WO2020042856A1 - 安全审计系统及方法 - Google Patents

安全审计系统及方法 Download PDF

Info

Publication number
WO2020042856A1
WO2020042856A1 PCT/CN2019/098469 CN2019098469W WO2020042856A1 WO 2020042856 A1 WO2020042856 A1 WO 2020042856A1 CN 2019098469 W CN2019098469 W CN 2019098469W WO 2020042856 A1 WO2020042856 A1 WO 2020042856A1
Authority
WO
WIPO (PCT)
Prior art keywords
network connection
security
control terminal
connection request
audit
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2019/098469
Other languages
English (en)
French (fr)
Inventor
唐晓柯
崔炳荣
闫天瑜
甘杰
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
State Grid Information and Telecommunication Group Co Ltd
Electric Power Research Institute of State Grid Fujian Electric Power Co Ltd
Beijing Smartchip Microelectronics Technology Co Ltd
State Grid Corp of China SGCC
Original Assignee
State Grid Information and Telecommunication Group Co Ltd
Electric Power Research Institute of State Grid Fujian Electric Power Co Ltd
Beijing Smartchip Microelectronics Technology Co Ltd
State Grid Corp of China SGCC
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by State Grid Information and Telecommunication Group Co Ltd, Electric Power Research Institute of State Grid Fujian Electric Power Co Ltd, Beijing Smartchip Microelectronics Technology Co Ltd, State Grid Corp of China SGCC filed Critical State Grid Information and Telecommunication Group Co Ltd
Priority to US16/969,736 priority Critical patent/US11184773B2/en
Publication of WO2020042856A1 publication Critical patent/WO2020042856A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/30Security of mobile devices; Security of mobile applications
    • H04W12/35Protecting application or service provisioning, e.g. securing SIM application provisioning
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/12Detection or prevention of fraud
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/30Security of mobile devices; Security of mobile applications
    • H04W12/37Managing security policies for mobile devices or for controlling mobile applications
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/40Security arrangements using identity modules
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/18Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
    • H04W8/183Processing at user equipment or user record carrier
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/18Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
    • H04W8/20Transfer of user or subscriber data
    • H04W8/205Transfer to or from user equipment or user record carrier

Definitions

  • the present application relates to the field of wireless communication, and in particular to a security audit system and method for remote connection.
  • wireless communication technologies have been widely used in various industries. This technology uses the existing wireless network resources of the operator, and has the advantages of large coverage, low use cost, and good communication quality. In the power system, wireless communication technology has also become the main transmission means.
  • the main control terminal does not have the function of directly connecting with the service master station.
  • the service master station such as wireless connection
  • the main control terminal sends a network connection instruction to the remote communication module, and the remote communication module connects the service master station unconditionally. This unconditional connection cannot guarantee data security.
  • the embodiments of the present application provide a security audit system and method, which can at least increase the security of communication data.
  • an embodiment of the present application provides a security audit system, including:
  • the embedded universal integrated circuit card eSIM module is configured as:
  • the security check is passed, it is confirmed that the network connection request is a legitimate request, and the master control terminal that initiated the network connection request is allowed to make a mobile network connection;
  • the security check is not passed, it is confirmed that the network connection request is an illegal request, and the master control terminal that initiated the network connection request is prohibited from making a mobile network connection.
  • the eSIM module is configured to record illegal request information.
  • system further includes:
  • the security server is coupled to the eSIM module and is configured to store illegal request information recorded by the eSIM module.
  • the security server is further configured to:
  • the eSIM module is configured to perform security review on the network connection request according to the audit rule; and upload the recorded illegal request information to the security server according to the upload rule.
  • system further includes:
  • the main control terminal is inserted with a remote communication module, and the eSIM module is welded to the remote communication module;
  • the remote communication module is configured to receive the network connection request initiated by the master control terminal and send the network connection request to the eSIM module;
  • the service master station establishes communication with the master control terminal through the remote communication module when the network connection request passes the security review of the eSIM module and successfully connects with the mobile network.
  • the embodiment of the present application further provides a security audit method, including:
  • the security check is passed, it is confirmed that the network connection request is a legitimate request, and the master control terminal that initiated the network connection request is allowed to make a mobile network connection;
  • the security check is not passed, it is confirmed that the network connection request is an illegal request, and the master control terminal that initiated the network connection request is prohibited from making a mobile network connection.
  • the method further includes:
  • the method further includes:
  • the method further includes:
  • the method further includes:
  • the master control terminal In a case where the network connection request passes the security review and the master control terminal is successfully connected to a mobile network, the master control terminal communicates with a service master station through the remote communication module.
