WO2017128542A1 - 网络驻留方法、网络驻留系统和终端 - Google Patents

网络驻留方法、网络驻留系统和终端 Download PDF

Info

Publication number
WO2017128542A1
WO2017128542A1 PCT/CN2016/080822 CN2016080822W WO2017128542A1 WO 2017128542 A1 WO2017128542 A1 WO 2017128542A1 CN 2016080822 W CN2016080822 W CN 2016080822W WO 2017128542 A1 WO2017128542 A1 WO 2017128542A1
Authority
WO
WIPO (PCT)
Prior art keywords
base station
authentication
terminal
core network
target base
Prior art date
Application number
PCT/CN2016/080822
Other languages
English (en)
French (fr)
Inventor
张祖辉
Original Assignee
宇龙计算机通信科技(深圳)有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 宇龙计算机通信科技(深圳)有限公司 filed Critical 宇龙计算机通信科技(深圳)有限公司
Publication of WO2017128542A1 publication Critical patent/WO2017128542A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/12Detection or prevention of fraud

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a network resident method, a network resident system, and a terminal.
  • the pseudo base station equipment is usually operated at a higher power than the core network base station, thereby misleading the user terminal to camp on the pseudo base station network, so that the user cannot normally use the service provided by the operator, and the pseudo base station forcibly
  • the user terminal sends short messages such as fraud and advertisement promotion, which not only affects the normal communication of the user, but also causes financial loss to the user.
  • the terminal performs neighbor cell measurement and cell reselection judgment according to the network protocol specification, and since the network authentication belongs to one-way authentication, and the terminal does not authenticate the network, the terminal cannot judge the network. Authenticity.
  • the present invention is based on at least one of the above technical problems, and proposes a new network residing scheme, which obtains a feedback instruction of a target base station by transmitting an erroneous authentication parameter to a target base station, thereby implementing a network-to-network knowledge by the terminal.
  • the weight discrimination and accurate resident reduce the possibility that the user terminal resides in the pseudo base station, reduce the interference of the pseudo base station to the communication service of the user terminal, and improve the security of the user terminal.
  • the present invention provides a network camping method, including: when detecting that a trigger condition of a location area update is established, acquiring a working frequency point of a base station in a region where the terminal is located; The update request is sent to the target base station corresponding to the working frequency point; the authentication random parameter fed back by the target base station is obtained; the first authentication parameter is generated according to the identification information of the user identification card of the terminal, the authentication random parameter and the specified authentication algorithm, and Generating a second authentication parameter different from the first authentication parameter; sending the second authentication parameter to the target base station; and determining, according to the feedback instruction of the target base station to the second authentication parameter, that the target base station is a pseudo base station or a core network base station.
  • the error authentication parameter is sent to the target base station to obtain the feedback instruction of the target base station, thereby realizing the authentication and accurate camping of the network by the terminal, thereby reducing the possibility that the user terminal camps on the pseudo base station.
  • the utility model reduces the interference of the pseudo base station to the communication service of the user terminal, and improves the security of the user terminal.
  • the process that the user terminal needs to complete in the idle state includes a PLMN (Public Land Mobile Network) selection, a cell selection/reselection, a location registration, etc., and once the resident is completed, the user terminal can read the system information. (such as camping, accessing and reselecting related information, location area information, etc.), reading paging information, and initiating a connection establishment process.
  • PLMN Public Land Mobile Network
  • the method for generating the first authentication parameter is that the terminal acquires the authentication random parameter from the network and the specified authentication algorithm according to the identification information of the Subscriber Identity Module (taken from the base station and the SIM card of the core network) Communication protocol). However, before accessing the network, the terminal generates a second authentication parameter different from the first authentication parameter, that is, the second authentication parameter is an error parameter that cannot be recognized by the core network base station. If the target base station still receives the error parameter and the authentication result of the terminal is still correct, the terminal can determine that the target base station is a pseudo base station according to the determination. In addition, if the authentication result of the target base station is an error, the target base station may be a core network base station, and the terminal may continue to request to camp on the core network base station by using the first authentication parameter, thereby implementing service communication.
  • the target base station is determined to be a pseudo base station or a core network base station according to the feedback instruction of the second authentication parameter by the target base station, and specifically includes the following steps: determining, when the feedback instruction is an authentication failure instruction, determining The target base station is a core network base station; the first authentication parameter is sent to the core network base station, so that the core network base station determines whether the terminal has the resident right according to the authentication random parameter and the first authentication parameter; After the successful authentication command, the camped cell is selected according to the channel quality of the cell of the core network base station.
  • the base station is further determined according to the cell reselection.
  • the cell selection follows the C1 criterion, that is, the C1 value of the cell selection C1>0 is allowed to stay: (The patent is for GSM, so the cell selection criterion is based on C1, and the S criterion is for 3G)
  • C1 represents a cell selection judgment criterion
  • RLA_C represents an average received signal level value of the measurement cell
  • RXLEV_ACCESS_MIN represents a terminal minimum access power level allowed by the network.
  • MS_TXPWR_MAX_CCH characterizes the maximum transmit power level of the terminal allowed by the network.
  • P characterizes the maximum RF transmit power of the terminal.
  • the trigger condition for determining the location area update is established.
  • the terminal when detecting that the position change of the terminal is not equal to the preset position change value, the terminal is triggered to perform cell reselection, thereby ensuring the strength of the terminal network signal, improving the fluency of the call, and improving the user's call experience.
  • the purpose of cell reselection is to select a cell that belongs to the best signal in the PLMN to camp.
  • the quality of the serving cell that the terminal camps on will decrease due to the increase of the distance.
  • the threshold that is, the serving cell C2 ⁇ neighbor C2 and continues to be less than 5 s, cell reselection will be triggered.
  • the method further includes: determining that the target base station is a pseudo base station when acquiring the feedback instruction is an authentication success instruction; determining a working frequency point of the pseudo base station, and sending the location area update request to the de-authentication A base station other than the base station.
  • the authentication succeeds, determining that the target base station is a pseudo base station, preventing communication between the user terminal and the pseudo base station, and reducing the user being subjected to short messages and telephone harassment and fraud. risk.
  • the pseudo base station does not normally perform authentication for the user to camp, so the pseudo base station sends the feedback command for successful authentication regardless of whether the authentication parameter sent by the user terminal is the correct result generated by the authentication algorithm.
  • the randomly generated error authentication parameter different from the identification information of the user identification card of the terminal, the authentication random parameter and the correct authentication parameter generated by the specified authentication algorithm is sent to the target base station, and then the determination can be determined. Whether the base station is a pseudo base station.
  • the method further includes: determining a pre-stored resident update period; determining, after the terminal camps on the cell, the triggering of the location area update when the running time of the terminal is greater than or equal to the resident update period The conditions are established.
  • the terminal when the running time of the terminal is greater than or equal to the resident update period, the terminal is triggered to perform cell reselection, the strength of the terminal network signal is ensured, the fluency of the call is improved, and the user's calling experience is improved.
  • the R criterion using the same-frequency cell reselection lasts at least the Treselection (cell reselection timer duration) time; for the low priority frequency, the cell reselection is performed.
  • the cell time exceeds 1 s, and the s value of the serving cell is less than a preset threshold, and the s value of the low priority frequency cell is greater than a preset threshold, and the duration exceeds Treselection for reselection.
  • a network resident system comprising: an acquiring unit, configured to acquire a working frequency point of a base station in a region where the terminal is located when the trigger condition for detecting the location area update is established; And the acquiring unit is further configured to: obtain an authentication random parameter fed back by the target base station; the network resident system further includes: a generating unit, configured to use the user identity of the terminal The identification information of the identification card, the authentication random parameter and the specified authentication algorithm generate a first authentication parameter, and generate a second authentication parameter different from the first authentication parameter; the sending unit is further configured to: use the second authentication parameter Sending to the target base station; the network camping system further includes: a determining unit, configured to determine, according to the feedback instruction of the target base station to the second authentication parameter, that the target base station is a pseudo base station or a core network base station.
  • the error authentication parameter is sent to the target base station to obtain the feedback instruction of the target base station, thereby realizing the authentication and accurate camping of the network by the terminal, thereby reducing the possibility that the user terminal camps on the pseudo base station.
  • Sexuality reduces the interference of the pseudo base station to the communication service of the user terminal. Improve the security of user terminal usage.
  • the method for generating the first authentication parameter is that the terminal acquires the authentication random parameter from the network and the specified authentication algorithm according to the identification information of the Subscriber Identity Module (taken from the base station and the SIM card of the core network) Communication protocol). However, before accessing the network, the terminal generates a second authentication parameter different from the first authentication parameter, that is, the second authentication parameter is an error parameter that cannot be recognized by the core network base station. If the target base station still receives the error parameter and the authentication result of the terminal is still correct, the terminal can determine that the target base station is a pseudo base station according to the determination. In addition, if the authentication result of the target base station is an error, the secondary target base station may be a core network base station, and the terminal may continue to request to camp on the core network base station by using the first authentication parameter, thereby implementing service communication.
  • the determining unit is further configured to: when the obtaining the feedback instruction is an authentication failure instruction, determining that the target base station is a core network base station; and the sending unit is further configured to: send the first authentication parameter to the core network
  • the base station is configured to determine, by the core network base station, whether the terminal has the resident right according to the authentication random parameter and the first authentication parameter;
  • the network resident system further includes: a selecting unit, configured to: after acquiring the authentication success instruction sent by the core network base station The camped cell is selected according to the channel quality of the cell of the core network base station.
  • the acquisition of the feedback instruction of the target base station is an authentication failure, determining that the target base station is a non-pseudo base station, and obtaining the resident right by sending the correct authentication parameter to the target base station, thereby realizing the network of the terminal in the core network base station. Resident ensures the security of the terminal network and the smoothness of communication.
  • the base station is further determined according to the cell reselection.
  • the cell selection follows the C1 criterion, that is, the C1 value of the cell selection C1>0 is allowed to stay:
  • C1 represents a cell selection judgment criterion
  • RLA_C represents an average received signal level value of the measurement cell
  • RXLEV_ACCESS_MIN represents a terminal minimum access power level allowed by the network.
  • MS_TXPWR_MAX_CCH characterizes the maximum transmit power level of the terminal allowed by the network.
  • P characterizes the maximum RF transmit power of the terminal.
  • the method further includes: a detecting unit, configured to: after the terminal camps on the cell of the core network base station, detect whether the terminal moves to an area other than the cell of the core network base station; When it is detected that the terminal moves to an area other than the cell of the core network base station, the trigger condition for determining the location area update is established.
  • the terminal when detecting that the position change of the terminal is not equal to the preset position change value, the terminal is triggered to perform cell reselection, thereby ensuring the strength of the terminal network signal, improving the fluency of the call, and improving the user's call experience.
  • the purpose of cell reselection is to select a cell that belongs to the best signal in the PLMN to camp.
  • the quality of the serving cell that the terminal camps on will decrease due to the increase of the distance.
  • the threshold that is, the serving cell C2 ⁇ neighbor C2 and continues to be less than 5 s, cell reselection will be triggered.
  • the determining unit is further configured to: when the obtaining the feedback instruction is an authentication success instruction, determining that the target base station is a pseudo base station; and the sending unit is further configured to: determine a working frequency of the pseudo base station, The location area update request is sent to a base station other than the pseudo base station.
