Terminal equipment access control method, communication system and zero-trust security management platform
By deploying a zero-trust client and a security management platform in the 5G MOCN architecture, terminal feature information is collected and access control is performed, solving the problem of being unable to eliminate terminals with security risks and realizing security management and resource protection for terminal devices.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-23
- Publication Date
- 2026-04-07
AI Technical Summary
In the 5G MOCN architecture, existing technologies cannot effectively remove access terminals with security vulnerabilities from the network, resulting in potential security threats persisting in shared base stations and affecting data transmission for other operators.
By deploying a zero-trust client on the terminal device, collecting terminal characteristic information, and using the zero-trust security management platform to generate access control information, a subscription data modification request is sent to the NEF network element to modify the subscription data in the UDM network element, triggering the PDU session modification of the terminal device, so as to realize security upgrade, downgrade, isolation or de-isolation processing.
It enables secure management of terminal device access status, avoids potential security risks, ensures that shared base station resources are not occupied by insecure terminals, and protects the normal data transmission of other operators.
Smart Images

Figure CN121815268A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and more specifically, to a terminal device access control method, a communication system, and a zero-trust security management platform. Background Technology
[0002] 5G MOCN (Multi-Operator Core Network) is a network architecture that allows multiple operators to share the same Radio Access Network (RAN). In this architecture, multiple operators share the same RAN while maintaining the independence of their respective core networks (CNs).
[0003] While the MOCN architecture can ensure secure isolation between data transmissions from different operators, it cannot remove access terminals with security vulnerabilities from the network. This could lead to security vulnerabilities persisting in shared base stations and triggering potential security risks. Summary of the Invention
[0004] The purpose of this application is to address the shortcomings of the prior art by providing a terminal device access control method, a communication system, and a zero-trust security management platform, so as to solve the aforementioned technical problems in the related technologies.
[0005] To achieve the above objectives, the technical solutions adopted in the embodiments of this application are as follows: In a first aspect, embodiments of this application provide a terminal device access control method applied to a zero-trust security management platform in a communication system. Both the zero-trust security management platform and the terminal device are connected to a target core network. The zero-trust security management platform also connects to other core networks. The target core network and the other core networks share the same base station. The method includes: Receive terminal characteristic information sent by a zero-trust client deployed on the terminal device; Based on the terminal feature information, the access control information of the terminal device is obtained; Based on the access control information, a subscription data modification request for the terminal device is sent to the Network Device Function (NEF) element, so that the NEF element modifies the subscription data of the terminal device in the Unified Data Management (UDM) element according to the subscription data modification request, thereby triggering the Protocol Data Unit (PDU) session modification of the terminal device.
[0006] Optionally, receiving terminal characteristic information sent by the zero-trust client deployed on the terminal device includes: Receive device characteristics, application characteristics, and traffic characteristics of the terminal device sent by the zero-trust client; The step of obtaining the access control information of the terminal device based on the terminal feature information includes: Based on the device characteristics, application characteristics, and traffic characteristics, the access control information of the terminal device is obtained.
[0007] Optionally, obtaining the access control information of the terminal device based on the device characteristics, the application characteristics, and the traffic characteristics includes: If the device's Internet Protocol address (IP address) and operating system version in the device characteristics change, or if any characteristic value in the traffic characteristics is less than a preset minimum security threshold, or if the system middleware software version in the application characteristics is a risky version, then the current security level of the terminal device will be downgraded, and the downgraded security level will be used as the access control information.
[0008] Optionally, obtaining the access control information of the terminal device based on the device characteristics, the application characteristics, and the traffic characteristics includes: If the device IP address and operating system version in the device characteristics are restored to the initial device IP address and initial operating system version, and all feature values in the traffic characteristics are greater than the preset minimum security threshold, and the system middleware software version in the application characteristics is a risk-free version, then the security level of the terminal device is upgraded, and the upgraded security level is used as the access control information. The initial device IP address and initial operating system version refer to the address and version of the terminal device when it accesses the target core network.
[0009] Optionally, obtaining the access control information of the terminal device based on the device characteristics, the application characteristics, and the traffic characteristics includes: If multiple pieces of information in the device characteristics change, or if any feature value in the traffic characteristics exceeds the maximum security threshold, or if the system middleware version in the application characteristics meets the preset risk conditions, then the terminal device is subjected to security isolation processing, and the security isolation result is used as the access control information.
[0010] Optionally, obtaining the access control information of the terminal device based on the device characteristics, the application characteristics, and the traffic characteristics includes: If multiple pieces of information in the device features are restored to their initial values, and if all feature values in the traffic features are less than the maximum security threshold, and if the system middleware version in the application features is a preset security condition, then the terminal device is subjected to security isolation removal processing, and the security isolation removal result is used as the access control information. The initial value is the value when the terminal device accesses the core network.
[0011] Optionally, the contract data modification request is used to indicate the following modifications: Modify the network slice on which the terminal device establishes a PDU session; Modify the type of wireless resources that the terminal device can use; Modify the data transmission rate limit configured for the terminal device.
[0012] Optionally, the contract data modification request is used to indicate the following modifications: Modify the access control parameters of the terminal device to determine whether access to the target core network is permitted.
