User terminal networking control method, electronic device and medium
Patent Information
- Application Number
- CN202610723970.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-25
- Publication Date
- 2026-08-18
AI Technical Summary
1.基于GPS/北斗地理围栏的限制方法:依赖卫星定位模块,在室内、地下车库、偏远区域等卫星信号薄弱或无信号的场景下,定位失效,导致区域限制功能无法正常工作,且增加设备硬件成本和功耗,不适用于低功耗、小型化CPE设备;
[0016] In the above technical solution, regional network access restrictions are implemented by comparing the cells obtained from each network search with the cell whitelist. On the one hand, this solution can be implemented purely on the terminal side, without relying on GPS/BeiDou positioning modules or complex configurations on the operator's network side, effectively reducing equipment hardware and maintenance costs. It can still work stably in indoor and underground scenarios with weak satellite signals, and is compatible with various CPE application scenarios. On the other hand, this solution can dynamically expand the cell whitelist, which can not only achieve regional locking of CPE devices, but also solve the problem that existing static whitelists cannot adapt to network changes such as base station expansion, frequency modification, and cutover, avoiding... The solution addresses the issue of CPE devices being unable to register and connect to the network due to base station changes, significantly improving operational stability and reducing after-sales failures. Furthermore, it sets strict verification conditions when dynamically expanding the cell whitelist, allowing only new cells within legal areas to join. This prevents the whitelist from expanding after CPE devices are moved to illegal areas, ensuring the accuracy of area restrictions. In short, this solution overcomes the shortcomings of existing CPE device area restriction methods, such as reliance on location tracking, complex configuration, inability to adapt to base station network changes, and susceptibility to failure. It achieves autonomous, zero-configuration, and highly robust area locking on the terminal side, while dynamically adapting to base station network changes to ensure long-term stable use of CPE devices. This solution is suitable for fixed CPE deployment, bulk sales, and industrial-grade applications, balancing compliance, ease of maintenance, and industrial-grade reliability. It can be widely applied to CPE devices in various scenarios, including home use, industrial IoT, vehicle-mounted, shared, and border control. It is compatible with mainstream CPE chip solutions such as ZTE Micro V3 and Qualcomm X62/X75, possessing strong practicality and industrialization value.
Smart Images

Figure CN122602141A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cellular communication equipment technology, and more specifically to a user terminal equipment network control method, electronic equipment, and medium. Background Technology
[0002] With the development of cellular communication technology, customer premises equipment (CPE devices), as terminal devices that convert cellular network signals into Wi-Fi or wired network signals, are widely used in scenarios such as home, industrial IoT, vehicle, and shared devices. In practical applications, some CPE devices have the need for regional sales restrictions and regional control. For example, operator-customized CPEs and industrial IoT-specific CPEs need to be restricted to use only in designated areas to prevent cross-regional abuse and cross-selling.
[0003] Currently, existing methods for restricting the location of CPE use have the following drawbacks: 1. GPS / BeiDou geofencing-based restriction method: This method relies on satellite positioning modules. In scenarios with weak or no satellite signals, such as indoors, underground garages, and remote areas, positioning fails, causing the area restriction function to malfunction. It also increases the hardware cost and power consumption of the device and is not suitable for low-power, miniaturized CPE devices. 2. Restriction method based on network-side configuration: The range of base stations that CPE can access is configured through network devices such as the operator's Home Location Register (HLR) and Access Control List (ACL). This method relies on operator network support, is not applicable in cross-operator scenarios, and has complex configuration, high operation and maintenance costs, and the terminal side cannot independently manage it. 3. Static cell whitelist-based restriction method: After the device is first powered on, it records the currently serving cell and neighboring cells to form a fixed cell whitelist. Subsequent registration is only allowed in cells on the whitelist. This method has a significant drawback: when the base station undergoes network changes such as expansion, frequency modification, cutover, cell merging, or deletion, cells in the original whitelist may become invalid, causing the CPE to fail to register with the network, resulting in numerous after-sales failures and impacting user experience. 4. SIM card-based area control method: This method achieves area restriction by binding network parameters of a specific area to the SIM card. However, due to the limitations of SIM card permissions, the terminal cannot adjust the settings independently and cannot adapt to dynamic changes in the base station network, resulting in poor flexibility.
[0004] Therefore, there is an urgent need for a method to restrict the use of CPE devices without relying on positioning modules, without complex network-side configuration, adaptable to dynamic changes in base station networks, and with high security and robustness, in order to overcome the shortcomings of existing technologies.
[0005] In view of this, the present invention is hereby proposed. Summary of the Invention
[0006] The present invention is proposed in view of the above-mentioned problems. According to one aspect of the present invention, a user terminal device network control method is provided for a user terminal device, the method comprising: Obtain the current cell set scanned by the user terminal device in normal working mode, the current cell set including all currently searchable cells; Verification is performed based on the cell information of each cell in the current cell set to determine whether there is at least one cell in the current cell set that is in the cell whitelist; If no cell in the cell whitelist exists in the current cell set, the user terminal device is refused network registration. When there is at least one cell in the current cell set that is on the cell whitelist, Determine that the user terminal device is in a legal usage area, and control the user terminal device to initiate network registration and establish a data connection in a cell that is currently found to be in the cell whitelist; For each new cell in the current cell set that is not in the cell whitelist, the new cell shall be added to the cell whitelist at least if any of the verification conditions are met. The verification conditions include: the new cell has the same tracking area code, the same frequency band information, or is in an adjacent sector as any cell in the cell whitelist.
