the Ue / eNB simulator and S6a data cleaner based on information such as PLMN and device load; 3. The Ue / eNB simulator initiates the Attach process to the operator network, uses the authentication vector sent by the S6a data scrubber to complete the authentication and Attach process, and activates the service bearer; 4. The Ue / eNB simulator reports the UE device is ready (Ready) to the task manager, and the task manager reports the UE device is ready (Ready) to the distributed crawler system; 5. The distributed crawler system triggers a login verification SMS, and the Ue / eNB simulator receives the login verification SMS and reports the login verification SMS to the task manager; 6. The task manager sends the login verification SMS to the distributed crawler system, and the distributed crawler system uses the verification SMS to complete the login action; 7. The distributed crawler system releases the IMSI task, and the task manager distributes the IMSI release instruction to the Ue / eNB simulator and S6a data scrubber.

[0047] In this embodiment, the task manager is deployed on the Internet, has a single instance, and is the central node of the system. The UE / eNB simulator and the S6a data cleaner have multiple instances. Figure 12 The task manager and global network topology of this embodiment are shown.

[0048] The S6a data cleaner includes (such as Figure 8 shown): UE management module: used to match Diameter messages with a specified IMSI using the IMSI and Session ID fields; Data analysis module: used for data analysis and sends all Diameter protocol data streams to the UE management module; Authentication / task interface: used to forward the authentication vector to the task manager.

[0049] The S6a data cleaner installs an optical splitter on the S6a interface, copies the data from the S6a interface, and then crawls the S6a data for the specified IMSI through data analysis by the data analysis module. This data is then sent to the task manager through the authentication interface. The S6a data cleaner is deployed in the operator's core network equipment room.

[0050] The workflow of S6a data cleaner includes (e.g. Figure 9 shown): 1. Report the device status Ready to the task manager, including the PLMN information it can identify; 2. The data analysis module sends all Diameter protocol data streams to the UE management module; 3. The task manager configures the monitored IMSI to the task interface of the S6a data cleaner, and the task interface configures the target IMSI to the UE management module; 4. The UE management module matches the Diameter data message with the specified IMSI through fields such as IMSI and Session ID; 5. When the specified authentication information response message is matched, the authentication vector is sent to the authentication / task interface, which forwards it to the task manager.

[0051] Diameter data messages such as Figure 10 、 Figure 11 The Authentication Information Request message in the S6a interface carries the Session-Id and IMSI number, and the Authentication Information Answer message carries the Session-Id and authentication vector. By associating the Session-Id, the authentication vector information of the specified IMSI can be matched.

[0052] Figure 2 The flowchart of the communication system for obtaining user text messages according to an embodiment of the present invention is shown.

[0053] The embodiment of the present invention also provides a communication method for obtaining user text messages, which is applied to the communication system for obtaining user text messages as described above, see Figure 14 As shown, the following steps are included: S1. Power on and start the UE / eNB simulator. The UE / eNB simulator establishes an S1 connection with the core network's MME, completes the base station's S1 Setup interaction process, and reports the device's readiness to the task manager. S6a. After the data scrubber is powered on and initialized successfully, it reports the device's readiness to the task manager. S2. The task manager reports the device status as ready to the distributed crawler system; the distributed crawler system configures one or more IMSIs to the task manager according to the user's needs; the task manager configures the target IMSIs to the S6a data cleaner and the UE / eNB simulator respectively; S3. The UE / eNB simulator starts the UE registration process. During the UE authentication process, the MME and HSS exchange authentication vector information for the specified IMSI. The S6a data cleaner obtains the authentication vector for the specified IMSI and sends it to the task manager. The task manager forwards the authentication vector to the UE / eNB simulator. S4. The UE / eNB simulator uses the authentication vector to complete the authentication and security mode process, and completes the registration and service bearer activation process; S5. The UE / eNB simulator reports the UE status as ready to the task manager, and the task manager sends the UE status as ready to the distributed crawler system; S6. The distributed crawler system triggers a login verification SMS; the UE / eNB simulator receives the login SMS and forwards the SMS content to the task manager; the task manager forwards the SMS content to the distributed crawler system; the distributed crawler system uses the verification SMS to complete the target user's account login.