  • an embedded universal integrated circuit card (eSIM) module with an Internet of Things (M2M) security level is used, and based on the eSIM module, security inspection is performed on a connection event initiated by the master control terminal. Passing the security review, it is confirmed that the network connection request is a legitimate request, and the controlling terminal that initiated the network connection request is allowed to make a mobile network connection.
  • the master control terminal described in the network connection request performs a mobile network connection.
  • a security audit of connection events initiated by the master control terminal based on the eSIM module ensures data security.
  • the improvement of security can further expand the application of eSIM module and remote communication module, ensure the security of connection with other business master stations, and meet the needs of business expansion.
  • FIG. 1 is a conventional remote connection structure between a master control terminal and a service master station;
  • Example 2 is a schematic structural diagram of a security audit system according to an implementation manner of Example 1 of the present application;
  • FIG. 3 is a flowchart of a security audit method according to an embodiment of Example 1 of the present application.
  • FIG. 1 is a schematic diagram of a remote connection of a conventional master control terminal.
  • the diagram includes four components: a main control terminal 10, a remote communication module 11, a subscriber identification module (SIM) card 11a, and a service master station 12.
  • the network connection process is as follows: the main control terminal 10 sends a network connection request instruction to the remote communication module 11, the remote communication module 11 performs mobile network connection through the SIM card 11a, and the remote communication module 11 connects with the service master station 12 to open a data path.
  • the remote communication module only assumes the role of the data path, and the SIM card inside the remote communication module is mainly used for network authentication. If the IP address configured by the master control terminal is maliciously tampered with, the data will be at risk of being leaked.
  • the embodiments of the present application provide a security audit system and method.
  • the principle is that the pluggable SIM card is upgraded to an eSIM module with M2M (machine to machine) security level of the Internet of Things.
  • M2M machine to machine
  • each connection event (network connection request) is subject to security review.
  • the remote communication module receives the network connection instruction sent by the master control terminal, it sends a connection event to the eSIM module.
  • the eSIM module analyzes connection events, mainly analyzing whether the connection event is a legal connection event or an illegal (malicious) connection event.
  • the security review confirms that the network connection request is a legitimate request, and the controlling terminal that initiated the network connection request is allowed to make a mobile network connection; if it is an illegal connection event, it is deemed to have failed the security review , Confirming that the network connection request is an illegal request, and prohibiting the master terminal that initiated the network connection request from making a mobile network connection.
  • it is judged as a malicious connection event, and the eSIM module reports to the security server.
  • the reporting by the eSIM module may be a real-time report or a regular report. It can be reported voluntarily, or it can be reported based on a certain triggering event, such as responding to a report request from a security server, which is not specifically limited.
  • the main control terminal since the main control terminal performs security audit through the eSIM module and connects with a remote security server, it is a security audit system and method for remote connection.
  • FIG. 2 is a schematic structural diagram of a security audit system according to an embodiment of the embodiment of the present application.
  • the security audit system includes a main control terminal 20, a remote communication module 21, an eSIM module 21a, a service master station 22, and a security server 23.
  • the master control terminal 20 in the embodiment of the present application is a communication entity that cannot connect with other devices such as a service master station and / or a security server, and needs to be connected through the remote communication module 21 inserted into the master control terminal 20.
  • the remote communication module 21 is soldered with an eSIM module 21 a, and the eSIM module 21 a is soldered on the bottom plate of the remote communication module 21.
  • the remote communication module 21 is configured to receive a network connection request initiated by the main control terminal 20 and send the network connection request to the eSIM module 21a.
  • the eSIM module 21a stores audit rules and is configured to perform a security review on each network connection request received according to the audit rules. If the security review is passed, the network connection request is confirmed to be a legitimate request, and the network connection request is allowed to be initiated. The main control terminal 20 makes a mobile network connection, otherwise, it is confirmed that the network connection request is an illegal request, and the main control terminal 20 that initiated the network connection request is prohibited or allowed to make a mobile network connection.
  • the network connection request initiated by the master control terminal sent by the remote communication module 21 to the eSIM module 21a carries information of the service master station that the master control terminal wants to access, such as the identity of the service master station 22 and / or the Internet Protocol address (IP).
  • IP Internet Protocol address
  • the eSIM module 21a performs security review on the network connection request initiated by the master control terminal 20, which is equivalent to judging whether the service master station 22 that the master control terminal wants to access appears in the service master station based on the identity and / or IP address of the service master station 22. On the list, if it appears, it is considered that the security review has passed. If it does not appear, it is considered that the security review has failed.
  • the service master station white list is a preset service master station, which records the service master station accessible by the master control terminal, and its identification and / or IP address information.