[0007] Exemplarily, the method further includes: Determine the number of whitelisted cells in the current cell set that are included in the cell whitelist; The operation of adding the new cell to the cell whitelist when at least one of the verification conditions is met is performed when the number of cells in the whitelist reaches a first preset number. And / or, the method further includes: Determine the number of communities in the community whitelist; The operation of adding the new cell to the cell whitelist when at least one of the verification conditions is met is performed when the number of cells in the cell whitelist has not reached a second preset number.
[0008] Exemplarily, the method further includes: For any cell in the cell whitelist, if the cell is not found for a first preset time period, the cell will be removed from the cell whitelist.
[0009] Exemplarily, the method further includes: When the user terminal device is not configured with the cell whitelist, control the user terminal device to enter learning mode; In the learning mode, cellular network scanning is initiated and continues for a second preset duration; Configure the cell whitelist based on the cell information of all cells searched within the second preset time period; Preferably, configuring the cell whitelist based on cell information of all cells searched within the second preset time period includes: Based on the cell information of all cells searched within the second preset time period, the cells searched within the second preset time period are deduplicated and merged to generate the cell whitelist.
[0010] Exemplarily, the method further includes: If the user terminal device scans for a preset number of consecutive times and none of the cells are in the cell whitelist, and the user terminal device has no emergency call request, an alarm message is generated and sent, and the network access function is locked until a cell in the cell whitelist is found again.
[0011] For example, the user terminal equipment is a 5G RedCap device, and the step of adding the new cell to the cell whitelist when at least any verification condition is met includes: When the new cell meets any of the verification conditions, determine whether the bandwidth of the new cell is the same as that of at least one cell in the cell whitelist; When the bandwidth of the new cell is the same as that of at least one cell in the cell whitelist, the new cell is added to the cell whitelist.
[0012] For example, determining whether there is at least one cell in the current cell set that is on the cell whitelist includes: For any cell in the current cell set, if the cell information of that cell is exactly the same as the cell information of any cell in the cell whitelist, then that cell is determined to be in the cell whitelist. The cell information includes the cell global identifier, physical cell identifier, tracking area code, and frequency band information.
[0013] For example, the cell whitelist is encrypted and stored in the non-volatile storage area of the user terminal device, and the non-volatile storage area is a one-time programmable storage area or a device security partition; Preferably, after each update of the cell whitelist, the updated cell whitelist is re-encrypted and stored in the non-volatile storage area to overwrite the original whitelist in the non-volatile storage area. Preferably, the method further includes: The whitelist of the community is bound to the International Mobile Equipment Identity (IMEI) or serial number of the user terminal device.
[0014] According to another aspect of the present invention, an electronic device is provided, including a processor and a memory, wherein the memory stores a computer program, and the processor is used to execute the computer program to implement the method as described above.
[0015] According to another aspect of the present invention, a computer-readable storage medium is provided, which stores a computer program / instructions that, when executed by a processor, implement the method described above.
[0016] In the above technical solution, regional network access restrictions are implemented by comparing the cells obtained from each network search with the cell whitelist. On the one hand, this solution can be implemented purely on the terminal side, without relying on GPS / BeiDou positioning modules or complex configurations on the operator's network side, effectively reducing equipment hardware and maintenance costs. It can still work stably in indoor and underground scenarios with weak satellite signals, and is compatible with various CPE application scenarios. On the other hand, this solution can dynamically expand the cell whitelist, which can not only achieve regional locking of CPE devices, but also solve the problem that existing static whitelists cannot adapt to network changes such as base station expansion, frequency modification, and cutover, avoiding... The solution addresses the issue of CPE devices being unable to register and connect to the network due to base station changes, significantly improving operational stability and reducing after-sales failures. Furthermore, it sets strict verification conditions when dynamically expanding the cell whitelist, allowing only new cells within legal areas to join. This prevents the whitelist from expanding after CPE devices are moved to illegal areas, ensuring the accuracy of area restrictions. In short, this solution overcomes the shortcomings of existing CPE device area restriction methods, such as reliance on location tracking, complex configuration, inability to adapt to base station network changes, and susceptibility to failure. It achieves autonomous, zero-configuration, and highly robust area locking on the terminal side, while dynamically adapting to base station network changes to ensure long-term stable use of CPE devices. This solution is suitable for fixed CPE deployment, bulk sales, and industrial-grade applications, balancing compliance, ease of maintenance, and industrial-grade reliability. It can be widely applied to CPE devices in various scenarios, including home use, industrial IoT, vehicle-mounted, shared, and border control. It is compatible with mainstream CPE chip solutions such as ZTE Micro V3 and Qualcomm X62 / X75, possessing strong practicality and industrialization value.
