Network switching method, device and equipment

By using AI to predict network state changes and combining it with quantum key distribution technology, the optimal IMSI is dynamically selected for switching, which solves the problems of low IMSI switching efficiency and high interruption risk of terminal devices, and achieves highly secure and efficient network switching.

CN121240161APending Publication Date: 2025-12-30CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511340531.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-18
Publication Date
2025-12-30

AI Technical Summary

Technical Problem

In existing technologies, terminal devices have low IMSI handover efficiency and a high risk of communication interruption during handover, and lack the ability to adapt to dynamic changes in the network environment.

Method used

By acquiring historical handover information, network status information, and location information of terminal devices, AI is used to predict network status change trends, generate handover strategies, and perform encrypted identity authentication based on quantum key technology to dynamically select the optimal IMSI for handover.

Benefits of technology

It improves the security and switching efficiency of terminal communication, adapts to the needs of high-security and high-dynamic communication scenarios, and reduces the risk of communication interruption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121240161A_ABST
    Figure CN121240161A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a network switching method, device and equipment, which are applied to the technical field of terminals, and the method comprises the following steps: obtaining historical switching information, network state information and terminal position information corresponding to terminal equipment; predicting a network state change trend corresponding to the terminal equipment based on the historical switching information, the network state information and the terminal position information, and generating a network switching strategy corresponding to the terminal equipment; the network switching strategy comprises a candidate international mobile subscriber identity (IMSI) set and a switching triggering condition; selecting a target IMSI from a plurality of candidate IMSIs based on a plurality of decision index values respectively corresponding to each candidate IMSI included in the candidate IMSI set when determining that a switching trigger condition is satisfied; and on the basis of the target IMSI, performing IMSI switching on the terminal equipment, thereby improving the switching efficiency of the terminal equipment and the IMSI.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of terminal technology, and in particular to a network switching method, apparatus and device. Background Technology

[0002] With the rapid development of IoT and mobile communication technologies, embedded SIM cards (Embedded Subscriber Identity Module, eSIM) are widely used in smart terminals and IoT devices due to their characteristics such as no need for physical insertion and removal and support for remote configuration.

[0003] Multiple International Mobile Subscriber Identity (IMSI) technology allows terminal devices to store multiple IMSIs, enabling flexible switching between different networks by switching IMSIs, thereby improving communication stability and coverage.

[0004] However, when performing IMSI handover on terminal devices in related technologies, the handover strategy used is usually determined based on fixed rules, which lacks the ability to adapt to dynamic changes in the network environment, resulting in low handover efficiency and a high risk of communication interruption. Summary of the Invention

[0005] This invention provides a network handover method, apparatus, and device to solve the problems of low handover efficiency and high risk of communication interruption when terminal devices perform IMSI handover in the prior art.

[0006] In a first aspect, embodiments of this application provide a network switching method applied to a terminal device, the method comprising:

[0007] Obtain historical handover information, network status information, and terminal location information corresponding to the aforementioned terminal devices;

[0008] Based on the aforementioned historical handover information, network status information, and terminal location information, the network status change trend corresponding to the aforementioned terminal device is predicted, and based on the predicted network status change trend, a network handover strategy corresponding to the aforementioned terminal device is generated; the aforementioned network handover strategy includes: a set of candidate International Mobile Subscriber Identity (IMSI) codes and handover triggering conditions.

[0009] When the above switching triggering conditions are met, the target IMSI is selected from the multiple candidate IMSIs based on the multiple decision index values ​​corresponding to each candidate IMSI included in the above candidate IMSI set.

[0010] Based on the aforementioned target IMSI, the IMSI of the aforementioned terminal devices is switched.

[0011] In one possible implementation, the above-mentioned prediction of the network status change trend corresponding to the terminal device based on the historical handover information, network status information, and terminal location information, and the generation of a network handover strategy corresponding to the terminal device based on the predicted network status change trend, includes:

[0012] The above-mentioned historical handover information, network status information and terminal location information are input into the target model. Based on the target model, the network change trend and location movement trend of the terminal device are predicted. Based on the predicted network status change trend and location movement trend, a network handover strategy corresponding to the terminal device is generated.

[0013] The target model mentioned above is obtained in the following way:

[0014] Obtain a training sample set, which includes: multiple training samples and the network handover strategy corresponding to each training sample. The training samples include: historical handover information, historical status information and historical terminal location information of each terminal device.

[0015] The above training samples are sequentially input into the basic model, and the basic model is trained with the network switching strategy corresponding to the output training samples as the target to obtain the above target model.

[0016] In one possible implementation, the selection of a target IMSI from multiple candidate IMSIs based on multiple decision index values ​​corresponding to each candidate IMSI in the candidate IMSI set includes:

[0017] For each candidate IMSI, obtain the decision indicator values ​​corresponding to the candidate IMSI and each decision indicator respectively;

[0018] Using the above candidate IMSI set as the initial population, and based on the decision index values ​​corresponding to each candidate IMSI in the above candidate IMSI set, the candidate IMSIs are non-dominated and sorted to obtain the Pareto optimal solution set, which includes at least one candidate IMSI.

[0019] Based on the weight coefficients corresponding to each decision indicator, the target IMSI is selected from the Pareto optimal solution set mentioned above.

[0020] In one possible implementation, the decision indicators include at least one of the following: a first decision indicator for characterizing network quality status, a second decision indicator for characterizing data transmission security level, and a third decision indicator for characterizing network package tariff.