  • the legal master terminal can access the business master station appearing on the white list of the business master station.
  • the eSIM module 21a performs the network connection request initiated by the master terminal.
  • the security review is to check the legitimacy of the master control terminal that needs to access the business master station and is inserted with the remote communication module 21 that solders the eSIM module 21a, so as to prevent malicious terminals from maliciously accessing the business master station.
  • the eSIM module 21a is also configured to record illegal request information; in addition, the eSIM module 21a is also configured to record network signal quality information during a security review process.
  • the eSIM module 21a is also configured to store upload rules.
  • the eSIM module 21a uploads the recorded illegal request information, network signal quality, and other information to the security server 23 according to the upload rule.
  • the eSIM module 21a uploads the foregoing content of the record to the security server 23 according to the upload rule.
  • the illegal request level of the record is higher than a preset level threshold, that is, the illegal request level is high, the recorded High illegal request upload to security server 23; eSIM module 21a uploads recorded content to security server 23 in response to the upload request from security server 23; also when the space capacity of eSIM module 21a for recording is below a preset capacity threshold That is, when the eSIM module 21 a has a large amount of recorded content, it actively uploads the recorded content to the security server 23.
  • the different content recorded by the eSIM module 21a may be uploaded at the same time, or may be uploaded in a certain order, such as the order of recording, which is not specifically limited.
  • the security server 23 analyzes the illegal connection request information, such as counting the number of illegal connection requests and / or identifying the master control terminal that initiated the illegal connection request. Statistics to avoid multiple visits to the same illegal terminal.
  • the security server 23 evaluates the current network environment and obtains the evaluation result. The uploading rules can be flexibly adjusted according to the evaluation results. For example, if the evaluation results indicate that the current network environment of the main control terminal 20 is better, more records can be uploaded to the security server 23. In a case where the network environment of the main control terminal 20 is currently poor, the record content allowed to be uploaded to the security server 23 is less. To avoid the problem of upload failure due to too many uploads in a poor network environment.
  • the master control terminal 20 establishes communication with the service master station 22 through the remote communication module 21.
  • the master control terminal 20 After the master control terminal 20 enters the network through the eSIM module 21a, it communicates with the security server through the remote communication module 21 23 for communication. Further, the main control terminal 20 sends its own identification information and uplink security authentication information to the security server 23 through the remote communication module 21, and the security server 23 sends the identification information and the uplink security authentication information to the main control terminal 20 according to the identification information and the received upstream security authentication information. Perform identity authentication and upstream security verification.
  • the security server 23 sends the downlink security authentication information to the master control terminal 20, specifically the remote communication module 21, and the remote communication module 21, specifically the eSIM module 21a performs the downlink security authentication information.
  • Authentication which is passed, allows the security server 23 to perform update operations such as modification, deletion, and writing.
  • the verification process is a two-way verification. After the two-way verification, update operations such as changes, maintenance, and deletion are allowed.
  • the security server 23 is configured to store information uploaded by the eSIM module 21a, and is also configured to configure audit rules and upload rules, and write the audit rules and upload rules into the eSIM module 21a for storage and use by the eSIM module 21a.
  • the security server 23 may reasonably configure upload rules according to factors such as the different distribution of the main control terminal in various places, the number of reads and writes of the eSIM module 21a, and / or its own processing capacity, that is, the upload rules in the embodiments of the present application may Situation and flexible configuration. For example, when the network environment between the security server 23 and the main control terminal 20 is poor, the record content allowed to be uploaded by the main control terminal 20 to the security server 23 through the remote communication module 21 may be considered as an upload rule.
  • the upload rule can be set to be in a case where the recordable space capacity is lower than a preset capacity threshold, that is, when the space capacity for recording is small. , Trigger the eSIM module 21a to upload the recorded information, so that the eSIM module 21a achieves the effect of intelligent uploading.
  • the eSIM module 21a can also upload geographic location data, security attack data, and network conditions such as network signal quality information of the main control terminal 20. It can be seen that the eSIM module 21a can upload various service data, which is equivalent to the function of the eSIM module 21a being expanded, which reflects the functional diversity of the eSIM module 21a.
  • the security attack data can be understood as there are any illegal security servers that want to access them.
  • the above-mentioned security audit system and method have added an eSIM module and a security server, and combined the audit mechanism (audit rules) and the upload mechanism (upload rules) to make the communication environment between the master control terminal and the business master station more secure.
  • the business master station can be further added to flexibly carry out business expansion.
  • FIG. 2 is a specific method of the security audit of this embodiment.
  • the security audit method includes steps S1-S3.