[0017] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and in order to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description
[0018] The above and other objects, features, and advantages of the present invention will become more apparent from the more detailed description of the embodiments of the invention in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of the invention and form part of the specification. They are used together with the embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same parts or steps.
[0019] Figure 1 A schematic flowchart illustrating a user terminal device network control method according to an embodiment of the present invention is shown. Figure 2 A schematic block diagram of an electronic device according to an embodiment of the present invention is shown. Detailed Implementation
[0020] To make the objectives, technical solutions, and advantages of the present invention more apparent, exemplary embodiments according to the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are merely a part of the embodiments of the present invention, and not all of the embodiments of the present invention. It should be understood that the present invention is not limited to the exemplary embodiments described herein. Based on the embodiments of the present invention described herein, all other embodiments obtained by those skilled in the art without inventive effort should fall within the protection scope of the present invention.
[0021] According to one aspect of the present invention, a user terminal device network control method is provided. This method is used for user terminal devices, specifically to restrict the applicable area of the user terminal device, enabling it to be used only within a designated area, thereby preventing problems such as cross-regional abuse and cross-selling. The user terminal device includes, but is not limited to, 4G and 5G CPE devices.
[0022] Figure 1 A schematic flowchart illustrating a user terminal device network control method according to an embodiment of the present invention is shown. Figure 1 As shown, the method may include the following steps S110, S120, S130 and S140.
[0023] In step S110, the current cell set obtained by the user terminal device in normal working mode is acquired. The current cell set includes all currently searchable cells.
[0024] When the user terminal device is in normal operating mode, it needs to re-search for the network after each power-on, cell reselection, handover, or disconnection. During this process, the CPE device scans surrounding cells to obtain information on all currently searchable cells, which constitute the current cell set. Steps S110 to S140 are executed each time the network is re-searched to ensure the real-time nature and accuracy of the area restrictions.
[0025] In step S120, a verification is performed based on the cell information of each cell in the current cell set to determine whether there is at least one cell in the current cell set that is in the cell whitelist.
[0026] In some embodiments, determining whether there is at least one cell in the current cell set that is in the cell whitelist includes: for any cell in the current cell set, if the cell information of that cell is exactly the same as the cell information of any cell in the cell whitelist, then that cell is determined to be in the cell whitelist; wherein, the cell information includes the Cell Global Identifier (CGI), Physical Cell Identifier (PCI), Tracking Area Code (TAC), and Frequency Band Information (EARFCN). This scheme directly uses all cell information as the basis for cell matching, and performs a complete consistency comparison between each cell in the current cell set and the cell whitelist, which can accurately identify the target cell in the whitelist, effectively avoid misjudgment caused by duplicate or conflicting single identifiers, and improve the accuracy and reliability of cell attribution determination.
[0027] In this example, the initial cell whitelist can be obtained through self-learning during the first power-on, or it can be obtained from the factory-preset whitelist.
[0028] In step S130, if there is no cell in the cell whitelist in the current cell set, the user device is refused network registration.
[0029] In this example, if no cell in the cell whitelist is found, the CPE device is denied network registration and remains in a no-service state, allowing only emergency calls (such as 112 and 911) while prohibiting data and regular voice services.
[0030] In step S140, when there is at least one cell in the cell whitelist in the current cell set, it is determined that the user terminal device is in a legal use area, and the user terminal device is controlled to initiate network registration and establish a data connection in the currently searched cell in the cell whitelist; for each new cell in the current cell set that is not in the cell whitelist, the new cell is added to the cell whitelist if at least one of the verification conditions is met; wherein, the verification conditions include: the new cell has the same tracking area code, the same frequency band information, or is in an adjacent sector as any cell in the cell whitelist.
[0031] In this example scenario, if at least one cell from the cell whitelist is found, it can be determined that the CPE device is in a legitimate usage area. At this point, the CPE device is allowed to initiate network registration and establish a data connection within one of the currently found cells from the whitelist.
[0032] Simultaneously, it can be further determined whether there are any new cells in the current cell set that are not on the cell whitelist. If so, it can be determined whether the new cell meets any of the verification conditions based on its cell information, i.e., whether the new cell belongs to the same TAC, frequency band, or adjacent sector as a cell on the cell whitelist. If the new cell meets at least one of the verification conditions, it is added to the cell whitelist, thereby achieving dynamic expansion of the cell whitelist.