[0021] In one possible implementation, determining that the switching trigger condition is met further includes:

[0022] Send a key acquisition request to the quantum key distribution system and receive the first key sent by the quantum key distribution system.

[0023] The above-mentioned IMSI switching for the aforementioned terminal devices based on the aforementioned target IMSI includes:

[0024] Send a network exit request to the first operator network currently accessed by the aforementioned terminal device. The network exit request is used to indicate that the aforementioned terminal device has exited the aforementioned first operator network.

[0025] Based on the first key mentioned above, encrypted identity authentication is performed with the second operator network corresponding to the target IMSI mentioned above.

[0026] Once authentication is successful, update the configuration files in the aforementioned terminal devices.

[0027] In one possible implementation, the encrypted identity authentication based on the first key and the second operator network corresponding to the target IMSI includes:

[0028] The target IMSI is encrypted using the first key to obtain the first encrypted information;

[0029] A network switching request is sent to the second operator network, the network switching request carrying the first encryption information and the first key, so that the second operator network can perform key validity authentication with the quantum key distribution system based on the first key;

[0030] The system receives an access instruction sent by the second operator network. The access instruction is as follows: after the second operator network confirms that the key validity authentication is successful, it encrypts the access instruction based on the second key and sends it; the second key and the first key constitute a key pair.

[0031] After decrypting the access command, if it is determined that the access command indicates that access is permitted, then IMSI registration is performed with the aforementioned second operator network.

[0032] In one possible implementation, the second key in the second operator network is: the key sent by the quantum key distribution system to the second operator network after the terminal device sends a key acquisition request to the quantum key distribution system; or...

[0033] When the aforementioned second operator network authenticates the key validity with the aforementioned quantum key distribution system based on the aforementioned first key, the aforementioned quantum key distribution system sends the following to the aforementioned second operator network.

[0034] Secondly, embodiments of this application provide a network switching device applied to a terminal device, the device comprising:

[0035] The acquisition module is used to acquire historical handover information, network status information, and terminal location information corresponding to the aforementioned terminal devices.

[0036] The strategy generation module is used to predict the network status change trend corresponding to the terminal device based on the above historical handover information, network status information and terminal location information, and generate a network handover strategy corresponding to the terminal device based on the predicted network status change trend; the above network handover strategy includes: a set of candidate International Mobile Subscriber Identity (IMSI) codes and handover triggering conditions.

[0037] The IMSI selection module is used to select the target IMSI from multiple candidate IMSIs based on multiple decision index values ​​corresponding to each candidate IMSI included in the above candidate IMSI set when the above switching triggering conditions are met.

[0038] The IMSI switching module is used to switch the IMSI of the terminal device based on the target IMSI.

[0039] In one possible implementation, the strategy generation module described above is specifically used for:

[0040] The above-mentioned historical handover information, network status information and terminal location information are input into the target model. Based on the target model, the network change trend and location movement trend of the terminal device are predicted. Based on the predicted network status change trend and location movement trend, a network handover strategy corresponding to the terminal device is generated.

[0041] The target model mentioned above is obtained in the following way:

[0042] Obtain a training sample set, which includes: multiple training samples and the network handover strategy corresponding to each training sample. The training samples include: historical handover information, historical status information and historical terminal location information of each terminal device.

[0043] The above training samples are sequentially input into the basic model, and the basic model is trained with the network switching strategy corresponding to the output training samples as the target to obtain the above target model.

[0044] In one possible implementation, the aforementioned IMSI selection module is specifically used for:

[0045] For each candidate IMSI, obtain the decision indicator values ​​corresponding to the candidate IMSI and each decision indicator respectively;

[0046] Using the above candidate IMSI set as the initial population, and based on the decision index values ​​corresponding to each candidate IMSI in the above candidate IMSI set, the candidate IMSIs are non-dominated and sorted to obtain the Pareto optimal solution set, which includes at least one candidate IMSI.

[0047] Based on the weight coefficients corresponding to each decision indicator, the target IMSI is selected from the Pareto optimal solution set mentioned above.

[0048] In one possible implementation, the decision indicators include at least one of the following: a first decision indicator for characterizing network quality status, a second decision indicator for characterizing data transmission security level, and a third decision indicator for characterizing network package tariff.

[0049] In one possible implementation, the above-described apparatus further includes a key management module for:

[0050] When the above switching triggering conditions are met, a key acquisition request is sent to the quantum key distribution system, and the first key sent by the quantum key distribution system is received.

[0051] The aforementioned IMSI switching module is specifically used for:

[0052] Send a network exit request to the first operator network currently accessed by the aforementioned terminal device. The network exit request is used to indicate that the aforementioned terminal device has exited the aforementioned first operator network.

[0053] Based on the first key mentioned above, encrypted identity authentication is performed with the second operator network corresponding to the target IMSI mentioned above.

[0054] Once authentication is successful, update the configuration files in the aforementioned terminal devices.

[0055] In one possible implementation, the aforementioned IMSI switching module is specifically used for:

[0056] The IMSI list of the terminal device is encrypted based on the first key to obtain the first encrypted information.

[0057] A network switching request is sent to the second operator network, the network switching request carrying the first encryption information and the first key, so that the second operator network can perform key validity authentication with the quantum key distribution system based on the first key;

[0058] The system receives an access instruction sent by the second operator network. The access instruction is as follows: after the second operator network confirms that the key validity authentication is successful, it encrypts the access instruction based on the second key and sends it; the second key and the first key constitute a key pair.