  • the authentication succeeds, determining that the target base station is a pseudo base station, preventing communication between the user terminal and the pseudo base station, and reducing the user being subjected to short messages and telephone harassment and fraud. risk.
  • the pseudo base station does not normally perform authentication for the user to camp, so the pseudo base station sends the feedback command for successful authentication regardless of whether the authentication parameter sent by the user terminal is the correct result generated by the authentication algorithm.
  • the randomly generated error authentication parameter different from the identification information of the user identification card of the terminal, the authentication random parameter and the correct authentication parameter generated by the specified authentication algorithm is sent to the target base station, and then the determination can be determined. Whether the base station is a pseudo base station.
  • the determining unit is further configured to: determine a pre-stored resident update period; the determining unit is further configured to: after the terminal camps on the cell, the running time of the terminal is greater than or equal to the resident update At the time of the cycle, the trigger condition for determining the location area update is established.
  • the running time of the terminal is greater than or equal to the resident update period, and the touch
  • the transmitting terminal performs cell reselection to ensure the strength of the terminal network signal, improve the fluency of the call, and improve the user's calling experience.
  • the R criterion using the same-frequency cell reselection lasts at least the Treselection (cell reselection timer duration) time; for the low priority frequency, the cell reselection is performed.
  • the cell time exceeds 1 s, and the s value of the serving cell is less than a preset threshold, and the s value of the low priority frequency cell is greater than a preset threshold, and the duration exceeds Treselection for reselection.
  • a terminal comprising a communication bus, an input device, an output device, a memory, and a processor, wherein:
  • the communication bus is configured to implement connection communication between the input device, the output device, the memory, and the processor;
  • the input device is configured to obtain a feedback instruction of the target base station to the second authentication parameter
  • the output device is configured to send a location area update request, and a second authentication parameter
  • the program stores a set of program codes, and the terminal calls the program code stored in the memory to perform the following operations:
  • the processor acquires a working frequency point of the base station in the area where the terminal is located when the trigger condition for detecting the location area update is established;
  • the output device sends a location area update request to the target base station corresponding to the working frequency point
  • the processor acquires an authentication random parameter fed back by the target base station
  • the processor generates a first authentication parameter according to the identifier information of the user identity card of the terminal, the authentication random parameter, and the specified authentication algorithm, and generates a second template different from the first authentication parameter.
  • the output device sends the second authentication parameter to the target base station
  • the processor determines, according to the feedback instruction of the target base station to the second authentication parameter, that the target base station is a pseudo base station or a core network base station.
  • the processor determines, according to the feedback instruction of the second authentication parameter by the target base station, that the target base station is a pseudo base station or a core network base station, and specifically includes the following steps:
  • the processor obtains the feedback instruction as an authentication failure instruction, determining that the target base station is a core network base station;
  • the output device sends the first authentication parameter to the core network base station, so that the core network base station determines whether the terminal has a resident according to the authentication random parameter and the first authentication parameter.
  • the processor selects a camped cell according to the channel quality of the cell of the core network base station.
  • it also includes:
  • the processor After the terminal camps on the cell of the core network base station, the processor detects whether the terminal moves to an area other than the cell of the core network base station;
  • the processor determines that a trigger condition of the location area update is established when detecting that the terminal moves to an area other than the cell of the core network base station.
  • it also includes:
  • the processor determines that the target base station is a pseudo base station
  • the processor determines a working frequency point of the pseudo base station, and sends a location area update request to a base station other than the pseudo base station.
  • it also includes:
  • the processor determines a pre-stored resident update period
  • the triggering condition that the location area update is determined is established.
  • the error authentication parameter is sent to the target base station to obtain the feedback instruction of the target base station, thereby realizing the authentication and accurate residence of the network by the terminal, thereby reducing the possibility that the user terminal camps on the pseudo base station.
  • the interference of the pseudo base station to the communication service of the user terminal is reduced, and the security of the user terminal is improved.
  • FIG. 1 shows a schematic flow chart of a network resident method according to an embodiment of the present invention
  • FIG. 2 shows a schematic block diagram of a network resident system in accordance with an embodiment of the present invention
  • Figure 3 shows a schematic block diagram of a terminal in accordance with an embodiment of the present invention
  • FIG. 4 shows a schematic diagram of a network camping scheme in accordance with one embodiment of the present invention
  • FIG. 5 shows a schematic diagram of a network camping scheme according to another embodiment of the present invention.
  • Figure 6 shows a schematic flow diagram of a network camping scheme in accordance with an embodiment of the present invention.
  • FIG. 1 shows a schematic flow chart of a network resident method in accordance with an embodiment of the present invention.
  • a network camping method includes: Step 102: When detecting that a trigger condition of a location area update is established, acquiring a working frequency point of a base station in a region where the terminal is located; The location area update request is sent to the target base station corresponding to the working frequency point; in step 106, the authentication random parameter fed back by the target base station is obtained; in step 108, the identification information of the user identification card, the authentication random parameter and the specified authentication algorithm are determined according to the user identity of the terminal.
  • the feedback instruction determines that the target base station is a pseudo base station or a core network base station.
  • the error authentication parameter is sent to the target base station to obtain the feedback instruction of the target base station, thereby realizing the authentication and accurate camping of the network by the terminal, thereby reducing the possibility that the user terminal camps on the pseudo base station.
  • the utility model reduces the interference of the pseudo base station to the communication service of the user terminal, and improves the security of the user terminal.
  • the process that the user terminal needs to complete in the idle state includes a PLMN (Public Land Mobile Network) selection, a cell selection/reselection, a location registration, etc., and once the resident is completed, the user terminal can read the system information. (such as camping, accessing and reselecting related information, location area information, etc.), reading paging information, and initiating a connection establishment process.
  • PLMN Public Land Mobile Network
  • the method for generating the first authentication parameter is that the terminal acquires the authentication random parameter from the network and the specified authentication algorithm according to the identification information of the Subscriber Identity Module (taken from the base station and the SIM card of the core network) Communication protocol). However, before accessing the network, the terminal generates a second authentication parameter different from the first authentication parameter, that is, the second authentication parameter pair. It is an incorrect parameter that cannot be recognized by the core network base station. If the target base station still receives the error parameter and the authentication result of the terminal is still correct, the terminal can determine that the target base station is a pseudo base station according to the determination. In addition, if the authentication result of the target base station is an error, the target base station may be a core network base station, and the terminal may continue to request to camp on the core network base station by using the first authentication parameter, thereby implementing service communication.
  • the target base station is determined to be a pseudo base station or a core network base station according to the feedback instruction of the second authentication parameter by the target base station, and specifically includes the following steps: determining, when the feedback instruction is an authentication failure instruction, determining The target base station is a core network base station; the first authentication parameter is sent to the core network base station, so that the core network base station determines whether the terminal has the resident right according to the authentication random parameter and the first authentication parameter; After the successful authentication command, the camped cell is selected according to the channel quality of the cell of the core network base station.
  • the acquisition of the feedback instruction of the target base station is an authentication failure, determining that the target base station is a non-pseudo base station, and obtaining the resident right by sending the correct authentication parameter to the target base station, thereby realizing the network of the terminal in the core network base station. Resident ensures the security of the terminal network and the smoothness of communication.
  • the base station is further determined according to the cell reselection.
  • the cell selection follows the C1 criterion, that is, the cell selection C1 value C1>0 allows the resident:
  • C1 represents a cell selection judgment criterion
  • RLA_C represents an average received signal level value of the measurement cell
  • RXLEV_ACCESS_MIN represents a terminal minimum access power level allowed by the network.
  • MS_TXPWR_MAX_CCH characterizes the maximum transmit power level of the terminal allowed by the network.
  • P characterizes the maximum RF transmit power of the terminal.
  • the trigger condition for determining the location area update is established.
  • the position change of the detection terminal is greater than or equal to the preset position change.
  • the terminal is triggered to perform cell reselection, which ensures the strength of the terminal network signal, improves the fluency of the call, and improves the user's call experience.
  • the purpose of cell reselection is to select a cell that belongs to the best signal in the PLMN to camp.
  • the quality of the serving cell that the terminal camps on will decrease due to the increase of the distance.
  • the threshold that is, the serving cell C2 ⁇ neighbor C2 and continues to be less than 5 s, cell reselection will be triggered.
  • the method further includes: determining that the target base station is a pseudo base station when acquiring the feedback instruction is an authentication success instruction; determining a working frequency point of the pseudo base station, and sending the location area update request to the de-authentication A base station other than the base station.
  • the authentication succeeds, determining that the target base station is a pseudo base station, preventing communication between the user terminal and the pseudo base station, and reducing the user being subjected to short messages and telephone harassment and fraud. risk.
  • the pseudo base station does not normally perform authentication for the user to camp, so the pseudo base station sends the feedback command for successful authentication regardless of whether the authentication parameter sent by the user terminal is the correct result generated by the authentication algorithm.
  • the randomly generated error authentication parameter different from the identification information of the user identification card of the terminal, the authentication random parameter and the correct authentication parameter generated by the specified authentication algorithm is sent to the target base station, and then the determination can be determined. Whether the base station is a pseudo base station.
  • the method further includes: determining a pre-stored resident update period; determining, after the terminal camps on the cell, the triggering of the location area update when the running time of the terminal is greater than or equal to the resident update period The conditions are established.
  • the terminal when the running time of the terminal is greater than or equal to the resident update period, the terminal is triggered to perform cell reselection, the strength of the terminal network signal is ensured, the fluency of the call is improved, and the user's calling experience is improved.
  • the R criterion using the same-frequency cell reselection lasts at least the Treselection (cell reselection timer duration) time; for the low priority frequency, the cell reselection is performed.
  • the cell time exceeds 1 s, and the s value of the serving cell is less than a preset threshold, and the s value of the low priority frequency cell is greater than a preset threshold, and the duration exceeds Treselection for reselection.
  • a network resident system 200 comprising: obtaining The unit 202 is configured to: when the trigger condition for detecting the location area update is established, acquire the working frequency of the base station in the area where the terminal is located; the sending unit 204 is configured to send the location area update request to the target base station corresponding to the working frequency point; The unit 202 is further configured to: obtain an authentication random parameter fed back by the target base station; the network resident system further includes: a generating unit 206, configured to generate, according to the identifier information of the user identification card of the terminal, the authentication random parameter, and the specified authentication algorithm a first authentication parameter, and generating a second authentication parameter different from the first authentication parameter; the sending unit 204 is further configured to: send the second authentication parameter to the target base station; the network resident system further includes: the determining unit 208 And determining, according to the feedback instruction of the target base station to the second authentication parameter, that the target base station is a pseudo base station or a core network base station.
  • the error authentication parameter is sent to the target base station to obtain the feedback instruction of the target base station, thereby realizing the authentication and accurate camping of the network by the terminal, thereby reducing the possibility that the user terminal camps on the pseudo base station.
  • the utility model reduces the interference of the pseudo base station to the communication service of the user terminal, and improves the security of the user terminal.