[0013] Secondly, embodiments of this application provide a communication system, including: a zero-trust security management platform, a target core network, other core networks, and a base station; The zero-trust security management platform and the terminal device are both connected to the target core network. The zero-trust security management platform is also connected to other core networks. The target core network and the other core networks share the same base station. The zero-trust security management platform is used to execute the method described in any of the first aspects above.
[0014] Thirdly, embodiments of this application provide a zero-trust security management platform, including: a memory and a processor, wherein the memory stores a computer program executable by the processor, and the processor executes the computer program to implement the method described in any of the first aspects above.
[0015] The beneficial effects of this application are as follows: This application provides a terminal device access control method, a communication system, and a zero-trust security management platform. The method includes: receiving terminal feature information sent by a zero-trust client deployed on the terminal device; obtaining access control information of the terminal device based on the terminal feature information; and sending a subscription data modification request for the terminal device to a Network Device Function (NEF) network element based on the access control information, so that the NEF network element modifies the subscription data of the terminal device in the Unified Data Management (UDM) network element according to the subscription data modification request, triggering a PDU session modification of the terminal device. Access control information for the terminal device is generated based on the terminal feature information collected by the zero-trust client. This allows for secure management of the terminal device's access to the target core network based on the access control information, avoiding potential security risks. Attached Figure Description
[0016] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0017] Figure 1 This application provides a schematic diagram of a structure in which multiple operators share the same set of base station equipment. Figure 2 This application provides a schematic diagram of the structure of a communication system according to an embodiment of the present application. Figure 3 A schematic diagram illustrating the connection structure of a zero-trust security management platform, terminal device, and target core network provided in this application embodiment; Figure 4 A flowchart illustrating a terminal device access control method provided in this application embodiment. Figure 1 ; Figure 5 A flowchart illustrating a terminal device access control method provided in this application embodiment. Figure 2 ; Figure 6 A flowchart illustrating a terminal device access control method provided in this application embodiment. Figure 3 ; Figure 7 This application provides a schematic diagram of the structure of a terminal device access control device according to an embodiment of the present application; Figure 8 This is a schematic diagram of the structure of a zero-trust security management platform provided in an embodiment of this application. Detailed Implementation
[0018] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of this application, but not all embodiments.
[0019] Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0020] In the description of this application, it should be noted that if the terms "upper", "lower", etc. appear to indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings, or the orientation or positional relationship that the product of this application is usually placed in, it is only for the convenience of describing this application and simplifying the description, and does not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of this application.
[0021] Furthermore, the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Additionally, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0022] It should be noted that, where there is no conflict, the features in the embodiments of this application can be combined with each other.
[0023] The following is an explanation of the terms used in the embodiments of this application.
[0024] 5G: 5th Generation Mobile Communication Technology.
[0025] UDM: Unified Data Management, whose functions include user identity management, policy management, and user configuration management.
[0026] SMF: Session Management Function, responsible for user session management. It is mainly used for session management, UE Internet Protocol (IP) address allocation and management, selection of manageable user plane functions, policy control, or endpoints for charging function interfaces, and downlink data notification. In this application embodiment, it can be used to implement the functions of a session management network element.
[0027] NEF: Network Equipment Functions, is a component of a network device that can be used to provide network services.
[0028] UE: User Equipment, also known as user equipment, terminal, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, wireless communication equipment, user agent, or user device. UE can also be a cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), handheld device with wireless communication capabilities, computing device or other processing device connected to a wireless modem, vehicle-mounted device, wearable device, terminal equipment in a 5G network, or terminal equipment in a future evolved public land mobile network (PLMN), etc. It can also be an end device, logical entity, smart device, such as a mobile phone, smart terminal, or other terminal equipment; or a server, gateway, base station, controller, or other communication equipment; or an Internet of Things (IoT) device, such as a sensor, electricity meter, water meter, etc. This application's embodiments do not limit this.
[0029] PDU session: Protocol Data Unit session is the process of communication between a user terminal and a data network, which establishes a data transmission channel between the user terminal and the data network.
[0030] UPF: User Plane Function, i.e., data plane gateway. It can be used for packet routing and forwarding, or for quality of service (QoS) processing of user plane data. User data can access the data network (DN) through this network element. In the embodiments of this application, it can be used to implement the functions of a user plane gateway.
[0031] RAN: Radio Access Network, is a part of a mobile communication system. It is the implementation of radio access technology. NG-RAN refers to 5G Line Access Network.
[0032] AMF: Access and Mobility Management Function, primarily used for mobility management and access management, can be used to implement functions of the Mobility Management Entity (MME) other than session management, such as lawful interception or access authorization (or authentication). In the embodiments of this application, it can be used to implement the functions of the access and mobility management network element.
[0033] NSSF: Network Slice Selection Function, responsible for managing network slices.
[0034] UDM: Unified Data Management, used for handling user identification, access authentication, registration, or mobility management, etc.
[0035] NRF: NF Repository Function. This function is a new feature that provides registration and discovery capabilities, enabling network functions to discover each other and communicate through an API (Application Programming Interface).
[0036] PCF: Policy Control Function, is one of the network functions of the 5G core network. Its main function is to manage network behavior using a unified policy framework and to coordinate with user information in the UDR (Unified Data Repository) to execute relevant policies.
[0037] AF: Application Function, refers to various services at the application layer. These are used for data routing affected by applications, accessing network open function elements, or interacting with policy frameworks for policy control, etc.
