Method and apparatus for identifying subscriber identity module clone attack

By analyzing the signaling time series characteristics in the communication network, the user identification module cloning attack is identified, which solves the problem that the existing technology cannot effectively identify this problem, improves detection efficiency and reduces false positives and missed negatives.

WO2025214151A1PCT designated stage Publication Date: 2025-10-16ZTE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/084790
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-11
Filing Date
2025-03-25
Publication Date
2025-10-16

AI Technical Summary

Technical Problem

Existing technologies cannot effectively identify user identification module cloning attacks, leading to privacy issues, financial risks and network security problems.

Method used

By collecting the request and response data of registration requests, deregistration requests, network-side deregistration requests, and service requests in the communication network, the features in the signaling time series are identified to determine whether there is a user identification module cloning attack.

Benefits of technology

The detection efficiency of user identification module cloning attacks is improved, false positives and missed negatives are reduced, and network security is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025084790_16102025_PF_FP_ABST
    Figure CN2025084790_16102025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the embodiments of the present disclosure are a method and apparatus for identifying a subscriber identity module clone attack. The method comprises: collecting request data and response data of registration requests, logout requests, network-side deregistration requests and service requests in a communication network, so as to obtain a signaling time sequence; and if it is identified in a signaling time sequence of the same SUPI that within a predetermined duration, a first feature occurs first, followed by at least two occurrences of a second feature, determining that a subscriber identity module clone attack occurs in the communication network.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for identifying user identity module cloning attack

[0001] Cross-reference to Related Applications

[0002] The present disclosure is based on and claims priority from Chinese Patent Application No. CN202410436615.2 entitled “Method and device for identifying user identity module cloning attack” filed on April 11, 2024, the disclosure of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0003] Embodiments of the present disclosure relate to the field of communication, in particular, to a method and device for identifying user identity module cloning attack. BACKGROUND

[0004] A user identity module (SIM) is a module installed on a computer terminal device to identify a user. The main function of the user identity module is to provide identity information and store data when the computer terminal device communicates with a network. The user identity module includes, but is not limited to, a user identity module, a universal user identity module (USIM), and an embedded user identity module (eSIM), etc.

[0005] For example, in a 5G network, the user identity module mainly stores information such as an integrated circuit card identifier (ICCID), a subscription permanent identifier (SUPI), a key identifier (Ki), and an encryption algorithm for authentication. If the user identity module is cloned, it may cause various problems, such as privacy issues, financial risks, network security issues, and device lock issues.

[0006] Although major operators have launched user identity modules with anti-copy programs that can perform anti-attack processes, such as self-destruction by burning the card once connected to a card reading system, or setting a user identity module lock, i.e., a personal identification number (PIN) code, new attack methods can still copy information in the SIM.

[0007] In the prior art, user identification module cloning attacks cannot be effectively identified, and no suitable solution has been proposed in the related art. SUMMARY

[0008] Embodiments of the present disclosure provide a user identification module cloning attack identification method and device to at least solve the problem that user identification module cloning attacks cannot be effectively identified in the related art.

[0009] According to an embodiment of the present disclosure, a user identification module cloning attack identification method is provided, including: collecting request data and response data of registration requests, logout requests, network-side deregistration requests, and service requests in a communication network to obtain a signaling time sequence; identifying a first feature of the signaling time sequence in a same subscriber permanent identifier (SUPI) signaling time sequence, wherein the first feature is that a user equipment (UE) with the same SUPI but different international mobile equipment identifiers (IMEIs) initiates at least two registration requests with an accepted response result successively, and no logout request or network-side deregistration request occurs within a gap between the at least two registration requests; identifying a second feature of the signaling time sequence in the same SUPI signaling time sequence, wherein the second feature is that the UE initiates a service request with a rejected response result and a failure reason that a UE identifier cannot be acquired by a network, and then initiates a registration request, and the IMEIs of the service request and the registration request are the same; and if the first feature appears first and the second feature appears at least twice in the same SUPI signaling time sequence within a set time threshold, and the IMEIs of the UEs corresponding to the at least two second features are different, it is determined that a user identification module cloning attack occurs in the communication network.

[0010] In an example embodiment, the request data and response data of the registration requests, the logout requests, the network-side deregistration requests, and the service requests in the communication network are collected, including: collecting the request data and response data of the registration requests, the logout requests, the network-side deregistration requests, and the service requests between the UE and the core network AMF network element from the XDR statement.