  • the process that the user terminal needs to complete in the idle state includes a PLMN (Public Land Mobile Network) selection, a cell selection/reselection, a location registration, etc., and once the resident is completed, the user terminal can read the system information. (such as camping, accessing and reselecting related information, location area information, etc.), reading paging information, and initiating a connection establishment process.
  • PLMN Public Land Mobile Network
  • the method for generating the first authentication parameter is that the terminal acquires the authentication random parameter from the network and the specified authentication algorithm according to the identification information of the Subscriber Identity Module (taken from the base station and the SIM card of the core network) Communication protocol). However, before accessing the network, the terminal generates a second authentication parameter different from the first authentication parameter, that is, the second authentication parameter is an error parameter that cannot be recognized by the core network base station. If the target base station still receives the error parameter and the authentication result of the terminal is still correct, the terminal can determine that the target base station is a pseudo base station according to the determination. In addition, if the authentication result of the target base station is an error, the target base station may be a core network base station, and the terminal may continue to request to camp on the core network base station by using the first authentication parameter, thereby implementing service communication.
  • the determining unit 208 is further configured to: when the acquiring the feedback instruction is an authentication failure instruction, determining that the target base station is a core network base station; and the sending unit 204 is further configured to: send the first authentication parameter to the Core network base station for base station base station based on authentication random parameters and The first authentication parameter determines whether the terminal has the resident right.
  • the network resident system further includes: a selecting unit 210, configured to select, according to the channel quality of the cell of the core network base station, after acquiring the authentication success instruction sent by the core network base station The community that stays.
  • the acquisition of the feedback instruction of the target base station is an authentication failure, determining that the target base station is a non-pseudo base station, and obtaining the resident right by sending the correct authentication parameter to the target base station, thereby realizing the network of the terminal in the core network base station. Resident ensures the security of the terminal network and the smoothness of communication.
  • the base station is further determined according to the cell reselection.
  • the cell selection follows the C1 criterion, that is, the C1 value of the cell selection C1>0 is allowed to stay:
  • C1 represents a cell selection judgment criterion
  • RLA_C represents an average received signal level value of the measurement cell
  • RXLEV_ACCESS_MIN represents a terminal minimum access power level allowed by the network.
  • MS_TXPWR_MAX_CCH characterizes the maximum transmit power level of the terminal allowed by the network.
  • P characterizes the maximum RF transmit power of the terminal.
  • the method further includes: a detecting unit 212, configured to: after the terminal camps on the cell of the core network base station, detect whether the terminal moves to a region value other than the cell of the core network base station; and the determining unit 214 is configured to: When it is detected that the terminal moves to an area other than the cell of the core network base station, the trigger condition for determining the location area update is established.
  • the terminal when detecting that the position change of the terminal is greater than or equal to the preset position change value, the terminal is triggered to perform cell reselection, thereby ensuring the strength of the terminal network signal, improving the fluency of the call, and improving the user's call experience.
  • the purpose of cell reselection is to select a cell that belongs to the best signal in the PLMN to camp.
  • the quality of the serving cell that the terminal camps on will decrease due to the increase of the distance.
  • the threshold that is, the serving cell C2 ⁇ neighbor C2 and continues to be less than 5 s, cell reselection will be triggered.
  • the determining unit 208 is further configured to: When the feed command is an authentication success command, the target base station is determined to be a pseudo base station; the sending unit 204 is further configured to: determine a working frequency point of the pseudo base station, and send the location area update request to a base station other than the pseudo base station.
  • the authentication succeeds, determining that the target base station is a pseudo base station, preventing communication between the user terminal and the pseudo base station, and reducing the user being subjected to short messages and telephone harassment and fraud. risk.
  • the pseudo base station does not normally perform authentication for the user to camp, so the pseudo base station sends the feedback command for successful authentication regardless of whether the authentication parameter sent by the user terminal is the correct result generated by the authentication algorithm.
  • the randomly generated error authentication parameter different from the identification information of the user identification card of the terminal, the authentication random parameter and the correct authentication parameter generated by the specified authentication algorithm is sent to the target base station, and then the determination can be determined. Whether the base station is a pseudo base station.
  • the determining unit 214 is further configured to: determine a pre-stored resident update period; the determining unit 214 is further configured to: after the terminal camps on the cell, the running time of the terminal is greater than or equal to the resident When the update period is left, the trigger condition for determining the location area update is established.
  • the terminal when the running time of the terminal is greater than or equal to the resident update period, the terminal is triggered to perform cell reselection, the strength of the terminal network signal is ensured, the fluency of the call is improved, and the user's calling experience is improved.
  • the R criterion using the same-frequency cell reselection lasts at least the Treselection (cell reselection timer duration) time; for the low priority frequency, the cell reselection is performed.
  • the cell time exceeds 1 s, and the s value of the serving cell is less than a preset threshold, and the s value of the low priority frequency cell is greater than a preset threshold, and the duration exceeds Treselection for reselection.
  • FIG. 3 shows a schematic block diagram of a terminal in accordance with an embodiment of the present invention.
  • a terminal according to an embodiment of the present invention includes a communication bus 302, an input device 303, an output device 304, a memory 305, and a processor 301, wherein:
  • the communication bus 302 is configured to implement connection communication between the input device 303, the output device 304, the memory 305, and the processor 301;
  • the input device 303 is configured to obtain a feedback instruction of the target base station to the second authentication parameter.
  • the output device 304 is configured to send a location area update request, and a second authentication parameter
  • a program code is stored in the memory 305, and the terminal calls the memory 305
  • the program code stored in it to do the following:
  • the processor 301 acquires a working frequency point of the base station in the area where the terminal is located when the trigger condition for detecting the location area update is established;
  • the output device 304 sends a location area update request to the target base station corresponding to the working frequency point;
  • the processor 301 acquires an authentication random parameter fed back by the target base station
  • the processor 301 generates a first authentication parameter according to the identifier information of the user identity card of the terminal, the authentication random parameter, and the specified authentication algorithm, and generates a second different from the first authentication parameter.
  • the output device 304 sends the second authentication parameter to the target base station
  • the processor 301 determines that the target base station is a pseudo base station or a core network base station according to the feedback instruction of the target base station to the second authentication parameter.
  • the processor 301 determines that the target base station is a pseudo base station or a core network base station according to the feedback instruction of the target base station to the second authentication parameter, and specifically includes the following steps:
  • the processor 301 determines that the target base station is a core network base station when acquiring the feedback instruction as an authentication failure instruction;
  • the output device 304 sends the first authentication parameter to the core network base station, so that the core network base station determines whether the terminal has a resident according to the authentication random parameter and the first authentication parameter. Leave permission
  • the processor 301 selects a resident cell according to the channel quality of the cell of the core network base station.
  • it also includes:
  • the processor 301 After the terminal camps on the cell of the core network base station, the processor 301 detects whether the terminal moves to an area other than the cell of the core network base station;
  • the processor 301 determines that the trigger condition of the location area update is established when detecting that the terminal moves to an area other than the cell of the core network base station.
  • it also includes:
  • the processor 301 determines that the target base station is a pseudo base station
  • the processor 301 determines a working frequency point of the pseudo base station, and sends a location area update request to a base station other than the pseudo base station.
  • it also includes:
  • the processor 301 determines a pre-stored resident update period
  • the processor 301 determines that the trigger condition of the location area update is established after the terminal camps on the cell, when the running time of the terminal is greater than or equal to the resident update period.
  • FIGS. 4 and 5 show schematic diagrams of a network camping scheme in accordance with an embodiment of the present invention.
  • the triggering terminal when the change of the terminal location is greater than or equal to the preset location change, or when the running time of the terminal is greater than or equal to the camping update period, the triggering terminal performs cell reselection, and the cell reselection process sends the cell reselection process to the target base station 2.
  • the first authentication parameter is generated according to the identification information of the user identification card of the terminal, the authentication random parameter, and the specified authentication algorithm. In different network standards, the specified authentication algorithm is also different.
  • Embodiment 1 is a diagrammatic representation of Embodiment 1:
  • a mobile subscriber directory number (MDN, Mobile Directory Number) is a number dialed when a calling subscriber calls a mobile subscriber.
  • IMSI International Mobile Subscriber Identification
  • the number of a mobile subscriber is CDMA (Code Division Multiple Access) network 2G phase.
  • the CAVE algorithm is used to enter the IMSI, ESN (UIM ID), and SSD-A ( Share the encrypted data) and RAND (random data) and calculate the AUTHR (calculation result).
  • the terminal sends registration signaling, including authentication data: RAND, AUTHR.
  • the CAVE algorithm is a Cellular Authentication Voice Encryption algorithm, which is an authentication and encryption algorithm authorized by the CDMA network
  • the A-KEY is The authentication key issued to a CDMA terminal.
  • the network After receiving the authentication signaling, the network obtains the AUTHR through the CAVE algorithm using the parameters IMSI, ESN, SSD-A (shared encrypted data) and the same RAND (random data), and then The AUTHR calculated by the terminal is compared. If they are the same, the authentication is successful.
  • Embodiment 2 is a diagrammatic representation of Embodiment 1:
  • 1xEV-DO Evolution Data only: CDMA2000 evolution first phase
  • 1xEV-DV Evolution Data and Voice: CDMA2000 evolution second phase
  • CHAP Chip Transfer Protocol
  • MD5 Message Digest 5
  • Embodiment 3 is a diagrammatic representation of Embodiment 3
  • the authentication vector After entering the LTE (Long Term Evolution) 4G era, the authentication vector includes RAND (a 128-bit random number), XERS (a 64-bit expected response), AUTH (authentication token), and KASME (access security).
  • RAND a 128-bit random number
  • XERS a 64-bit expected response
  • AUTH authentication token
  • KASME access security
  • the K value of the managed entity is implemented using the Milesage algorithm based on AES-128 cyclic shift + XOR.
  • Figure 6 shows a schematic flow diagram of a network camping scheme in accordance with an embodiment of the present invention.
  • Step 602 After the terminal is powered on, searching for the working frequency of the base station; step 604, sending the location area update request to the target base station; step 606, acquiring the authentication random parameter fed back by the target base station; and step 608, identifying the card according to the user identity of the terminal
  • the identification information, the authentication random parameter, and the specified authentication algorithm generate a first authentication parameter, and generate a second authentication parameter different from the first authentication parameter;
  • Step 610 send the second authentication parameter to the target base station;
  • Step 612 And determining whether the authentication is successful, if yes, executing step 622; if not, executing step 614; step 614, the target base station is a core network base station; step 616, transmitting the first authentication parameter to the core network base station; Selecting the camped cell, and periodically measuring the serving cell and the area signal strength, and calculating the cell reselection criterion;
  • Step 620 after the cell reselection criterion is met, the terminal forcibly performs the periodic location area update
  • the target is obtained by transmitting the wrong authentication parameter to the target base station.
  • the feedback instruction of the base station realizes the authentication and accurate reservation of the network by the terminal, reduces the possibility that the user terminal camps on the pseudo base station, reduces the interference of the pseudo base station to the communication service of the user terminal, and improves the use of the user terminal. Security.
  • the present invention proposes a new network resident solution, which will pass the wrong After the authentication parameter is sent to the target base station, the feedback instruction of the target base station is obtained, thereby realizing the authentication and accurate camping of the network by the terminal, reducing the possibility that the user terminal camps on the pseudo base station, and reducing the pseudo base station to the user terminal.
  • the interference of the communication service improves the security of the use of the user terminal.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明提供了一种网络驻留方法、网络驻留系统和终端,其中,网络驻留方法包括:在检测到位置区更新的触发条件成立时,获取终端所在区域的基站的工作频点;将位置区更新请求发送至工作频点对应的目标基站;获取目标基站反馈的鉴权随机参数;根据终端的用户身份识别卡的标识信息、鉴权随机参数和指定鉴权算法生成第一鉴权参数,并生成与第一鉴权参数不同第二鉴权参数;将第二鉴权参数发送至目标基站;根据目标基站对第二鉴权参数的反馈指令,判断目标基站是伪基站或核心网基站。通过本发明技术方案,减少了用户终端驻留伪基站的可能性,降低了伪基站对用户终端的通信业务的干扰,提升了用户终端使用的安全性。

