A method, system, device and medium for intelligent management and control of mobile terminals
By introducing a whitelist mechanism, regional spatial modeling, and time-sharing strategy dynamic scheduling into the wireless communication system, combined with a feedback learning mechanism, precise and dynamic control of mobile terminals is achieved. This solves the problems of accuracy and adaptability in terminal identification and control in existing technologies, and improves the security and flexibility of the wireless environment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-03
- Publication Date
- 2026-03-06
AI Technical Summary
Existing wireless communication control schemes struggle to accurately match the dynamic behavior characteristics of terminals in high-density environments, resulting in high response delays and false alarm rates. Furthermore, they have limitations in terms of compatibility with multiple communication standards and in-depth protocol identification, making it difficult to achieve accurate identification and targeted control of abnormal or illegal terminals.
It adopts a three-dimensional intelligent control method based on 'identity + time + space'. By loading a whitelist dataset and a time-sharing control strategy configuration file, and combining radio frequency signal coverage parameters to divide independent control areas, it analyzes terminal identification and location in real time, generates dynamic control instructions, and optimizes the strategy through feedback and learning mechanisms to achieve non-intrusive blocking.
It enables precise, dynamic, and regional control of mobile terminals, improving the system's adaptability, scalability, and security protection capabilities. It can accurately identify and target illegal terminals in high-security scenarios, reduce the false positive rate, and adapt to changes in complex network environments.
Smart Images

Figure CN121262575B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication security management technology, and in particular to a method, system, device and medium for intelligent control of mobile terminals. Background Technology
[0002] With the widespread application of 5G, LTE, and other cellular communication technologies, the number of mobile terminal devices has grown rapidly, and the trends of terminal diversification and fragmented connection methods are becoming increasingly significant. Simultaneously, the high degree of freedom of movement of terminal devices in physical space further increases the challenges to communication network stability and regional information security management. Especially in highly confidential and sensitive areas, such as examination rooms and important office areas, unauthorized terminal access may not only lead to data leakage risks but also cause security incidents by disrupting normal communication. Therefore, how to achieve accurate identification and targeted control of abnormal or illegal terminals without affecting normal terminal communication needs has become a crucial issue in the field of communication security.
[0003] Currently, traditional wireless control solutions commonly employ base station positioning, signal strength estimation, or hard-coded blacklists for terminal identification and management. These methods largely rely on static configuration, failing to accurately match the dynamic behavioral characteristics of terminals across time and space. Furthermore, they are prone to high response latency and false alarm rates when dealing with a surge in terminal numbers in high-density environments. Moreover, existing blocking technologies rely too heavily on manually set strategies, lacking flexibility and real-time capabilities, making them ill-suited for complex control scenarios with rapidly changing terminal behavior patterns. Especially with mobile terminals supporting multiple communication standards, control systems must be able to adapt to different signaling structures, protocol parsing logic, and identification methods. Existing solutions often have limitations in terms of standard compatibility and deep protocol identification. Summary of the Invention
[0004] In order to improve the level of security protection while reducing interference with normal communication, this application provides a method, system, device and medium for intelligent management and control of mobile terminals.
[0005] Firstly, this application provides a method for intelligent management and control of mobile terminals, employing the following technical solution:
[0006] A mobile terminal intelligent management and control method, the intelligent management and control method includes:
[0007] Load the pre-stored whitelist dataset and time-sharing management policy configuration file;
[0008] Radio frequency signal coverage parameters are generated based on the equipment deployment topology data. These radio frequency signal coverage parameters are used to divide the physical space into multiple independent control areas.
[0009] The system receives raw radio frequency signals from the radio frequency module in real time and extracts the mobile terminal identifier, signal strength value, and spatial location of the signal source from the raw radio frequency signals; wherein, the spatial location of the signal source is mapped and matched with the independent control area through radio frequency signal coverage parameters.
[0010] The parsed mobile terminal identifier is compared with the whitelist dataset. If the match fails, it is marked as an abnormal terminal.
[0011] Based on the current timestamp, the corresponding control rules are extracted from the time-sharing control strategy configuration file, and a set of terminal control instructions is generated by combining the spatial location of the signal source.
[0012] Adjust the transmission parameters of the radio frequency module according to the set of terminal control instructions, and perform a terminal blocking operation on the abnormal terminal;
[0013] Collect terminal response data after executing a terminal blocking operation;
[0014] The whitelist dataset is updated based on the terminal response data, and the control rules in the time-sharing control strategy configuration file are optimized based on historical blocking records.
[0015] By adopting the above technical solution, precise, dynamic, and regionalized control of mobile terminals is achieved based on the three dimensions of "identity + time + space." A perception foundation for terminal behavior is built through radio frequency spatial modeling and real-time signal analysis, and non-intrusive blocking is achieved through dynamic scheduling of interference strategies. Furthermore, this application continuously improves the whitelist and policies through feedback and learning mechanisms, constructing a closed-loop intelligent evolution system with high adaptability, scalability, and security protection capabilities, making it particularly suitable for high-security scenarios requiring wireless communication control, such as examination rooms and important office areas.
[0016] Optionally, the step of receiving raw radio frequency signals from the radio frequency module in real time and parsing the mobile terminal identifier, signal strength value, and spatial location of the signal source from the raw radio frequency signals includes:
[0017] The system receives raw radio frequency signals collected by the radio frequency module in real time, and the raw radio frequency signals contain mixed carrier signals of multiple communication standards.
[0018] The original radio frequency signal is subjected to a fast Fourier transform operation, and the spectrum is divided according to the preset operator frequency band configuration table to output different types of sub-frequency band signal groups after division.
[0019] The physical layer protocol parser extracts control channel messages from each sub-band signal group and obtains the corresponding device identification field or user identification field.
[0020] Generate the mobile terminal identifier corresponding to the sub-band signal group based on the device identifier field or the user identifier field;
[0021] Obtain the real-time beamforming parameters of the radio frequency antenna array;
[0022] The signal spatial propagation vector is calculated based on the real-time beamforming parameters, and the corrected signal strength value is output by combining the received signal power value and the pre-stored radio frequency attenuation coefficient matrix.
[0023] The mobile terminal identifier, the corrected signal strength value, and the current sub-band type are bound together as a primary feature set;
[0024] Based on the radio frequency signal coverage parameters, the beam-area mapping table is queried, and the corresponding independent control area number is output by matching the range of the horizontal azimuth and vertical elevation angles in the current beamforming parameters.
[0025] The primary feature set is associated with the independent control area number to generate a structured terminal feature record.
[0026] By adopting the above technical solution, the ability to accurately sense mobile terminals in wireless space is improved. This technical solution not only solves the problem of multi-standard mixed signal processing, but also innovatively introduces a spatial decoupling mechanism of beamforming and region mapping, enabling the system to achieve high-precision terminal identification and spatial positioning even without GPS or terminal cooperation. It also has extremely high real-time performance, reliability and scalability, and is particularly suitable for complex application scenarios of directional wireless control of specific areas.
[0027] Optionally, when the type of the sub-band signal group is a 4G / 5G sub-band, the step of extracting control channel messages from each sub-band signal group through a physical layer protocol parser and obtaining the corresponding device identification field includes:
[0028] The scheduling authorization field in the downlink control information of the 4G / 5G sub-band signal group is parsed, and the uplink shared channel resources are located based on the scheduling authorization field.
[0029] Cyclic redundancy check is performed on the downlink control information. When the check passes, the resource block allocation field is extracted.
[0030] The radio resource control connection request message in the uplink shared channel resource is located according to the resource block allocation field.
[0031] The International Mobile Equipment Identity (IMSI) is parsed from the Media Access Control (MAC) header of the Radio Resource Control (RRC) Connection Request message to obtain the device identification field.
[0032] By employing the aforementioned technical solution, the unique identity of 4G / 5G terminal devices can be deciphered and their spatial behavior path determined solely by passively received airborne radio frequency signals, without the need for terminal cooperation. This mechanism, based on the protocol layer and utilizing a standard physical layer structure to reverse-analyze control signaling, significantly enhances the system's ability to proactively identify and accurately track multi-mode terminals, making it particularly suitable for non-intrusive security management scenarios.
[0033] Optionally, when the type of the sub-band signal group is a 2G / 3G sub-band, the step of extracting control channel messages from each sub-band signal group and obtaining the corresponding user identifier field through the physical layer protocol parser includes:
[0034] Perform frequency hopping and deinterleaving operations on the independent dedicated control channels of 2G / 3G sub-band signal groups to output the original bit stream;
[0035] The original bitstream is Viterbi decoded to output unencrypted network layer protocol data units;
[0036] Parse the header bytes of the network layer protocol data unit, identify the location update request message type identifier code, and extract the location area identifier field;
[0037] The location area identifier field is matched against a preset mobile country code mapping table to verify the mobile country code to which the location area identifier field belongs;
[0038] If the mobile country code belongs to a preset license list, extract the temporary mobile subscriber identifier binary data from the user identifier container of the network layer protocol data unit;
[0039] Perform a bit rearrangement operation on the binary data of the temporary mobile subscriber identifier and output the subscriber identifier field.