[0011] In an example embodiment, the request data and response data of the registration requests, the logout requests, the network-side deregistration requests, and the service requests in the communication network are collected to obtain a signaling time sequence, including: processing the collected request data and response data to obtain a first signaling time sequence, wherein the first signaling time sequence includes at least one of the following fields: request time, request type, SUPI, IMEI, response result, and failure reason; and splitting the first signaling time sequence into a plurality of second signaling time sequences with the SUPI as a key value, wherein the SUPI in each second signaling time sequence is the same.

[0012] In an example embodiment, the collected request data and response data are processed to obtain a first signaling time sequence, including: parsing the data packets of the collected request data and response data, and correlating the following parts or all fields obtained by parsing to form a first signaling time sequence: request time, request type, SUPI, IMEI, response result, failure cause.

[0013] In an example embodiment, the first signaling time sequence further includes a geographic location, and in the first feature, the geographic locations of the consecutively initiated registration requests are different.

[0014] In an example embodiment, the geographic location is a cell identity or latitude and longitude of the request initiator UE.

[0015] In an example embodiment, the request time is the time of request initiation; the request type includes a registration request, a deregistration request, a network-side deregistration request, and a service request; the SUPI is the SUPI of the request initiator UE; and the IMEI is the IMEI of the request initiator UE.

[0016] According to an embodiment of the present disclosure, a user identification module cloning attack identification device is provided, including: a collection module configured to collect request data and response data of registration requests, deregistration requests, network-side deregistration requests, and service requests in a communication network to obtain a signaling time sequence; a first identification module configured to identify a first feature of the signaling time sequence in a signaling time sequence of the same SUPI, wherein the first feature is that a UE with the same SUPI and different IMEIs consecutively initiates at least two registration requests with an accepted response result, and no deregistration request or network-side deregistration request occurs within the interval of the at least two registration requests; a second identification module configured to identify a second feature of the signaling time sequence in the signaling time sequence of the same SUPI, wherein the second feature is that the UE first initiates a service request with a rejected response result and a failure cause of UE identity being unable to be acquired by the network, and then initiates a registration request, and the IMEIs of the service request and the registration request are the same, as the identified second feature; and a judgment module configured to determine that a user identification module cloning attack occurs in the communication network if, within a set time threshold, the first feature appears first in the signaling time sequence of the same SUPI, and then the second feature appears at least twice, and the IMEIs of the UEs corresponding to the at least twice second features are different.

[0017] According to still another embodiment of the present disclosure, a computer readable storage medium is also provided, in which a computer program is stored, wherein the computer program is configured to perform the steps of any of the above method embodiments when executed.

[0018] According to still another embodiment of the present disclosure, a computer program product is also provided, comprising computer instructions which, when executed by a processor, implement the steps of any of the above method embodiments.

[0019] According to still another embodiment of the present disclosure, an electronic device is also provided, comprising a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the computer program to perform the steps of any of the above method embodiments. BRIEF DESCRIPTION OF DRAWINGS

[0020] FIG. 1 is a hardware structure block diagram of a computer terminal of a user identification module cloning attack identification method according to an embodiment of the present disclosure;

[0021] FIG. 2 is a flowchart of a user identification module cloning attack identification method according to an embodiment of the present disclosure;

[0022] FIG. 3 is a structure block diagram of a user identification module cloning attack identification device according to an embodiment of the present disclosure;

[0023] FIG. 4 is a flowchart of a user identification module cloning attack identification method according to another embodiment of the present disclosure;

[0024] FIG. 5 is a signaling flowchart of a user identification module cloning attack identification method according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0025] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the accompanying drawings and in conjunction with embodiments.

[0026] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-described drawings are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence.

[0027] The most important information in a subscriber identification module (SIM) is used for authentication, which is SUPI, authentication key (Ki), and encryption algorithm for authentication. SUPI is used to uniquely identify a user. The authentication key and the authentication algorithm are used for authentication to the core network, and the authentication algorithm is a general and public algorithm. The key information for authentication is the authentication key (Ki) information. If the above information is copied, an attacker can use the above information to initiate a registration request to the core network, impersonate a user to steal information, and perform other malicious operations.

[0028] In order to effectively identify a user identification module cloning attack, an identification method and device that can effectively identify a user identification module cloning attack are provided in the embodiments of the present disclosure.