Description

网络驻留方法、网络驻留系统和终端
本申请要求于2016年01月29日提交中国专利局,申请号为201610064472.2、发明名称为“网络驻留方法、网络驻留系统和终端”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及通信技术领域,具体而言,涉及一种网络驻留方法、一种网络驻留系统和一种终端。
背景技术
随着通信技术的发展,伪基站设备运行时,通常以高于核心网基站的功率运行,进而误导用户终端驻留于伪基站网络,导致用户无法正常使用运营商提供的服务,伪基站强行向用户终端发送诈骗、广告推销等短信息,不仅影响了用户的正常通讯,甚至会给用户造成财务损失。
在相关技术中,终端都是按照网络协议规范进行邻区测量和小区重选判断,并且由于网络的鉴权属于单向鉴权,而终端不会鉴权网络,这样就导致终端无法判断网络的真实性。
因此,如何设计一种新的小区驻留方案,以实现终端对网络的甄别和准确驻留成为亟待解决的技术问题。
发明内容
本发明正是基于上述技术问题至少之一,提出了一种新的网络驻留方案,通过将错误的鉴权参数发送至目标基站后得到目标基站的反馈指令,实现了由终端对网络的鉴权甄别和准确驻留,减少了用户终端驻留伪基站的可能性,降低了伪基站对用户终端的通信业务的干扰,提升了用户终端使用的安全性。
有鉴于此,本发明提出了一种网络驻留方法,包括:在检测到位置区更新的触发条件成立时,获取终端所在区域的基站的工作频点;将位置区 更新请求发送至工作频点对应的目标基站;获取目标基站反馈的鉴权随机参数;根据终端的用户身份识别卡的标识信息、鉴权随机参数和指定鉴权算法生成第一鉴权参数,并生成与第一鉴权参数不同的第二鉴权参数;将第二鉴权参数发送至目标基站;根据目标基站对第二鉴权参数的反馈指令,判断目标基站是伪基站或核心网基站。
在该技术方案中,通过将错误的鉴权参数发送至目标基站后得到目标基站的反馈指令,实现了由终端对网络的鉴权甄别和准确驻留,减少了用户终端驻留伪基站的可能性,降低了伪基站对用户终端的通信业务的干扰,提升了用户终端使用的安全性。
具体地,空闲状态下的用户终端需要完成的过程包括PLMN(Public Land Mobile Network,公共陆地移动网络)选择,小区选择/重选、位置登记等,一旦完成驻留,用户终端可以读取系统信息(如驻留、接入和重选相关信息、位置区域信息等),读取寻呼信息,发起连接建立过程。
其中,第一鉴权参数生成的一种方式是终端根据SIM卡(Subscriber Identity Module)的标识信息、获取来自网络的鉴权随机参数和指定鉴权算法(取自于核心网基站和SIM卡采用的通信协议)。但是,终端在接入网络之前,生成与第一鉴权参数不同的第二鉴权参数,也即第二鉴权参数对于核心网基站而言是不能被识别的错误参数。如果目标基站在接收错误参数的前提下,对终端的鉴权结果仍为正确,那终端可以据此判定目标基站为伪基站。另外,如果目标基站的鉴权结果为错误,则此目标基站可能为核心网基站,则终端可以继续通过第一鉴权参数请求驻留于上述核心网基站,从而实现业务通信。
在上述技术方案中,优选地,根据目标基站对第二鉴权参数的反馈指令,判断目标基站是伪基站或核心网基站,具体包括以下步骤:在获取反馈指令为鉴权失败指令时,判定目标基站是核心网基站;将第一鉴权参数发送至核心网基站,以供核心网基站根据鉴权随机参数和第一鉴权参数判断终端是否具有驻留权限;在获取核心网基站发送的鉴权成功指令后,根据核心网基站的小区的信道质量选择驻留的小区。
在该技术方案中,通过获取目标基站的反馈指令为鉴权失败,判定目标基站为非伪基站,通过向目标基站发送正确的鉴权参数获取驻留权限, 实现了终端在核心网基站的网络驻留,保证了终端网络驻留的安全性和通讯的流畅性。
而在终端获取目标基站的反馈指令为鉴权成功时,进一步地根据小区重选准确确定驻留的基站,例如,小区选择遵循C1准则,即小区选择的C1值C1>0时允许驻留:(该专利是正对GSM,所以小区选择判断准则是基于C1,S准则是正对3G而言)
C1=(A-Max(B,0)),其中,Max(B,0)表示取B和0两个数据中的最大值
A=RLA_C-RXLEV_ACCESS_MIN;
B=MS_TXPWR_MAX_CCH-P,
其中,C1表征小区选择判断准则,RLA_C表征测量小区的平均接收信号电平(average of received signal level)值,RXLEV_ACCESS_MIN表征网络允许的终端最小接入功率等级。MS_TXPWR_MAX_CCH表征网络允许的终端最大发射功率等级。P表征终端最大射频发射功率。
在上述技术方案中,优选地,还包括:在终端驻留核心网基站的小区后,检测终端是否移动至核心网基站的小区以外的区域;在检测到终端移动至核心网基站的小区以外的区域时,确定位置区更新的触发条件成立。
在该技术方案中,通过检测终端的位置变化不等于预设位置变化值时,触发终端进行小区重选,保证了终端网络信号的强度,提高了通话的流畅性,提升了用户通话体验。
具体地,小区重选的目的是选择属于这个PLMN中信号最好的小区进行驻留,当终端处于高速移动状态时,终端驻留的服务小区质量会由于距离的增加而降低,当下降到规定的门限值时,即服务小区C2<邻区C2,且持续小于5s以上,将触发小区重选。
在上述任一项技术方案中,优选地,还包括:在获取反馈指令为鉴权成功指令时,判定目标基站是伪基站;确定伪基站的工作频点,将位置区更新请求发送至除伪基站以外的基站。
在该技术方案中,通过获取目标基站的反馈指令为鉴权成功,判定该目标基站为伪基站,防止了用户终端与伪基站之间的通讯,降低了用户遭到短信和电话骚扰以及诈骗的风险。
具体地,伪基站为了让用户驻留,通常不会进行鉴权,因此无论用户终端发送的鉴权参数是否为通过鉴权算法生成的正确结果,伪基站均会将鉴权成功的反馈指令发送至用户终端,因此将随机生成的与根据终端的用户身份识别卡的标识信息、鉴权随机参数和指定鉴权算法生成的正确鉴权参数不同的错误鉴权参数发送至目标基站,即可判定该基站是否为伪基站。
在上述任一项技术方案中,优选地,还包括:确定预存储的驻留更新周期;在终端驻留小区后,终端的运行时间大于或等于驻留更新周期时,确定位置区更新的触发条件成立。
在该技术方案中,通过终端的运行时间大于或等于驻留更新周期,触发终端进行小区重选,保证了终端网络信号的强度,提高了通话的流畅性,提升了用户通话体验。
具体地,对于同等优先级频点/同频,采用同频小区重选的R准则至少持续Treselection(小区重选定时器时长)时间;对于低优先级频率的小区重选,当驻留原小区时间超过1s,且服务小区的s值小于预设的门限,并且低优先级频率小区的s值大于预设的门限,且持续时间超过Treselection,进行重选。
根据本发明第二方面,还提出了一种网络驻留系统,包括:获取单元,用于在检测到位置区更新的触发条件成立时,获取终端所在区域的基站的工作频点;发送单元,用于将位置区更新请求发送至工作频点对应的目标基站;获取单元还用于:获取目标基站反馈的鉴权随机参数;网络驻留系统还包括:生成单元,用于根据终端的用户身份识别卡的标识信息、鉴权随机参数和指定鉴权算法生成第一鉴权参数,并生成与第一鉴权参数不同的第二鉴权参数;发送单元还用于:将第二鉴权参数发送至目标基站;网络驻留系统还包括:判断单元,用于根据目标基站对第二鉴权参数的反馈指令,判断目标基站是伪基站或核心网基站。
在该技术方案中,通过将错误的鉴权参数发送至目标基站后得到目标基站的反馈指令,实现了由终端对网络的鉴权甄别和准确驻留,减少了用户终端驻留伪基站的可能性,降低了伪基站对用户终端的通信业务的干扰, 提升了用户终端使用的安全性。
具体地,空闲状态下的用户终端需要完成的过程包括PLMN(Public Land Mobile Network,公共陆地移动网络)选择,小区选择/重选、位置登记等,一旦完成驻留,用户终端可以读取系统信息(如驻留、接入和重选相关信息、位置区域信息等),读取寻呼信息,发起连接建立过程。
其中,第一鉴权参数生成的一种方式是终端根据SIM卡(Subscriber Identity Module)的标识信息、获取来自网络的鉴权随机参数和指定鉴权算法(取自于核心网基站和SIM卡采用的通信协议)。但是,终端在接入网络之前,生成与第一鉴权参数不同的第二鉴权参数,也即第二鉴权参数对于核心网基站而言是不能被识别的错误参数。如果目标基站在接收错误参数的前提下,对终端的鉴权结果仍为正确,那终端可以据此判定目标基站为伪基站。另外,如果目标基站的鉴权结果为错误,则次目标基站可能为核心网基站,则终端可以继续通过第一鉴权参数请求驻留于上述核心网基站,从而实现业务通信。
在上述技术方案中,优选地,判断单元还用于:在获取反馈指令为鉴权失败指令时,判定目标基站是核心网基站;发送单元还用于:将第一鉴权参数发送至核心网基站,以供核心网基站根据鉴权随机参数和第一鉴权参数判断终端是否具有驻留权限;网络驻留系统还包括:选择单元,用于在获取核心网基站发送的鉴权成功指令后,根据核心网基站的小区的信道质量选择驻留的小区。
在该技术方案中,通过获取目标基站的反馈指令为鉴权失败,判定目标基站为非伪基站,通过向目标基站发送正确的鉴权参数获取驻留权限,实现了终端在核心网基站的网络驻留,保证了终端网络驻留的安全性和通讯的流畅性。
而在终端获取目标基站的反馈指令为鉴权成功时,进一步地根据小区重选准确确定驻留的基站,例如,小区选择遵循C1准则,即小区选择的C1值C1>0时允许驻留:
C1=(A-Max(B,0)),其中,Max(B,0)表示取B和0两个数据中的最大值
A=RLA_C-RXLEV_ACCESS_MIN;
B=MS_TXPWR_MAX_CCH-P,
其中,C1表征小区选择判断准则,RLA_C表征测量小区的平均接收信号电平(average of received signal level)值,RXLEV_ACCESS_MIN表征网络允许的终端最小接入功率等级。MS_TXPWR_MAX_CCH表征网络允许的终端最大发射功率等级。P表征终端最大射频发射功率。
在上述技术方案中,优选地,还包括:检测单元,用于在终端驻留核心网基站的小区后,检测终端是否移动至所述核心网基站的小区以外的区域;确定单元,用于在检测到终端移动至核心网基站的小区以外的区域时,确定位置区更新的触发条件成立。
在该技术方案中,通过检测终端的位置变化不等于预设位置变化值时,触发终端进行小区重选,保证了终端网络信号的强度,提高了通话的流畅性,提升了用户通话体验。
具体地,小区重选的目的是选择属于这个PLMN中信号最好的小区进行驻留,当终端处于高速移动状态时,终端驻留的服务小区质量会由于距离的增加而降低,当下降到规定的门限值时,即服务小区C2<邻区C2,且持续小于5s以上,将触发小区重选。
在上述任一项技术方案中,优选地,判断单元还用于:在获取反馈指令为鉴权成功指令时,判定目标基站是伪基站;发送单元还用于:确定伪基站的工作频点,将位置区更新请求发送至除伪基站以外的基站。
在该技术方案中,通过获取目标基站的反馈指令为鉴权成功,判定该目标基站为伪基站,防止了用户终端与伪基站之间的通讯,降低了用户遭到短信和电话骚扰以及诈骗的风险。
具体地,伪基站为了让用户驻留,通常不会进行鉴权,因此无论用户终端发送的鉴权参数是否为通过鉴权算法生成的正确结果,伪基站均会将鉴权成功的反馈指令发送至用户终端,因此将随机生成的与根据终端的用户身份识别卡的标识信息、鉴权随机参数和指定鉴权算法生成的正确鉴权参数不同的错误鉴权参数发送至目标基站,即可判定该基站是否为伪基站。