[0038] AUSF: Authentication Server Function.
[0039] NG-RAN: Next Generation Radio Access Network.
[0040] SDP: Software-Defined Perimeter.
[0041] 5G MOCN is a network architecture that allows multiple operators to share the same radio access network (RAN). In this architecture, multiple operators share the same RAN while maintaining the independent operation of their respective core networks (CNs). Figure 1 This application provides a schematic diagram of a structure in which multiple operators share the same set of base station equipment, as shown in the embodiments. Figure 1 As shown, 5GC-A (operator A's 5G core network) and 5GC-B (operator B's 5G core network) operate independently. 5GC-A and 5GC-B share the same base station, which can be called a shared base station. Specifically, it can be a gNB (5G base station) or an ng-eNB (4G base station).
[0042] Both 5GC-A and 5GC-B include: AMF, SMF, and UPF. The AMF communicates with the base station via the N2 interface, the AMF connects to the UPF via the SMF, and the UPF also communicates with the base station via the N3 interface. In 5GC-A, the UPF interacts with the data network of Operator A, while in 5GC-B, the UPF interacts with the data network of Operator B. Operator A and Operator B each process their own user data and service control through their own core networks, operating independently without interference.
[0043] It's worth noting that the MOCN architecture reduces network construction costs by allowing multiple operators to share the hardware costs of base station equipment, data centers, and power. It also improves resource utilization, preventing single-operator base stations from becoming idle, and allows for on-demand allocation of wireless resources (such as spectrum and time slots) through sharing, increasing network load. Furthermore, it ensures operational independence; an independent core network means operators can independently set tariffs and launch specialized services (such as industrial internet and vehicle-to-everything), without relying on other parties. In newly built industrial parks, multiple operators can jointly deploy base stations to quickly achieve 5G coverage.
[0044] Figure 2 This is a schematic diagram of the structure of a communication system provided in an embodiment of this application, such as... Figure 2 As shown, the communication system includes: a zero-trust security management platform, a target core network, other core networks, and base stations.
[0045] In this system, both the zero-trust security management platform and the terminal devices are connected to the target core network. The zero-trust security management platform is also connected to other core networks, and the target core network and other core networks share the same base station. The zero-trust security management platform is used to execute a terminal device access control method provided in this application embodiment.
[0046] It should be noted that other core networks can also access other terminal devices. The zero-trust security management platform can use terminal device access control methods to control the access of any terminal device connected to any core network in the target core network and other core networks.
[0047] Figure 3 A schematic diagram illustrating the connection structure of a zero-trust security management platform, terminal device, and target core network provided in this application embodiment is shown below. Figure 3 As shown, the target core network includes: NSSF entity, NEF entity, NRF entity, PCF entity, UDM entity, AF entity, SMF entity, AMF entity, and AUSF entity connected to the communication bus; terminal devices communicate with the UPF entity through the NG-RAN entity, and the terminal devices also communicate with the AMF entity, the AMF entity communicates with the NG-RAN entity, and the SMF entity communicates with the UPF entity.
[0048] The UPF entity communicates with the Zero Trust Security Management Platform through the SDP gateway, the Zero Trust Security Management Platform also communicates with the NEF entity, and the SDP gateway communicates with the business server.
[0049] Additionally, the N1 interface serves as the reference point between the terminal device and the AMF entity; the N2 interface serves as the reference point between the AN and the AMF entities, used for sending non-access stratum (NAS) messages; the N3 interface serves as the reference point between the AN and the UPF entity, used for transmitting user plane data; the N4 interface serves as the reference point between the SMF entity and the UPF entity, used for transmitting information such as tunnel identification information for the N3 connection, data buffer indication information, and downlink data notification messages; and the N6 interface serves as the reference point between the UPF entity and the SDP gateway.
[0050] It should be understood that the network architecture described above in the embodiments of this application is merely an example illustrating a network architecture from the perspective of a traditional point-to-point architecture and a service-oriented architecture. The network architecture applicable to the embodiments of this application is not limited to this; any network architecture capable of implementing the functions of the above-described network elements is applicable to the embodiments of this application. It should be understood that the above-described network elements can communicate with each other through preset interfaces, which will not be elaborated further here.
[0051] It should also be understood that Figure 3 The NSSF, NEF, NRF, PCF, UDM, AF, SMF, AMF, AUSF, NG-RAN, and UPF entities shown can be understood as network elements in the core network used to implement different functions, such as network slices that can be combined as needed. These core network elements can be independent devices or integrated into the same device to implement different functions; this application does not limit this.
[0052] In the following text, for ease of explanation, the entity used to implement NEF will be referred to as NEF, and the entity used to implement UDM will be referred to as UDM. Other designations are similar and will not be repeated here. It should be understood that the above naming is only for distinguishing different functions and does not mean that these network elements are independent physical devices. This application does not limit the specific form of the above network elements. For example, they can be integrated into the same physical device or they can be different physical devices. In addition, the above naming is only for distinguishing different functions and should not constitute any limitation on this application. This application does not exclude the possibility of using other names in 5G networks and other future networks. For example, in 6G networks, some or all of the above network elements can use the terminology in 5G, or they may use other names, etc. This is explained uniformly here and will not be repeated below.