[0059] After decrypting the access command, if it is determined that the access command indicates that access is permitted, then IMSI registration is performed with the aforementioned second operator network.

[0060] In one possible implementation, the second key in the second operator network is: the key sent by the quantum key distribution system to the second operator network after the terminal device sends a key acquisition request to the quantum key distribution system; or...

[0061] When the aforementioned second operator network authenticates the key validity with the aforementioned quantum key distribution system based on the aforementioned first key, the aforementioned quantum key distribution system sends the following to the aforementioned second operator network.

[0062] Thirdly, embodiments of this application provide a network switching device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements any step of the network switching method in the first aspect described above.

[0063] Fourthly, embodiments of this application provide a computer-readable storage medium having computer program instructions stored thereon, which, when executed by a processor, implement any step of the network switching method described in the first aspect above.

[0064] Fifthly, embodiments of this application provide a computer program product, including a computer program stored in a computer-readable storage medium; when a processor of a memory access device reads the computer program from the computer-readable storage medium, the processor executes the computer program, causing the memory access device to perform any step of the network switching method in the first aspect described above.

[0065] The network switching method, apparatus, and device provided in this application have the following advantages:

[0066] By predicting the network status change trend of the terminal device based on historical handover information, network status information, and terminal location information, a network handover strategy is generated based on the prediction results. When the handover triggering conditions are met, the target IMSI is selected from multiple candidate IMSIs based on multiple decision index values ​​corresponding to each candidate IMSI included in the candidate IMSI set, realizing dynamic and secure handover of multiple IMSIs. This improves the security and handover efficiency of terminal communication and can adapt to the needs of high-security and high-dynamic communication scenarios. Attached Figure Description

[0067] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0068] Figure 1 A flowchart illustrating a network switching method provided in an embodiment of this application;

[0069] Figure 2 A schematic diagram illustrating the overall network handover process provided in an embodiment of this application;

[0070] Figure 3 A flowchart illustrating a quantum key encryption process provided in this application embodiment;

[0071] Figure 4 A schematic diagram of a network switching device provided in an embodiment of this application;

[0072] Figure 5 This is a schematic diagram of a network switching device provided in an embodiment of this application. Detailed Implementation

[0073] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will now be described in further detail with reference to the accompanying drawings.

[0074] The application scenarios described in this application are for the purpose of more clearly illustrating the technical solutions of this application, and do not constitute a limitation on the technical solutions provided in this application. Those skilled in the art will understand that with the emergence of new application scenarios, the technical solutions provided in this application are also applicable to similar technical problems. In the description of this application, unless otherwise stated, "multiple" means two or more.

[0075] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without inventive effort are within the scope of protection of this application.

[0076] To facilitate understanding, the professional fields involved in the embodiments of this application will first be explained:

[0077] (1) International Mobile Subscriber Identity (IMSI): A unique identifier used to distinguish different users in a cellular network.

[0078] (2) Embedded SIM card (Embedded Subscriber Identity Module, eSIM): A new generation SIM card standard developed by the Global System for Mobile Communications Association (GSMA). It embeds the functions of the traditional SIM card directly into the device chip in an electronic form, eliminating the need for a physical card slot. Users can switch and manage operator networks through remote configuration.

[0079] (3) Long Short-Term Memory (LSTM): It is a specially designed Recurrent Neural Network (RNN) used to solve the gradient vanishing or gradient explosion problems encountered by traditional RNNs when processing long sequence data.

[0080] With the rapid development of IoT and mobile communication technologies, eSIM cards are widely used in smart terminals and IoT devices due to their features such as no physical insertion or removal and support for remote configuration. Multi-IMSI technology allows terminal devices to store multiple IMSIs, enabling flexible switching between different networks by switching IMSIs, thus improving communication stability and coverage.

[0081] However, traditional multi-IMSI handover technology has the following problems:

[0082] First, during the handover process, identity authentication and data transmission rely on traditional encryption algorithms, and the encryption keys are easily cracked, making it impossible to guarantee communication security.

[0083] Second, the handover strategies used are usually determined based on fixed rules, which lack the ability to adapt to dynamic changes in the network environment, resulting in low handover efficiency and high risk of communication interruption.

[0084] To address the aforementioned issues, this application provides a network switching method applied to eSIM terminal devices. By integrating eSIM, artificial intelligence (AI), and quantum security technologies, it enables dynamic and secure switching of multiple IMSIs, improving the security and switching efficiency of terminal communication and adapting to the needs of high-security and high-dynamic communication scenarios.

[0085] Specifically, the network handover method provided in this application embodiment can be executed by a system, the system architecture of which includes the following core modules:

[0086] The data acquisition module, deployed in the eSIM terminal device, is used to collect data such as the network status information, location information, and historical handover information of the terminal device in real time, and to preprocess the collected data.

[0087] The AI ​​decision engine is used to predict the network status change trend and location movement trend of the terminal based on data such as the terminal device's network status information, terminal device location information, and historical handover information, and generate handover strategies accordingly; and to generate Pareto optimal solution sets based on multiple decision indicators using algorithms such as NSGA-III, and make intelligent decisions in multiple dimensions.

[0088] The multi-IMSI management module stores multiple IMSIs of the terminal device and their corresponding network environment adaptation information (such as network coverage area, tariff standards, and service quality parameters). Based on the handover strategy generated by the AI ​​decision engine, it selects the optimal target IMSI from among the multiple IMSIs and pre-connects it to the target network (i.e., the second operator network corresponding to the target IMSI). The multi-IMSI management module provides diverse network selection and can automatically match the optimal network based on factors such as tariff and signal quality, reducing communication costs and improving user experience.