[0040] By adopting the above technical solution, a passive user identifier extraction method for 2G / 3G communication standards is provided. Relying on standard protocol structures and signal processing techniques, it fully recovers the key fields required for mobile terminal identification through a layer-by-layer parsing path of "physical layer → link layer → network layer". The advantages of this technical solution are that it does not require terminal cooperation and does not rely on operator signaling links. At the same time, it can accurately restore terminal identity in heterogeneous mixed coverage environments, providing unified data support for terminal classification and management.
[0041] Optionally, the intelligent control method further includes:
[0042] When a mobile terminal carrying an unauthorized network identifier is detected, the network registration code in the mobile terminal identifier is extracted;
[0043] Query the pre-stored risk feature mapping table to obtain the device behavior feature parameters associated with the network registration code;
[0044] Calculate the risk score of the mobile terminal based on the device behavior characteristic parameters;
[0045] If the risk score exceeds a preset dynamic threshold, an enhanced blocking command is generated and the security alarm device is activated;
[0046] Write the network registration code, terminal risk score, and corresponding timestamp into the abnormal terminal behavior log database.
[0047] By adopting the above technical solutions, accurate identification and dynamic control of unauthorized network terminals are achieved. Compared with the traditional blacklist and whitelist mechanism based on a single identifier, this application introduces a risk feature mapping table and a dynamic scoring algorithm, which can assess the risk level by combining multi-dimensional information such as the terminal's network affiliation and behavior patterns, significantly reducing the false positive rate. The enhanced blocking command solves the problem of terminals evading control by switching frequency bands or moving locations through multi-channel coordinated interference and regional extended coverage, improving the comprehensiveness of security protection. The establishment of an abnormal behavior log database provides data support for risk model iteration and strategy optimization, enabling the system to adapt to the ever-changing network environment and attack methods.
[0048] Optionally, the terminal response data includes the mobile terminal identifier, the number of connection requests, the alarm trigger flag, and the timestamp;
[0049] The steps of updating the whitelist dataset based on the terminal response data and optimizing the control rules in the time-sharing control policy configuration file based on historical blocking records include:
[0050] The terminal response data is stored in a historical blocking record database; wherein, the historical blocking record database stores mobile terminal blocking records of each independent control area in a time sequence.
[0051] Extract the mobile terminal identifier, the corresponding number of connection requests, and the alarm trigger flag from the terminal response data;
[0052] Based on the preset connection request count threshold and alarm time window threshold, mobile terminal identifiers with a connection request count greater than the preset connection request count threshold and an alarm trigger flag of "not triggered" are filtered out.
[0053] Write the selected mobile terminal identifiers into a temporary whitelist dataset;
[0054] Retrieve blocking operation records for each independent control area within a specified time period from the historical blocking record database;
[0055] The frequency of blocking operations for each independent control area is statistically analyzed at different time periods, which are divided according to preset time segmentation rules;
[0056] Query the preset frequency threshold mapping table, which stores the maximum allowable blocking frequency value corresponding to each time period;
[0057] When the frequency of blocking operations in any independent control area exceeds the corresponding maximum allowable blocking frequency value within a specific time period, update the blocking duration parameter in the time-sharing control policy configuration file.
[0058] By adopting the above technical solutions, not only is the initial loading of static whitelists and policy rules supported, but also a temporary whitelist mechanism and a dynamic policy adjustment mechanism based on frequency statistics are introduced. This enables flexible response to different user behavior patterns, automatic identification of risk density in different regional spaces, and intelligent blocking that is "differentiated and spatiotemporal" by fine-tuning the intervention intensity.
[0059] Optionally, the intelligent control method further includes:
[0060] Continuously collect terminal movement trajectory data from each independently controlled area;
[0061] Based on the terminal motion trajectory data within a preset time window, a spatiotemporal transfer matrix is constructed; wherein, the row vector of the spatiotemporal transfer matrix represents the starting independent control area number, the column vector represents the target independent control area number, and the matrix element value is the number of terminals that undergo area transfer within the preset time window;
[0062] When the sum of the element values of a specific row vector exceeds a preset transfer threshold, the starting independent control area number corresponding to the specific row vector is extracted.
[0063] Query the control rules in the time-sharing control strategy configuration file that are associated with the starting independent control area number;
[0064] Traverse all non-zero column elements in the specific row vector and obtain the target independent control area number corresponding to all non-zero column elements;
[0065] The control rules are copied to the time-sharing control strategies associated with all target independent control area numbers corresponding to the non-zero column elements.
[0066] By adopting the above technical solutions, the static regional management model is effectively upgraded to a dynamic and interconnected intelligent control system. The system is no longer limited to static "point-like" spatial control, but can capture the migration trends of people between regions in real time. It constructs a spatial mobility model through a spatiotemporal transfer matrix and realizes that the strategy "follows the person" by means of strategy migration and synchronization mechanisms. Thus, in the face of situations such as emergencies, concentrated entry and exit, and regional linkage, the system can proactively respond, intervene in advance, and prevent policy gaps, which greatly improves the sensitivity, responsiveness, and coverage integrity of the wireless terminal control system.
[0067] Secondly, this application provides a mobile terminal intelligent management and control system, which adopts the following technical solution:
[0068] A mobile terminal intelligent management and control system, the intelligent management and control system comprising:
[0069] The loading module is used to load the pre-stored whitelist dataset and time-sharing management policy configuration file;
[0070] The radio frequency coverage parameter generation module is used to generate radio frequency signal coverage parameters based on the device deployment topology data. The radio frequency signal coverage parameters are used to divide the physical space into multiple independent control areas.
[0071] The radio frequency signal parsing module is used to receive raw radio frequency signals from the radio frequency module in real time, and to parse the mobile terminal identifier, signal strength value, and spatial location of the signal source from the raw radio frequency signals; wherein, the spatial location of the signal source is mapped and matched with the independent control area through radio frequency signal coverage parameters;
[0072] The abnormal terminal identification module is used to compare the parsed mobile terminal identifier with the whitelist dataset. If the match fails, it is marked as an abnormal terminal.
[0073] The terminal control instruction generation module is used to extract the corresponding control rules from the time-sharing control strategy configuration file according to the current timestamp, and generate a set of terminal control instructions in combination with the spatial location of the signal source.
[0074] The terminal blocking execution module is used to adjust the transmission parameters of the radio frequency module according to the terminal control instruction set, and to perform terminal blocking operation on the abnormal terminal.
[0075] The terminal response feedback module is used to collect terminal response data after the terminal blocking operation is performed;
[0076] The optimization and update module is used to update the whitelist dataset based on the terminal response data and optimize the control rules in the time-sharing control strategy configuration file based on historical blocking records.
[0077] Thirdly, this application provides a computer device, which adopts the following technical solution:
[0078] A computer device includes a memory, a processor, and a computer program stored in the memory, the processor executing the computer program to perform the steps of the method as described in the first aspect.
[0079] Fourthly, this application provides a computer-readable storage medium, which adopts the following technical solution:
[0080] A computer-readable storage medium storing a computer program that can be loaded by a processor and executed as in any of the methods in the first aspect.
[0081] In summary, this application achieves at least one of the following beneficial technical effects: By constructing a closed-loop intelligent mobile terminal management system centered on "identity recognition + spatial positioning + time strategy," it realizes accurate identification, targeted positioning, and dynamic blocking of illegal or abnormal terminals. While ensuring the normal operation of legitimate communication, it effectively prevents unauthorized wireless access in sensitive areas. The technical solution of this application introduces a whitelist mechanism, regionalized spatial modeling, time-sharing strategy dynamic scheduling, and behavior feedback learning mechanism on the basis of traditional radio frequency interference. This not only improves the system's real-time performance, accuracy, and flexibility but also possesses adaptive optimization capabilities. It can continuously improve rule configuration based on terminal response data and historical blocking effects, ultimately achieving intelligent, secure, and efficient wireless environment management. It has significant engineering practical value and promising prospects for promotion, especially suitable for application scenarios with strict requirements for wireless communication security, such as examination centers and important office areas. Attached Figure Description
[0082] Figure 1 This is a first flowchart illustrating a mobile terminal intelligent management and control method according to one embodiment of this application.
[0083] Figure 2 This is a second flowchart illustrating a mobile terminal intelligent management method according to one embodiment of this application.
[0084] Figure 3 This is a schematic diagram of the third process of a mobile terminal intelligent management and control method according to one embodiment of this application.
[0085] Figure 4 This is a schematic diagram of the fourth process of a mobile terminal intelligent management and control method according to one embodiment of this application.
[0086] Figure 5 This is a schematic diagram of the fifth process of a mobile terminal intelligent management and control method according to one embodiment of this application.
[0087] Figure 6This is a schematic diagram of the sixth process of a mobile terminal intelligent management and control method according to one embodiment of this application.