[0029] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking the case of running on a computer terminal, FIG. 1 is a hardware structure block diagram of a computer terminal on which a user identification module cloning attack identification method according to an embodiment of the present disclosure runs. As shown in FIG. 1, the computer terminal can include one or more (only one is shown in FIG. 1) processors 102 (the processor 102 can include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the computer terminal can further include a transmission device 106 for communication function and an input and output device 108. Those skilled in the art can understand that the structure shown in FIG. 1 is only schematic, which does not limit the structure of the computer terminal. For example, the computer terminal can further include more or fewer components than those shown in FIG. 1, or have a different configuration from that shown in FIG. 1.

[0030] The memory 104 can be used to store computer programs, for example, software programs of application software and modules, such as a computer program corresponding to a user identification module cloning attack identification method according to an embodiment of the present disclosure. The processor 102 executes various functional applications and data processing by running the computer programs stored in the memory 104, that is, implements the above-mentioned method. The memory 104 can include a high-speed random access memory, and can further include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 104 can further include a memory remotely arranged with respect to the processor 102, which can be connected to the computer terminal through a network. Examples of the network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0031] The transmission device 106 is used to receive or send data via a network. Specific examples of the network can include a wireless network provided by a communication provider of the computer terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC for short), which can be connected to other network devices through a gateway so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (Radio Frequency, RF for short) module, which is used to communicate with the Internet in a wireless manner.

[0032] The embodiment provides a method for identifying a user identification module clone attack running on the computer terminal, and FIG. 2 is a flowchart of the method for identifying a user identification module clone attack according to the embodiment of the present disclosure. As shown in FIG. 2, the flowchart comprises the following steps.

[0033] In step S202, request data and response data of a registration request (Registration Request), a deregistration request (Deregistration Request), a network side de-registration request (De-registration Request) and a service request (Service Request) in a communication network are collected to obtain a signaling time sequence, wherein the signaling time sequence can comprise the following information: request time, request type, user permanent identification SUPI, international mobile equipment identity IMEI, response result and failure cause.

[0034] For example, the required request data and response data can be collected on an XDR bill. Of course, other data collection methods can also be used, for example, packet capturing. However, collecting the required request data and response data on the XDR bill is a simple and efficient collection method.

[0035] In the embodiment, taking 5G as an example, the registration request can be a registration request initiated by a UE (User Equipment) to a core network AMF network element on a 5G network N1 / N2 port, and the response is a registration acceptance (Registration Accept) or registration rejection (Registration Reject) response returned by the AMF to the UE.

[0036] The deregistration request can be a deregistration request initiated by the UE to the core network AMF network element on the 5G network N1 / N2 port, and the response is a deregistration acceptance (De-registration Accept) response returned by the AMF to the UE.

[0037] The network side de-registration request is a de-registration request initiated by the core network AMF network element to the UE on the 5G network N1 / N2 port, and the response is a De-registration Accept response returned by the UE to the AMF.

[0038] The service request is a request initiated by a UE to a core network AMF network element through a 5G network N1 / N2 interface. The UE in the CM-IDLE state initiates the service request, mainly to send uplink signaling messages, user data or respond to a network paging request. The UE in the CM-CONNECTED state initiates the service request to activate the PDU session user plane, and the response is a service accept (Service Accept) or service reject (Service Reject) response returned by the AMF to the UE.

[0039] In step S204, a first feature of the signaling time sequence is identified in the signaling time sequence with the same SUPI, wherein the first feature is that a user equipment (UE) with the same SUPI but different international mobile equipment identification (IMEI) continuously initiates at least two registration requests with an accepted response result, and no deregistration request or network side deregistration request occurs within the gap of the at least two registration requests.

[0040] Specifically, in the embodiment, the data packets of the collected request data and response data are parsed to obtain relevant information fields, such as request time, request type, SUPI, IMEI, response result, failure cause, etc. The relevant fields obtained by parsing are associated to form a signaling time sequence (which can be referred to as a first signaling time sequence), and the first signaling time sequence is further split into a plurality of second signaling time sequences with the same SUPI as a key value.

[0041] Specifically, the time is the time when the request is initiated. The request type has four values: “Registration”, “Deregistration”, “De-registration” and “Service”. The SUPI is the SUPI of the UE initiating the request. The SUPI may not be carried in the signaling request, and needs to be associated with other signaling to obtain the request SUPI and backfill. The IMEI is the IMEI of the UE initiating the request. The IMEI may not be carried in the signaling request, and needs to be associated with other signaling to obtain the request IMEI and backfill. The response result is the response result of the request, which has two values: “Accept” and “Reject”, representing success and failure. The failure cause is the failure cause of the response of the request. If the response is “Accept”, the value is empty. If the response result is “Reject”, the value is the cause value (cause) of Reject. If there is no cause value for Reject, the value is also empty.