[0089] The eSIM configuration module, based on eSIM technology, supports remote configuration and fast switching between multiple IMSIs without the need to physically replace the SIM card. It is used to update the configuration file of the eSIM terminal device via over-the-air download technology based on the IMSI selection result of the multi-IMSI management module, thereby enabling fast IMSI switching and network access.

[0090] The quantum key management module is used for key management, namely, based on quantum key distribution technology, it negotiates and distributes quantum keys with the target network to provide quantum-secure encryption keys for identity authentication and data transmission during multi-IMSI handover; and it supports dynamic key updates and management to ensure communication security.

[0091] The security authentication module is used to encrypt and verify the identity authentication process between the terminal and the target network using the key pair provided by the quantum key management module, ensuring the security of the handover process.

[0092] Based on the above system architecture, this application provides a network switching method for eSIM terminal devices. It should be noted that the network switching method provided in this application is not limited to the above system architecture. Other system architectures can also be designed in specific implementations, as long as they can achieve the functions of the network switching device described below.

[0093] Figure 1 This is a flowchart illustrating a network handover method provided in an embodiment of this application; as shown below. Figure 1 As shown in the figure, this application provides a network switching method applied to a terminal device, which specifically includes the following steps:

[0094] Step S101: Obtain historical handover information, network status information, and terminal location information corresponding to the terminal device;

[0095] In some embodiments, the aforementioned historical handover information includes one or more parameters such as the time, location, network quality, handover result (e.g., successful or failed handover), failure reason, handover success rate, and handover latency when the terminal device historically performed an IMSI handover; the aforementioned network status information includes one or more parameters such as the current signal strength and network latency; the aforementioned terminal location information includes one or more parameters such as the terminal device's positioning information, moving speed, moving direction, and moving acceleration. Specifically, the positioning information can be determined by technologies such as Global Positioning System (GPS), Wireless Fidelity (Wi-Fi) positioning, and Bluetooth beacons, while the moving speed, moving direction, and moving acceleration can be determined by sensors such as accelerometers and gyroscopes in the terminal device. This information can be used to subsequently predict the network status change trend and location movement trend of the terminal device.

[0096] In some embodiments, after collecting the aforementioned historical handover information, network status information, and terminal location information, preprocessing operations are performed on each piece of information, such as removing noise and outliers. The specific content of the preprocessing operations is not limited in the embodiments of this application.

[0097] In some embodiments, this application may set up a database to store historical handover information of each terminal device, network status information collected each time, and terminal location information, so as to facilitate subsequent review and use. In addition, the database may also store the network handover strategy generated by each terminal device during each IMSI handover, which can be used for subsequent iterative training of the target model to improve its accuracy.

[0098] Step S102: Based on historical handover information, network status information and terminal location information, predict the network status change trend corresponding to the terminal device, and generate a network handover strategy corresponding to the terminal device based on the predicted network status change trend.

[0099] The aforementioned network handover strategy includes: IMSI set and handover triggering conditions.

[0100] Specifically, the aforementioned handover triggering condition is a threshold corresponding to an evaluation index. This evaluation index can be set based on requirements, such as the value and duration of the Reference Signal Receiving Power (RSRP). After obtaining the first threshold corresponding to the RSRP value and the second threshold corresponding to the duration based on the above method, when the RSRP value is less than the first threshold and the duration reaches the second threshold, it is determined that the handover triggering condition is met, and the candidate IMSI handover process is executed.

[0101] In some embodiments, the process of generating a network switching strategy in step S102 can be implemented by a model. In specific implementation, this application does not limit the type of model used. It can use various models such as reinforcement learning models or recurrent neural network models. Preferably, an LSTM model can be used to predict the network state change trend corresponding to the terminal device and generate a network switching strategy based on the prediction results.

[0102] As an optional implementation method, the process of generating network handover strategies based on models specifically includes:

[0103] Historical handover information, network status information, and terminal location information are input into the target model. Based on the target model, the network change trend and location movement trend of the terminal device are predicted. Based on the predicted network status change trend and location movement trend, a network handover strategy corresponding to the terminal device is generated.

[0104] The target model mentioned above was trained in the following manner:

[0105] Obtain a training sample set, which includes: multiple training samples and the network handover strategy corresponding to each training sample. The training samples include: historical handover information, historical status information and historical terminal location information of each terminal device.

[0106] The aforementioned training samples are sequentially input into the basic model, and the basic model is trained using the network switching strategy corresponding to the output training samples as the objective, resulting in the aforementioned target model, as shown below. Figure 2 As shown.

[0107] In specific implementation, this application embodiment does not impose restrictions on the number of training samples or the loss function used during training, and can be set according to requirements.

[0108] In some embodiments, such as Figure 2 As shown, after each IMSI switch, the target model can be trained and optimized based on the switch result and parameters such as the switch strategy during the switch process.

[0109] Step S103: When the switching triggering condition is met, select the target IMSI from the multiple candidate IMSIs based on the multiple decision index values ​​corresponding to each candidate IMSI included in the candidate IMSI set.

[0110] In some embodiments, such as Figure 2 As shown, after generating the handover policy, it is determined whether the handover triggering conditions are met. If so, the subsequent IMSI handover process is executed; otherwise, the process of obtaining the historical handover information, network status information, and terminal location information corresponding to the terminal device (i.e., step S101) is returned. It should be noted that when it is determined that the handover triggering conditions are not met, a preset time can be waited before returning to execute the steps described in step S101. The preset time can be set based on the requirements.