[0053] It should also be understood that Figure 3 The interface names between the various network elements are merely examples; in actual implementations, the interface names may differ, and this application does not impose any specific limitations on them. Furthermore, the names of the messages (or signaling) transmitted between the aforementioned network elements are also merely examples and do not constitute any limitation on the function of the messages themselves.
[0054] The terminal device access control method provided in this application embodiment is based on zero trust technology. The underlying logic of zero trust technology is that it does not assume that any network location (internal network / external network), device or user is trusted. Regardless of whether the access source is an enterprise intranet, a remote office terminal or a third-party device, it must pass multi-dimensional verification of "identity legitimacy + terminal security + behavior compliance", and the verification runs through the entire access lifecycle (not a single authentication).
[0055] Zero Trust technology relies on the SDP architecture for implementation. Its core consists of three parts: SDP client, zero trust security management platform, and SDP gateway. The three interact through "control flow + data flow" and strictly follow the logic of "authentication first, connection establishment then access to resources".
[0056] The MOCN integrated zero-trust capability in this embodiment connects the zero-trust security management platform with the UEF, enabling the 5G network to promptly modify the subscription data in the UDM based on the access control information from the zero-trust security management platform via the UEF, thereby removing terminal devices with security vulnerabilities from the network. Furthermore, by integrating an SDP client and an SDP gateway on the terminal device and UPF sides respectively, secure isolation of data transmission between different operators can be achieved within the 5G network.
[0057] This application provides a terminal device access control method, applied to the aforementioned zero-trust security management platform. The following explains the terminal device access control method provided in this application.
[0058] Figure 4 A flowchart illustrating a terminal device access control method provided in this application embodiment. Figure 1 ,like Figure 4 As shown, the method may include: S101. Receive terminal characteristic information sent by the zero-trust client deployed on the terminal device.
[0059] Among them, the zero-trust client is the SDP client. The terminal feature information consists of multi-dimensional terminal feature information.
[0060] In some implementations, the terminal device accesses the target core network, and the zero-trust client deployed on the terminal device sequentially sends terminal characteristic information to the zero-trust security management platform through the NG-RAN, UPF, and SDP gateways; the zero-trust security management platform can receive the terminal characteristic information.
[0061] It should be noted that the terminal device accesses the target core network in the following manner: The terminal device completes initial registration according to the 3GPP (3rd Generation Partnership Project) standard process; the terminal device completes PDU session establishment according to the 3GPP standard process; the terminal device's built-in SDP client establishes an encrypted data transmission tunnel with the SDP gateway; the terminal device forwards all encrypted service data to the UPF through the SDP client; the UPF forwards the encrypted service data to the SDP gateway; the SDP gateway decrypts the service data and forwards it to the service server.
[0062] S102. Obtain the access control information of the terminal device based on the terminal characteristic information.
[0063] After receiving the terminal feature information, the zero-trust security management platform comprehensively evaluates the security status of the terminal based on the preset security policy rule set and generates corresponding access control information.
[0064] In some implementations, based on terminal characteristic information, the terminal device is subjected to security upgrade, security downgrade, security isolation, or security isolation removal processes to obtain the processing result; the processing result is used as access control information for the interrupting device so as to perform access control on the terminal device based on the access control information.
[0065] S103. Based on the access control information, send a subscription data modification request for the terminal device to the NEF network element, so that the NEF network element can modify the subscription data of the terminal device in the UDM network element according to the subscription data modification request, and trigger the PDU session modification of the terminal device.
[0066] In some implementations, based on the access control information of the terminal device, a subscription data modification request for the terminal device is sent to the Network Device Function (NEF) element. Correspondingly, the NEF element receives the subscription data modification request and modifies the subscription data of the terminal device in the UDM element according to the subscription data modification request. After the subscription data of the terminal device in the UDM element is modified, the UDM element is triggered.
[0067] It should be noted that the terminal device access control method provided in this application embodiment does not require modification of the underlying network elements and has good compatibility and deployability.
[0068] In summary, this application provides a terminal device access control method, which includes: receiving terminal feature information sent by a zero-trust client deployed on the terminal device; obtaining access control information of the terminal device based on the terminal feature information; and sending a subscription data modification request for the terminal device to a Network Device Function (NEF) element based on the access control information, so that the NEF element modifies the subscription data of the terminal device in the Unified Data Management (UDM) element according to the subscription data modification request, triggering a PDU session modification of the terminal device. Based on the terminal feature information collected by the zero-trust client, access control information for the terminal device is generated. This allows for secure management of the terminal device's access to the target core network based on the access control information, avoiding potential security risks.
[0069] Optionally, Figure 5 A flowchart illustrating a terminal device access control method provided in this application embodiment. Figure 2 ,like Figure 5 As shown, the process of receiving terminal feature information sent by the zero-trust client deployed on the terminal device in S101 above may include: S201. Receive device characteristics, application characteristics, and traffic characteristics of the terminal device sent by the zero-trust client.
[0070] The device characteristics of the terminal device include: CPU (Central Processing Unit) model, BIOS (Basic Input / Output System) serial number, operating system version, 5G communication module IMSI (International Mobile Subscriber Identity), and device IP address (Internet Protocol Address).