[0042] Then, based on each field in the second signaling time sequence, a feature of the second signaling time sequence is identified, and in this embodiment, first, identification of a first feature is performed. Specifically, in the second signaling time sequence of the same SUPI, it is identified whether there is a UE with the same SUPI but with different IMEIs that continuously initiates at least two registration requests (Registration Request) with a response result of "accept" and no deregistration request (Deregistration Request) or network de-registration request (De-registration Request) occurs within the interval of the at least two registration requests. The first feature is used to identify that a registration request is continuously initiated multiple times without deregistration in the case of different IMEIs but the same SUPI.

[0043] In another embodiment, the signaling time sequence can also include a geographic location, and in the first feature, the geographic locations of the continuously initiated registration requests are different. Since user identification module cloning behavior can occur in the same geographic location or base station cell area of the cloned user identification module or in different geographic locations or base station cell areas, the different geographic locations serve as an optional condition. The geographic location can be a cell identifier or latitude and longitude of the UE that initiates the request, etc. The geographic location information can not be carried in the signaling request, and other signaling needs to be associated to obtain the geographic location information and backfilled.

[0044] In step S206, in the signaling time sequence of the same SUPI, a second feature of the signaling time sequence is identified, where the second feature is that the UE initiates a service request with a response result of rejection and a failure reason that the UE identity cannot be acquired by the network, and then initiates a registration request, and the IMEIs of the service request and the registration request are the same.

[0045] Specifically, in this embodiment, if the first feature is identified in the signaling time sequence, the second feature needs to be further identified. That is, in the signaling time sequence of the same SUPI, it is identified that the UE initiates a service request (Service Request) with a response result of rejection Reject and a failure reason of #9, and then initiates a registration request (Registration Request), and the IMEIs of the service request and the registration request are the same (that is, the IMEI associated with the service request and the IMEI associated with the registration request are the same IMEI, indicating that the same UE initiates the service request and the registration request).

[0046] The second feature is to identify the identity of the UE in the core network (such as SUCI or 5G-GUTI) and its authentication key Kc expires, resulting in the initiated service request being rejected Reject, and the rejection reason is #9 (the UE identity cannot be obtained by the network), and then a registration request (Registration Request) is initiated again.

[0047] Step S208, when the same SUPI signaling time sequence, first appears the first feature, and then appears the second feature of at least two different IMEIs (that is, the service request rejection reason for #9 caused by the alternation of different IMEIs), it can be determined that the SIM card cloning attack occurs in the communication network.

[0048] For example, when the user identification module is cloned, two UEs with the same user identification module information are inserted into the core network for registration. When UE1 registers and authenticates successfully, the second UE with the same user identification module information initiates a registration request again, which can also be authenticated and accessed to the operator network. However, when the two cards are used at the same time, a problem will occur. After the user identification module accesses the operator network, all communications are encrypted using the Kc key, and the Kc key is randomly generated during the authentication process. Therefore, although the original authentication information of the two cards is the same, the Kc key information obtained is different because the authentication is performed separately, and the Kc key stored in the core network is the Kc key that passes the authentication. When the user equipment that first accesses the network initiates a service request to the AMF, because the Kc key of the core network authentication has been refreshed by the user equipment that enters the network later, the AMF will reply to the user equipment that first enters the network Service reject signaling, and the rejection reason is #9. Then the user equipment that first enters the network needs to be re-registered and authenticated once to obtain a new Kc, which will cause the Kc key of the user equipment that enters the network later to be invalid, and the user equipment that enters the network later will also receive Service reject signaling, and the rejection reason is #9. Then it needs to be re-registered and authenticated once, and so on, which can be determined as a SIM card cloning attack.

[0049] The above steps of the embodiment can solve the problem that the related art cannot detect the cloning attack of the similar user identification module and the 5G network user identification module, effectively detect the cloning attack of the user identification module, increase the detectable scene, improve the detection efficiency, and reduce the false positives and false negatives.