在上述任一项技术方案中,优选地,确定单元还用于:确定预存储的驻留更新周期;确定单元还用于:在终端驻留小区后,终端的运行时间大于或等于驻留更新周期时,确定位置区更新的触发条件成立。
在该技术方案中,通过终端的运行时间大于或等于驻留更新周期,触 发终端进行小区重选,保证了终端网络信号的强度,提高了通话的流畅性,提升了用户通话体验。
具体地,对于同等优先级频点/同频,采用同频小区重选的R准则至少持续Treselection(小区重选定时器时长)时间;对于低优先级频率的小区重选,当驻留原小区时间超过1s,且服务小区的s值小于预设的门限,并且低优先级频率小区的s值大于预设的门限,且持续时间超过Treselection,进行重选。
根据本发明第三方面,还提出了一种终端,包括通信总线、输入装置、输出装置、存储器以及处理器,其中:
所述通信总线,用于实现所述输入装置、输出装置、存储器以及处理器之间的连接通信;
所述输入装置,用于获取目标基站对第二鉴权参数的反馈指令;
所述输出装置,用于发送位置区更新请求,以及第二鉴权参数;
所述存储器中存储一组程序代码,且所述终端调用所述存储器中存储的程序代码,用于执行以下操作:
所述处理器在检测到位置区更新的触发条件成立时,获取终端所在区域的基站的工作频点;
所述输出装置将位置区更新请求发送至所述工作频点对应的目标基站;
所述处理器获取所述目标基站反馈的鉴权随机参数;
所述处理器根据所述终端的用户身份识别卡的标识信息、所述鉴权随机参数和指定鉴权算法生成第一鉴权参数,并生成与所述第一鉴权参数不同的第二鉴权参数;
所述输出装置将所述第二鉴权参数发送至所述目标基站;
所述处理器根据所述目标基站对所述第二鉴权参数的反馈指令,判断所述目标基站是伪基站或核心网基站。
可选的,所述处理器根据所述目标基站对所述第二鉴权参数的反馈指令,判断所述目标基站是伪基站或核心网基站,具体包括以下步骤:
所述处理器在获取所述反馈指令为鉴权失败指令时,判定所述目标基站是核心网基站;
所述输出装置将所述第一鉴权参数发送至所述核心网基站,以供所述核心网基站根据所述鉴权随机参数和所述第一鉴权参数判断所述终端是否具有驻留权限;
在所述输入装置获取所述核心网基站发送的鉴权成功指令后,所述处理器根据所述核心网基站的小区的信道质量选择驻留的小区。
可选的,还包括:
所述处理器在所述终端驻留所述核心网基站的小区后,检测所述终端是否移动至所述核心网基站的小区以外的区域;
所述处理器在检测到所述终端移动至所述核心网基站的小区以外的区域时,确定所述位置区更新的触发条件成立。
可选的,还包括:
在所述输入装置获取所述反馈指令为鉴权成功指令时,所述处理器判定所述目标基站是伪基站;
所述处理器确定所述伪基站的工作频点,将位置区更新请求发送至除所述伪基站以外的基站。
可选的,还包括:
所述处理器确定预存储的驻留更新周期;
所述处理器在所述终端驻留小区后,所述终端的运行时间大于或等于所述驻留更新周期时,确定所述位置区更新的触发条件成立。
通过以上技术方案,通过将错误的鉴权参数发送至目标基站后得到目标基站的反馈指令,实现了由终端对网络的鉴权甄别和准确驻留,减少了用户终端驻留伪基站的可能性,降低了伪基站对用户终端的通信业务的干扰,提升了用户终端使用的安全性。
附图说明
图1示出了根据本发明的实施例的网络驻留方法的示意流程图;
图2示出了根据本发明的实施例的网络驻留系统的示意框图;
图3示出了根据本发明的实施例的终端的示意框图;
图4示出了根据本发明的一个实施例的网络驻留方案的示意图;
图5示出了根据本发明的另一个实施例的网络驻留方案的示意图
图6示出了根据本发明的实施例的网络驻留方案的示意流程图。
具体实施方式
为了能够更清楚地理解本发明的上述目的、特征和优点,下面结合附图和具体实施方式对本发明进行进一步的详细描述。需要说明的是,在不冲突的情况下,本申请的实施例及实施例中的特征可以相互组合。
在下面的描述中阐述了很多具体细节以便于充分理解本发明,但是,本发明还可以采用第三方不同于在此描述的第三方方式来实施,因此,本发明的保护范围并不受下面公开的具体实施例的限制。
图1示出了根据本发明的实施例的网络驻留方法的示意流程图。
如图1所示,根据本发明的实施例的网络驻留方法,包括:步骤102,在检测到位置区更新的触发条件成立时,获取终端所在区域的基站的工作频点;步骤104,将位置区更新请求发送至工作频点对应的目标基站;步骤106,获取目标基站反馈的鉴权随机参数;步骤108,根据终端的用户身份识别卡的标识信息、鉴权随机参数和指定鉴权算法生成第一鉴权参数,并生成与第一鉴权参数不同的第二鉴权参数;步骤110,将第二鉴权参数发送至目标基站;步骤112,根据目标基站对第二鉴权参数的反馈指令,判断目标基站是伪基站或核心网基站。
在该技术方案中,通过将错误的鉴权参数发送至目标基站后得到目标基站的反馈指令,实现了由终端对网络的鉴权甄别和准确驻留,减少了用户终端驻留伪基站的可能性,降低了伪基站对用户终端的通信业务的干扰,提升了用户终端使用的安全性。
具体地,空闲状态下的用户终端需要完成的过程包括PLMN(Public Land Mobile Network,公共陆地移动网络)选择,小区选择/重选、位置登记等,一旦完成驻留,用户终端可以读取系统信息(如驻留、接入和重选相关信息、位置区域信息等),读取寻呼信息,发起连接建立过程。
其中,第一鉴权参数生成的一种方式是终端根据SIM卡(Subscriber Identity Module)的标识信息、获取来自网络的鉴权随机参数和指定鉴权算法(取自于核心网基站和SIM卡采用的通信协议)。但是,终端在接入网络之前,生成与第一鉴权参数不同的第二鉴权参数,也即第二鉴权参数对 于核心网基站而言是不能被识别的错误参数。如果目标基站在接收错误参数的前提下,对终端的鉴权结果仍为正确,那终端可以据此判定目标基站为伪基站。另外,如果目标基站的鉴权结果为错误,则此目标基站可能为核心网基站,则终端可以继续通过第一鉴权参数请求驻留于上述核心网基站,从而实现业务通信。
在上述技术方案中,优选地,根据目标基站对第二鉴权参数的反馈指令,判断目标基站是伪基站或核心网基站,具体包括以下步骤:在获取反馈指令为鉴权失败指令时,判定目标基站是核心网基站;将第一鉴权参数发送至核心网基站,以供核心网基站根据鉴权随机参数和第一鉴权参数判断终端是否具有驻留权限;在获取核心网基站发送的鉴权成功指令后,根据核心网基站的小区的信道质量选择驻留的小区。
在该技术方案中,通过获取目标基站的反馈指令为鉴权失败,判定目标基站为非伪基站,通过向目标基站发送正确的鉴权参数获取驻留权限,实现了终端在核心网基站的网络驻留,保证了终端网络驻留的安全性和通讯的流畅性。
而在终端获取目标基站的反馈指令为鉴权成功时,进一步地根据小区重选准确确定驻留的基站,
例如,小区选择遵循C1准则,即小区选择的C1值C1>0时允许驻留:
C1=(A-Max(B,0)),其中,Max(B,0)表示取B和0两个数据中的最大值
A=RLA_C-RXLEV_ACCESS_MIN;
B=MS_TXPWR_MAX_CCH-P,
其中,C1表征小区选择判断准则,RLA_C表征测量小区的平均接收信号电平(average of received signal level)值,RXLEV_ACCESS_MIN表征网络允许的终端最小接入功率等级。MS_TXPWR_MAX_CCH表征网络允许的终端最大发射功率等级。P表征终端最大射频发射功率。
在上述技术方案中,优选地,还包括:在终端驻留核心网基站的小区后,检测终端是否移动至核心网基站的小区以外的区域;在检测到终端移动至核心网基站的小区以外的区域时,确定位置区更新的触发条件成立。
在该技术方案中,通过检测终端的位置变化大于或等于预设位置变化 值时,触发终端进行小区重选,保证了终端网络信号的强度,提高了通话的流畅性,提升了用户通话体验。
具体地,小区重选的目的是选择属于这个PLMN中信号最好的小区进行驻留,当终端处于高速移动状态时,终端驻留的服务小区质量会由于距离的增加而降低,当下降到规定的门限值时,即服务小区C2<邻区C2,且持续小于5s以上,将触发小区重选。
在上述任一项技术方案中,优选地,还包括:在获取反馈指令为鉴权成功指令时,判定目标基站是伪基站;确定伪基站的工作频点,将位置区更新请求发送至除伪基站以外的基站。
在该技术方案中,通过获取目标基站的反馈指令为鉴权成功,判定该目标基站为伪基站,防止了用户终端与伪基站之间的通讯,降低了用户遭到短信和电话骚扰以及诈骗的风险。
具体地,伪基站为了让用户驻留,通常不会进行鉴权,因此无论用户终端发送的鉴权参数是否为通过鉴权算法生成的正确结果,伪基站均会将鉴权成功的反馈指令发送至用户终端,因此将随机生成的与根据终端的用户身份识别卡的标识信息、鉴权随机参数和指定鉴权算法生成的正确鉴权参数不同的错误鉴权参数发送至目标基站,即可判定该基站是否为伪基站。
在上述任一项技术方案中,优选地,还包括:确定预存储的驻留更新周期;在终端驻留小区后,终端的运行时间大于或等于驻留更新周期时,确定位置区更新的触发条件成立。
在该技术方案中,通过终端的运行时间大于或等于驻留更新周期,触发终端进行小区重选,保证了终端网络信号的强度,提高了通话的流畅性,提升了用户通话体验。
具体地,对于同等优先级频点/同频,采用同频小区重选的R准则至少持续Treselection(小区重选定时器时长)时间;对于低优先级频率的小区重选,当驻留原小区时间超过1s,且服务小区的s值小于预设的门限,并且低优先级频率小区的s值大于预设的门限,且持续时间超过Treselection,进行重选。
根据本发明第二方面,还提出了一种网络驻留系统200,包括:获取 单元202,用于在检测到位置区更新的触发条件成立时,获取终端所在区域的基站的工作频点;发送单元204,用于将位置区更新请求发送至工作频点对应的目标基站;获取单元202还用于:获取目标基站反馈的鉴权随机参数;网络驻留系统还包括:生成单元206,用于根据终端的用户身份识别卡的标识信息、鉴权随机参数和指定鉴权算法生成第一鉴权参数,并生成与第一鉴权参数不同的第二鉴权参数;发送单元204还用于:将第二鉴权参数发送至目标基站;网络驻留系统还包括:判断单元208,用于根据目标基站对第二鉴权参数的反馈指令,判断目标基站是伪基站或核心网基站。
在该技术方案中,通过将错误的鉴权参数发送至目标基站后得到目标基站的反馈指令,实现了由终端对网络的鉴权甄别和准确驻留,减少了用户终端驻留伪基站的可能性,降低了伪基站对用户终端的通信业务的干扰,提升了用户终端使用的安全性。
具体地,空闲状态下的用户终端需要完成的过程包括PLMN(Public Land Mobile Network,公共陆地移动网络)选择,小区选择/重选、位置登记等,一旦完成驻留,用户终端可以读取系统信息(如驻留、接入和重选相关信息、位置区域信息等),读取寻呼信息,发起连接建立过程。
其中,第一鉴权参数生成的一种方式是终端根据SIM卡(Subscriber Identity Module)的标识信息、获取来自网络的鉴权随机参数和指定鉴权算法(取自于核心网基站和SIM卡采用的通信协议)。但是,终端在接入网络之前,生成与第一鉴权参数不同的第二鉴权参数,也即第二鉴权参数对于核心网基站而言是不能被识别的错误参数。如果目标基站在接收错误参数的前提下,对终端的鉴权结果仍为正确,那终端可以据此判定目标基站为伪基站。另外,如果目标基站的鉴权结果为错误,则此目标基站可能为核心网基站,则终端可以继续通过第一鉴权参数请求驻留于上述核心网基站,从而实现业务通信。