[0111] In some embodiments, when the switching triggering condition is determined to be met, this application embodiment can perform multi-dimensional decision-making on each candidate IMSI based on multiple decision index values ​​corresponding to each candidate IMSI, and select the optimal target IMSI from them. Various algorithms can be used to implement the decision-making process. In some embodiments, the NSGA-III algorithm can be used to generate a Pareto optimal solution set, and then the target IMSI can be selected from the Pareto optimal solution set.

[0112] As an optional implementation, the process of selecting the target IMSI using the NSGA-III algorithm described above specifically includes:

[0113] For each candidate IMSI, obtain the decision indicator values ​​corresponding to the candidate IMSI and each decision indicator respectively;

[0114] Using the above candidate IMSI set as the initial population, and based on the decision index values ​​corresponding to each candidate IMSI in the above candidate IMSI set, the candidate IMSIs are non-dominated and sorted to obtain the Pareto optimal solution set, which includes at least one candidate IMSI.

[0115] Based on the weight coefficients corresponding to each decision indicator, the target IMSI is selected from the Pareto optimal solution set mentioned above.

[0116] In practice, after obtaining the Pareto optimal solution set, it is necessary to perform weighted calculations based on the weight coefficients corresponding to each decision index and the decision index values ​​corresponding to each candidate IMSI in the Pareto optimal solution set, to determine the total decision value corresponding to each candidate IMSI in the Pareto optimal solution set, and take the IMSI with the largest total decision value as the target IMSI.

[0117] As an optional implementation, the decision indicators include at least one of the following: a first decision indicator for characterizing network quality status, a second decision indicator for characterizing data transmission security level, and a third decision indicator for characterizing network package tariff.

[0118] Specifically, the decision index values ​​of each candidate IMSI set can be preset or determined based on preset determination rules and relevant information of each candidate IMSI. In this embodiment, the content of the determination rules and relevant information is not limited. For example, the index value of the first decision index can be set to the first value when RSRP≥-100dBm and SINR≥10dB.

[0119] This application embodiment does not limit the specific indicators of the first decision indicator, the second decision indicator, and the third decision indicator. Optionally, as shown in Table 1 below, the first decision indicator may include RSRP and the signal-to-interference-plus-noise ratio (SINR), etc. The second decision indicator may include the quantum key update frequency and the encryption algorithm strength, etc. The third decision indicator may include the cost-effectiveness of the operator's package, etc.

[0120] Table 1

[0121] Decision indicators Weighting coefficient index First decision indicator 40% For example: RSRP ≥ -100dBm, SINR ≥ 10dB Second decision indicator 30% For example: quantum key update frequency, encryption algorithm strength Second decision indicator 30% Carrier plan cost-effectiveness

[0122] In some embodiments, this application does not restrict the value of the weighting coefficient and supports user-defined weighting coefficients, such as prioritizing security for enterprise users (i.e., the weighting coefficient of the second decision indicator is higher) and prioritizing tariffs for ordinary users (i.e., the weighting coefficient of the third decision indicator is higher), in order to balance multiple objectives and meet the needs of different users.

[0123] Step S104: Based on the target IMSI, switch the IMSI of the terminal device.

[0124] In some embodiments, such as Figure 2 As shown, to ensure the security of data transmission, after determining that the handover triggering conditions are met, this embodiment of the application needs to perform a quantum key pre-distribution process through quantum key negotiation before performing IMSI handover on the terminal device (see steps S301-S302 below). That is, the terminal device requests a key pair (including the first key and the second key) from the key distribution system, and the key distribution system distributes quantum keys to the terminal device and the network operator (optionally) to establish a secure key channel to ensure the security of candidate data transmission.

[0125] As an optional implementation, when the above-mentioned switching triggering conditions are met, the terminal device sends a key acquisition request to the quantum key distribution system and receives the first key sent by the quantum key distribution system.

[0126] In some embodiments, during the IMSI handover process, the terminal device uses a pre-distributed quantum key to perform two-way authentication between the terminal device and the second operator network corresponding to the target IMSI; after successful authentication, the eSIM configuration file in the terminal device is updated to complete the IMSI handover and network access.

[0127] As an optional implementation, the above-mentioned IMSI switching of the terminal device includes:

[0128] Send a network exit request to the first operator network currently accessed by the terminal device, wherein the network exit request is used to indicate that the terminal device has exited the first operator network;

[0129] Based on the first key, encrypted identity authentication is performed with the second operator network corresponding to the target IMSI;

[0130] Once authentication is successful, update the configuration file on the terminal device.

[0131] The process for updating the configuration file in the terminal device described above can be found in relevant technologies and will not be repeated here.

[0132] As an optional implementation, the above-mentioned encrypted identity authentication based on the first key and the second operator network corresponding to the target IMSI includes:

[0133] The target IMSI is encrypted using the first key mentioned above to obtain the first encrypted information;

[0134] A network switching request is sent to the second operator network, the network switching request carrying the first encryption information and the first key, so that the second operator network can perform key validity authentication with the quantum key distribution system based on the first key;

[0135] The system receives an access instruction sent by the second operator network. The access instruction is as follows: after the second operator network confirms that the key validity authentication is successful, it encrypts the access instruction based on the second key and sends it; the second key and the first key constitute a key pair.