[0033] The above technical solution achieves regional network access restriction by comparing the cells obtained from each network search with the cell whitelist. On the one hand, this solution can be implemented purely on the terminal side, without relying on GPS / BeiDou positioning modules or complex configurations on the operator's network side, effectively reducing equipment hardware and maintenance costs. It can still work stably in indoor and underground scenarios with weak satellite signals, and is compatible with various CPE application scenarios. On the other hand, this solution can dynamically expand the cell whitelist, which can not only achieve regional locking of CPE devices, but also solve the problem that existing static whitelists cannot adapt to network changes such as base station expansion, frequency modification, and cutover, avoiding the need for... This solution addresses the issue of CPE devices being unable to register and connect to the network due to base station changes, significantly improving stability and reducing after-sales failures. Furthermore, it sets strict verification conditions when dynamically expanding the cell whitelist, allowing only new cells within legal areas to join. This prevents the whitelist from expanding after the CPE device is moved to an illegal area, ensuring the accuracy of area restrictions. In short, this solution overcomes the shortcomings of existing CPE device area restriction methods, such as reliance on location, complex configuration, inability to adapt to base station network changes, and susceptibility to failure. It achieves autonomous, zero-configuration, and highly robust area locking on the terminal side, while dynamically adapting to base station network changes to ensure long-term stable use of CPE devices. This solution is suitable for fixed deployment, bulk sales, and industrial-grade CPE applications, balancing compliance, ease of maintenance, and industrial-grade reliability. It can be widely used in various scenarios such as home, industrial IoT, vehicle-mounted, shared, and border control CPE devices, and is compatible with mainstream CPE chip solutions such as ZTE Micro V3 and Qualcomm X62 / X75, possessing strong practicality and industrialization value.
[0034] Furthermore, this solution is particularly well-suited for 5G and 5G RedCap terminal scenarios. In these scenarios, it leverages 5G beam information, SSB measurement, and TAU pre-verification to improve area locking accuracy and reduce resource consumption. Simultaneously, considering the low power consumption and limited capabilities of RedCap terminals, the solution optimizes measurement and demodulation strategies, achieving area restriction while reducing power consumption. This enhances the applicability and stability of RedCap terminals in IoT and industrial scenarios, further expanding the application scope of this invention and increasing its practical value. A detailed description follows with a specific embodiment.
[0035] In one specific embodiment, the user terminal equipment can be a 5G RedCap device. When the user terminal equipment is a 5G RedCap device, due to its low power consumption and limited partial bandwidth (BWP) capability, measurements and demodulation can be performed only on the frequency bands and bandwidth of cells within the whitelist, eliminating the need to measure other frequency bands and bandwidths, thus reducing invalid measurements and lowering power consumption. Simultaneously, bandwidth parameters can be used as a criterion for dynamically expanding the cell whitelist. Specifically, in some embodiments, a new cell is added to the cell whitelist at least if it meets any one of the verification conditions, including: determining whether the bandwidth of the new cell is the same as at least one cell in the cell whitelist when the new cell meets any verification condition; and adding the new cell to the cell whitelist when its bandwidth is the same as at least one cell in the cell whitelist. Therefore, only new cells with bandwidth consistent with cells in the cell whitelist can be expanded, ensuring stable 5G RedCap network registration.
[0036] In some implementations of this example, the cell whitelist can be encrypted and stored in the non-volatile storage area of the user terminal device. This non-volatile storage area is either a one-time programmable (OTP) storage area or a device security partition, accessible only to the device's core program and prohibited from modification by ordinary users. Furthermore, after each cell whitelist update, the updated whitelist can be re-encrypted and stored in the non-volatile storage area to overwrite the original whitelist within that area. This helps ensure the security and consistency of the whitelist.
[0037] In some solutions, the community whitelist can be linked to the International Mobile Equipment Identity (IMEI) code or serial number of the user's device. This can further improve the security of the community whitelist, prevent it from being copied or tampered with, effectively prevent device hacking and cross-regional abuse, and meet the needs of regional sales restrictions and control.
[0038] For example, the method further includes: when the user terminal device has not configured a cell whitelist, controlling the user terminal device to enter a learning mode; in the learning mode, starting a cellular network scan and continuously scanning for a second preset duration; configuring a cell whitelist based on the cell information of all cells searched within the second preset duration. After the cell whitelist is stored, the CPE device can directly and automatically exit the learning mode and enter the normal working mode, and execute steps S110-S140 each time it re-searches for the network to achieve area restriction verification.
[0039] CPE devices do not have a pre-installed cell whitelist when they are sold. In this case, they can automatically enter learning mode upon first power-on. In learning mode, the CPE device initiates cellular network scanning and continuously scans for a second preset duration (selectable as needed, for example, within the range of [30s, 120s]) to obtain cell information of the currently serving cell and surrounding neighboring cells. That is, multiple scans are performed within the second preset duration to obtain multiple cell sets. Then, a cell whitelist can be configured based on the results of multiple scans. For example, all cells in the multiple cell sets can be directly identified as the cell whitelist. In some embodiments, configuring the cell whitelist based on the cell information of all cells searched within the second preset duration includes: deduplicating and merging all cells searched within the second preset duration to generate a cell whitelist. In this embodiment, considering that some cells may be scanned repeatedly during multiple scans, all cells are first deduplicated and merged. Specifically, cells with identical cell information can be identified as the same cell, and the results are merged after deleting duplicate cells. This effectively eliminates duplicate and redundant cell data, integrates valid cell information, improves the accuracy and simplicity of the cell whitelist, reduces the amount of data processing required for subsequent network connectivity based on the cell whitelist, improves cell screening and matching efficiency, and ensures the stability and reliability of the cell identification and application process.