在上述技术方案中,优选地,判断单元208还用于:在获取反馈指令为鉴权失败指令时,判定目标基站是核心网基站;发送单元204还用于:将第一鉴权参数发送至核心网基站,以供核心网基站根据鉴权随机参数和 第一鉴权参数判断终端是否具有驻留权限;网络驻留系统还包括:选择单元210,用于在获取核心网基站发送的鉴权成功指令后,根据核心网基站的小区的信道质量选择驻留的小区。
在该技术方案中,通过获取目标基站的反馈指令为鉴权失败,判定目标基站为非伪基站,通过向目标基站发送正确的鉴权参数获取驻留权限,实现了终端在核心网基站的网络驻留,保证了终端网络驻留的安全性和通讯的流畅性。
而在终端获取目标基站的反馈指令为鉴权成功时,进一步地根据小区重选准确确定驻留的基站,例如,小区选择遵循C1准则,即小区选择的C1值C1>0时允许驻留:
C1=(A-Max(B,0)),其中,Max(B,0)表示取B和0两个数据中的最大值
A=RLA_C-RXLEV_ACCESS_MIN;
B=MS_TXPWR_MAX_CCH-P,
其中,C1表征小区选择判断准则,RLA_C表征测量小区的平均接收信号电平(average of received signal level)值,RXLEV_ACCESS_MIN表征网络允许的终端最小接入功率等级。MS_TXPWR_MAX_CCH表征网络允许的终端最大发射功率等级。P表征终端最大射频发射功率。
在上述技术方案中,优选地,还包括:检测单元212,用于在终端驻留核心网基站的小区后,检测终端是否移动至核心网基站的小区以外的区域值;确定单元214,用于在检测到终端移动至核心网基站的小区以外的区域时,确定位置区更新的触发条件成立。
在该技术方案中,通过检测终端的位置变化大于或等于预设位置变化值时,触发终端进行小区重选,保证了终端网络信号的强度,提高了通话的流畅性,提升了用户通话体验。
具体地,小区重选的目的是选择属于这个PLMN中信号最好的小区进行驻留,当终端处于高速移动状态时,终端驻留的服务小区质量会由于距离的增加而降低,当下降到规定的门限值时,即服务小区C2<邻区C2,且持续小于5s以上,将触发小区重选。
在上述任一项技术方案中,优选地,判断单元208还用于:在获取反 馈指令为鉴权成功指令时,判定目标基站是伪基站;发送单元204还用于:确定伪基站的工作频点,将位置区更新请求发送至除伪基站以外的基站。
在该技术方案中,通过获取目标基站的反馈指令为鉴权成功,判定该目标基站为伪基站,防止了用户终端与伪基站之间的通讯,降低了用户遭到短信和电话骚扰以及诈骗的风险。
具体地,伪基站为了让用户驻留,通常不会进行鉴权,因此无论用户终端发送的鉴权参数是否为通过鉴权算法生成的正确结果,伪基站均会将鉴权成功的反馈指令发送至用户终端,因此将随机生成的与根据终端的用户身份识别卡的标识信息、鉴权随机参数和指定鉴权算法生成的正确鉴权参数不同的错误鉴权参数发送至目标基站,即可判定该基站是否为伪基站。
在上述任一项技术方案中,优选地,确定单元214还用于:确定预存储的驻留更新周期;确定单元214还用于:在终端驻留小区后,终端的运行时间大于或等于驻留更新周期时,确定位置区更新的触发条件成立。
在该技术方案中,通过终端的运行时间大于或等于驻留更新周期,触发终端进行小区重选,保证了终端网络信号的强度,提高了通话的流畅性,提升了用户通话体验。
具体地,对于同等优先级频点/同频,采用同频小区重选的R准则至少持续Treselection(小区重选定时器时长)时间;对于低优先级频率的小区重选,当驻留原小区时间超过1s,且服务小区的s值小于预设的门限,并且低优先级频率小区的s值大于预设的门限,且持续时间超过Treselection,进行重选。
图3示出了根据本发明的实施例的终端的示意框图。如图3所示,根据本发明的实施例的终端,包括通信总线302、输入装置303、输出装置304、存储器305以及处理器301,其中:
所述通信总线302,用于实现所述输入装置303、输出装置304、存储器305以及处理器301之间的连接通信;
所述输入装置303,用于获取目标基站对第二鉴权参数的反馈指令;
所述输出装置304,用于发送位置区更新请求,以及第二鉴权参数;
所述存储器305中存储一组程序代码,且所述终端调用所述存储器305 中存储的程序代码,用于执行以下操作:
所述处理器301在检测到位置区更新的触发条件成立时,获取终端所在区域的基站的工作频点;
所述输出装置304将位置区更新请求发送至所述工作频点对应的目标基站;
所述处理器301获取所述目标基站反馈的鉴权随机参数;
所述处理器301根据所述终端的用户身份识别卡的标识信息、所述鉴权随机参数和指定鉴权算法生成第一鉴权参数,并生成与所述第一鉴权参数不同的第二鉴权参数;
所述输出装置304将所述第二鉴权参数发送至所述目标基站;
所述处理器301根据所述目标基站对所述第二鉴权参数的反馈指令,判断所述目标基站是伪基站或核心网基站。
可选的,所述处理器301根据所述目标基站对所述第二鉴权参数的反馈指令,判断所述目标基站是伪基站或核心网基站,具体包括以下步骤:
所述处理器301在获取所述反馈指令为鉴权失败指令时,判定所述目标基站是核心网基站;
所述输出装置304将所述第一鉴权参数发送至所述核心网基站,以供所述核心网基站根据所述鉴权随机参数和所述第一鉴权参数判断所述终端是否具有驻留权限;
在所述输入装置303获取所述核心网基站发送的鉴权成功指令后,所述处理器301根据所述核心网基站的小区的信道质量选择驻留的小区。
可选的,还包括:
所述处理器301在所述终端驻留所述核心网基站的小区后,检测所述终端是否移动至所述核心网基站的小区以外的区域;
所述处理器301在检测到所述终端移动至所述核心网基站的小区以外的区域时,确定所述位置区更新的触发条件成立。
可选的,还包括:
在所述输入装置303获取所述反馈指令为鉴权成功指令时,所述处理器301判定所述目标基站是伪基站;
所述处理器301确定所述伪基站的工作频点,将位置区更新请求发送至除所述伪基站以外的基站。
可选的,还包括:
所述处理器301确定预存储的驻留更新周期;
所述处理器301在所述终端驻留小区后,所述终端的运行时间大于或等于所述驻留更新周期时,确定所述位置区更新的触发条件成立。
图4和图5示出了根据本发明的实施例的网络驻留方案的示意图。
如图4所示,当终端开机后,需要选择一个合适的网络小区驻留,终端根据工作频点确定目标基站1和目标基站2等,此时为了鉴别目标基站1和目标基站2是否是伪基站,向目标基站1和目标基站2发送不同于正确的第一鉴权参数的第二鉴权参数,由于伪基站为了让终端驻留,不进行鉴权就会向终端发送鉴权成功指令,当用户接收到错误的第二鉴权参数鉴权成功的反馈指令时,则可判定目标基站1为伪基站,目标基站2是核心网基站,如图5所示,终端向目标基站2发送正确的第一鉴权参数,鉴权成功后即可驻留在目标基站1的网络。
如图5所示,当终端位置的变化大于或等于预设位置变化时,或终端的运行时间大于或等于驻留更新周期时,触发终端进行小区重选,小区重选过程向目标基站2发送第一鉴权参数,第一鉴权参数根据终端的用户身份识别卡的标识信息、鉴权随机参数和指定鉴权算法生成,在不同网络制式下,指定鉴权算法也不同。
实施例一:
在2G网络中,移动用户号码簿号码(MDN,Mobile Directory Number)为主叫用户呼叫一个移动用户时所拨的号码,IMSI(International Mobile Subscriber Identification,国际移动台标识)是在移动网中唯一识别一个移动用户的号码,以CDMA(Code Division Multiple Access:码分多址通信技术)网络2G阶段为例,当终端开机登记时使用CAVE算法,入参IMSI、ESN(UIM ID)、SSD-A(共享加密数据)和RAND(随机数据),计算得到AUTHR(计算结果)。终端发送登记信令,包括鉴权数据:RAND、AUTHR。其中,CAVE算法是蜂窝鉴权和语音加密(Cellular Authentication Voice Encryption)算法,是CDMA网络授权的鉴权加密算法,A-KEY是 发布给一个CDMA终端的鉴权密钥,网络收到鉴权信令后,使用参数IMSI、ESN、SSD-A(共享加密数据)和同一个RAND(随机数据)通过CAVE算法得到AUTHR,然后与终端计算得到的AUTHR进行比较,如果相同,则鉴权成功。
实施例二:
进入3G演进阶段后,3G演进时存在两条不同的技术路线,一条是1xEV-DO(Evolution Data only:CDMA2000演进第一阶段),一条是1xEV-DV(Evolution Data and Voice:CDMA2000演进第二阶段),1xEV-DO的接入鉴权方式采用的是基于MD5(Message Digest 5)算法的CHAP(Challenge Handshake Authentication Protocol)鉴权,1xEV-DO网络中增加了新的鉴权设备支持MD5算法。
实施例三:
进入LTE(Long Term Evolution,长期演进)4G时代后,鉴权向量包括RAND(一个128bit的随机数),XERS(一个64位的期望响应),AUTH(鉴权令牌),KASME(接入安全管理实体的K值),使用基于AES-128循环移位+异或的Milenage算法实现鉴权过程。
图6示出了根据本发明的实施例的网络驻留方案的示意流程图。
如图6所示,根据本发明的实施例的网络驻留方案:
步骤602,终端开机后搜索基站的工作频点;步骤604,将位置区更新请求发送至目标基站;步骤606,获取目标基站反馈的鉴权随机参数;步骤608,根据终端的用户身份识别卡的标识信息、鉴权随机参数和指定鉴权算法生成第一鉴权参数,并生成与第一鉴权参数不同第二鉴权参数;步骤610,将第二鉴权参数发送至目标基站;步骤612,判断鉴权是否成功,若是,则执行步骤622,若否,则执行步骤614;步骤614,目标基站是核心网基站;步骤616,将第一鉴权参数发送至核心网基站;步骤618,选择驻留的小区,并且周期性测量服务小区和临区信号强度,计算小区重选准则;步骤620,满足小区重选准则后,终端强制执行周期性位置区更新;步骤622,目标基站为伪基站;步骤624,将位置区更新请求发送至除伪基站以外的基站,并循环执行步骤606。
在该技术方案中,通过将错误的鉴权参数发送至目标基站后得到目标 基站的反馈指令,实现了由终端对网络的鉴权甄别和准确驻留,减少了用户终端驻留伪基站的可能性,降低了伪基站对用户终端的通信业务的干扰,提升了用户终端使用的安全性。
以上结合附图详细说明了本发明的技术方案,考虑到相关技术中如何实现终端对网络的甄别和准确驻留的技术问题,本发明提出了一种新的网络驻留方案,通过将错误的鉴权参数发送至目标基站后得到目标基站的反馈指令,实现了由终端对网络的鉴权甄别和准确驻留,减少了用户终端驻留伪基站的可能性,降低了伪基站对用户终端的通信业务的干扰,提升了用户终端使用的安全性。
以上所述仅为本发明的优选实施例而已,并不用于限制本发明,对于本领域的技术人员来说,本发明可以有各种更改和变化。凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。