[0054] The communication method for obtaining user text messages further includes: user conflict detection and avoidance, wherein the user conflict detection and avoidance method includes: ping detection, wherein the ping detection includes: After the simulated UE is registered with the operator network, on the running Ubuntu system, the IP address assigned by the core network to the UE is bound to the virtual network port, and the public network address is pinged through the virtual network port to determine in real time whether the simulated UE registration is still valid; In this embodiment, the virtual network port bound to the IP allocated to the simulated UE is SimUe1, so you can use "ping -I SimUe18.8.8.8".

[0055] After the simulated UE registers with the operator network, it does not immediately report the UE ready status. Instead, it continuously pings the public network address for 30 seconds. If the ping is not interrupted within 30 seconds, the UE ready status is reported to the distributed crawler system. At this time, the simulated UE ping detection will timeout. Once the ping times out, the UE offline status is immediately reported to the distributed crawler system. If a real phone is in a state of low-frequency traffic interaction (including browsing the Internet or watching videos), there is a high probability of traffic interaction within 30 seconds, thus triggering the real phone's registration and bearer activation process. If the phone has no traffic interaction, the real phone will only initiate access due to the periodic Tracking Area Update (TAU) process. The periodic TAU period is generally greater than 30 minutes. In this case, the login action is secure and confidential. If the ping to the public network address times out within 30 seconds, the simulated UE needs to wait for a while before initiating the Attach process. If the 30-second ping timeout occurs frequently, the waiting time needs to be increased accordingly. The waiting time can be increased in the following sequence of minutes: 2, 4, 8, 16...

[0056] According to the actual test of this embodiment: if the real mobile phone is in a situation of high-frequency traffic interaction with the operator network (such as voice calls), the real mobile phone will immediately start the registration process and activate the service bearer within 1 second after the simulated UE registration is completed, and the voice call of the mobile phone will not be interrupted.

[0057] The method for detecting and avoiding user conflicts further includes: reporting the UE status according to the UE Context Release process of the S1AP interface, including: After the simulated UE is registered with the operator network, if the real mobile phone is registered with the operator network again, the core network will initiate the S1AP UE release process for the simulated UE on the S1AP interface: UE Context Release Command / Complete. After the UE / eNB simulator receives the S1AP UE release process, it immediately reports the UE offline status to the distributed crawler system.

[0058] The method for detecting and avoiding user conflicts further includes: reporting the UE status according to the authentication information Authentication-Information message and the location update Update-Location message of the S6a interface, including: After the simulated UE registers with the operator network, if the real mobile phone is also registered with the operator network, the core network will include authentication and location update messages on the S6a interface; if the UE / eNB simulator is not registered itself, after receiving the authentication and location update messages on the S6a interface, it will immediately report the UE offline status to the distributed crawler system.

[0059] This embodiment simulates multiple user terminals using a base station approach, eliminating the need for an air interface wireless module and making the simulated UE more stable. Because the number of supported simulated UEs depends on the performance of the server running the simulator, a large number of UEs can be simulated simultaneously, supporting investigations involving large sample populations. The 3GPP protocol stack of the UE / eNB simulator can be rapidly developed based on the Open Air Interface (OAI) open source project, significantly reducing development difficulty and cost.

[0060] The communication system and method for obtaining user text messages in this embodiment are based on the system structure of the mobile communication network. They simulate multiple user terminals in batches through base stations. After confirming the IMSI of the target user's mobile phone, they can quickly and effectively obtain the target user's mobile phone text message verification code, thereby assisting the background program to log in to the target user's network account and obtain the target user's network whereabouts, providing important support for the investigation of network security cases; user conflict detection and avoidance methods can make obtaining the target user's text messages more confidential, thereby enhancing the confidentiality of the operation of obtaining user text messages.

[0061] An embodiment of the present invention further provides a computer device, Figure 15 This is a schematic diagram of the structure of a computer device provided by an embodiment of the present invention; see the accompanying drawings Figure 15 As shown, the computer device includes: an input system 23, an output system 24, a memory 22 and a processor 21; the memory 22 is used to store one or more programs; when the one or more programs are executed by the one or more processors 21, the one or more processors 21 implement the communication method for obtaining user text messages provided in the above embodiment; wherein the input system 23, the output system 24, the memory 22 and the processor 21 can be connected by a bus or other means, Figure 15 The bus connection is taken as an example.