[0040] The above technical solution can realize the automated and intelligent generation of the community whitelist without manual configuration, effectively improving the efficiency and accuracy of the community whitelist configuration on the user terminal device.
[0041] For example, the method further includes: determining the number of whitelisted cells in the current cell set that are in the cell whitelist; and adding the new cell to the cell whitelist when the number of whitelisted cells reaches a first preset number, at least when the new cell meets any of the verification conditions.
[0042] The first preset quantity can be selected as needed, for example, it can be 1, 2, 3, 4, etc. In a preferred embodiment, the first preset quantity is 2.
[0043] In the above scheme, before verifying each new cell using verification conditions, a trust vote is first performed based on the number of cells in the currently searched cell whitelist. If the number of currently searched whitelist cells reaches a first preset number, further judgment is made using verification conditions. This can improve the effectiveness of area determination, ensure that the CPE device can dynamically expand the cell whitelist within the legal use area, avoid the accidental addition of new cells after the device is moved to an illegal area, and further improve the security and accuracy of area restrictions.
[0044] For example, the method further includes: determining the number of cells in the cell whitelist; and adding the new cell to the cell whitelist when the number of cells in the cell whitelist has not reached a second preset number, at least when the new cell meets any of the verification conditions.
[0045] The second preset quantity can be set according to actual needs, and will not be elaborated further.
[0046] The above solution, by setting a limit on the number of whitelist entries, can prevent the whitelist from growing indefinitely and ensure device operating efficiency.
[0047] For example, the method further includes: for any cell in the cell whitelist, if the cell is not found for a continuous first preset time period, the cell is removed from the cell whitelist. The first preset time period can be selected according to actual needs, for example, it can be one year. The above solution, by performing real-time search and monitoring of each cell in the cell whitelist, automatically removes any cell from the whitelist when it is not found for a continuous first preset time period. This dynamically maintains the effectiveness of the cell whitelist, promptly removes invalid or unsearchable cell information, avoids invalid cells occupying whitelist resources, improves the accuracy and practicality of the cell whitelist, and reduces invalid matching and misjudgment when performing related services based on the whitelist in the future, thus optimizing the overall cell identification and scheduling efficiency.
[0048] For example, the method further includes: upon receiving a whitelist update instruction sent via an encrypted communication channel, and when the user terminal device is in a legal usage area, updating the cell whitelist according to the whitelist update instruction. In this example solution, a remote encrypted update function is considered. Specifically, the management platform can directly issue a whitelist update instruction to the CPE device via an encrypted channel. When the CPE device is currently in a legal usage area, the whitelist update operation is performed. This achieves convenient remote whitelist updates, ensures the security and reliability of instruction transmission through an encrypted channel, and further enhances the compliance of whitelist updates and the security of device operation by combining legal usage area verification, effectively preventing unauthorized instruction tampering or unauthorized updates to the cell whitelist.
[0049] For example, the method further includes: when the user terminal device scans for a preset number of consecutive times and none of the cells are in the cell whitelist, and the user terminal device has no emergency call request, generating and sending alarm information, and locking the network access function until a cell in the cell whitelist is found again.
[0050] The preset number of attempts can be set as needed, for example, up to 3. In this solution, if the CPE device repeatedly searches for cells that are not on the cell whitelist and there is no emergency call request, it can automatically report an alarm to the management platform and lock network access until a cell on the whitelist is found again. This effectively prevents devices from accessing unauthorized cells, improves network access security and controllability, and avoids network risks caused by abnormal access.
[0051] The following examples illustrate the solution presented in this paper in more detail.
[0052] In home 5G CPE area restriction scenarios, the equipment can be customized for operators to use home 5G CPE. In this scenario, the equipment needs to be restricted to use only in the area where the user's home is located to prevent cross-regional sales and abuse.
[0053] The specific steps in this scenario are as follows: After the CPE device leaves the factory, when the user powers it on for the first time, the device automatically enters learning mode without requiring manual configuration. In learning mode, the CPE device starts a 5G network scan, which continues for 60 seconds. It searches for the currently serving cell (CGI: 460001234567890, PCI: 123, TAC: 456, frequency band: n78) and three neighboring cells (CGIs are 460001234567891, 460001234567892, and 460001234567893, all with the same TAC and frequency band as the serving cell). The device performs deduplication on the four cell information, generates an initial cell whitelist, and encrypts and writes the initial cell whitelist into the CPE's OTP storage area, binding it with the device's IMEI code (861234567890123), preventing ordinary users and third-party software from modifying it. After the initial whitelist is stored, the CPE automatically exits the learning mode and enters the normal working mode.
[0054] When the user powers on the device again, the CPE scans the surrounding 5G cells and finds two cells in the initial whitelist (460001234567890 and 460001234567891). It determines that the user is in a legal area and allows network registration, establishing Wi-Fi and wired data connections. At the same time, it detects a new cell (CGI: 460001234567894, which has the same TAC and frequency band as the cell in the whitelist).