[0071] In this application embodiment, application features include: system middleware software version, and ports in an open state. Traffic features include: 5G uplink or downlink rate, data flow rate of a specified IP 5-tuple, packet arrival interval of a specified IP 5-tuple, and uplink or downlink rate and packet arrival interval of a specified Ethernet data type.
[0072] The process of obtaining access control information of the terminal device based on terminal feature information in S102 above may include: S202. Obtain access control information for terminal devices based on device characteristics, application characteristics, and traffic characteristics.
[0073] In some implementations, based on multiple dimensions such as device characteristics, application characteristics, and traffic characteristics, the terminal device is subjected to security upgrades, security downgrades, security isolation, or de-isolation processes to obtain processing results; the processing results are used as access control information for interrupting devices so that access control can be performed on the terminal device based on the access control information.
[0074] In summary, in the embodiments of this application, device features, application features, and traffic features can comprehensively and accurately characterize the feature information of terminal devices. The access control information determined based on device features, application features, and traffic features is also more accurate, thereby enabling accurate and reliable access control of terminal devices.
[0075] Optionally, the process of obtaining the access control information of the terminal device based on device characteristics, application characteristics, and traffic characteristics in S202 above may include: If the device IP address and operating system version in the device characteristics change, or if any characteristic value in the traffic characteristics is less than the preset minimum security threshold, or if the system middleware software version in the application characteristics is a risky version, then the current security level of the terminal device will be downgraded, and the downgraded security level will be used as the access control information.
[0076] In some implementations, a change in the device IP address or operating system version in the device characteristics compared to its initial state is considered a change in the device IP address and operating system version. Here, the initial state refers to the initial device IP address or initial operating system version of the terminal device when it first successfully accesses the target core network.
[0077] In addition, the application characteristics indicate that the system middleware software version is a risky version, which means that the system middleware software version has potential security risks.
[0078] Optionally, the process of obtaining access control information of the terminal device based on device characteristics, application characteristics, and traffic characteristics in S202 above includes: If the device IP address and operating system version in the device characteristics are restored to the initial device IP address and initial operating system version, and all characteristic values in the traffic characteristics are greater than the preset minimum security threshold, and the system middleware software version in the application characteristics is a risk-free version, then the security level of the terminal device will be upgraded, and the upgraded security level will be used as access control information.
[0079] The initial device IP address and initial operating system version are the address and version of the terminal device when it accesses the target core network.
[0080] It should be noted that if the device IP address and operating system version in the device characteristics are restored to the initial device IP address and initial operating system version, it indicates that the device characteristics are secure; if all characteristic values in the traffic characteristics are greater than the preset minimum security threshold, it indicates that the traffic characteristics are secure; if the system middleware software version in the application characteristics is a risk-free version, it indicates that the application characteristics are secure; if the device characteristics, traffic characteristics, and application characteristics are all secure, the security level of the terminal device is upgraded to ensure accurate and reliable security level upgrade.
[0081] In summary, in this embodiment of the application, the security level of the terminal device is updated based on multiple dimensions of characteristics such as device features, traffic features, and application features, so that the updated security level can accurately reflect the security level of the terminal device.
[0082] Optionally, the process of obtaining the access control information of the terminal device based on device characteristics, application characteristics, and traffic characteristics in S202 above may include: If multiple pieces of information in the device characteristics change, or if any characteristic value in the traffic characteristics exceeds the maximum security threshold, or if the system middleware version in the application characteristics meets the preset risk conditions, then the terminal device will be subjected to security isolation processing, and the security isolation result will be used as access control information.
[0083] Among them, several pieces of information in the device characteristics have changed, namely the CPU model, BIOS serial number, operating system version, and 5G communication module IMSI.
[0084] Additionally, if the system middleware version in the application features meets the preset risk conditions, it means that the system middleware version is a version with security risks or that unauthorized ports are open.
[0085] It is worth noting that if multiple pieces of information in the device characteristics change, or if any characteristic value in the traffic characteristics exceeds the maximum security threshold, or if the system middleware version in the application characteristics meets the preset risk conditions, indicating that the terminal device has security risks, in order to avoid the terminal device's adverse effects on the shared base station, the terminal device will be security isolated and will not be able to access the target core network.
[0086] Optionally, the process of obtaining the access control information of the terminal device based on device characteristics, application characteristics, and traffic characteristics in S202 above may include: If multiple pieces of information in the device characteristics are restored to their initial values, and if all feature values in the traffic characteristics are less than the maximum security threshold, and if the system middleware version in the application characteristics is a preset security condition, then the terminal device will be de-security isolated, and the result of de-security isolation will be used as access control information. The initial value is the value when the terminal device accesses the core network.
[0087] In this embodiment, restoring multiple pieces of information in the device features to their initial values means that the CPU model, BIOS serial number, operating system version, and 5G communication module IMSI in the device features are all restored to their initial values. Setting the system middleware version to a preset security condition in the application features means that the system middleware software version is a risk-free version and all unauthorized ports are closed.
[0088] It is worth noting that if multiple pieces of information in the device characteristics are restored to their initial values, and if all characteristic values in the traffic characteristics are less than the maximum security threshold, and if the system middleware version in the application characteristics is within the preset security conditions, it indicates that there are no security risks in the terminal device. In this case, the terminal device will be released from security isolation, and the terminal device can then access the target core network.