[0062] The memory 22 is a readable and writable storage medium of a computing device and can be used to store software programs and computer executable programs, such as the program instructions corresponding to the communication method for obtaining user text messages described in the embodiment of the present invention. The memory 22 may mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system and at least one application required for a function; the data storage area can store data created based on the use of the device, etc. In addition, the memory 22 may include a high-speed random access memory and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some instances, the memory 22 may further include a memory remotely located relative to the processor 21, and these remote memories may be connected to the device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0063] The input system 23 may be used to receive input digital or character information, and generate key signal input related to user settings and function control of the device; the output system 24 may include display devices such as a display screen.

[0064] The processor 21 executes various functional applications and data processing of the device by running the software programs, instructions and modules stored in the memory 22, that is, realizes the above-mentioned communication method for obtaining user text messages.

[0065] The computer device provided above can be used to execute the communication method for obtaining user text messages provided in the above embodiment, and has corresponding functions and beneficial effects.

[0066] An embodiment of the present invention also provides a storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to perform the communication method for obtaining user text messages provided in the above embodiment. The storage medium is any of various types of memory devices or storage devices, including: installation media, such as CD-ROM, floppy disk or tape system; computer system memory or random access memory, such as DRAM, DDR RAM, SRAM, EDORAM, Rambus RAM, etc.; non-volatile memory, such as flash memory, magnetic media (such as hard disk or optical storage); registers or other similar types of memory elements; the storage medium may also include other types of memory or a combination thereof; in addition, the storage medium may be located in the first computer system in which the program is executed, or may be located in a different second computer system, the second computer system being connected to the first computer system via a network (such as the Internet); the second computer system may provide program instructions to the first computer for execution. The storage medium includes two or more storage media that can reside in different locations (for example, in different computer systems connected via a network). The storage medium can store program instructions (for example, specifically implemented as a computer program) that can be executed by one or more processors.

[0067] Of course, the storage medium containing computer-executable instructions provided in an embodiment of the present invention is not limited to the communication method for obtaining user text messages as described in the above embodiment, and can also execute related operations in the communication method for obtaining user text messages provided in any embodiment of the present invention.

[0068] Thus far, the technical solutions of the present invention have been described in conjunction with preferred embodiments. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is clearly not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art may make equivalent changes or substitutions to the relevant technical features, and the technical solutions after such changes or substitutions will fall within the scope of protection of the present invention.

[0069] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that the present invention is susceptible to various modifications and variations. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.

Claims

1. A communication system for obtaining user text messages, characterized in that: include: UE / eNB simulator: used to simulate a base station and multiple terminals. By interacting with the task manager, it obtains the IMSI to be simulated and implements the simulation function of one base station + multiple UEs. Task Manager: It is used to receive IMSI tasks that the distributed crawler system needs to obtain SMS messages, assign the IMSI tasks to the UE / eNB simulator and S6a data cleaner, and pass the user authentication data collected by the S6a data cleaner to the UE / eNB simulator; S6a data cleaner: used to obtain the authentication and location update data of the S6a interface of the specified IMSI and send it to the task manager; Distributed crawler system: used to configure IMSI to the task manager according to network security investigation requirements, receive user login verification SMS sent by the task manager, log in to the user's network account, and crawl the user's whereabouts information; The UE / eNB simulator is interactively connected to the task manager, and the task manager is respectively connected to the S6a data cleaner and the distributed crawler system.

2. The communication system for obtaining user text messages according to claim 1, characterized in that: The UE / eNB simulator includes: a simulation module and an interface module; The simulation module is used to implement the 3GPP protocol stack of the terminal and the base station based on the open source project OAI, and the 3GPP protocol stack includes the SCTP / S1AP / NAS protocol of the control plane and the GTPU protocol of the user plane; The simulation module includes: a NAS submodule and an S1AP interface. The NAS submodule is used to initiate the Attach process of the NAS protocol; the S1AP interface is used to carry the AttachRequest message and send the AttachRequest message to the control node of the 3GPP protocol stack access network: the mobility management entity MME; The interface module includes a task interface and an authentication interface. The task interface is used to obtain the IMSI task issued by the task manager, and the authentication interface is used to obtain the S6a interface message forwarded by the task manager; The simulation module is connected to the interface module.

3. The communication system for obtaining user text messages according to claim 1, characterized in that: The task manager includes: Ue / eNB interface and management module: used for management and task distribution of Ue / eNB simulator; S6a data cleaner interface and management module: used for the management and task dispatching of S6a data cleaner; Crawler system interface and management module: used for task acquisition, status and SMS reporting; The Ue / eNB interface and management module.