Claims (15)

  1. 一种网络驻留方法,适用于终端,其特征在于,包括:
    在检测到位置区更新的触发条件成立时,获取终端所在区域的基站的工作频点;
    将位置区更新请求发送至所述工作频点对应的目标基站;
    获取所述目标基站反馈的鉴权随机参数;
    根据所述终端的用户身份识别卡的标识信息、所述鉴权随机参数和指定鉴权算法生成第一鉴权参数,并生成与所述第一鉴权参数不同的第二鉴权参数;
    将所述第二鉴权参数发送至所述目标基站;
    根据所述目标基站对所述第二鉴权参数的反馈指令,判断所述目标基站是伪基站或核心网基站。
  2. 根据权利要求1所述的网络驻留方法,其特征在于,根据所述目标基站对所述第二鉴权参数的反馈指令,判断所述目标基站是伪基站或核心网基站,具体包括以下步骤:
    在获取所述反馈指令为鉴权失败指令时,判定所述目标基站是核心网基站;
    将所述第一鉴权参数发送至所述核心网基站,以供所述核心网基站根据所述鉴权随机参数和所述第一鉴权参数判断所述终端是否具有驻留权限;
    在获取所述核心网基站发送的鉴权成功指令后,根据所述核心网基站的小区的信道质量选择驻留的小区。
  3. 根据权利要求2所述的网络驻留方法,其特征在于,还包括:
    在所述终端驻留所述核心网基站的小区后,检测所述终端是否移动至所述核心网基站的小区以外的区域;
    在检测到所述终端移动至所述核心网基站的小区以外的区域时,确定所述位置区更新的触发条件成立。
  4. 根据权利要求1所述的网络驻留方法,其特征在于,还包括:
    在获取所述反馈指令为鉴权成功指令时,判定所述目标基站是伪基站;
    确定所述伪基站的工作频点,将位置区更新请求发送至除所述伪基站 以外的基站。
  5. 根据权利要求1至4中任一项所述的网络驻留方法,其特征在于,还包括:
    确定预存储的驻留更新周期;
    在所述终端驻留小区后,所述终端的运行时间大于或等于所述驻留更新周期时,确定所述位置区更新的触发条件成立。
  6. 一种网络驻留系统,适用于终端,其特征在于,包括:
    获取单元,用于在检测到位置区更新的触发条件成立时,获取终端所在区域的基站的工作频点;
    发送单元,用于将位置区更新请求发送至所述工作频点对应的目标基站;
    所述获取单元还用于:获取所述目标基站反馈的鉴权随机参数;
    所述网络驻留系统还包括:
    生成单元,用于根据所述终端的用户身份识别卡的标识信息、所述鉴权随机参数和指定鉴权算法生成第一鉴权参数,并生成与所述第一鉴权参数不同的第二鉴权参数;
    所述发送单元还用于:将所述第二鉴权参数发送至所述目标基站;
    所述网络驻留系统还包括:
    判断单元,用于根据所述目标基站对所述第二鉴权参数的反馈指令,判断所述目标基站是伪基站或核心网基站。
  7. 根据权利要求6所述的网络驻留系统,其特征在于,
    所述判断单元还用于:在获取所述反馈指令为鉴权失败指令时,判定所述目标基站是核心网基站;
    所述发送单元还用于:将所述第一鉴权参数发送至所述核心网基站,以供所述核心网基站根据所述鉴权随机参数和所述第一鉴权参数判断所述终端是否具有驻留权限;
    所述网络驻留系统还包括:
    选择单元,用于在获取所述核心网基站发送的鉴权成功指令后,根据所述核心网基站的小区的信道质量选择驻留的小区。
  8. 根据权利要求7所述的网络驻留系统,其特征在于,还包括:
    检测单元,用于在所述终端驻留所述核心网基站的小区后,检测所述终端是否移动至所述核心网基站的小区以外的区域;
    确定单元,用于在检测到所述终端移动至所述核心网基站的小区以外的区域时,确定所述位置区更新的触发条件成立。
  9. 根据权利要求6所述的网络驻留系统,其特征在于,
    所述判断单元还用于:在获取所述反馈指令为鉴权成功指令时,判定所述目标基站是伪基站;
    所述发送单元还用于:确定所述伪基站的工作频点,将位置区更新请求发送至除所述伪基站以外的基站。
  10. 根据权利要求6至9中任一项所述的网络驻留系统,其特征在于,
    所述确定单元还用于:确定预存储的驻留更新周期;
    所述确定单元还用于:在所述终端驻留小区后,所述终端的运行时间大于或等于所述驻留更新周期时,确定所述位置区更新的触发条件成立。
  11. 一种终端,其特征在于,包括通信总线、输入装置、输出装置、存储器以及处理器,其中:
    所述通信总线,用于实现所述输入装置、输出装置、存储器以及处理器之间的连接通信;
    所述输入装置,用于获取目标基站对第二鉴权参数的反馈指令;
    所述输出装置,用于发送位置区更新请求,以及第二鉴权参数;
    所述存储器中存储一组程序代码,且所述终端调用所述存储器中存储的程序代码,用于执行以下操作:
    所述处理器在检测到位置区更新的触发条件成立时,获取终端所在区域的基站的工作频点;
    所述输出装置将位置区更新请求发送至所述工作频点对应的目标基站;
    所述处理器获取所述目标基站反馈的鉴权随机参数;
    所述处理器根据所述终端的用户身份识别卡的标识信息、所述鉴权随机参数和指定鉴权算法生成第一鉴权参数,并生成与所述第一鉴权参数不 同的第二鉴权参数;
    所述输出装置将所述第二鉴权参数发送至所述目标基站;
    所述处理器根据所述目标基站对所述第二鉴权参数的反馈指令,判断所述目标基站是伪基站或核心网基站。
  12. 根据权利要求11所述的终端,其特征在于,所述处理器根据所述目标基站对所述第二鉴权参数的反馈指令,判断所述目标基站是伪基站或核心网基站,具体包括以下步骤:
    所述处理器在获取所述反馈指令为鉴权失败指令时,判定所述目标基站是核心网基站;
    所述输出装置将所述第一鉴权参数发送至所述核心网基站,以供所述核心网基站根据所述鉴权随机参数和所述第一鉴权参数判断所述终端是否具有驻留权限;
    在所述输入装置获取所述核心网基站发送的鉴权成功指令后,所述处理器根据所述核心网基站的小区的信道质量选择驻留的小区。
  13. 根据权利要求12所述的终端,其特征在于,还包括:
    所述处理器在所述终端驻留所述核心网基站的小区后,检测所述终端是否移动至所述核心网基站的小区以外的区域;
    所述处理器在检测到所述终端移动至所述核心网基站的小区以外的区域时,确定所述位置区更新的触发条件成立。
  14. 根据权利要求11所述的终端,其特征在于,还包括:
    在所述输入装置获取所述反馈指令为鉴权成功指令时,所述处理器判定所述目标基站是伪基站;
    所述处理器确定所述伪基站的工作频点,将位置区更新请求发送至除所述伪基站以外的基站。
  15. 根据权利要求11至14中任一项所述的终端,其特征在于,还包括:
    所述处理器确定预存储的驻留更新周期;
    所述处理器在所述终端驻留小区后,所述终端的运行时间大于或等于所述驻留更新周期时,确定所述位置区更新的触发条件成立。
PCT/CN2016/080822 2016-01-29 2016-04-29 网络驻留方法、网络驻留系统和终端 WO2017128542A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201610064472.2 2016-01-29
CN201610064472.2A CN105722077A (zh) 2016-01-29 2016-01-29 网络驻留方法、网络驻留系统和终端