[0136] After decrypting the access command, if it is determined that the access command indicates that access is permitted, then IMSI registration is performed with the aforementioned second operator network.

[0137] In practice, after the aforementioned terminal device sends a network switching request to the second operator network, the second operator network first sends a key validity authentication request to the quantum key distribution system, carrying a first key in the request. When the quantum key distribution system finds the second key corresponding to the first key, it determines that the validity authentication is successful and notifies the second operator network of the result. After determining that the key validity authentication is successful, the second operator network determines whether the current network supports the target IMSI based on the target IMSI decrypted using the second key. If it supports it, it determines that the terminal device can access the network. At this time, it generates an access command for access, encrypts it using the second key, and sends it to the terminal device. If it determines that it does not support it, it sends an instruction that access is not allowed to the terminal device and does not execute the subsequent IMSI registration process.

[0138] As an optional implementation, the second key in the second operator network is:

[0139] After the aforementioned terminal device sends a key acquisition request to the aforementioned quantum key distribution system, the aforementioned quantum key distribution system sends it to the aforementioned second operator network; or,

[0140] When the aforementioned second operator network authenticates the key validity with the aforementioned quantum key distribution system based on the aforementioned first key, the aforementioned quantum key distribution system sends the following to the aforementioned second operator network.

[0141] Figure 3 This application provides a schematic flowchart of a quantum key encryption process, as shown in the embodiments below. Figure 3 As shown, the process of two-way authentication between the terminal and the second operator's network based on quantum keys specifically includes:

[0142] Step S301: The terminal device sends a key acquisition request to the quantum key distribution system;

[0143] In some embodiments, after receiving a key acquisition request, the quantum key distribution system generates a key pair and returns it to the terminal device, while storing the key pair information; the key pair includes a first key and a second key.

[0144] It should be noted that step S301 above is executed when the switching trigger condition is determined to be met.

[0145] Step S302: The quantum key distribution system sends the first key to the terminal device;

[0146] In some embodiments, after the quantum key distribution system generates a key pair, it can send the second key to the operator networks corresponding to multiple IMSIs of the terminal device. Alternatively, it can send the second key at the same time when performing key validity authentication and returning a validity certificate to the operator network after confirming that the authentication has passed.

[0147] Step S303: The terminal device sends a network exit request to the first operator network; the network exit request is used to indicate that the terminal device has exited the first operator network.

[0148] It should be noted that step S303 above is performed after the target IMSI is determined.

[0149] Step S304: The terminal device encrypts the target IMSI based on the first key to obtain the first encrypted information;

[0150] Step S305: The terminal device sends a network switching request to the second operator's network;

[0151] The aforementioned network switching request carries the first encrypted information and the first key.

[0152] Step S306: The second operator network sends a key validity authentication request to the quantum key distribution system;

[0153] The first key is carried in the aforementioned key validity authentication request.

[0154] Step S307: The quantum key distribution system performs key validity authentication;

[0155] Specifically, the quantum key distribution system checks whether a corresponding second key is stored based on the first key. If it exists, the validity authentication is confirmed to be successful; otherwise, the validity authentication is confirmed to be unsuccessful.

[0156] Step S308: The quantum key distribution system sends the key validity authentication result to the second operator network;

[0157] The key validity authentication result is used to indicate whether the validity authentication has passed or failed. If the validity authentication fails, the second operator network directly sends an instruction that access is not allowed to the terminal device and will not execute the subsequent IMSI registration process.

[0158] Step S309: After the second operator network confirms that the key validity authentication is successful, it sends an access command to the terminal device.

[0159] Specifically, an access command is generated, encrypted using a second key, and then sent to the terminal device;

[0160] In step S310, the terminal device decrypts the access command and, if the access command indicates that access is permitted, registers its IMSI with the second operator's network.

[0161] The process for IMSI registration described above can be found in the relevant technical documentation and will not be repeated here.

[0162] In this embodiment, quantum key distribution technology is used to provide theoretically unconditionally secure encryption for the multi-IMSI handover process, which can effectively resist quantum computing attacks. The quantum key is used to encrypt and verify the identity authentication process between the terminal and the target network (second operator network), preventing identity information leakage and forgery, improving the level of communication security, and ensuring the security of the handover process.

[0163] Based on the same disclosed concept, this application also provides a network switching device. Since this device is the same as the device in the method of this application, and the principle of the device in solving the problem is similar to that of the method, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.

[0164] Figure 4 Please refer to the schematic diagram of a network handover provided in this application embodiment. Figure 4 This application provides a network switching device, which includes:

[0165] The acquisition module 401 is used to acquire historical handover information, network status information and terminal location information corresponding to the aforementioned terminal devices.

[0166] The strategy generation module 402 is used to predict the network status change trend corresponding to the terminal device based on the above-mentioned historical handover information, network status information and terminal location information, and generate a network handover strategy corresponding to the terminal device based on the predicted network status change trend; the network handover strategy includes: a set of candidate International Mobile Subscriber Identity (IMSI) codes and handover triggering conditions.

[0167] IMSI selection module 403 is used to select a target IMSI from multiple candidate IMSIs based on multiple decision index values ​​corresponding to each candidate IMSI included in the above candidate IMSI set when the above switching triggering conditions are met.

[0168] IMSI switching module 404 is used to switch the IMSI of the terminal device based on the target IMSI.

[0169] In one possible implementation, the strategy generation module 402 described above is specifically used for:

[0170] The above-mentioned historical handover information, network status information and terminal location information are input into the target model. Based on the target model, the network change trend and location movement trend of the terminal device are predicted. Based on the predicted network status change trend and location movement trend, a network handover strategy corresponding to the terminal device is generated.