[0055] Verify the new cell to confirm that it shares the same TAC and frequency band as cells in the whitelist. Then, encrypt and add it to the cell whitelist. At this point, the number of cells in the whitelist is 5 (below the preset limit of 10). Re-encrypt the updated whitelist and write it to the OTP storage area, overwriting the original whitelist.
[0056] If the user takes the CPE to another area, and it cannot scan any whitelisted cells after powering on, the CPE will refuse to register with the network, only allowing emergency calls, and will report alarm information to the operator's management platform.
[0057] If the base station capacity in the user's home area is expanded, adding two new cells with the same TAC and frequency band, the CPE will automatically add the new cells to the whitelist when it is powered on next time, ensuring that the device can be registered in the network normally.
[0058] In industrial IoT CPE area-restricted scenarios, the device can be a CPE device used in industrial IoT scenarios to connect industrial sensors. In this scenario, the device needs to be restricted to use only within the factory area, adapt to the dynamic changes of base stations within the factory area, and ensure the stability of industrial data transmission.
[0059] The specific steps in this scenario are as follows: After the CPE device leaves the factory, it is automatically put into learning mode upon its first power-on within the factory premises. In learning mode, the CPE continuously scans the 4G network for 90 seconds, acquiring information on 3 serving cells and 5 neighboring cells within the factory area (all belonging to the same TAC: 789, frequency band: FDD-LTE 1800MHz). After deduplication, an initial cell whitelist is generated and encrypted, written to the CPE's secure partition and bound to the device serial number. The maximum number of cells in the whitelist is set to 15. After storage, the CPE exits learning mode and enters normal operating mode, connecting to industrial sensors and transmitting industrial data.
[0060] Three months later, the base stations within the factory area underwent a cutover. Two old cells were deleted, and three new cells with the same TAC and frequency band were added. When the CPE device was powered on again, it scanned the four cells in the initial whitelist, determined that they were in a legal area, and allowed them to register with the network. At the same time, it detected the three new cells, verified that they all met the requirements, and added them to the whitelist. At this point, the number of cells in the whitelist was 4 + 3 = 7, which did not reach the limit. The updated whitelist was then stored encrypted.
[0061] If the frequency band of a base station around the factory is adjusted, and the frequency band of the new cell is inconsistent with the frequency band of cells in the whitelist, the CPE will not add the new cell to the whitelist after scanning it, thus ensuring the accuracy of the area restriction.
[0062] If the CPE device is reset to factory settings due to a malfunction, it will re-enter learning mode upon the next power-on and scan within the factory area to generate a new initial whitelist, thus preventing the regional restrictions from becoming invalid due to the factory reset.
[0063] To further illustrate the effectiveness of this solution, it will be compared with existing technologies below.
[0064] Compared with GPS / BeiDou-based geofencing methods, the proposed solution relies on satellite positioning modules to define usage areas using positioning coordinates, thus restricting CPE areas. This solution, however, does not depend on GPS / BeiDou positioning modules. It achieves area locking purely on the terminal side through a cell whitelist and dynamic expansion mechanism. It can still operate stably in scenarios with weak or no satellite signals, such as indoors, underground parking garages, and remote areas. It requires no additional hardware, reducing equipment costs and power consumption, and is compatible with low-power, miniaturized CPE devices. Furthermore, its technical approach is completely different from existing technologies.
[0065] Compared with network-side configuration-based restriction methods, the proposed solution employs two approaches: one is configuring the range of base stations accessible to the CPE via network equipment such as the operator's HLR and ACL; the other is restricting the UE's access area by issuing a TA list from the network side according to 3GPP standard TS 23.501 / 22.011, with the UE only registering within the allowed TAs. This proposed solution does not rely on complex operator network-side configuration. The terminal autonomously completes initial learning, area verification, and dynamic whitelist expansion, making it applicable across operator scenarios with low maintenance costs. It possesses local whitelist learning, dynamic expansion, and trust verification capabilities, adapting to dynamic changes in the base station network and overcoming the shortcomings of existing technologies, such as the inability of the terminal to autonomously manage and poor adaptability.
[0066] Compared with the proposed solution, existing technologies, represented by China Telecom's authorized patent CN113286265B, require the CPE to enter a learning mode upon initial power-on, scan surrounding base stations to generate a fixed whitelist, and store it encrypted. Subsequent access is only permitted to base stations within the whitelist, and remote updates to the whitelist are supported, but there is no dynamic automatic expansion or trust verification mechanism. This proposed solution, based on the initial whitelist generated through self-learning upon initial power-on, introduces a "trust vote" mechanism and a dynamic whitelist expansion mechanism. This solves the problems of existing technologies where the whitelist is fixed and cannot adapt to network changes such as the addition, expansion, frequency modification, and cutover of operator base stations, preventing the CPE from being unable to register with the network due to base station changes. Simultaneously, the trust vote mechanism (allowing the addition of new cells only when the number of cells in the whitelist is ≥ threshold N) ensures the legitimacy of new base stations, eliminating the risk of being cracked, and balancing the security of area locking with network adaptability.