[0050] There is also provided in the embodiment a device for identifying a user identification module cloning attack, which implements the above-mentioned embodiments and preferred embodiments, and the description of which has been made above. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, implementation in hardware, or a combination of software and hardware, is also possible and contemplated.

[0051] FIG. 3 is a structural block diagram of a device for identifying a user identification module cloning attack according to an embodiment of the present disclosure. As shown in FIG. 3, the device 300 for identifying a user identification module cloning attack provided in the embodiment can include a collection module 31, a first identification module 32, a second identification module 33, and a judgment module 34.

[0052] The collection module 31 is configured to collect request and response data of a registration request, a deregistration request, a network-side deregistration request, and a service request in a communication network to obtain a signaling time sequence, wherein the signaling time sequence can include the following information: request time, request type, subscriber permanent identity (SUPI), international mobile equipment identity (IMEI), response result, and failure cause.

[0053] The first identification module 32 is configured to identify a first feature in the signaling time sequence of the same SUPI, wherein the first feature is that a UE with the same SUPI but different IMEIs successively initiates at least two registration requests with an accepted response result, and no deregistration request or network-side deregistration request occurs within the interval of the at least two registration requests.

[0054] The second identification module 33 is configured to identify a second feature in the signaling time sequence of the same SUPI, wherein the second feature is that the UE first initiates a service request with a rejected response result and a failure cause of UE identity being unable to be acquired by the network, and then initiates a registration request, and the IMEIs of the service request and the registration request are the same.

[0055] The judgment module 34 is configured to determine that a user identification module cloning attack occurs when the first feature appears first and then the second feature of at least two different IMEIs appears within the set time threshold.

[0056] The identification device of the embodiment can be integrated in a certain network element of a communication network, for example, a network management center. It can also be independent of the communication network, collect data from the network side through an interface, process and analyze the collected data, detect features, and thus determine whether a user identification module cloning attack has occurred. For example, the identification device can be an XDR bill probe product of a 5G online log retention system, which can detect 5G network user identification module cloning attacks. The probe product can associate and backfill the SUPI, IMEI, and location information of the signaling.

[0057] It should be noted that the above modules can be implemented by software or hardware. For the latter, the following implementation manners can be used, but are not limited thereto: the above modules are located in the same processor; or the above modules are located in different processors in any combination.

[0058] The identification device provided in the embodiment can effectively detect user identification module cloning attacks, improve detection efficiency, and reduce false positives and false negatives.

[0059] In order to facilitate the understanding of the technical solutions provided by the present disclosure, a specific embodiment will be described below.

[0060] The embodiment provides another method for identifying network user identification module cloning attacks. For the purpose of description, the 5G network is taken as an example in the embodiment, as shown in FIG. 4. The embodiment can include the following steps:

[0061] In step S402, request and response data of a registration request (Registration Request), a deregistration request (Deregistration Request), a network side de-registration request (De-registration Request), and a service request (Service Request) are collected and processed to obtain a signaling time sequence.

[0062] In step S402, the deregistration request is a deregistration request initiated by a 5G network N1 / N2 UE to a core network AMF network element, and the response is a Registration Accept or Registration Reject response returned by the AMF to the UE. The registration request is a registration request initiated by a 5G network N1 / N2 UE to a core network AMF network element, and the response is a De-registration Accept response returned by the AMF to the UE. The network deregistration request is a deregistration request initiated by a 5G network N1 / N2 core network AMF network element to the UE, and the response is a De-registration Accept response returned by the UE to the AMF. The service request is a request initiated by a 5G network N1 / N2 UE to a core network AMF network element. The UE in the CM-IDLE state initiates the Service Request service request, mainly to send uplink signaling messages, user data, or respond to a network paging request; the UE in the CM-CONNECTED state initiates the Service Request request for PDU session user plane activation, and the response is a Service Accept or Service Reject response returned by the AMF to the UE.

[0063] In the embodiment, the above request and response data can be collected from the XDR bill of the 5G online log retention system. The request and response data collected in step S402 are processed to obtain a signaling time sequence, which can include time, type, SUPI, IMEI, geographic location, response result, and failure cause. The time is the time when the request is initiated. The type is the request type, which has four values: “Registration”, “Deregistration”, “De-registration”, or “Service”. The SUPI is the SUPI of the UE initiating the request, which may not be carried in the signaling request and needs to be associated with other signaling to obtain the request SUPI and backfill. The IMEI is the IMEI of the UE initiating the request, which may not be carried in the signaling request and needs to be associated with other signaling to obtain the request IMEI and backfill. The geographic location is the cell identifier and / or latitude and longitude of the UE initiating the request, which may not be carried in the signaling request and needs to be associated with other signaling to obtain the request geographic location information and backfill. The response result is the response result of the request, which has two values: “Accept” and “Reject”, representing success and failure. The failure cause is the failure cause of the request response. If the response is “Accept”, the value is empty. If the response result is “Reject”, the value is the case value of Reject. If Reject has no reason value, the value is also empty.