[0171] The target model mentioned above is obtained in the following way:

[0172] Obtain a training sample set, which includes: multiple training samples and the network handover strategy corresponding to each training sample. The training samples include: historical handover information, historical status information and historical terminal location information of each terminal device.

[0173] The above training samples are sequentially input into the basic model, and the basic model is trained with the network switching strategy corresponding to the output training samples as the target to obtain the above target model.

[0174] In one possible implementation, the IMSI selection module 403 described above is specifically used for:

[0175] For each candidate IMSI, obtain the decision indicator values ​​corresponding to the candidate IMSI and each decision indicator respectively;

[0176] Using the above candidate IMSI set as the initial population, and based on the decision index values ​​corresponding to each candidate IMSI in the above candidate IMSI set, the candidate IMSIs are non-dominated and sorted to obtain the Pareto optimal solution set, which includes at least one candidate IMSI.

[0177] Based on the weight coefficients corresponding to each decision indicator, the target IMSI is selected from the Pareto optimal solution set mentioned above.

[0178] In one possible implementation, the decision indicators include at least one of the following: a first decision indicator for characterizing network quality status, a second decision indicator for characterizing data transmission security level, and a third decision indicator for characterizing network package tariff.

[0179] In one possible implementation, the above-described apparatus further includes a key management module for:

[0180] When the above switching triggering conditions are met, a key acquisition request is sent to the quantum key distribution system, and the first key sent by the quantum key distribution system is received.

[0181] The aforementioned IMSI switching module 404 is specifically used for:

[0182] Send a network exit request to the first operator network currently accessed by the aforementioned terminal device. The network exit request is used to indicate that the aforementioned terminal device has exited the aforementioned first operator network.

[0183] Based on the first key mentioned above, encrypted identity authentication is performed with the second operator network corresponding to the target IMSI mentioned above.

[0184] Once authentication is successful, update the configuration files in the aforementioned terminal devices.

[0185] In one possible implementation, the aforementioned IMSI switching module 404 is specifically used for:

[0186] The IMSI list of the terminal device is encrypted based on the first key to obtain the first encrypted information.

[0187] A network switching request is sent to the second operator network, the network switching request carrying the first encryption information and the first key, so that the second operator network can perform key validity authentication with the quantum key distribution system based on the first key;

[0188] The system receives an access instruction sent by the second operator network. The access instruction is as follows: after the second operator network confirms that the key validity authentication is successful, it encrypts the access instruction based on the second key and sends it; the second key and the first key constitute a key pair.

[0189] After decrypting the access command, if it is determined that the access command indicates that access is permitted, then IMSI registration is performed with the aforementioned second operator network.

[0190] In one possible implementation, the second key in the second operator network is: the key sent by the quantum key distribution system to the second operator network after the terminal device sends a key acquisition request to the quantum key distribution system; or...

[0191] When the aforementioned second operator network authenticates the key validity with the aforementioned quantum key distribution system based on the aforementioned first key, the aforementioned quantum key distribution system sends the following to the aforementioned second operator network.

[0192] Based on the same disclosed concept, this application also provides a network switching device. Since this device is the same as the device in the method of this application, and the principle of the device in solving the problem is similar to that of the method, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.

[0193] Those skilled in the art will understand that various aspects of this application can be implemented as a system, method, or program product. Therefore, various aspects of this application can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, collectively referred to herein as a "circuit," "module," or "system."

[0194] In some possible implementations, the device according to this application may include at least one processor and at least one memory. The memory stores program code that, when executed by the processor, causes the processor to perform the steps of the network switching methods according to the various exemplary embodiments of this application described above.

[0195] The following reference Figure 5 The device 500 according to this embodiment of the present application is described. Figure 5 The device 500 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0196] like Figure 5 As shown, device 500 is presented in the form of a general-purpose device. The components of device 500 may include, but are not limited to: at least one processor 501, at least one memory 502, and a bus 503 connecting different system components (including memory 502 and processor 501), wherein the memory stores program code, which, when executed by the processor, causes the processor to perform the steps in the network switching method.

[0197] Bus 503 represents one or more of several bus structures, including a memory bus or memory controller, peripheral bus, processor, or local bus using any of the various bus structures.

[0198] The memory 502 may include a readable medium in the form of volatile memory, such as random access memory (RAM) 5021 and / or cache memory 5022, and may further include read-only memory (ROM) 5023.

[0199] The memory 502 may also include a program / utility 5025 having a set (at least one) of program modules 5024, including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.

[0200] Device 500 can also communicate with one or more external devices 504 (e.g., keyboard, pointing device, etc.), and with one or more devices that enable a user to interact with device 500, and / or with any device that enables device 500 to communicate with one or more other devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 505. Furthermore, device 500 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 506. As shown, network adapter 506 communicates with other modules used with device 500 via bus 503. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with device 500, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0201] This application also provides a computer-readable storage medium storing computer-executable instructions required to execute the processor, including a program required to execute the processor.

[0202] In some possible implementations, various aspects of the network handover method provided in this application can also be implemented in the form of a program product, which includes program code that, when the program product is run on a computer device, causes the computer device to perform the steps of a network handover method according to various exemplary embodiments of this application as described above.