[0088] Figure 7 This is a schematic diagram of the seventh process of a mobile terminal intelligent management and control method according to one embodiment of this application. Detailed Implementation
[0089] To make the purpose, technical solution, and advantages of this application clearer, the following description is provided in conjunction with the appendix. Figure 1 -Appendix Figure 7 The present application will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the application.
[0090] This application discloses a method for intelligent management and control of mobile terminals.
[0091] Reference Figure 1 A mobile terminal intelligent management and control method, the intelligent management and control method includes:
[0092] Step S101: Load the pre-stored whitelist dataset and time-sharing control policy configuration file;
[0093] The whitelist dataset is essentially an authorization database for identification, containing multiple authorized mobile terminal identifiers, such as International Mobile Equipment Identity (IMEI), International Mobile Subscriber Identity (IMSI), or Temporary Mobile Subscriber Identity (TMSI). These identifiers are pre-authorized and registered, representing legitimate users. Loading the time-sharing control policy configuration file involves parsing the mapping relationship between timestamp intervals and control rules, generating a set of time-sharing control policies that includes time period identifiers, permitted service types, and blocking strength levels.
[0094] Specifically, the time-sharing control policy configuration file contains control rules associated with time intervals and is responsible for dynamic time scheduling. Its structure is usually based on timestamps (Unix Epoch or ISO 8601 time format) and policy mapping tables. The configuration file includes control rules applicable to different time intervals, such as blocking strength level, allowed service types (such as VoLTE, HTTP, FTP, etc.) and spatial coverage priority.
[0095] Step S102: Generate radio frequency signal coverage parameters based on device deployment topology data. The radio frequency signal coverage parameters are used to divide the physical space into multiple independent control areas.
[0096] The equipment deployment topology data consists of physical layout information collected during system deployment, recording the spatial coordinates of the RF transmitting antenna, receiving module, and room structure. Based on this topology data, the coverage beam angle and signal strength attenuation coefficient corresponding to each independent control area can be calculated using wireless propagation models (such as the free space propagation model and the COST-231 model). The beam angle defines the direction of the antenna main lobe, while the power attenuation value indicates the intensity change of the signal as it propagates to each spatial point. These parameters are used to construct an "RF signal coverage parameter table," forming independent "logical region" divisions in the spatial dimension. This is similar to slicing space through beamforming, allowing the system to map any RF signal to a specific logical region number, thereby achieving an abstract transformation from physical space to signal space.
[0097] For example, the coordinates of the geometric center point of each independent control area are solved, and the azimuth angle θ (horizontal plane angle) and elevation angle φ (vertical plane angle) from the radio frequency module to the geometric center are calculated using the following formula: , ;
[0098] In the above formula, (x0, y0, z0) represents the three-dimensional spatial coordinates of the radio frequency module (antenna), which is the reference point for signal transmission or reception; (x c ,y c ,z c This represents the three-dimensional spatial coordinates of the geometric center point of a specific, independently controlled area. The system divides the physical space into multiple such areas and performs calculations using the geometric center as the representative point.
[0099] Then, calculate the power attenuation value based on the building attenuation model: L(dB) = 20log 10 (d)+0.3d+5.5 (d is the distance), the output parameters are the RF beam angle range [θ±Δθ, φ±Δφ] and the corresponding attenuation value L, forming a space-signal mapping matrix; where θ±Δθ is the azimuth angle range, representing the horizontal sector formed by extending Δθ angles to the left and right sides with the calculated azimuth angle θ as the center; φ±Δφ represents the vertical opening angle range formed by extending Δφ in the up and down directions with the elevation angle φ as the center.
[0100] Step S103: Receive the raw radio frequency signal from the radio frequency module in real time, and parse the mobile terminal identifier, signal strength value, and spatial location of the signal source from the raw radio frequency signal;
[0101] Among them, the spatial location of the signal source is mapped and matched with the independent control area through radio frequency signal coverage parameters;
[0102] The radio frequency module includes multi-standard receiving channels, capable of simultaneously processing 2G (GSM), 3G (WCDMA / CDMA2000), 4G (LTE), and 5G (NR) signals. Through the corresponding protocol stack structures for each standard, the system can extract the mobile terminal identifier from the Broadcast Control Channel (BCCH), Primary Synchronization Signal (PSS), or RRC connection request. Signal strength values (RSSI, RSRP) are used to assist in determining the distance between the terminal and the receiving point.
[0103] In addition, the matching of the spatial location of the signal source includes: by querying the preset beam-area mapping table based on the beamforming number of the radio frequency signal coverage parameters, the independent control area number where the mobile terminal is located can be determined.
[0104] Step S104: Compare the parsed mobile terminal identifier with the whitelist dataset. If the match fails, mark it as an abnormal terminal.
[0105] Specifically, the mobile terminal identifier is compared with a whitelist dataset; if a match fails, the terminal is marked as abnormal. This comparison process emphasizes both efficiency and accuracy. First, a Bloom filter is used for approximate searching; it's a highly space-efficient probabilistic data structure suitable for quickly determining whether an element is not in the set. If the Bloom filter fails to find a match, a hash table is used for precise comparison to ensure the false negative rate remains within acceptable limits. This two-stage comparison mechanism significantly improves the system's efficiency in processing high-concurrency radio frequency data streams, making it particularly suitable for network environments requiring real-time responses.
[0106] Step S105: Extract the corresponding control rules from the time-sharing control strategy configuration file based on the current timestamp, and generate a set of terminal control instructions by combining the spatial location of the signal source;
[0107] The generation of the terminal control instruction set includes: performing modulo operation matching on the current timestamp based on the time period identifier in the time-sharing control strategy, and generating an instruction queue containing blocking effective time, interference method, and priority parameters.
[0108] Specifically, once an abnormal terminal is identified, the system needs to extract the corresponding control rules from the time-sharing control policy configuration file based on the current timestamp, and generate a set of terminal control instructions by combining the spatial location of the signal source. The current timestamp is matched with the time period identifier through modulo operation (e.g., dividing a day into 48 30-minute segments) to determine the applicable policy set. This policy set, combined with the control area number where the terminal is located, generates a detailed set of instructions. Each instruction typically includes: the blocking effective time (e.g., lasting 10 minutes), the interference method (downlink emulation base station injection, uplink random access blocking, etc.), and the priority (used for conflict resolution and resource scheduling).
[0109] Step S106: Adjust the transmission parameters of the radio frequency module according to the terminal control instruction set, and perform terminal blocking operation on abnormal terminals;
[0110] The radio frequency (RF) module controls the active transmission signal, and its parameters include beam direction, transmit power, and time-frequency resource allocation in the control channel. Terminal blocking operations include uplink interference or downlink blocking. Uplink interference includes injecting simulated base station system information blocks, such as sending an RRC connection rejection message carrying a false cell handover command to a target terminal when it initiates a random access request. Downlink blocking includes dynamically adjusting the reference signal power, such as allocating invalid time-frequency resource blocks for abnormal terminals in the physical downlink control channel and reducing the transmit power value of their dedicated reference signal.
[0111] Step S107: Collect terminal response data after the terminal blocking operation is performed;
[0112] Terminal response data can be obtained through signaling feedback, radio frequency responses, or background network logs, such as whether the access request continues to be initiated or whether the base station handover failed. This data can be used to indirectly evaluate the effectiveness of the blocking strategy and the terminal's behavioral response, thus providing a basis for subsequent strategy optimization.
[0113] In one embodiment of this application, the terminal response data includes a mobile terminal identifier, a number of connection requests, an alarm trigger flag, and a timestamp. The mobile terminal identifier (such as IMSI, TMSI, or IMEI) is a field that uniquely identifies the terminal. The number of connection requests represents the number of times the terminal attempts to re-establish a connection after being blocked. The alarm trigger flag is a logical field set in the system to indicate whether there is an abnormal behavior event triggered by the terminal (such as abnormal roaming, frequent location switching, repeated access failures, etc.). The timestamp records the system time when the response behavior occurred, used for subsequent timing analysis and dynamic window judgment.
[0114] Step S108: Update the whitelist dataset based on the terminal response data, and optimize the control rules in the time-sharing control strategy configuration file based on historical blocking records.
[0115] The dynamic updating of the whitelist data employs a "grey list" mechanism. If a terminal repeatedly attempts to access the network within a certain time period without triggering an alarm (e.g., unauthorized external connections, frequent roaming), it is added to a temporary whitelist cache for future decision-making. The optimization of the time-sharing strategy is achieved through adaptive policy adjustments based on the blocking frequency across a two-dimensional control area and time period. For example, if abnormal terminals frequently occur in a certain area within a certain time period, the blocking duration for that period can be automatically extended or the interference intensity level increased, thereby improving protection capabilities and reducing false positive rates.