[0067] Compared with SIM card-based area control methods, the proposed solution relies on binding network parameters of a specific area to the SIM card to achieve CPE area restrictions, which cannot be adjusted independently by the terminal. Our solution, however, allows the terminal to autonomously learn, verify, and dynamically expand the whitelist without relying on SIM card permissions. It can flexibly adapt to dynamic changes in the base station network, overcoming the shortcomings of existing technologies in terms of poor flexibility and inability to adapt to network changes. This approach differs from existing technologies.
[0068] This paper compares the proposed solution with other relevant patents and technologies. The core of patent CN117119463A is dual authentication using SIM + device certificate. It relies on the network side issuing a list of allowed base stations, which the terminal passively executes. It lacks local dynamic learning, trust voting, and automatic whitelist expansion, still depending on network-side control. Our proposed solution, however, is purely terminal-side autonomous, possessing dynamic expansion and trust verification capabilities, and does not require a network-side base station list. US11019563 and US20230071425 relate to CPE self-organizing interaction and CPE anti-theft detection, respectively, but do not involve the core mechanisms of base station whitelisting, trust voting, and area locking, thus differing from the technical direction of our proposed solution. The CN219204704U solution only involves the hardware structure and shielding design of the 5G CPE, lacking software-level whitelisting, trust mechanisms, and area restriction logic, and is unrelated to the technical solution presented in this paper.
[0069] The above comparisons show that existing technologies either rely on positioning modules or network-side configurations, resulting in poor applicability and flexibility; or they are static whitelist solutions, unable to adapt to dynamic changes in base stations and containing security vulnerabilities; or they do not involve the core technical mechanism of this invention. This solution, through a collaborative design of "first-time boot self-learning + trust voting + dynamic whitelist expansion," solves all the shortcomings of existing technologies, achieving high security, high robustness, and high adaptability of CPE area locking, and possesses significant technological innovation and practical value.
[0070] According to another aspect of the present invention, an electronic device is also provided. Figure 2 A schematic block diagram of an electronic device according to an embodiment of the present invention is shown. Figure 2 As shown, the electronic device 200 includes a processor 210 and a memory 220. The memory 220 stores a computer program, which the processor 210 executes to implement the method described above.
[0071] According to another aspect of the present invention, a computer-readable storage medium is also provided. The storage medium stores a computer program / instructions that, when executed by a processor, implement the method described above. The storage medium may, for example, include a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a portable compact disc read-only memory (CD-ROM), a USB memory, or any combination of the above storage media. The computer-readable storage medium may be any combination of one or more computer-readable storage media.
[0072] Those skilled in the art will readily understand the implementation structure, working principle, and beneficial effects of electronic devices and computer-readable storage media by reading the above methods. For the sake of brevity, further details will not be elaborated here.
[0073] Although exemplary embodiments have been described herein with reference to the accompanying drawings, it should be understood that the above exemplary embodiments are merely illustrative and are not intended to limit the scope of the invention. Various changes and modifications can be made therein by those skilled in the art without departing from the scope and spirit of the invention. All such changes and modifications are intended to be included within the scope of the invention as claimed in the appended claims.
[0074] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0075] In the several embodiments provided by this invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed.
[0076] Numerous specific details are set forth in the specification provided herein. However, it will be understood that embodiments of the invention may be practiced without these specific details. In some instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this specification.
[0077] Similarly, it should be understood that, in order to streamline the invention and aid in understanding one or more of the various aspects of the invention, features of the invention are sometimes grouped together in a single embodiment, figure, or description thereof in the description of exemplary embodiments of the invention. However, this approach should not be construed as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim. Rather, as reflected in the corresponding claims, its inventive point lies in solving the corresponding technical problem with fewer features than all of those in a single disclosed embodiment. Therefore, the claims following the detailed description are hereby expressly incorporated into that detailed description, wherein each claim itself is a separate embodiment of the invention.
[0078] Those skilled in the art will understand that, apart from the mutual exclusion of features, all features disclosed in this specification (including the accompanying claims, abstract, and drawings) and all processes or elements of any method or apparatus so disclosed may be combined in any combination. Unless otherwise expressly stated, each feature disclosed in this specification (including the accompanying claims, abstract, and drawings) may be replaced by an alternative feature that serves the same, equivalent, or similar purpose.
[0079] Furthermore, those skilled in the art will understand that although some embodiments described herein include certain features but not others included in other embodiments, combinations of features from different embodiments are intended to be within the scope of the invention and form different embodiments. For example, in the claims, any of the claimed embodiments can be used in any combination.
[0080] The various component embodiments of the present invention can be implemented in hardware, or as software modules running on one or more processors, or a combination thereof. Those skilled in the art will understand that microprocessors or digital signal processors (DSPs) can be used in practice to implement some or all of the functions of some modules in the electronic device according to embodiments of the present invention. The present invention can also be implemented as an apparatus program (e.g., a computer program and computer program product) for performing some or all of the methods described herein. Such programs implementing the present invention can be stored on a computer-readable medium or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.