[0203] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0204] The monitoring program product of the embodiments of this application can be a portable compact disc read-only memory (CD-ROM) and include program code, and can run on a device. However, the program product of this application is not limited to this. In this document, the readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0205] A readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying readable program code. This propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0206] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0207] Program code for performing the operations of this application can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user device, partially on the user device, as a standalone software package, partially on the user device and partially on a remote device, or entirely on a remote device or server. In cases involving remote devices, the remote device can be connected to the user device via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external device (e.g., via the Internet using an Internet service provider).

[0208] It should be noted that although several units or sub-units of the device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of this application, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.

[0209] Furthermore, although the operations of the method of this application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0210] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0211] This application is described with reference to flowchart illustrations and block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block and / or block in the flowchart illustrations and block diagrams, as well as combinations of blocks and processes in the flowchart illustrations and block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the process. Figure 1 One or more processes and boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0212] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and boxes Figure 1 The function specified in one or more boxes.

[0213] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and boxes Figure 1 The steps of the function specified in one or more boxes.

[0214] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.

[0215] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A network handover method, characterized by, The method is applied to a terminal device, and comprises: obtaining historical handover information, network state information and terminal location information corresponding to the terminal device; based on the historical handover information, network state information and terminal location information, predicting a network state change trend corresponding to the terminal device, and generating a network handover strategy corresponding to the terminal device based on the predicted network state change trend; the network handover strategy includes a candidate international mobile subscriber identity (IMSI) set and a handover trigger condition; when the handover trigger condition is met, selecting a target IMSI from the candidate IMSI set based on a plurality of decision indicator values corresponding to each candidate IMSI in the candidate IMSI set; based on the target IMSI, performing IMSI handover on the terminal device.

2. The method of claim 1, wherein, The method further comprises: inputting the historical handover information, network state information and terminal location information into a target model, predicting a network change trend and a location movement trend of the terminal device based on the target model, and generating a network handover strategy corresponding to the terminal device based on the predicted network state change trend and location movement trend; wherein the target model is obtained based on the following method: obtaining a training sample set, the training sample set including a plurality of training samples and a network handover strategy corresponding to each training sample, the training sample including historical handover information, historical state information and historical terminal location information of each terminal device; inputting the plurality of training samples into a basic model in turn, and training the basic model to obtain the target model, with the goal of outputting the network handover strategy corresponding to the training sample.

3. The method of claim 1, wherein, The method further comprises: for each candidate IMSI, obtaining a decision indicator value corresponding to each decision indicator and the candidate IMSI; taking the candidate IMSI set as an initial population, performing non-dominated sorting on each candidate IMSI based on the decision indicator value corresponding to each candidate IMSI in the candidate IMSI set, to obtain a Pareto optimal solution set, the Pareto optimal solution set including at least one candidate IMSI; selecting a target IMSI from the Pareto optimal solution set based on the weight coefficient corresponding to each decision indicator.

4. The method of claim 3, wherein: the decision indicators include at least one of a first decision indicator for representing a network quality state, a second decision indicator for representing a data transmission security level, and a third decision indicator for representing a network package cost.

5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises: A vector quantum key distribution system sends a key acquisition request to a quantum key distribution system and receives a first key sent by the quantum key distribution system; The IMSI switching of the terminal device is performed based on the target IMSI, and the method comprises the steps of: sending a network exit request to a first operator network to which the terminal device currently accesses, wherein the network exit request is used to identify that the terminal device exits the first operator network; performing encrypted identity authentication with a second operator network corresponding to the target IMSI based on the first key; updating a configuration file in the terminal device after determining that the authentication is passed.

6. The method of claim 5, wherein, The encrypted identity authentication with the second operator network corresponding to the target IMSI based on the first key comprises the steps of: encrypting the target IMSI based on the first key to obtain first encrypted information; sending a network switching request to the second operator network, wherein the network switching request carries the first encrypted information and the first key, so that the second operator network performs key validity authentication with the quantum key distribution system based on the first key; receiving an access instruction sent by the second operator network, wherein the access instruction is encrypted and sent by the second operator network based on a second key after the second operator network determines that the key validity authentication is passed, and the second key and the first key constitute a key pair; after decrypting the access instruction, determining that the access instruction indicates that access is allowed, and performing IMSI registration with the second operator network.

7. The method of claim 6, wherein, The second key in the second operator network is sent by the quantum key distribution system to the second operator network after the terminal device sends a key acquisition request to the quantum key distribution system; or The second key in the second operator network is sent by the quantum key distribution system to the second operator network when the second operator network performs key validity authentication with the quantum key distribution system based on the first key.

8. A network switching apparatus, characterized by comprising: The device applied to a terminal device comprises: an acquisition module configured to acquire historical switching information, network state information, and terminal location information corresponding to the terminal device; a strategy generation module configured to predict a network state change trend corresponding to the terminal device based on the historical switching information, the network state information, and the terminal location information, and generate a network switching strategy corresponding to the terminal device based on the predicted network state change trend, wherein the network switching strategy comprises a candidate international mobile subscriber identity (IMSI) set and a switching trigger condition; an IMSI selection module configured to select a target IMSI from the candidate IMSI set based on a plurality of decision indicator values corresponding to each candidate IMSI in the candidate IMSI set when the switching trigger condition is met; an IMSI switching module configured to perform IMSI switching of the terminal device based on the target IMSI.

9. A network switching device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, The processor executes the computer program to implement the steps of the method of any one of claims 1 to 7.

10. A computer-readable storage medium having stored thereon computer program instructions, wherein, The computer program instructions are executed by the processor to implement the steps of the method of any one of claims 1 to 7.