[0116] The above embodiments achieve precise, dynamic, and regionalized control of mobile terminals based on the three dimensions of "identity + time + space." A perception foundation for terminal behavior is built through radio frequency spatial modeling and real-time signal analysis, and non-intrusive blocking is achieved through dynamic scheduling of interference strategies. Furthermore, this application continuously improves the whitelist and strategies through feedback and learning mechanisms, constructing a closed-loop intelligent evolution system with high adaptability, scalability, and security protection capabilities, making it particularly suitable for high-security scenarios requiring wireless communication control, such as examination rooms and important office areas.
[0117] Reference Figure 2 As one implementation of step S103, the step of receiving the raw radio frequency signal from the radio frequency module in real time and parsing the mobile terminal identifier, signal strength value, and spatial location of the signal source from the raw radio frequency signal includes:
[0118] Step S201: Receive the raw radio frequency signal collected by the radio frequency module in real time. The raw radio frequency signal contains mixed carrier signals of multiple communication standards.
[0119] Specifically, in practical wireless communication systems, mobile terminals may access networks of different generations (such as 2G GSM, 3G WCDMA, 4G LTE, and 5G NR). Each standard uses different modulation methods, bandwidths, and signaling structures at the physical layer, resulting in a superposition of heterogeneous multi-standard signals. Radio frequency modules typically employ wideband multi-channel receivers to simultaneously capture these mixed signals, a prerequisite for building a fully covered radio frequency sensing network.
[0120] Step S202: Perform a fast Fourier transform operation on the original radio frequency signal, divide the spectrum according to the preset operator frequency band configuration table, and output the different types of sub-frequency band signal groups after division.
[0121] The Fast Fourier Transform (FFT) is a fundamental digital signal processing algorithm that essentially maps a signal from the time domain to the frequency domain to extract frequency components and their corresponding amplitude information. Subsequently, the system segments the spectrum into multiple sub-band signal groups based on the operator frequency band configuration table, which defines the downlink or uplink frequency band resources used by different operators (such as China Mobile, China Unicom, and China Telecom). This process helps decouple the mixed signal into several structurally defined sub-signal segments, laying the foundation for subsequent protocol layer analysis.
[0122] Step S203: Extract control channel messages from each sub-band signal group through the physical layer protocol parser and obtain the corresponding device identifier field or user identifier field;
[0123] The system calls a physical layer protocol parser to process each sub-band signal group. The physical layer protocol parser is a decoder implemented for different communication standards, capable of identifying and extracting information from control channels (such as BCCH in GSM, PDCCH in LTE, and CORESET0 in NR). These control channels typically contain temporary or permanent identification fields for devices, such as TMSI (Temporary Mobile Subscriber Identity), IMSI (International Mobile Subscriber Identity), S-TMSI, and C-RNTI. Depending on the specifications of different standards and protocol structures, the system can extract device identification fields or subscriber identification fields from the sub-band signal groups.
[0124] Step S204: Generate the mobile terminal identifier corresponding to the sub-band signal group based on the device identifier field or user identifier field;
[0125] After obtaining the identification field, the system parses and formats it into a universal mobile terminal identifier. The core of this step lies in standardizing the expression of heterogeneous identification fields across various network standards, enabling the system to process identification information from multiple networks within a unified structure. For example, it maps IMSI and GUTI to internal terminal IDs. The generated terminal identifier is the foundational field for subsequent whitelist comparisons and initiating blocking decisions.
[0126] Step S205: Obtain the real-time beamforming parameters of the radio frequency antenna array;
[0127] Beamforming is a spatial directional enhancement technique that concentrates beam energy in a specific direction by controlling the phase and amplitude of each element in an antenna array. Beamforming parameters specifically include the horizontal azimuth, vertical elevation, and gain. These parameters characterize the spatial features of the current signal reception direction and are crucial for spatial positioning.
[0128] Step S206: Calculate the signal spatial propagation vector based on the real-time beamforming parameters, and output the corrected signal strength value by combining the received signal power value and the pre-stored radio frequency attenuation coefficient matrix.
[0129] The signal space propagation vector describes the propagation path of the radio frequency signal in three-dimensional space. To improve the accuracy of signal strength determination, the system also introduces a pre-stored radio frequency attenuation coefficient matrix to compensate for path loss caused by factors such as spatial multipath, obstacle obstruction, and wall penetration. By combining the received raw power values (such as RSSI and RSRP) with the path loss parameters, a corrected signal strength value can be output, which is closer to the actual transmit power level of the signal source. This step is of great significance for realizing the terminal's "energy determination" and can be used to determine the actual spatial distance between the terminal and the receiving device and the effectiveness of the blocking strategy.
[0130] Step S207: Bind the mobile terminal identifier, the corrected signal strength value, and the current sub-band type into a primary feature set;
[0131] Specifically, the mobile terminal identifier, the corrected signal strength value, and the current sub-band type are bound together to form a unified primary feature set. Among them, the sub-band type provides information about the communication standard to which the signal belongs, which helps to select different blocking or guidance strategies based on the standard; the signal strength reflects the relative distance or degree of control between the terminal and the device; and the terminal identifier is the unique anchor point pointing to the specific object.
[0132] Step S208: Based on the radio frequency signal coverage parameters, query the beam-area mapping table, and output the corresponding independent control area number by matching the range of the horizontal azimuth and vertical elevation angles in the current beamforming parameters.
[0133] The system utilizes a pre-established beam-area mapping table to convert spatial direction information into physical spatial location. This mapping table stores the correspondence between beam angle ranges (Azimuth, Elevation) and independently controlled area numbers. By matching the angle range of the current beamforming parameters, the corresponding area number can be found. This conversion is a one-to-one mapping from "signal angle space" to "physical area space," achieving high-precision "radio frequency spatial positioning" without relying on GPS or external positioning.
[0134] Step S209: Associate the primary feature set with the independent control area number to generate a structured terminal feature record.
[0135] Specifically, the previously constructed primary feature set is associated with the identified independent control area numbers to form a structured terminal feature record. This record not only contains multi-dimensional attributes such as the terminal's unique identification information, communication standard, and signal strength, but also clearly defines the terminal's physical location. This structured record serves as the basis for subsequent control operations such as whitelist comparison, policy matching, and blocking command generation, while also possessing good storability and log tracking capabilities.
[0136] The above embodiments improve the ability to accurately sense mobile terminals in wireless space. This technical solution not only solves the problem of multi-standard mixed signal processing, but also innovatively introduces a spatial decoupling mechanism of beamforming and region mapping, enabling the system to achieve high-precision terminal identification and spatial positioning even without GPS or terminal cooperation. It also has extremely high real-time performance, reliability and scalability, and is particularly suitable for complex application scenarios of directional wireless control of specific areas.
[0137] Reference Figure 3 As one implementation of step S203, when the type of the sub-band signal group is a 4G / 5G sub-band, the step of extracting control channel messages from each sub-band signal group through the physical layer protocol parser and obtaining the corresponding device identification field includes:
[0138] Step S301: Analyze the scheduling authorization field in the downlink control information of the 4G / 5G sub-band signal group, and locate the uplink shared channel resources based on the scheduling authorization field;
[0139] Specifically, in 4G LTE and 5G NR radio access networks, downlink control information (DCI) is carried through the physical downlink control channel (PDCCH) and is the core mechanism for control interactions such as resource scheduling, power control, and uplink / downlink commands between the base station (eNodeB / gNodeB) and the terminal (UE).
[0140] The downlink control information includes a "scheduling authorization field," which indicates the uplink resources available to the terminal, including frequency domain resource block (RB) allocation, time domain scheduling, and modulation and coding schemes for the Physical Uplink Shared Channel (PUSCH). Parsing the scheduling authorization field requires first locating the starting position of the DCI format, typically determined by the CORESET definition and DCI search space parameters. Through this field, the system can determine whether the base station allows a (anonymous) UE to transmit uplink information in a specific uplink time slot. This parsing process provides path guidance for subsequent control requests initiated by the terminal.
[0141] Step S302: Perform cyclic redundancy check on the downlink control information. When the check passes, extract the resource block allocation field.
[0142] CRC checksum is a common method used in communication systems to verify the correctness of received data. In PDCCH, a CRC checksum of a specific length is appended to the DCI message before transmission. After demodulation at the terminal, the CRC value is restored by the decoder and compared for verification.
[0143] In this embodiment, since the signal source is not the terminal but a passively receiving radio frequency module, the demodulation process must be reconstructed, and the terminal's reception process of the PDCCH must be simulated. The system considers the DCI message valid only when the CRC check passes, avoiding incorrect resource allocation due to mismodulation and ensuring the accuracy of subsequent location and identifier extraction operations.
[0144] Next, after the CRC check passes, the system further extracts the resource block allocation field from the DCI. In 4G / 5G, the RB is the smallest frequency domain resource unit, and the resource block allocation field describes the spectrum location and bandwidth range involved in the scheduling authorization. This field is usually encoded using a bitmap or indicator (such as Type 0 / 1 / 2 format) to indicate the index of the allocated resource block. Parsing this field can accurately indicate where uplink data will be transmitted.