[0081] It should be noted that the above embodiments are illustrative of the invention and not restrictive, and that those skilled in the art can devise alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses should not be construed as limiting the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The invention can be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In the unit claims enumerating several means, several of these means may be embodied by the same item of hardware. The use of the words first, second, and third, etc., does not indicate any order. These words can be interpreted as names.
[0082] The above description is merely a specific embodiment of the present invention or an explanation of that embodiment. The scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. The scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A method for controlling network connectivity of user terminal equipment, characterized in that, For use with a user terminal device, the method includes: Obtain the current cell set scanned by the user terminal device in normal working mode, the current cell set including all currently searchable cells; Verification is performed based on the cell information of each cell in the current cell set to determine whether there is at least one cell in the current cell set that is in the cell whitelist; If no cell in the cell whitelist exists in the current cell set, the user terminal device is refused network registration. When there is at least one cell in the current cell set that is on the cell whitelist, Determine that the user terminal device is in a legal usage area, and control the user terminal device to initiate network registration and establish a data connection in a cell that is currently found to be in the cell whitelist; For each new cell in the current cell set that is not in the cell whitelist, the new cell shall be added to the cell whitelist at least if any of the verification conditions are met. The verification conditions include: the new cell has the same tracking area code, the same frequency band information, or is in an adjacent sector as any cell in the cell whitelist.
2. The control method according to claim 1, characterized in that, The method further includes: Determine the number of whitelisted cells in the current cell set that are included in the cell whitelist; The operation of adding the new cell to the cell whitelist when at least one of the verification conditions is met is performed when the number of cells in the whitelist reaches a first preset number. And / or, the method further includes: Determine the number of communities in the community whitelist; The operation of adding the new cell to the cell whitelist when at least one of the verification conditions is met is performed when the number of cells in the cell whitelist has not reached a second preset number.
3. The control method according to claim 1 or 2, characterized in that, The method further includes: For any cell in the cell whitelist, if the cell is not found for a first preset time period, the cell will be removed from the cell whitelist.
4. The control method according to claim 1, characterized in that, The method further includes: When the user terminal device is not configured with the cell whitelist, control the user terminal device to enter learning mode; In the learning mode, cellular network scanning is initiated and continues for a second preset duration; Configure the cell whitelist based on the cell information of all cells searched within the second preset time period; Preferably, configuring the cell whitelist based on cell information of all cells searched within the second preset time period includes: Based on the cell information of all cells searched within the second preset time period, the cells searched within the second preset time period are deduplicated and merged to generate the cell whitelist.
5. The control method according to claim 1, characterized in that, The method further includes: If the user terminal device scans for a preset number of consecutive times and none of the cells are in the cell whitelist, and the user terminal device has no emergency call request, an alarm message is generated and sent, and the network access function is locked until a cell in the cell whitelist is found again.
6. The control method according to claim 1, characterized in that, The user terminal equipment is a 5G RedCap device, and the step of adding the new cell to the cell whitelist when at least one verification condition is met includes: When the new cell meets any of the verification conditions, determine whether the bandwidth of the new cell is the same as that of at least one cell in the cell whitelist; When the bandwidth of the new cell is the same as that of at least one cell in the cell whitelist, the new cell is added to the cell whitelist.
7. The control method according to claim 1, characterized in that, Determining whether there is at least one cell in the current cell set that is on the cell whitelist includes: For any cell in the current cell set, if the cell information of that cell is exactly the same as the cell information of any cell in the cell whitelist, then that cell is determined to be in the cell whitelist. The cell information includes the cell global identifier, physical cell identifier, tracking area code, and frequency band information.
8. The control method according to claim 1, characterized in that, The cell whitelist is encrypted and stored in the non-volatile storage area of the user terminal device. The non-volatile storage area is a one-time programmable storage area or a device security partition. Preferably, after each update of the cell whitelist, the updated cell whitelist is re-encrypted and stored in the non-volatile storage area to overwrite the original whitelist in the non-volatile storage area. Preferably, the method further includes: The whitelist of the community is bound to the International Mobile Equipment Identity (IMEI) or serial number of the user terminal device.
9. An electronic device, characterized in that, It includes a processor and a memory, wherein the memory stores a computer program, and the processor is used to execute the computer program to implement the method as claimed in any one of claims 1-8.
10. A computer-readable storage medium, characterized in that, The system stores a computer program / instructions that, when executed by a processor, implement the method as described in any one of claims 1-8.
Citation Information
Patent Citations
CPE equipment, control devices, communication methods, communication systems, and storage media
CN113286265B
5G cellular network access CPE (Customer Premise Equipment)
CN219204704U
Customer premises equipment (CPE) self-organization in fixed wireless access (FWA) network
US11019563B1
System And Method For Customer Premise Equipment (CPE) Theft of Service (TOS) Detection and Prevention
US20230071425A1