4. The communication system for obtaining user text messages according to claim 1, characterized in that: The S6a data cleaner includes: UE management module: used to match Diameter messages with a specified IMSI using the IMSI and Session ID fields; Data analysis module: used for data analysis and sends all Diameter protocol data streams to the UE management module; Authentication / task interface: used to forward the authentication vector to the task manager.

5. A communication method for obtaining user text messages, characterized in that: A communication system for obtaining user text messages as described in any one of claims 1 to 4, comprising the following steps: S1. Power on and start the UE / eNB simulator. The UE / eNB simulator establishes an S1 connection with the core network's MME, completes the base station's S1 Setup interaction process, and reports the device's readiness to the task manager. S6a. After the data scrubber is powered on and initialized successfully, it reports the device's readiness to the task manager. S2. The task manager reports the device status as ready to the distributed crawler system; the distributed crawler system configures one or more IMSIs to the task manager according to the user's needs; the task manager configures the target IMSIs to the S6a data cleaner and the UE / eNB simulator respectively; S3. The UE / eNB simulator starts the UE registration process. During the UE authentication process, the MME and HSS exchange authentication vector information for the specified IMSI. The S6a data cleaner obtains the authentication vector for the specified IMSI and sends it to the task manager. The task manager forwards the authentication vector to the UE / eNB simulator. S4. The UE / eNB simulator uses the authentication vector to complete the authentication and security mode process, and completes the registration and service bearer activation process; S5. The UE / eNB simulator reports the UE status as ready to the task manager, and the task manager sends the UE status as ready to the distributed crawler system; S6. The distributed crawler system triggers a login verification SMS; the UE / eNB simulator receives the login SMS and forwards the SMS content to the task manager; the task manager forwards the SMS content to the distributed crawler system; the distributed crawler system uses the verification SMS to complete the target user's account login.

6. The communication method for obtaining user text messages according to claim 5, characterized in that: Also includes: User conflict detection and avoidance, the user conflict detection and avoidance method includes: ping detection, the ping detection includes: After the simulated UE is registered with the operator network, on the running Ubuntu system, the IP address assigned by the core network to the UE is bound to the virtual network port, and the public network address is pinged through the virtual network port to determine in real time whether the simulated UE registration is still valid; After the simulated UE registers with the operator network, it does not immediately report the UE ready status. Instead, it continuously pings the public network address for a set period of time. If the ping is not interrupted within the set time, the UE ready status is reported to the distributed crawler system. At this time, the simulated UE ping detection will timeout. Once the ping times out, the UE offline status is immediately reported to the distributed crawler system. If the real phone is in a state of low-frequency traffic interaction, there is a high probability of traffic interaction within the set time, thereby triggering the real phone's registration and bearer activation process. If the phone has no traffic interaction, the real phone will only initiate access due to the periodic Tracking Area Update (TAU) process. In this case, the login action is secure and confidential. If the ping of the public network address times out within the set time, the simulated UE needs to delay and wait before initiating the Attach process. If the ping timeout occurs frequently within the set time, the waiting time needs to be increased accordingly. The waiting time increases in a sequence of even multiples of more than 4 times the set time.

7. The communication method for obtaining user text messages according to claim 6, characterized in that: The method for detecting and avoiding user conflicts further includes: reporting the UE status according to the UE Context Release process of the S1AP interface, including: After the simulated UE registers with the operator network, if the real phone registers with the operator network again, the core network will initiate the S1AP UE release process for the simulated UE on the S1AP interface: UE Context Release Command / Complete. After the UE / eNB simulator receives the S1AP UE release process, it immediately reports the UE offline status to the distributed crawler system.

8. The communication method for obtaining user text messages according to claim 6, characterized in that: The method for detecting and avoiding user conflicts further includes: reporting the UE status according to the authentication information Authentication-Information message and the location update Update-Location message of the S6a interface, including: After the simulated UE registers with the operator network, if the real mobile phone is also registered with the operator network, the core network will include authentication and location update messages on the S6a interface; if the UE / eNB simulator is not registered itself, after receiving the authentication and location update messages on the S6a interface, it will immediately report the UE offline status to the distributed crawler system.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the communication method for obtaining user text messages described in any one of claims 5 to 8 are implemented.

10. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the communication method for obtaining user text messages as described in any one of claims 5 to 8 are implemented.