[0145] Step S303: Locate the Radio Resource Control Connection Request message in the uplink shared channel resource according to the resource block allocation field;
[0146] Specifically, during 4G / 5G access, the terminal needs to perform a random access procedure (RA) when accessing the network for the first time. This procedure involves the base station granting temporary scheduling resources, and the terminal then sends a Radio Resource Control Connection Request (RRCConnection Request) message in the PUSCH. This message contains the terminal's initial identity information, such as the UE Identity field, for network identification. This embodiment of the application determines the specific location of the PUSCH by analyzing the authorization information of the PDCCH, thus enabling targeted demodulation within a specified resource block, avoiding blind scanning, and significantly improving parsing efficiency and accuracy.
[0147] Step S304: Parse the International Mobile Equipment Identity (IMSI) from the Media Access Control (MAC) header of the Radio Resource Control (RRC) Connection Request message to obtain the device identification field.
[0148] Specifically, once the RRC connection request message is located, the system can parse the International Mobile Equipment Identity (IMEI) from the Media Access Control header of the message. In non-emergency calls or initial access scenarios, the UE Identity field in the RRC connection request message may contain the IMEI or GUTI in plaintext or encrypted form. The MAC Header is an encapsulation structure above the RLC PDU, typically containing fields for identifying the message type, segmentation information, and length indication, which the system can use to locate the start position of the RRC Payload. Further analysis of the structure of each field in the RRC Payload allows for the extraction of the IMEI value, serving as a globally unique identifier for the terminal device. This process is crucial for achieving "over-the-air identification" without relying on the terminal's active cooperation.
[0149] It should be noted that although the access protocols of 4G and 5G differ in detailed structures, such as 5G using BWP (Bandwidth Part) and its more complex CORESET / PDCCH mapping mechanism, their basic process (locating uplink resources through DCI authorization, then decoding RRC connection requests and extracting device identifiers) remains highly consistent. The protocol parser in this application embodiment automatically adapts to the corresponding structure according to different standards, ensuring cross-standard compatibility.
[0150] In the above implementation, without the cooperation of any terminal, the unique identity of the 4G / 5G terminal device is resolved solely by passively received air radio frequency signals, and its spatial behavior path is further determined. This mechanism, based on the protocol layer and using a standard physical layer structure to reverse-parse control signaling, greatly enhances the system's ability to actively identify and accurately track multi-mode terminals, making it particularly suitable for non-intrusive security management scenarios.
[0151] Reference Figure 4 As another implementation of step S203, when the type of the sub-band signal group is a 2G / 3G sub-band, the step of extracting control channel messages from each sub-band signal group and obtaining the corresponding user identifier field through the physical layer protocol parser includes:
[0152] Step S401: Perform frequency hopping and deinterleaving operations on the independent dedicated control channel of the 2G / 3G sub-band signal group, and output the original bit stream;
[0153] Specifically, when a signal is identified as belonging to a 2G / 3G sub-band, the system targets the dedicated control channel (DCCH). This control channel carries point-to-point signaling data between the mobile terminal and the base station, serving as the communication channel for critical processes such as initial access, location updates, and authentication. In GSM systems, this channel is typically SDCCH or FACCH, while in WCDMA it may be DCH or RACH.
[0154] Upon receiving the physical layer bitstream from the control channel, the system first performs de-frequency hopping and de-interleaving operations. Frequency hopping is a dynamic frequency change mechanism used in systems like GSM to enhance anti-interference capabilities; the system needs to rearrange the received data packets according to the frequency hopping sequence. Interleaving is a method of transmitting bits in a scattered manner to enhance error correction capabilities; the original order needs to be restored for decoding. Through the combination of these two steps, the original bitstream arranged in chronological order is output, which forms the basis for further parsing by the protocol stack.
[0155] Step S402: Perform Viterbi decoding on the original bitstream and output unencrypted network layer protocol data units;
[0156] After physical layer reconstruction, the system needs to perform Viterbi decoding on the bitstream. This process is used to decode the channel-coded data from convolutional coding. In 2G / 3G systems, convolutional coding with interleaving is widely used to improve error resilience. Decoding in this system requires the Viterbi algorithm to achieve maximum likelihood path search. This algorithm constructs a state transition diagram and uses dynamic programming to find the most likely original bit sequence in the path, ultimately obtaining the unencrypted Network Layer Protocol Data Unit (PDU), which is the logical signaling message between the mobile terminal and the core network, such as "location update request" and "authentication request".
[0157] Step S403: Parse the header bytes of the network layer protocol data unit, identify the location update request message type identifier code, and extract the location area identifier field;
[0158] Specifically, the system performs header parsing on the network layer protocol data unit, focusing on identifying the Message Type ID. In the GSM system, this identifier typically appears in the low-order bit of the first byte or the start bit of the second byte of the PDU, used to distinguish different types of messages, such as "Attach Request" and "Location Updating Request".
[0159] After the system identifies the message as a "location update request," it continues to extract the Location Area Identity (LAI) field from the message. This field consists of three parts: Mobile Country Code (MCC), Mobile Network Code (MNC), and Location Area Code (LAC). It indicates the core network location area where the terminal is currently located and is an important basis for determining the terminal's legitimacy and home domain.
[0160] Step S404: Match the location area identifier field with a preset mobile country code mapping table to verify the mobile country code to which the location area identifier field belongs;
[0161] After obtaining the LAI field, the system performs a homepage verification using a pre-defined MCC mapping table to confirm whether the terminal belongs to a licensed operating country or region. This operation aims to filter out international roaming terminals or suspicious illegal roaming activities.
[0162] Step S405: Determine whether the mobile country code belongs to the preset license list;
[0163] If so, proceed to step S406;
[0164] Step S406: Extract temporary mobile subscriber identifier binary data from the subscriber identifier container of the network layer protocol data unit;
[0165] Specifically, if the verification is successful, meaning the mobile country code (e.g., 460 for China) falls within the licensed list, the system considers the terminal to be within an identifiable and controllable network range. The system then locates and extracts the Temporary Mobile Subscriber Identifier (TMSI) field from the user identification container of the PDU.
[0166] It should be noted that in actual communication, in order to prevent the tracking of user privacy, the terminal does not directly report the IMSI (International Mobile Subscriber Identity), but instead the network issues the TMSI as a temporary user identity credential.
[0167] Step S407: Perform a bit rearrangement operation on the temporary mobile subscriber identifier binary data and output the subscriber identifier field.
[0168] The TMSI is typically a 4-byte binary value, and its storage format may vary depending on the protocol stack implementation. After reading the content of this field from a specified offset, the system performs a bit reassembly operation to restore the segmented bit stream in the protocol field to the standard format user identification field. This process may include byte order adjustment (such as big-endian / little-endian format), redundant field cleanup, or masking operations to ensure that the generated TMSI can be identified and traced within the system.
[0169] The above embodiments provide a passive user identifier extraction method for 2G / 3G communication standards. Relying on standard protocol structures and signal processing techniques, it fully recovers the key fields required for mobile terminal identification through a layer-by-layer parsing path of "physical layer → link layer → network layer." The advantages of this technical solution are that it requires no terminal cooperation, does not rely on operator signaling links, and can accurately restore terminal identity in heterogeneous mixed coverage environments, providing unified data support for terminal classification and management.
[0170] Reference Figure 5 As a further implementation of the intelligent management and control method for mobile terminals, it also includes:
[0171] Step S501: When a mobile terminal carrying an unauthorized network identifier is detected, the network registration code in the mobile terminal identifier is extracted;
[0172] The unauthorized network identifier refers to the terminal identity information not included in the system's whitelist dataset, while the network registration code is an identifier assigned by the core network to the terminal during network access. This code may include the Mobile Country Code (MCC), Mobile Network Code (MNC), or Location Area Code (LAC), directly reflecting the terminal's operator network and geographical location. By parsing this code, the system can initially determine whether the terminal originates from a trusted network, providing a basis for subsequent risk assessment.
[0173] Step S502: Query the pre-stored risk feature mapping table to obtain the device behavior feature parameters associated with the network registration code;
[0174] The risk feature mapping table is a multi-dimensional parameter library built based on historical data and security policies. It stores typical risk behavior characteristics corresponding to different network registration codes, such as international roaming frequency, percentage of abnormal access periods, and number of abnormal signaling interactions. For example, if a network registration code repeatedly exhibits behaviors such as frequent location switching and forgery of Temporary Identity Specifiers (TMSI) in its historical records, the "abnormal switching frequency" parameter associated with that code will be marked as high-risk. These parameters are not statically fixed but dynamically updated through continuous learning from terminal behavior data to ensure the timeliness and accuracy of risk assessment.