Publications (1)

Publication Number Publication Date
WO2017128542A1 true WO2017128542A1 (zh) 2017-08-03

Family

ID=56154356

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/080822 WO2017128542A1 (zh) 2016-01-29 2016-04-29 网络驻留方法、网络驻留系统和终端

Country Status (2)

Country Link
CN (1) CN105722077A (zh)
WO (1) WO2017128542A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110896537A (zh) * 2019-12-19 2020-03-20 武汉虹信通信技术有限责任公司 通信管控方法及装置
CN112640512A (zh) * 2018-08-31 2021-04-09 华为技术有限公司 一种伪基站识别方法及装置
CN112868247A (zh) * 2018-12-27 2021-05-28 深圳市欢太科技有限公司 小区连接处理方法、装置、移动终端及存储介质

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107241721A (zh) * 2016-03-29 2017-10-10 努比亚技术有限公司 移动终端网络重选控制方法及装置
CN106211157B (zh) * 2016-06-30 2019-08-27 北京奇虎科技有限公司 基站重定向方法和基站重定向装置
CN106454776B (zh) * 2016-09-30 2022-03-18 宇龙计算机通信科技(深圳)有限公司 伪基站的防护方法及装置
CN107466041B (zh) * 2017-09-30 2020-09-01 奇酷互联网络科技(深圳)有限公司 识别伪基站方法、装置及移动终端
CN107708115B (zh) * 2017-10-16 2020-11-06 奇酷互联网络科技(深圳)有限公司 重定向管控方法、装置及移动终端
CN111465020A (zh) * 2019-01-18 2020-07-28 中兴通讯股份有限公司 一种防伪基站方法及装置、计算机可读存储介质
CN113225756B (zh) * 2021-04-30 2022-07-15 Oppo广东移动通信有限公司 驻留网络的方法、装置、终端和计算机可读存储介质

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2014154634A1 (fr) * 2013-03-25 2014-10-02 Gemalto Sa Procede d'authentification mutuelle entre un element de securite d'un terminal de telecommunications et un element d'un reseau de telecommunications de type gsm
CN104581732A (zh) * 2014-12-25 2015-04-29 中国科学院信息工程研究所 一种基于短信的伪基站实时判别方法及系统
CN105101200A (zh) * 2014-05-23 2015-11-25 中国移动通信集团公司 一种伪基站识别方法、装置及终端设备

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1953369A (zh) * 2006-09-30 2007-04-25 中国移动通信集团公司 一种发起与识别更新密钥请求的方法、系统和装置
WO2012149982A1 (en) * 2011-05-05 2012-11-08 Telefonaktiebolaget L M Ericsson (Publ) Security mechanism for mobile users
CN104838681B (zh) * 2012-10-11 2019-03-12 诺基亚通信公司 利用核心网络支持的伪基站检测
CN104683965B (zh) * 2013-11-27 2018-12-18 中国移动通信集团公司 一种对伪基站垃圾短信的拦截方法和设备

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2014154634A1 (fr) * 2013-03-25 2014-10-02 Gemalto Sa Procede d'authentification mutuelle entre un element de securite d'un terminal de telecommunications et un element d'un reseau de telecommunications de type gsm
CN105101200A (zh) * 2014-05-23 2015-11-25 中国移动通信集团公司 一种伪基站识别方法、装置及终端设备
CN104581732A (zh) * 2014-12-25 2015-04-29 中国科学院信息工程研究所 一种基于短信的伪基站实时判别方法及系统

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112640512A (zh) * 2018-08-31 2021-04-09 华为技术有限公司 一种伪基站识别方法及装置
CN112868247A (zh) * 2018-12-27 2021-05-28 深圳市欢太科技有限公司 小区连接处理方法、装置、移动终端及存储介质
CN112868247B (zh) * 2018-12-27 2023-04-07 深圳市欢太科技有限公司 小区连接处理方法、装置、移动终端及存储介质
CN110896537A (zh) * 2019-12-19 2020-03-20 武汉虹信通信技术有限责任公司 通信管控方法及装置
CN110896537B (zh) * 2019-12-19 2023-07-28 武汉虹信科技发展有限责任公司 通信管控方法及装置

Also Published As

Publication number Publication date
CN105722077A (zh) 2016-06-29

Similar Documents

Publication Publication Date Title
WO2017128542A1 (zh) 网络驻留方法、网络驻留系统和终端
CN106028331B (zh) 一种识别伪基站的方法及设备
US10595198B2 (en) Communication method and device
JP5784776B2 (ja) 認証能力のセキュアなネゴシエーション
RU2665064C1 (ru) Беспроводная связь, включающая в себя кадр обнаружения быстрого первоначального установления линии связи, fils, для сетевой сигнализации
CN112106439A (zh) 用于无线接入点的智能带选择
JP2016106505A (ja) ユーザ装置が移動している間の競り下げ攻撃を防止する方法、システム、及び装置
US10772033B2 (en) Avoiding reselection of a fake cell in a wireless communication network
US9398459B2 (en) Prevention of eavesdropping type of attack in hybrid communication system
US20080159245A1 (en) Determination of a Network Identity for a Network Access Point
CN108459317A (zh) 定位方法及系统、定位服务器、核心网设备、基站
WO2020042176A1 (zh) 一种伪基站识别方法及装置
US20150319672A1 (en) Method and apparatus for controlling association of a station with a wlan
US9420460B2 (en) WLAN authentication restriction
CN104507065A (zh) 异构无线网络中不可否认性计费方法
ES2780177T3 (es) Autenticación
CN109379744B (zh) 伪基站识别方法、装置及通信终端
KR102017373B1 (ko) 이동통신기반 사물인터넷 장치의 가입자 인증 방법, 가입자 인증을 위한 사물 인터넷 장치 및 가입자 인증을 위한 기지국 장치
CN107969000B (zh) 无线中继器上行链路的状态探测方法、装置、设备及介质
KR101133347B1 (ko) 무선랜의 로밍 방법
CN112312398A (zh) 一种小区接入的方法、装置和系统
WO2019047943A1 (zh) 一种伪基站识别以及防御方法和终端
JP2017055165A (ja) 無線通信システムおよび基地局

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16887424

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16887424

Country of ref document: EP

Kind code of ref document: A1