  • the master control terminal sends a network connection request: the master control terminal 20 sends a network connection request to the remote communication module 21.
  • the remote communication module forwards the network connection request: the remote communication module 21 sends the network connection request to the eSIM module 21a.
  • the eSIM module 21a performs a security review of the network connection request according to the audit rules. If the security review is passed, the network connection request is confirmed as a legitimate request, and a corresponding prompt is returned to the remote communication module. 21, the remote communication module 21 normally performs network connection and establishes communication with the service master station 22. If the security check is not passed, the network connection request is confirmed as an illegal request, and a corresponding prompt is returned to the remote communication module 21. The remote communication module 21 does not perform a mobile network connection, that is, does not perform a network connection. According to the upload rule, the eSIM module 21a uploads the information of the illegal request to the security server 23 in the case of an upload request from the security server 23, a high level of illegal request for the record, or a small amount of space remaining for recording.
  • the security audit system and method of the embodiments of the present application use the eSIM module of the Internet of Things M2M security level, which can ensure data security on the one hand, and expand the functions of the eSIM module on the other, to enable multiple Upload of various business data.
  • a security review is performed on a network connection event initiated by the master control terminal. If the security review is passed, it is confirmed that the network connection request is a legitimate request, and the master control terminal that initiated the network connection request is allowed to make a mobile network connection. If the security check is not passed, it is confirmed that the network connection request is an illegal request, and the master control terminal that initiated the network connection request is prohibited from making a mobile network connection.
  • the security review of the connection events initiated by the master control terminal based on the eSIM module ensures data security.
  • the improvement of security can further expand the application of eSIM module and remote communication module, ensure the security of connection with other business master stations, and meet the needs of business expansion. Among them, if it is judged as a malicious connection event, the eSIM module reports it to the security server.