[0089] Optionally, Figure 6 A flowchart illustrating a terminal device access control method provided in this application embodiment. Figure 3 ,like Figure 6 As shown, the contract data modification request is used to instruct the following modifications: S301. Modify the network slice on which the terminal device establishes a PDU session.
[0090] S302. Modify the type of wireless resources that the terminal device can use.
[0091] S303, Modify the data transmission rate limit configured for terminal devices.
[0092] In some implementations, if the access control information is a downgraded security level, then the modified terminal device can only establish PDU sessions on the default network slice; the modified terminal device can only use dynamically allocated wireless resources; and the modified terminal device can only configure the maximum data transmission rate limit, and cannot configure the minimum data transmission rate limit.
[0093] In other implementations, if the access control information is an upgraded security level, then the modified terminal device can establish a PDU session on a dedicated network slice; the modified terminal device can use statically allocated wireless resources; and the modified terminal device can be configured with a minimum data transmission rate limit.
[0094] Optionally, a contract data modification request is used to instruct the following modifications: Modify the access control parameters of the terminal device to determine whether access to the target core network is permitted.
[0095] It should be noted that if the access control information is a security isolation result, the access control parameters of the terminal device should be modified to prohibit access to the target core network; if the access control information is a security isolation release result, the access control parameters of the terminal device should be modified to allow access to the target core network.
[0096] In related technologies, it is impossible to remove access terminals with security vulnerabilities from the network. This may lead to the long-term existence of security vulnerabilities in shared base stations and cause potential security risks. For example, insecure terminal access may employ attack methods similar to DDoS (Distributed Denial-of-Service) attacks, rapidly consuming base station resources and thus affecting the normal transmission of data from other operators. In this embodiment, terminal devices with security vulnerabilities are securely isolated. After secure isolation, the terminal devices cannot access the target core network and therefore cannot occupy shared base station resources, thus avoiding affecting the normal transmission of data from other operators and preventing adverse effects on shared base stations or other operators.
[0097] In summary, the embodiments of this application provide a terminal device access control method, which can prevent users from affecting the normal operation of other operators' terminals in the MOCN architecture due to the access of insecure terminals by some operators. When an insecure terminal appears in the MOCN architecture network, the system can automatically isolate it for security without additional manual configuration. When the terminal in the MOCN architecture network returns to a secure state, the system can automatically remove the security isolation for it without additional manual configuration.
[0098] Furthermore, the SDP client, zero-trust security management platform, and SDP gateway involved in this application strictly follow the logic of "authentication first, connection establishment later, and resource access later," with the specific process as follows: The terminal initiates an authentication request: The user installs an SDP client (supporting multiple systems). The client collects terminal environment information (device configuration, operating system, network environment, EDR status, etc.) and carries identity information (static password / OTP / U-key (identity authentication tool) and other multi-factor authentication information) to initiate a "knock" request to the Zero Trust Security Management Platform. Here, EDR status refers to the real-time security status of the terminal detection and response system on a specific device.
[0099] Trust assessment of the management platform: The zero-trust security management platform verifies the user's identity (multi-factor authentication) and the terminal security (environmental awareness results) to generate an initial trust level; after passing the verification, it sends "connectable SDP gateway information" to the SDP client and sends a control command to the SDP gateway to "allow the client".
[0100] The gateway establishes a secure tunnel: Based on the gateway information, the SDP client establishes an encrypted tunnel with the SDP gateway (to prevent data transmission leakage); the gateway only accepts connections from clients authorized by the management platform and rejects all unauthorized requests by default.
[0101] Resource Access and Continuous Verification: Clients access business resources through an encrypted tunnel. During the access process, the management platform continuously collects data such as terminal behavior, network traffic, and abnormal events, and dynamically adjusts the trust level. If the trust level drops (e.g., the terminal has vulnerabilities or exhibits abnormal behavior), it immediately implements control measures such as demotion and forced shutdown.
[0102] The terminal is the entry point for access. Zero Trust achieves "terminal trust" verification through SDP clients. The core principles include: Holographic terminal environment awareness: The client collects terminal characteristics (CPU model, BIOS serial number, operating system version), user behavior (keyboard and mouse operation frequency, access interval), security status (whether EDR protection is enabled, vulnerability patching status), and network environment (IP address, base station information) in real time, and reports them to the management platform as the basic data for trust assessment.
[0103] Multi-Factor Authentication (MFA): Supports seven authentication methods, including static passwords, OTP (One-Time Password), LDAP (Lightweight Directory Access Protocol), AD (Active Directory Domain), digital certificates, SMS, and U-key (a hardware authentication device). These methods can be combined (e.g., "static password + U-key") to solve the problem of unauthorized access caused by the theft of a single password, ensuring "trustworthy user identity".
[0104] SDP gateways block unauthorized probes through "stealth + proactive protection," the principles of which include: Network stealth mechanism: By default, the gateway closes all service ports and only opens UDP ports (User Datagram Protocol) (and "only receives, does not respond"), so attackers cannot scan or probe the location of service resources; the gateway only temporarily opens the corresponding service port after the client is authenticated by the management platform (it automatically closes after timeout), thus achieving "true application stealth".