[0064] Step S404, split the signaling time sequence into multiple signaling time sequences with SUPI as the key key value, ensure that the SUPI in each signaling time sequence is the same.

[0065] For example, Table 1 is a signaling time sequence after splitting, with one SUPI being imsi-460011234567890.

[0066] Table 1

[0067] Step S406, in the same SUPI signaling time sequence, identify that the UE with the same SUPI but different IMEI successively initiates at least two registration requests with the response result being "Accept", and optionally the geographical positions of the two registration requests are also different, as feature 1. Feature 1 is used to identify that the UE with different IMEI but the same SUPI successively initiates registration requests without logging out. Since the user identification module cloning behavior is likely to occur in the same geographical position or base station cell area of the cloned user identification module, or in different geographical positions or base station cell areas, the different geographical positions are used as optional conditions.

[0068] For example, in the above Table 1, search with the user identification SUPI as the key key value, search out all the signaling corresponding to the SUPI imsi-460011234567890 with the SUPI as the key key value, further identify that there are UE with the same SUPI but at least two different IMEI (4370816125816151 and 5532436678012345 respectively) successively initiating Registration Request in the time threshold 1 time period, and the registration response is Registration Accept, and optionally the geographical positions of the two registration requests are also different. Therefore, it is identified that feature 1 appears in Table 1.

[0069] Step S408, in the case of identifying feature 1, further, in the same SUPI signaling time sequence, identify that the UE first initiates Service Request with the response result being Reject and the failure reason being #9, and then initiates Registration Request, the IMEI of the two requests being the same, as feature 2.

[0070] Feature 2 is used to identify the identity of the UE in the core network (such as SUCI or 5G-GUTI) and the expiration of its authentication key Kc, resulting in the initiated Service Request request being rejected, and the rejection reason is #9 (UE identity cannot be derived by the network, UE identity cannot be obtained by the network), and then a Registration Request registration request will be initiated again.

[0071] For example, in the above Table 1, in the signaling time sequence of the same SUPI (imsi-460011234567890), taking the time of the first Registration Request signaling in Feature 1 as the time starting point, within the time threshold 1 time period, the UE with the device serial number IMEI 4370816125816151 is identified to first initiate a Service Request service request but the response result is Service Reject, the rejection reason is #9, and then initiates a Registration Request registration request, and the device serial numbers IMEI associated in the Registration Request and Service Request are the same (4370816125816151).

[0072] After the UE with the device serial number IMEI 4370816125816151 initiates the registration request, the UE with the SUPI imsi-460011234567890 and the IMEI 5532436678012345 also appears the signaling sequence feature of Feature 2.

[0073] Step S410, when Feature 1 appears first, and then Feature 2 appears at least twice with different IMEIs, it is determined that a SIM card cloning attack has occurred.

[0074] For example, it is determined that within the time threshold 1, the user identity module with the same SUPI (imsi-460011234567890) first appears Feature 1, and then appears Feature 2 at least twice with different IMEIs (4370816125816151 and 5532436678012345 respectively), it is determined that the user identity module with the SUPI imsi-460011234567890 has a user identity module cloning attack. The setting of the time threshold 1 can be less than or equal to the value of the periodic registration timer, such as 54 minutes.

[0075] In the embodiment, by collecting relevant signaling data and analyzing whether the characteristics meet the user identification module cloning, the cloning attack of the user identification module can be effectively detected. Compared with the method adopted in the related art, the cloning attack of the related user identification module and the 5G network user identification module cannot be detected, the detectable scene is increased, the detection efficiency is improved, and the false alarm and the missed alarm are reduced.

[0076] Figure 5 is a signaling flowchart of a user identification module cloning attack identification method according to an embodiment of the present disclosure. As shown in Figure 5, when the user identification module is cloned, two UEs 1 and 2 with the same user identification module information are inserted into the core network AMF to send a request.

[0077] (1) UE1 sends a registration request to AMF.