  • An embodiment of the present application further provides a computer-readable storage medium on which a computer program is stored, and when the program is executed by a processor, at least the steps of the security audit method of the foregoing embodiment are performed.
  • the computer-readable storage medium may specifically be a memory.
  • An embodiment of the present application further provides a security audit system, including a processor and a memory for storing a computer program capable of running on the processor; when the processor runs the foregoing computer program, the processor executes the steps of the foregoing security audit method. .
  • this application may be provided as a method, a system, or a computer program product. Therefore, this application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, this application may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
  • computer-usable storage media including, but not limited to, disk storage, CD-ROM, optical storage, etc.
  • These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to work in a particular manner such that the instructions stored in the computer-readable memory produce a manufactured article including an instruction device, the instructions
  • the device implements the functions specified in one or more flowcharts and / or one or more blocks of the block diagram.
  • These computer program instructions can also be loaded on a computer or other programmable data processing device, so that a series of steps can be performed on the computer or other programmable device to produce a computer-implemented process, which can be executed on the computer or other programmable device.
  • the instructions provide steps for implementing the functions specified in one or more flowcharts and / or one or more blocks of the block diagrams.
  • an eSIM module with IoT M2M security level is used.
  • the network connection event initiated by the master control terminal is subject to security review.
  • the master terminal is allowed to make a network connection. If it is determined as a malicious connection event, the master terminal is prohibited or not allowed to perform network connection, and the eSIM module reports the malicious connection event to the security server.
  • the security review of the connection event initiated by the main control terminal based on the eSIM module ensures data security.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Databases & Information Systems (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请实施例公开了一种安全审计系统及方法。其中,所述安全审计系统包括eSIM模块;eSIM模块,配置为:根据预先存储的审计规则对每次收到的网络连接请求进行安全审查;若通过安全审查,则确认该网络连接请求为合法请求,则允许发起所述网络连接请求的主控终端进行移动网络连接;若未通过安全审查,则确认该网络连接请求为非法请求,禁止发起所述网络连接请求的主控终端进行移动网络连接。