[0105] Full protocol parsing and attack detection: Supports parsing TCP (Transmission Control Protocol) / IP (Internet Protocol) (DNS, FTP, HTTP, etc.), IoT protocols (MQTT, CoAP, LwM2M, etc.), and industrial control protocols (TSN, FC, AFDX, etc.), and detects malicious traffic (DDoS attacks, SQL injection, port scanning) and malware (Shellcode attacks, LFI (Local File Inclusion) anomalies) in real time, providing data support for anomaly analysis of the management platform.
[0106] Fine-grained control based on URLs (Uniform Resource Locators): Only authorized users (based on identity and trust level) are allowed to access resources at specified URLs, preventing users from accessing sensitive pages without authorization and reducing the risk of data leakage.
[0107] The Zero Trust Security Management Platform ensures compliance throughout the access process through "dynamic assessment + intelligent decision-making." Its core principles include: Multi-factor continuous trust assessment: Based on the "terminal environment information + attack capture data + abnormal behavior data" reported by the client, combined with the "adaptive assessment model" (integrating subjective expert assignment and objective entropy weight method), the user's trust level (high / medium / low) is calculated in real time; for example, a vulnerability in the terminal leads to a decrease in the trust level, and consecutive login failures trigger enhanced authentication.
[0108] Dynamic permission control: Following the "principle of least privilege", permissions are dynamically adjusted based on "user identity (role / department) + trust level + business scenario".
[0109] Anomaly analysis and contingency planning based on large models: A dedicated security model is built using a large language model (LLM) to detect behaviors such as "excessively short access intervals, abnormal traffic, and abnormal state transitions" in real time (with higher detection speed and accuracy than traditional models); at the same time, emergency plans are generated based on historical "alarm-response" data, supporting automatic handling (such as blocking abnormal traffic) or manual approval, thereby improving threat response efficiency.
[0110] Identity and Organization Management: Enables full lifecycle management of accounts (master / sub-account creation, expiration, and cancellation), supports integration with enterprise AD domains or HR (Human Resources) systems to synchronize organizational structures, and sets up hierarchical administrators based on the "separation of powers" to ensure compliant identity management.
[0111] The following describes the terminal device access control device, zero-trust security management platform, and storage medium used to implement the terminal device access control method provided in this application. For the specific implementation process and technical effects, please refer to the relevant content of the aforementioned terminal device access control method, which will not be repeated below.
[0112] Figure 7 This application provides a schematic diagram of the structure of a terminal device access control device according to an embodiment of the present application. Figure 7 As shown, this device is applied to a zero-trust security management platform in a communication system. Both the zero-trust security management platform and the terminal device are connected to a target core network. The zero-trust security management platform is also connected to other core networks. The target core network and the other core networks share the same base station. The device includes: The receiving module 101 is used to receive terminal characteristic information sent by the zero-trust client deployed on the terminal device; The acquisition module 102 is used to acquire the access control information of the terminal device based on the terminal feature information; The sending module 103 is used to send a subscription data modification request for the terminal device to the Network Device Function (NEF) network element according to the access control information, so that the NEF network element modifies the subscription data of the terminal device in the Unified Data Management (UDM) network element according to the subscription data modification request, thereby triggering the PDU session modification of the terminal device.
[0113] Optionally, the receiving module 101 is specifically used to receive the device characteristics, application characteristics, and traffic characteristics of the terminal device sent by the zero-trust client; The acquisition module 102 is specifically used to acquire the access control information of the terminal device based on the device characteristics, the application characteristics, and the traffic characteristics.
[0114] Optionally, the acquisition module 102 is specifically used to downgrade the current security level of the terminal device if the device Internet Protocol address (IP address) and operating system version in the device characteristics change, or if any feature value in the traffic characteristics is less than a preset minimum security threshold, or if the system middleware software version in the application characteristics is a risky version, and obtain the downgraded security level as the access control information.
[0115] Optionally, the acquisition module 102 is specifically used to upgrade the security level of the terminal device if the device IP address and operating system version in the device features are restored to the initial device IP address and initial operating system version, and all feature values in the traffic features are greater than the preset minimum security threshold, and the system middleware software version in the application features is a risk-free version, and the upgraded security level is used as the access control information. The initial device IP address and initial operating system version refer to the address and version of the terminal device when it accesses the target core network.
[0116] Optionally, the acquisition module 102 is specifically used to perform security isolation processing on the terminal device if multiple pieces of information in the device features change, or if any feature value in the traffic features is greater than the maximum security threshold, or if the system middleware version in the application features meets the preset risk conditions, and obtain the security isolation result as the access control information.
[0117] Optionally, the acquisition module 102 is specifically used to perform security isolation removal processing on the terminal device if multiple pieces of information in the device features are restored to their initial values, and if all feature values in the traffic features are less than the maximum security threshold, and if the system middleware version in the application features is a preset security condition, and obtain the security isolation removal result as the access control information. The initial value is the value when the terminal device accesses the core network.
[0118] Optionally, the contract data modification request is used to indicate the following modifications: Modify the network slice on which the terminal device establishes a PDU session; Modify the type of wireless resources that the terminal device can use; Modify the data transmission rate limit configured for the terminal device.
[0119] Optionally, the contract data modification request is used to indicate the following modifications: Modify the access control parameters of the terminal device to determine whether access to the target core network is permitted.