[0175] Step S503: Calculate the risk score of the mobile terminal based on the device behavior characteristic parameters;
[0176] The system employs a weighted summation algorithm to convert multiple behavioral feature parameters into a comparable comprehensive score. Specifically, each parameter is assigned a preset weight (e.g., "international roaming frequency" weight 0.3, "signaling anomaly count" weight 0.5), and mapped to a score based on the parameter value's range (e.g., abnormal handover frequency > 5 times / hour scores 8 points, 3-5 times / hour scores 5 points). For example, a terminal's network registration code might be associated with the following parameters: international roaming frequency 0.8 (weight 0.3, score 2.4), signaling anomaly count 6 times (weight 0.5, score 4.0), and access time anomaly value 0.2 (weight 0.2, score 0.4). The comprehensive risk score would then be 2.4 + 4.0 + 0.4 = 6.8 points. This quantification method avoids the limitations of relying on a single parameter and comprehensively reflects the terminal's potential risk level.
[0177] Step S504: If the risk score exceeds the preset dynamic threshold, an enhanced blocking command is generated and the security alarm device is activated.
[0178] The preset dynamic threshold is not a fixed value, but is adjusted in real time according to the current network environment and security requirements. For example, during exams or important meetings, the threshold will be lowered (e.g., from 7 points to 5 points) to strengthen control. Enhanced blocking commands have higher priority and stronger intervention intensity compared to regular commands. Specifically, in terms of interference methods, both the uplink random access channel (PRACH) and downlink synchronization signals (PSS / SSS) are blocked simultaneously to prevent terminals from circumventing control by switching frequency bands or reselecting cells. In terms of scope, it not only covers the independent control area where the terminal is currently located, but also extends to the signal coverage boundary of adjacent areas to prevent the terminal from escaping control after moving. Simultaneously, the activation of security alarm devices enables the linkage between technical means and manual intervention. For example, audible and visual alarms can alert management personnel to high-risk terminals, or alarm information containing the terminal's location can be sent to the monitoring system to ensure timely handling of risk events.
[0179] Step S505: Write the network registration code, terminal risk score, and corresponding timestamp into the abnormal terminal behavior log database.
[0180] The database employs a time-series data structure, storing risk behavior records of terminals in a time-series format, and supports multi-dimensional retrieval and analysis. For example, by querying the risk score change trend of a network registration code over the past 24 hours, it is possible to identify whether there are persistent attack behaviors; by combining timestamps and independent control area numbers, the spatial movement trajectory of high-risk terminals can be plotted, providing data support for optimizing regional control strategies.
[0181] In addition, log data is used to periodically update the risk feature mapping table. For example, when the average risk score of a network registration code is consistently below the threshold, the system will automatically reduce the weight of its associated parameters to achieve self-optimization of the risk assessment model.
[0182] The above embodiments achieve accurate identification and dynamic control of unauthorized network terminals. Compared with traditional blacklist and whitelist mechanisms based on a single identifier, this application introduces a risk feature mapping table and a dynamic scoring algorithm, which can assess the risk level by combining multi-dimensional information such as the terminal's network affiliation and behavior patterns, significantly reducing the false positive rate. The enhanced blocking command solves the problem of terminals evading control by switching frequency bands or moving locations through multi-channel coordinated interference and regional extended coverage, improving the comprehensiveness of security protection. The establishment of an abnormal behavior log database provides data support for risk model iteration and strategy optimization, enabling the system to adapt to constantly changing network environments and attack methods. This application effectively improves the identification efficiency and blocking power of high-risk terminals while ensuring the normal communication of legitimate terminals, and is especially suitable for scenarios with stringent communication security requirements.
[0183] Reference Figure 6 As one implementation of step S108, the steps of updating the whitelist dataset based on terminal response data and optimizing the control rules in the time-sharing control strategy configuration file based on historical blocking records include:
[0184] Step S601: Store the terminal response data in the historical blocking record database;
[0185] Among them, the historical blocking record database stores mobile terminal blocking records of each independent control area in time series;
[0186] The historical blocking record database is organized according to a time series structure, meaning that each record corresponds to a specific timestamp and is associated with its respective independent control area number. This design allows for efficient querying of frequency statistics and strategy optimization analysis over subsequent time periods through sliding time windows or periodic resampling.
[0187] Step S602: Extract the mobile terminal identifier and the corresponding number of connection requests and alarm trigger flag from the terminal response data;
[0188] Step S603: Based on the preset connection request count threshold and alarm time window threshold, filter out mobile terminal identifiers whose connection request count is greater than the preset connection request count threshold and whose alarm trigger flag is not triggered.
[0189] Step S604: Write the selected mobile terminal identifiers into the temporary whitelist dataset;
[0190] Specifically, the system extracts key behavioral indicators from the response data: terminal identifier, number of connection requests, and alarm trigger flag, for use in determining the "temporary whitelist." Two threshold judgment mechanisms are introduced in this process: a connection request count threshold and an alarm time window threshold. The connection request count threshold represents the maximum number of reconnection attempts allowed by the system. If a terminal does not trigger any alarms (i.e., the flag is not triggered) and the number of connection requests exceeds this threshold, it can be preliminarily considered a false alarm blocking or a tolerable access request. The alarm time window is used to limit whether the statistical behavior is continuously active, in order to exclude terminals with occasional reconnection.
[0191] Terminal identifiers meeting the above two conditions will be written into the temporary whitelist dataset. Unlike the main whitelist, the temporary whitelist employs a dynamic caching mechanism to store potentially trusted but not yet formally authorized terminal identifiers. This design reduces user experience degradation due to false blocking and provides the system with space for further manual verification or time-delayed formal authorization. The temporary, hierarchical whitelist strategy effectively improves the system's flexibility and fault tolerance.
[0192] Step S605: Retrieve blocking operation records for each independent control area within a specified time period from the historical blocking record database;
[0193] The blocking operation record includes the blocking time point and the corresponding independent control area number;
[0194] Step S606: Calculate the frequency of blocking operations for each independent control area at different time periods;
[0195] Specifically, the number of blocking events in each independent control area within different time periods is accumulated according to preset time segmentation rules (such as hours, half hours, 15 minutes, etc.). This process can be carried out in the form of sliding window or bucket aggregation, ultimately resulting in a two-dimensional structure: area × time period → blocking frequency.
[0196] Step S607: Query the preset frequency threshold mapping table. The frequency threshold mapping table stores the maximum allowable blocking frequency value corresponding to each time period.
[0197] After the statistics are completed, the system will query a preset frequency threshold mapping table. This mapping table is a strategy reference table used to store the maximum allowed blocking frequency values for each time period, based on cluster analysis, empirical rules, or risk tolerance settings that may be derived from historical data. For example, stricter thresholds may be set for peak nighttime periods to control false alarm interference, while higher frequencies may be allowed during low-density periods to improve interference capability.
[0198] Step S608: When the blocking operation frequency of any independent control area exceeds the corresponding maximum allowable blocking frequency value within a specific time period, update the blocking effective duration parameter in the time-sharing control strategy configuration file.
[0199] The specific update strategy includes increasing the effective duration of blocking for this independent control area during a specific time period to address high-frequency abnormal events within that area. The effective duration of blocking refers to the window of time during which the system allows blocking operations to be performed within a certain time period; modifying this value will directly affect the blocking strength and intervention time in the next cycle.
[0200] Specifically, when the system detects that the frequency of blocking operations in a certain independent control area exceeds a threshold within a certain time period, it will trigger the policy adjustment logic: dynamically update the "blocking duration" parameter in the time-sharing control policy configuration file. For example, if the number of blocking operations in a certain area exceeds the threshold of 5 times between 23:00 and 23:30 at night, the blocking duration for that time period in the next cycle can be extended from the default 5 minutes to 15 minutes.
[0201] The above implementation not only supports the initial loading of static whitelists and policy rules, but also introduces a temporary whitelist mechanism and a dynamic policy adjustment mechanism based on frequency statistics, thereby enabling flexible response to different user behavior patterns, automatic identification of risk density in different regional spaces, and intelligent blocking that is "differentiated and spatiotemporal" by fine-tuning the intervention intensity.
[0202] Reference Figure 7 As a further implementation of the intelligent control method, it also includes:
[0203] Step S701: Continuously collect terminal motion trajectory data from each independent control area;
[0204] The motion trajectory data includes the mobile terminal identifier, timestamp sequence, and corresponding spatial location sequence;
[0205] Specifically, in actual deployment, terminal location identification does not rely on GPS, but rather on independent control area numbers mapped by radio frequency signal coverage parameters and beamforming information. Therefore, a "trajectory" refers to a sequence of different control area numbers where the terminal is located at different points in time, i.e., a discrete spatial movement path. Each trajectory data consists of three parts: mobile terminal identifier (such as TMSI / IMSI), timestamp sequence (i.e., time sequence information), and spatial location sequence (i.e., control area number sequence). A trajectory can be formed by sorting the control area numbers of the same terminal within a continuous time period.
[0206] Step S702: Construct a spatiotemporal transition matrix based on the terminal motion trajectory data within a preset time window;
[0207] In this context, the row vectors of the spatiotemporal transfer matrix represent the initial independent control area number, the column vectors represent the target independent control area number, and the matrix element values are the number of terminals that have undergone area transfer within a preset time window.