Description

安全审计系统及方法
相关申请的交叉引用
本申请基于申请号为201810980737.2、申请日为2018年08月27日的中国专利申请提出,并要求该中国专利申请的优先权,该中国专利申请的内容在此以引入方式并入本申请。
技术领域
本申请涉及无线通信领域,具体是一种用于远程连接的安全审计系统及方法。
背景技术
随着无线网络的不断发展,无线通信技术已被广泛应用到各行各业中。这种技术使用运营商现有的无线网络资源,具有覆盖范围大,使用成本低,通信质量好等优点。在电力系统当中,无线通信技术也已成为主要的传输手段。
现有的电力采集系统中,主控终端不具有与业务主站进行直接连接的功能,当其需要与业务主站进行连接如无线连接时,主要依靠远程通信模块与业务主站进行连接。进一步的,主控终端向远程通信模块发送网络连接指令,远程通信模块无条件的连接业务主站。这种无条件的连接方式无法保证数据安全性。
公开于该背景技术部分的信息仅仅旨在增加对本申请实施例的总体背景的理解,而不应当被视为承认或以任何形式暗示该信息构成已为本领域一般技术人员所公知的现有技术。
发明内容
本申请实施例在于提供一种安全审计系统及方法,至少能够增加通信 数据的安全性。
为实现上述目的,本申请实施例提供了一种安全审计系统,包括:
嵌入式通用集成电路卡eSIM模块,配置为:
根据预先存储的审计规则对接收的网络连接请求进行安全审查;
若通过安全审查,则确认该网络连接请求为合法请求,则允许发起所述网络连接请求的主控终端进行移动网络连接;
若未通过安全审查,则确认该网络连接请求为非法请求,禁止发起所述网络连接请求的主控终端进行移动网络连接。
在一实施方式中,所述eSIM模块,配置为:对非法请求信息进行记录。
在一实施方式中,所述系统还包括:
安全服务器,与所述eSIM模块相耦合,配置为存储所述eSIM模块记录的非法请求信息。
在一实施方式中,所述安全服务器,还配置为:
配置所述审计规则以及上传规则,将所述审计规则以及所述上传规则写入所述eSIM模块中以供所述eSIM模块存储;
相应的,所述eSIM模块,配置为根据所述审计规则对所述网络连接请求进行安全审查;根据所述上传规则将记录的非法请求信息上传至所述安全服务器。
在一实施方式中,所述系统还包括:
主控终端,插入有远程通信模块,所述eSIM模块焊接在所述远程通信模块上;
所述远程通信模块,配置为接收所述主控终端发起的所述网络连接请求并将该网络连接请求发送给所述eSIM模块;以及
业务主站,在所述网络连接请求通过所述eSIM模块的安全审查并与移动网络成功连接的情况下,通过所述远程通信模块与所述主控终端建立通 信。
本申请实施例还提供了一种安全审计方法,包括:
根据预先存储的审计规则,对接收的网络连接请求进行安全审查;
若通过安全审查,则确认该网络连接请求为合法请求,则允许发起所述网络连接请求的主控终端进行移动网络连接;
若未通过安全审查,则确认该网络连接请求为非法请求,禁止发起所述网络连接请求的主控终端进行移动网络连接。
在一实施方式中,所述方法还包括:
对非法请求信息进行记录。
在一实施方式中,所述方法还包括:
将记录的非法请求信息进行上传。
在一实施方式中,所述方法还包括:
接收配置的所述审计规则和上传规则;
根据所述审计规则对所述网络连接请求进行安全审查;
根据所述上传规则将记录的非法请求信息进行上传。
在一实施方式中,所述方法还包括:
接收由远程通信模块转发的所述主控终端发起的所述网络连接请求,其中所述主控终端插入有所述远程通信模块;
在所述网络连接请求通过安全审查、所述主控终端与移动网络成功连接的情况下,所述主控终端通过所述远程通信模块与业务主站进行通信。
与现有技术相比,本申请实施例中,采用物联网(M2M)安全级别的嵌入式通用集成电路卡(eSIM)模块,基于eSIM模块,对主控终端发起的连接事件进行安全审查,若通过安全审查,则确认该网络连接请求为合法请求,则允许发起所述网络连接请求的主控终端进行移动网络连接;若未通过安全审查,则确认该网络连接请求为非法请求,禁止发起所述网络 连接请求的主控终端进行移动网络连接。在不改变现有主站模式和采集系统架构,不增加主控终端硬件成本的前提下,基于eSIM模块对主控终端发起的连接事件的安全审计,确保了数据的安全性。该安全性的提高可以进一步扩展eSIM模块和远程通信模块的应用,保证了与其他业务主站连接的安全,满足了业务拓展的需求。
附图说明
图1是现有的一种主控终端与业务主站的远程连接结构;
图2是根据本申请实施例一实施方式的安全审计系统的结构示意图;
图3是根据本申请实施例一实施方式的安全审计方法的流程图。
具体实施方式
下面结合附图,对本申请实施例的具体实施方式进行详细描述,但应当理解本申请实施例的保护范围并不受具体实施方式的限制。
除非另有其它明确表示,否则在整个说明书和权利要求书中,术语“包括”或其变换如“包含”或“包括有”等等将被理解为包括所陈述的元件或组成部分,而并未排除其它元件或其它组成部分。
相关技术中,针对现有电力采集系统中,通过远程通信模块无条件与业务主站进行连接使得主控终端与业务主站进行连接的方案具体可以如下所述:
远程通信模块具有分组无线数据包的功能。图1是现有的一种主控终端的远程连接示意图。在该示意图中包括4个组成部分:主控终端10、远程通信模块11、用户识别模块(SIM)卡11a、业务主站12。网络连接过程为:主控终端10发送网络连接请求指令至远程通信模块11,远程通信模块11通过SIM卡11a进行移动网络连接,远程通信模块11再与业务主站12进行连接,打开数据通路。
前述方案中,远程通信模块只承担了数据通路的作用,而远程通信模块内部的SIM卡主要用来做网络鉴权。如果主控终端配置的IP地址遭到恶意篡改,数据将存在被泄露的风险。