[0120] The above-described device is used to execute the method provided in the foregoing embodiments, and its implementation principle and technical effect are similar, so they will not be described again here.
[0121] These modules can be one or more integrated circuits configured to implement the above methods, such as one or more Application Specific Integrated Circuits (ASICs), one or more digital signal processors (DSPs), or one or more Field Programmable Gate Arrays (FPGAs). Alternatively, when a module is implemented using processing element scheduler code, the processing element can be a general-purpose processor, such as a Central Processing Unit (CPU) or other processor capable of calling program code. Furthermore, these modules can be integrated together as a system-on-a-chip (SOC).
[0122] Figure 8 This application provides a schematic diagram of the structure of a zero-trust security management platform, as shown in the embodiments. Figure 8 As shown, the zero-trust security management platform includes: processor 201 and memory 202.
[0123] The memory 202 is used to store programs, and the processor 201 calls the programs stored in the memory 202 to execute the above method embodiments. The specific implementation and technical effects are similar, and will not be described in detail here.
[0124] Optionally, this application also provides a program product, such as a computer-readable storage medium, including a program that, when executed by a processor, performs the above-described method embodiments.
[0125] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0126] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0127] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional units.
[0128] The integrated units implemented as software functional units described above can be stored in a computer-readable storage medium. These software functional units, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0129] The above are merely preferred embodiments of this application and are not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A terminal device access control method, characterized in that, A zero-trust security management platform applied in a communication system, wherein both the zero-trust security management platform and the terminal device are connected to a target core network, and the zero-trust security management platform is also connected to other core networks, wherein the target core network and the other core networks share the same base station, the method comprising: Receive terminal characteristic information sent by a zero-trust client deployed on the terminal device; Based on the terminal feature information, the access control information of the terminal device is obtained; Based on the access control information, a subscription data modification request for the terminal device is sent to the Network Device Function (NEF) element, so that the NEF element modifies the subscription data of the terminal device in the Unified Data Management (UDM) element according to the subscription data modification request, thereby triggering the Protocol Data Unit (PDU) session modification of the terminal device.
2. The method according to claim 1, characterized in that, The receipt of terminal characteristic information sent by the zero-trust client deployed on the terminal device includes: Receive device characteristics, application characteristics, and traffic characteristics of the terminal device sent by the zero-trust client; The step of obtaining the access control information of the terminal device based on the terminal feature information includes: Based on the device characteristics, application characteristics, and traffic characteristics, the access control information of the terminal device is obtained.
3. The method according to claim 2, characterized in that, The step of obtaining the access control information of the terminal device based on the device characteristics, the application characteristics, and the traffic characteristics includes: If the device's Internet Protocol address (IP address) and operating system version in the device characteristics change, or if any characteristic value in the traffic characteristics is less than a preset minimum security threshold, or if the system middleware software version in the application characteristics is a risky version, then the current security level of the terminal device will be downgraded, and the downgraded security level will be used as the access control information.
4. The method according to claim 2, characterized in that, The step of obtaining the access control information of the terminal device based on the device characteristics, the application characteristics, and the traffic characteristics includes: If the device IP address and operating system version in the device characteristics are restored to the initial device IP address and initial operating system version, and all feature values in the traffic characteristics are greater than the preset minimum security threshold, and the system middleware software version in the application characteristics is a risk-free version, then the security level of the terminal device is upgraded, and the upgraded security level is used as the access control information. The initial device IP address and initial operating system version refer to the address and version of the terminal device when it accesses the target core network.
5. The method according to claim 2, characterized in that, The step of obtaining the access control information of the terminal device based on the device characteristics, the application characteristics, and the traffic characteristics includes: If multiple pieces of information in the device characteristics change, or if any feature value in the traffic characteristics exceeds the maximum security threshold, or if the system middleware version in the application characteristics meets the preset risk conditions, then the terminal device is subjected to security isolation processing, and the security isolation result is used as the access control information.
6. The method according to claim 2, characterized in that, The step of obtaining the access control information of the terminal device based on the device characteristics, the application characteristics, and the traffic characteristics includes: If multiple pieces of information in the device features are restored to their initial values, and if all feature values in the traffic features are less than the maximum security threshold, and if the system middleware version in the application features is a preset security condition, then the terminal device is subjected to security isolation removal processing, and the security isolation removal result is used as the access control information. The initial value is the value when the terminal device accesses the core network.
7. The method according to claim 3 or 4, characterized in that, The contract data modification request is used to instruct the following modifications: Modify the network slice on which the terminal device establishes a PDU session; Modify the type of wireless resources that the terminal device can use; Modify the data transmission rate limit configured for the terminal device.
8. The method according to claim 5 or 6, characterized in that, The contract data modification request is used to instruct the following modifications: Modify the access control parameters of the terminal device to determine whether access to the target core network is permitted.
9. A communication system, characterized in that, include: Zero-trust security management platform, target core network, other core networks and base stations; The zero-trust security management platform and the terminal device are both connected to the target core network. The zero-trust security management platform is also connected to other core networks. The target core network and other core networks share the same base station. The zero-trust security management platform is used to execute the method described in any one of claims 1-8.
10. A zero-trust security management platform, characterized in that, include: A memory and a processor, the memory storing a computer program executable by the processor, the processor executing the computer program to implement the method according to any one of claims 1-8.