[0078] (2) UE2 sends a registration request to AMF.

[0079] When UE1 registers and authenticates successfully, the second UE with the same user identification module information initiates a registration request again, which can also be authenticated and accessed to the operator network. However, when the two cards are used at the same time, a problem will occur. After the user identification module accesses the operator network, all communications are encrypted by the Kc key, and the Kc key is randomly generated in the authentication process. Therefore, although the original authentication information of the two cards is the same, the Kc key information obtained is different because the authentication is performed separately, and the Kc key that passes the network authentication is stored in the core network.

[0080] (3) UE1 sends a service request to AMF.

[0081] (4) AMF sends a service rejection to UE1.

[0082] When the first user equipment (UE1) accesses the network and initiates a service request to the AMF, because the Kc key of the core network authentication has been refreshed by the second user equipment (UE2) accessing the network, the AMF will reply to the first user equipment (UE1) with service rejection signaling Service reject, and the rejection reason is #9 (UE identity cannot be derived by the network, UE identity cannot be derived by the network).

[0083] (5) UE1 sends a registration request to AMF.

[0084] (6) UE2 sends a service request to AMF.

[0085] (7) AMF sends a service rejection to UE2.

[0086] (8) UE2 sends a registration request to the AMF.

[0087] The first UE (UE1) re-registers and performs authentication once again, and obtains a new Kc, which causes the Kc key of the second UE (UE2) to be invalidated, and the second UE also receives a service rejection signaling Service reject, and the rejection reason is #9 (UE identity cannot be derived by the network, UE identity cannot be derived by the network), and then re-registers and performs authentication again, and so on.

[0088] When it is found that the UE with the same SUPI continuously initiates at least two registration requests Initial Registration Request without logging out, and the device serial numbers at the time of registration are different, and the subsequent rejection reasons are #9 (UE identity cannot be derived by the network, UE identity cannot be derived by the network) service rejection Service reject signaling and registration request Registration Request, and optionally, the geographical positions where the above behaviors occur are different, it can be judged that the user identification module cloning attack occurs.

[0089] As shown in FIG. 5, the signaling fingerprint for judging the user identification module cloning is that the registration request result is acceptance and the service request result is rejection, and the related signaling also includes the logoff request and the network side deregistration request. In order to consider the storage space, in actual operation, only the signaling with the registration request result being acceptance Accept and the service request result being rejection Reject and the rejection reason being #9, and the logoff request and the network side deregistration request are collected, and other signaling call records can not be collected.

[0090] From the above description of the embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be realized by means of software and necessary general hardware platforms, and of course, it can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the disclosure can be embodied in the form of a software product, which is stored in a storage medium (such as a ROM / RAM, a magnetic disk, or an optical disc), and includes a plurality of instructions for causing a terminal device (which can be a user equipment, a computer, a server, or a network device) to execute the method described in the various embodiments of the disclosure.

[0091] The embodiments of the present disclosure further provide a computer readable storage medium, which stores a computer program, wherein the computer program is configured to execute the steps in any of the method embodiments described above when executed.

[0092] In an example embodiment, the computer readable storage medium described above can include, but is not limited to, a U disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store computer programs.

[0093] The embodiments of the present disclosure further provide a computer program product, which comprises computer instructions, and the computer instructions are executed by a processor to execute the steps in any of the method embodiments described above.

[0094] The embodiments of the present disclosure further provide an electronic device, which comprises a memory and a processor, the memory stores a computer program, and the processor is configured to execute the computer program to execute the steps in any of the method embodiments described above.

[0095] In an example embodiment, the electronic device described above can further comprise a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.

[0096] The specific examples in the embodiments can refer to the examples described in the above embodiments and example embodiments, and the embodiments will not be described here.

[0097] Obviously, those skilled in the art should understand that the modules or steps of the present disclosure described above can be realized by general computing devices, which can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, and they can be realized by program codes executable by computing devices, so that they can be stored in storage devices and executed by computing devices, and in some cases, the steps shown or described can be executed in different order, or they can be manufactured into individual integrated circuit modules, or multiple modules or steps can be manufactured into a single integrated circuit module. Thus, the present disclosure is not limited to any specific combination of hardware and software.

[0098] The above only describes the preferred embodiments of the present disclosure and is not intended to limit the present disclosure. For those skilled in the art, the present disclosure can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. within the principles of the present disclosure shall be included in the protection scope of the present disclosure.