[0208] Specifically, the system statistically analyzes the trajectories of all terminals within a preset time window to construct a spatiotemporal transfer matrix. This matrix is an aggregated model of the migration trends of terminals in the spatial dimension. Its row vectors represent the starting independent control area numbers of the trajectories, the column vectors represent the target independent control area numbers, and each matrix element represents the number of individual terminals that transferred from the starting area to the target area within that time window.
[0209] For example, if a matrix element T(3,5)=27, it means that 27 terminals migrated from region 3 to region 5. This matrix essentially constructs a dynamic migration graph between regions, revealing the macroscopic movement trend of the group of terminals.
[0210] Step S703: When the sum of the element values of a specific row vector exceeds a preset transfer threshold, extract the starting independent control area number corresponding to the specific row vector.
[0211] Specifically, when the system detects that the sum of the element values of a specific row vector (i.e., the total number of terminals migrating from a certain controlled area) exceeds a preset transfer threshold, it can determine that the area is an active source area with large-scale terminal migration. This transfer threshold is a sensitivity adjustment parameter set by the system to distinguish between normal flow and possible sudden aggregation or migration phenomena (such as exam entrances and exits, construction site off-get off work hours, and assembly dispersal). If the threshold is exceeded, it indicates that there is a risk of policy spillover in the area, meaning that the policy currently deployed only in this area may not be able to effectively control the subsequent behavior of mobile terminals.
[0212] Step S704: Query the control rules associated with the starting independent control area number in the time-sharing control strategy configuration file;
[0213] Specifically, the starting independent control area number corresponding to the specific row vector is extracted, and the configured control rules are queried in the time-sharing control policy configuration file accordingly. These rules include the permitted service types, channel interference levels, whitelist priority policies, etc., for the current time period, which describe the communication behavior constraints of the area within this time window.
[0214] Step S705: Traverse all non-zero column elements in a specific row vector and obtain the target independent control area number corresponding to the non-zero column elements;
[0215] Specifically, the system will iterate through all non-zero column elements in the aforementioned row vector, i.e., all target region numbers into which terminals migrate from the starting region within the time window. These target regions are the potential policy spillover carrying regions. To ensure that migrating terminals are still subject to the same level of policy control in these regions, the system needs to implement fast policy synchronization for the target regions.
[0216] Step S706: Copy the control rules to the time-sharing control strategies associated with all target independent control area numbers corresponding to the non-zero column elements.
[0217] The system copies the control rules in the starting area to the time-sharing control policies associated with these target areas, thus achieving "cross-regional policy transmission".
[0218] It's important to note that within the system's policy structure, the same policy within the same time period may already exist in the target area, and their priorities may differ. Therefore, if a policy entry with the same name (e.g., the same rule type identifier) is detected, the system will compare it against the pre-defined rule priorities in the configuration file and retain the version with the higher priority, thus avoiding policy conflicts or abnormal overwriting. The definition of rule priorities is typically pre-coded and sorted by the time-sharing management policy configuration file using multiple dimensions, including business type, interference level, and risk level.
[0219] In the above implementation, by effectively upgrading the static regional management model to a dynamic and interconnected intelligent control system, the system is no longer limited to "point-like" spatial static prevention and control, but can capture the migration trend of people between regions in real time, construct a spatial mobility model through a spatiotemporal transfer matrix, and realize that the strategy "follows the person" by means of strategy migration and synchronization mechanism. Thus, when facing situations such as emergencies, concentrated entry and exit, and regional linkage, the system can actively respond, intervene in advance, and prevent policy gaps, which greatly improves the sensitivity, responsiveness and coverage integrity of the wireless terminal control system.
[0220] For example, a region is divided into three independently controlled areas: Area A: a secure room (mobile phones are disabled at all times); Area B: a training area (mobile phones are disabled during training hours); and Area C: a living area (open all day). In existing technologies, when personnel move across areas in large numbers, the policies of the target areas are not adjusted in a timely manner (e.g., personnel in the secure room can still use mobile phones illegally after entering the training area). Based on the above technical solution, when it is detected that 60 terminals move from Area A to Area B between 8:00 and 8:30 AM (exceeding the threshold of 50 terminals), the "all-time disabled" policy for Area A is extracted; this policy is copied to the time-sharing policy for Area B; the original "training hour disabled" policy for Area B has a priority of 2, while the newly copied policy has a priority of 1 (the smaller the value, the higher the priority), therefore, Area B implements a full-time disabled policy after 8:30 AM. This technical solution automatically strengthens control through group behavior prediction, eliminating security blind spots caused by policy lag.
[0221] This application also discloses a mobile terminal intelligent management and control system.
[0222] A mobile terminal intelligent management and control system, the intelligent management and control system comprising:
[0223] The loading module is used to load the pre-stored whitelist dataset and time-sharing management policy configuration file;
[0224] The radio frequency coverage parameter generation module is used to generate radio frequency signal coverage parameters based on the equipment deployment topology data. The radio frequency signal coverage parameters are used to divide the physical space into multiple independent control areas.
[0225] The radio frequency signal analysis module is used to receive the raw radio frequency signal from the radio frequency module in real time and extract the mobile terminal identifier, signal strength value and signal source spatial location from the raw radio frequency signal; wherein, the signal source spatial location is mapped and matched with the independent control area through radio frequency signal coverage parameters;
[0226] The abnormal terminal identification module is used to compare the parsed mobile terminal identifier with the whitelist dataset. If the match fails, it is marked as an abnormal terminal.
[0227] The terminal control instruction generation module is used to extract the corresponding control rules from the time-sharing control strategy configuration file based on the current timestamp, and generate a set of terminal control instructions in combination with the spatial location of the signal source.
[0228] The terminal blocking execution module is used to adjust the transmission parameters of the radio frequency module according to the terminal control instruction set and to perform terminal blocking operation on abnormal terminals.
[0229] The terminal response feedback module is used to collect terminal response data after the terminal blocking operation is performed;
[0230] The optimization and update module is used to update the whitelist dataset based on terminal response data and optimize the control rules in the time-sharing control strategy configuration file based on historical blocking records.
[0231] The mobile terminal intelligent management and control system of this application embodiment can implement any of the above-mentioned intelligent management and control methods, and the specific working process of each module in the intelligent management and control system can refer to the corresponding process in the above-mentioned method embodiments.
[0232] In the several embodiments provided in this application, it should be understood that the provided methods and systems can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for example, the division of a certain module is merely a logical functional division, and in actual implementation there may be other division methods, such as multiple modules can be combined or integrated into another system, or some features can be ignored or not executed.
[0233] This application also discloses a computer device.
[0234] Computer equipment includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the intelligent management and control method for mobile terminals as described above.
[0235] This application also discloses a computer-readable storage medium.
[0236] A computer-readable storage medium storing a computer program that can be loaded by a processor and executed as in any of the mobile terminal intelligent management methods described above.
[0237] The computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus, or device; the program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.
[0238] It should be noted that the computer device and storage medium in the embodiments of this application are respectively electronic devices and storage media applying the above-described intelligent management and control method for mobile terminals. Therefore, all embodiments of the above-described intelligent management and control method for mobile terminals are applicable to the computer device and storage medium, and can achieve the same or similar beneficial effects. For the computer device / storage medium embodiments, since they are basically similar to the method embodiments, the description is relatively simple; relevant details can be found in the descriptions of the method embodiments.
[0239] In this invention, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.
[0240] Although the invention has been described herein in conjunction with various embodiments, those skilled in the art will understand and implement other variations of the disclosed embodiments by reviewing the accompanying drawings, disclosure, and appended claims in carrying out the claimed invention. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude a plurality. A single processor or other unit can implement several functions listed in the claims. While different dependent claims may recite certain measures, this does not mean that these measures cannot be combined to produce good results.
[0241] The above are all preferred embodiments of this application and are not intended to limit the scope of protection of this application. Any feature disclosed in this specification (including the abstract and drawings) may be replaced by other equivalent or similar features unless specifically stated otherwise. That is, unless specifically stated otherwise, each feature is only one example of a series of equivalent or similar features.