针对现有的主控终端的远程连接过程没有安全审计而存在的泄露风险的问题,本申请实施例提供了一种安全审计系统及方法。其原理是:将可插拔的SIM卡升级为物联网M2M(machine to machine)安全级别的eSIM模块,基于远程通信模块和eSIM模块,将每次连接事件(网络连接请求)进行安全审查。进一步的,当远程通信模块接收到主控终端发送的网络连接指令后,将连接事件下发到eSIM模块。eSIM模块对连接事件进行分析,主要进行连接事件是合法连接事件还是非法(恶意)连接事件的分析。如果为合法连接事件,则通过安全审查,确认该网络连接请求为合法请求,则允许发起所述网络连接请求的主控终端进行移动网络连接;如果为非法连接事件,则视为未通过安全审查,确认该网络连接请求为非法请求,禁止发起所述网络连接请求的主控终端进行移动网络连接。其中,判断为恶意连接事件,eSIM模块上报到安全服务器。其中,eSIM模块的上报可以是实时上报、也可以是定期上报。可以是主动上报、也可以是基于一定的触发事件如应安全服务器的上报请求而上报,具体不做限定。
可以理解,本申请实施例,由于主控终端通过eSIM模块进行安全审计,并与远程的安全服务器进行连接,为一种用于远程连接的安全审计系统和方法。
图2是根据本申请实施例一实施方式的安全审计系统的结构示意图。该安全审计系统包括主控终端20、远程通信模块21、eSIM模块21a、业务主站22、安全服务器23。
需要说明的是,本申请实施例中的主控终端20为无法与其它设备如业务主站和/或安全服务器进行连接的通信实体,需要通过插入主控终端20 的远程通信模块21进行连接。其中,远程通信模块21焊接有eSIM模块21a,eSIM模块21a焊接在远程通信模块21的底板上。远程通信模块21用于接收主控终端的20发起的网络连接请求并将该网络连接请求发送给eSIM模块21a。
eSIM模块21a存储审计规则,配置为:根据审计规则对每次接收到的网络连接请求进行安全审查,若通过安全审查,则确认该网络连接请求为合法请求,则允许发起所述网络连接请求的主控终端20进行移动网络连接,否则,确认该网络连接请求为非法请求,禁止也即不允许发起所述网络连接请求的主控终端20进行移动网络连接。
其中,对于远程通信模块21发送至eSIM模块21a的由主控终端发起的网络连接请求中携带有主控终端想要访问的业务主站的信息如业务主站22的标识和/或网际协议地址(IP)。eSIM模块21a对主控终端20发起的网络连接请求进行安全审查,相当于基于业务主站22的标识和/或IP地址判断主控终端想要访问的业务主站22是否出现在业务主站白名单上,如果出现则认为是安全审查通过,如果未出现则认为安全审查未通过。业务主站白名单为预先设置的、记载有主控终端可访问的业务主站、及其标识和/或IP地址信息。
实际应用中,对于业务主站白名单上出现的业务主站,合法终端可以对其进行访问,为避免非法终端对其进行访问,可以理解,eSIM模块21a对主控终端发起的网络连接请求进行安全审查,也就是对需要对业务主站进行访问且插入有焊接所述eSIM模块21a的远程通信模块21的主控终端的合法性进行审查,以避免非法终端对业务主站进行恶意访问。
eSIM模块21a还配置为记录非法请求信息;此外,eSIM模块21a还配置为记录安全审查过程中的网络信号质量信息。eSIM模块21a还配置为存储上传规则。eSIM模块21a根据该上传规则将记录的非法请求信息、网络 信号质量等信息上传至安全服务器23。其中,eSIM模块21a根据上传规则将记录的前述内容上传到安全服务器23可以这样理解:在记录的非法请求级别高于预设级别阈值也即非法请求级别较高的情况下,即刻将记录的较高非法请求上传至安全服务器23;eSIM模块21a应安全服务器23的上传请求将记录的内容上传至安全服务器23;在eSIM模块21a的用于记录的空间容量低于预设容量阈值的情况下也即eSIM模块21a记录的内容较多的情况下主动上传记录的内容至安全服务器23。其中,对于eSIM模块21a记录的不同内容可以同时进行上传,也可以按照一定的顺序如记录的先后顺序进行上传,具体不做限定。
可以理解,对于eSIM模块21a上传的非法连接请求信息,安全服务器23通过该非法连接请求信息进行分析,如对非法连接请求的数量进行统计和/或对发起非法连接请求的主控终端的标识进行统计,以避免同一非法终端多次访问。对于eSIM模块21a上传的网络信号质量信息,安全服务器23对当前所处的网络环境进行评估,得到评估结果。其中,上传规则可根据评估结果进行灵活调整,如在评估结果表征主控终端20当前所处的网络环境较好的情况下,允许上传至安全服务器23的记录内容多些;如在评估结果表征主控终端20当前所处的网络环境较差的情况下,允许上传至安全服务器23的记录内容少些。以避免在网络环境差的情况下由于上传过多而导致的上传失败的问题。
在网络连接请求通过eSIM模块21a的安全审查并成功连接至移动网络的情况下,主控终端20通过远程通信模块21与业务主站22建立通信。
eSIM模块21a内存储的这些数据无法进行外部读写,只可由自己及可信任的安全服务器23进行更新从而保证了eSIM模块21a的数据的安全性。
其中,eSIM模块21a可由可信任的安全服务器23进行更改、维护、删除等操作之前,还需要执行以下的验证过程:在主控终端20通过eSIM 模块21a入网后,通过远程通信模块21与安全服务器23进行通信。进一步的,主控终端20通过远程通信模块21向安全服务器23发送自身的身份标识信息和上行安全认证信息,安全服务器23依据该身份标识信息和接收到的上行安全认证信息,对主控终端20进行身份认证和上行安全验证。在身份认证和上行安全验证均通过的情况下,安全服务器23向主控终端20、具体是远程通信模块21发送下行安全认证信息,远程通信模块21、具体是eSIM模块21a对下行安全认证信息进行认证,认证通过,允许安全服务器23对其进行更改、删除、写入等更新操作。可以理解,以上验证过程为eSIM模块21a和安全服务器23双方均需要通过对方验证,该验证过程为一种双向验证,双向验证后允许执行更改、维护、删除等更新操作。
安全服务器23配置为存储eSIM模块21a上传的信息,还配置为配置审计规则以及上传规则,并将审计规则以及上传规则写入eSIM模块21a中,以供eSIM模块21a存储与使用。安全服务器23可以根据主控终端在各地的不同分布情况、eSIM模块21a的读写次数和/或自身的处理能力等因素,合理配置上传规则,也即本申请实施例中的上传规则可根据实际情况而灵活配置的。例如,在安全服务器23与主控终端20之间连接的网络环境较差的情况下,允许主控终端20通过远程通信模块21上传至安全服务器23的记录内容少些,可视为对上传规则的一种根据实际网络环境进行灵活配置的方案。考虑到一个eSIM模块21a的用于记录的空间容量较为有限,可以设置上传规则可以为在可记录的空间容量低于预设容量阈值的情况下也即用于记录的空间容量较少的情况下,触发eSIM模块21a进行记录信息的上传,从而使eSIM模块21a达到智能上传的效果。