Claims

1. A method for identifying a subscriber identity module (SIM) cloning attack, comprising: Collect request data and response data of registration requests, deregistration requests, network-side deregistration requests, and service requests in the communication network to obtain signaling time series; In a signaling time sequence of a same user permanent identifier (SUPI), identifying a first feature in the signaling time sequence, wherein the first feature is: a user equipment (UE) having the same SUPI but different international mobile equipment identities (IMEIs) initiates at least two consecutive registration requests with an accepted response, and no deregistration request or network-side deregistration request occurs between the at least two registration requests; In the signaling time sequence of the same SUPI, identifying a second feature in the signaling time sequence, wherein the second feature is: after the UE first initiates a service request whose response result is rejection and the failure reason is that the UE identity cannot be obtained by the network, the UE initiates a registration request, and the IMEI of the service request and the registration request are the same; Within a set duration threshold, if the first feature appears first and then the second feature appears at least twice in the signaling time sequence of the same SUPI, and the IMEIs of the UEs corresponding to the at least two second features are different, it is determined that a subscriber identity module cloning attack has occurred in the communication network.

2. The method according to claim 1, wherein Collects request and response data for registration requests, deregistration requests, network-side deregistration requests, and service requests in the communication network, including: Collect the request data and response data of registration request, deregistration request, network-side deregistration request, and service request between UE and core network AMF network element from XDR call records.

3. The method according to claim 1, wherein Collect request and response data for registration requests, deregistration requests, network-side deregistration requests, and service requests in the communication network to obtain signaling time series, including: Processing the collected request data and response data to obtain a first signaling time sequence, wherein the first signaling time sequence includes at least one of the following fields: request time, request type, SUPI, IMEI, response result, and failure reason; The first signaling time sequence is split into multiple second signaling time sequences using the SUPI as a key value, wherein the SUPI in each of the second signaling time sequences is the same.

4. The method according to claim 3, wherein: The collected request data and response data are processed to obtain a first signaling time series, including: Parse the collected data packets of the request data and response data, and associate some or all of the following fields obtained by parsing to form a first signaling time sequence: request time, request type, SUPI, IMEI, response result, and failure reason.

5. The method according to claim 3, wherein The first signaling time sequence further includes a geographical location. In the first feature, the geographical locations of the registration requests initiated consecutively are different.

6. The method according to claim 5, wherein: The geographical location is the cell identifier or the longitude and latitude of the UE that initiates the request.

7. The method according to claim 3, wherein: The request time is the time when the request is initiated; The request types include registration request, deregistration request, network-side deregistration request, and service request; The SUPI is the SUPI of the request initiator UE; The IMEI is the IMEI of the UE that initiates the request.

8. A device for identifying a subscriber identity module (SIM) cloning attack, comprising: A collection module is configured to collect request data and response data of registration requests, deregistration requests, network-side deregistration requests, and service requests in the communication network to obtain a signaling time series; a first identifying module configured to identify, in a signaling time sequence of the same SUPI, a first feature of the signaling time sequence, wherein the first feature is: a UE with the same SUPI but a different IMEI initiates at least two consecutive registration requests with an accepted response result, and no deregistration request or network-side deregistration request occurs between the at least two registration requests; a second identification module configured to identify, in the signaling time sequence of the same SUPI, a second feature of the signaling time sequence, wherein the second feature is: the UE first initiates a service request with a rejection response and a failure reason being that the UE identity cannot be obtained by the network, and then initiates a registration request, and the IMEI of the service request and the IMEI of the registration request are the same, as the second feature identified; The judgment module is configured to determine that a subscriber identity module cloning attack has occurred in the communication network if, within a set duration threshold, the first feature first appears in the signaling time sequence of the same SUPI, and then the second feature appears at least twice, and the IMEIs of the UEs corresponding to the at least two second features are different.

9. A computer-readable storage medium having a computer program stored therein, wherein: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer program product comprising computer instructions, which, when executed by a processor, implement the steps of the method according to any one of claims 1 to 7.

11. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method according to any one of claims 1 to 7 when executing the computer program.

Citation Information

Patent Citations

  • Method and system for judging copying state of subscriber identification card

    CN101754222A

  • Anti-cloning method and device of user identification module

    CN101938746A

  • Identification method and device for clone of subscriber identity module (SIM) card information of mobile subscriber

    CN102065405A

  • Controlling equipment access to slices in a 5g network

    US20220078696A1