Claims
1. A mobile terminal intelligent management and control method applied to an area requiring communication management and control, characterized in that, The intelligent management and control method comprises: loading a pre-stored whitelist dataset and a time-sharing management and control strategy configuration file; generating radio frequency signal coverage parameters according to device deployment topology data, the radio frequency signal coverage parameters being used to divide a physical space into a plurality of independent management and control areas; real-time receiving of raw radio frequency signals collected by a radio frequency module, and resolving mobile terminal identifiers, signal strength values and signal source spatial positions from the raw radio frequency signals; wherein the signal source spatial positions are mapped and matched with the independent management and control areas through the radio frequency signal coverage parameters; comparison of the resolved mobile terminal identifiers with the whitelist dataset, and marking as abnormal terminals if the comparison fails; extraction of corresponding management and control rules from the time-sharing management and control strategy configuration file according to a current timestamp, and generation of a terminal management and control instruction set in combination with the signal source spatial positions; adjustment of transmission parameters of the radio frequency module according to the terminal management and control instruction set, and execution of a terminal blocking operation on the abnormal terminals; collection of terminal response data fed back after execution of the terminal blocking operation; updating of the whitelist dataset according to the terminal response data, and optimization of the management and control rules in the time-sharing management and control strategy configuration file based on historical blocking records; The terminal response data comprises mobile terminal identifiers, connection request times, alarm trigger flags and timestamps. The steps of updating the whitelist dataset according to the terminal response data, and optimizing the management and control rules in the time-sharing management and control strategy configuration file based on historical blocking records comprise: storing the terminal response data into a historical blocking record database; wherein the historical blocking record database stores mobile terminal blocking records of each independent management and control area in chronological order; extracting mobile terminal identifiers and corresponding connection request times and alarm trigger flags from the terminal response data; screening out mobile terminal identifiers whose connection request times are greater than a preset connection request time threshold value and whose alarm trigger flags are not triggered according to the preset connection request time threshold value and an alarm time window threshold value; writing the screened-out mobile terminal identifiers into a temporary whitelist dataset; retrieving blocking operation records of each independent management and control area within a specified time period from the historical blocking record database; statistically analyzing blocking operation frequencies of each independent management and control area in different time periods, the time periods being divided according to a preset time segmentation rule; inquiring a preset frequency threshold value mapping table, the frequency threshold value mapping table storing maximum allowed blocking frequency values corresponding to each time period; updating a blocking effective duration parameter in the time-sharing management and control strategy configuration file when the blocking operation frequency of any independent management and control area in a specific time period exceeds the corresponding maximum allowed blocking frequency value.
2. The method of claim 1, wherein: The steps of real-time receiving of raw radio frequency signals collected by a radio frequency module, and resolving mobile terminal identifiers, signal strength values and signal source spatial positions from the raw radio frequency signals comprise: real-time receiving of raw radio frequency signals collected by a radio frequency module, the raw radio frequency signals containing mixed carrier signals of a plurality of communication systems; performing a fast Fourier transform operation on the raw radio frequency signals, performing frequency spectrum segmentation according to a preset operator frequency band configuration table, and outputting segmented sub-frequency band signal groups of different types; extracting a control channel message from each sub-band signal group through a physical layer protocol analyzer, and obtaining a corresponding device identification field or a user identification field; generating a mobile terminal identification corresponding to the sub-band signal group according to the device identification field or the user identification field; obtaining real-time beamforming parameters of a radio frequency antenna array; calculating a signal space propagation vector based on the real-time beamforming parameters, combining a received signal power value and a pre-stored radio frequency attenuation coefficient matrix, and outputting a corrected signal strength value; binding the mobile terminal identification, the corrected signal strength value and a current sub-band type as a primary feature set; querying a beam-area mapping table based on the radio frequency signal coverage parameters, and outputting a corresponding independent control area number by matching a horizontal azimuth angle and a vertical elevation angle belonging to a range in the current beamforming parameters; associating the primary feature set with the independent control area number to generate a structured terminal feature record.
3. The method of claim 2, wherein the method further comprises: When the type of the sub-band signal group is a 4G / 5G sub-band, the step of extracting a control channel message from each sub-band signal group through a physical layer protocol analyzer, and obtaining a corresponding device identification field includes: analyzing a scheduling grant field in downlink control information of the 4G / 5G sub-band signal group, and locating an uplink shared channel resource according to the scheduling grant field; performing a cyclic redundancy check on the downlink control information, and extracting a resource block allocation domain when the check passes; locating a radio resource control connection request message in the uplink shared channel resource according to the resource block allocation domain; analyzing an international mobile equipment identity from a medium access control header of the radio resource control connection request message to obtain a device identification field.
4. The method of claim 2, wherein the method further comprises: When the type of the sub-band signal group is a 2G / 3G sub-band, the step of extracting a control channel message from each sub-band signal group through a physical layer protocol analyzer, and obtaining a corresponding user identification field includes: performing frequency hopping and interleaving operations on an independent dedicated control channel of the 2G / 3G sub-band signal group to output an original bit stream; performing Viterbi decoding on the original bit stream to output an unencrypted network layer protocol data unit; analyzing a header byte of the network layer protocol data unit to identify a location update request message type identification code and extract a location area identification field; matching a pre-stored mobile country code mapping table according to the location area identification field to verify a mobile country code to which the location area identification field belongs; if the mobile country code belongs to a pre-set permission list, extracting a temporary mobile user identifier binary data from a user identification container of the network layer protocol data unit; performing a bit reorganization operation on the temporary mobile user identifier binary data to output a user identification field.
5. The method of claim 2, wherein the method further comprises: The intelligent control method further includes: when a mobile terminal carrying an unauthorized network identification is detected, extracting a network registration code in the mobile terminal identification; querying a pre-stored risk feature mapping table to obtain a device behavior feature parameter associated with the network registration code; calculating a risk score value of the mobile terminal based on the device behavior feature parameter; If the risk score value exceeds a preset dynamic threshold, an enhanced blocking instruction is generated and a safety alarm device is activated; The network registration code, terminal risk score value and corresponding timestamp are written into an abnormal terminal behavior log database.
6. The intelligent management and control method of a mobile terminal according to any one of claims 1 to 5, characterized in that, The intelligent management and control method further comprises: Continuously collecting terminal motion trajectory data of each independent management and control area; Based on the terminal motion trajectory data within a preset time window, a space-time transfer matrix is constructed; wherein, the row vector of the space-time transfer matrix represents the starting independent management and control area number, the column vector represents the target independent management and control area number, and the matrix element value is the number of terminals that have transferred areas within the preset time window; When it is detected that the sum of the element values of a specific row vector exceeds a preset transfer threshold, the starting independent management and control area number corresponding to the specific row vector is extracted; The management and control rule associated with the starting independent management and control area number in the time-sharing management and control strategy configuration file is queried; All non-zero column elements in the specific row vector are traversed to obtain the target independent management and control area numbers corresponding to all non-zero column elements; The management and control rule is copied to the time-sharing management and control strategies associated with all target independent management and control area numbers corresponding to the non-zero column elements.
7. A mobile terminal intelligent management and control system applied to an area requiring communication management and control, characterized in that, The intelligent management and control system comprises: A loading module for loading a pre-stored whitelist dataset and a time-sharing management and control strategy configuration file; A radio frequency coverage parameter generation module for generating radio frequency signal coverage parameters according to device deployment topology data, the radio frequency signal coverage parameters being used to divide a physical space into multiple independent management and control areas; A radio frequency signal analysis module for receiving raw radio frequency signals collected by a radio frequency module in real time, and analyzing mobile terminal identifiers, signal strength values and signal source spatial positions from the raw radio frequency signals; wherein, the signal source spatial positions are mapped and matched with the independent management and control areas through the radio frequency signal coverage parameters; An abnormal terminal identification module for comparing the analyzed mobile terminal identifiers with the whitelist dataset, and marking as an abnormal terminal if the comparison fails; A terminal management and control instruction generation module for extracting a corresponding management and control rule from the time-sharing management and control strategy configuration file according to a current timestamp, and generating a terminal management and control instruction set in combination with the signal source spatial position; A terminal blocking execution module for adjusting the transmission parameters of the radio frequency module according to the terminal management and control instruction set, and performing a terminal blocking operation on the abnormal terminal; A terminal response feedback module for collecting terminal response data fed back after the terminal blocking operation is performed; An optimization update module for updating the whitelist dataset according to the terminal response data, and optimizing the management and control rules in the time-sharing management and control strategy configuration file based on historical blocking records; wherein, the terminal response data includes mobile terminal identifiers, connection request times, alarm trigger flags and timestamps; The optimization update module is configured to: Store the terminal response data to a historical blocking record database; wherein, the historical blocking record database stores mobile terminal blocking records of each independent management and control area in chronological order; Extract mobile terminal identifiers and corresponding connection request times and alarm trigger flags from the terminal response data; According to the preset connection request number threshold and the alarm time window threshold, mobile terminal identifiers with the connection request number greater than the preset connection request number threshold and the alarm trigger flag not triggered are screened out; The screened mobile terminal identifiers are written into a temporary white list dataset; The blocking operation records of each independent management area in a specified time period are retrieved from the historical blocking record database; The blocking operation frequency of each independent management area in different time periods is counted, and the time periods are divided according to a preset time segmentation rule; A preset frequency threshold mapping table is queried, and the frequency threshold mapping table stores the maximum allowed blocking frequency values corresponding to each time period; When the blocking operation frequency of any independent management area in a specific time period exceeds the corresponding maximum allowed blocking frequency value, the blocking effective duration parameter in the time-sharing management strategy configuration file is updated.
8. A computer device, comprising: The computer program stored on the memory and executable on the processor, when the processor executes the program, implements the method of any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that: The computer program stored on the memory and executable on the processor, when the processor executes the program, implements the method of any one of claims 1 to 6.
Citation Information
Patent Citations
Real-time management and control method for terminal and base station control module
CN104980954A
All-system cellphone terminal control method and device
CN105142142A