本领域技术人员可以理解,eSIM模块21a除了能够进行以上信息的上传之外,还可以对主控终端20的地理位置数据、安全攻击数据、网络情况如网络信号质量信息等进行上传。可见,eSIM模块21a能够实现对多种业 务数据的上传,相当于eSIM模块21a的功能被扩展,体现了eSIM模块21a的功能多样性。其中,安全攻击数据可以理解为存在有哪些非法安全服务器想要对其访问。
上述的安全审计系统和方法,相对于现有技术加入了eSIM模块和安全服务器,并结合审计机制(审计规则)和上传机制(上传规则)使得主控终端与业务主站的通信环境更加的安全,在此系统的安全保障下,可以进一步增加业务主站从而灵活进行业务扩展。
基于上述实施例的安全审计系统,图2是该实施方式的安全审计的具体方法。该安全审计方法包括步骤S1-S3。
在S1中主控终端发送网络连接请求:主控终端20向远程通信模块21发送网络连接请求。
在S2中远程通信模块转发网络连接请求:远程通信模块21将该网络连接请求发送给eSIM模块21a。
在S3中对网络连接请求进行安全审查:eSIM模块21a根据审计规则对该网络连接请求进行安全审查,若通过安全审查,则将该网络连接请求确认为合法请求,且返回相应提示至远程通信模块21,远程通信模块21正常进行入网连接,并与业务主站22建立通信。若未通过安全审查,则该网络连接请求确认为非法请求,且将返回相应提示至远程通信模块21,远程通信模块21不进行移动网络连接也即不进行入网连接。根据上传规则,eSIM模块21a应安全服务器23的上传请求、该记录的非法请求级别高或用于记录的空间容量剩余较少的情况下,将该非法请求的信息上传至安全服务器23。
其中,主控终端20与业务主站22之间的数据通信的具体实现过程参见现有相关说明,不做赘述。
综上,本申请实施例的安全审计系统及方法,采用物联网M2M安全级 别的eSIM模块,一方面可保证数据的安全性,另一方面通过对eSIM模块的功能的扩展,使其实现对多种业务数据的上传。其中,基于eSIM模块,对主控终端发起的网络连接事件进行安全审查,若通过安全审查,则确认该网络连接请求为合法请求,则允许发起所述网络连接请求的主控终端进行移动网络连接;若未通过安全审查,则确认该网络连接请求为非法请求,禁止发起所述网络连接请求的主控终端进行移动网络连接。在不改变现有主站模式和采集系统架构,不增加主控终端硬件成本的前提下,基于eSIM模块对主控终端发起的连接事件的安全审查,确保了数据的安全性。该安全性的提高可以进一步扩展eSIM模块和远程通信模块的应用,保证了与其他业务主站连接的安全,满足了业务拓展的需求。其中,如果判断为恶意连接事件,eSIM模块将其上报安全服务器。
本申请实施例还提供一种计算机可读存储介质,其上存储有计算机程序,该程序被处理器执行时至少用于执行前述实施例的安全审计方法的步骤。所述计算机可读存储介质具体可以为存储器。
本申请实施例还提供一种安全审计系统,包括处理器和用于存储能够在处理器上运行的计算机程序的存储器;所述处理器在运行前述的计算机程序时执行前述的安全审计方法的步骤。
本领域内的技术人员应明白,本申请的实施例可提供为方法、系统、或计算机程序产品。因此,本申请可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本申请可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
本申请是参照根据本申请实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流 程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
最后应当说明的是:以上实施例仅用于说明本申请实施例的技术方案而非对其保护范围的限制,尽管参照上述实施例对本申请进行了详细的说明,所属领域的普通技术人员应当理解:本领域技术人员阅读本申请后依然可对申请的具体实施方式进行种种变更、修改或者等同替换,但这些变更、修改或者等同替换,均在申请待批的权利要求保护范围之内。
工业实用性
本申请实施例中,采用物联网M2M安全级别的eSIM模块,对于主控终端而言,基于eSIM模块,对主控终端发起的网络连接事件进行安全审查,如果判断为非恶意连接事件如正常连接事件,则允许主控终端进行网络连接。如果判断为恶意连接事件,则禁止也即不允许主控终端进行网络连接, 且eSIM模块将恶意连接事件上报至安全服务器。本申请实施例,不增加主控终端硬件成本的前提下,基于eSIM模块对主控终端发起的连接事件的安全审查,确保了数据的安全性。

Claims (10)

  1. 一种安全审计系统,包括:
    嵌入式通用集成电路卡eSIM模块,配置为:
    根据存储的审计规则对接收的网络连接请求进行安全审查;
    若通过安全审查,则确认该网络连接请求为合法请求,则允许发起所述网络连接请求的主控终端进行移动网络连接;
    若未通过安全审查,则确认该网络连接请求为非法请求,禁止发起所述网络连接请求的主控终端进行移动网络连接。
  2. 如权利要求1所述的安全审计系统,其中,所述eSIM模块,配置为:对非法请求信息进行记录。
  3. 如权利要求2所述的安全审计系统,其中,所述系统还包括:
    安全服务器,配置为存储所述eSIM模块记录的非法请求信息。
  4. 如权利要求3所述的安全审计系统,其中,
    所述安全服务器,还配置为:
    配置所述审计规则以及上传规则,将所述审计规则以及所述上传规则写入所述eSIM模块中以供所述eSIM模块存储;
    相应的,所述eSIM模块,配置为:
    根据所述审计规则对所述网络连接请求进行安全审查;根据所述上传规则将记录的非法请求信息上传至所述安全服务器。
  5. 如权利要求1所述的安全审计系统,其中,所述系统还包括:
    主控终端,插入有远程通信模块,所述eSIM模块焊接在所述远程通信模块上;
    所述远程通信模块,配置为接收所述主控终端发起的所述网络连接请求并将该网络连接请求发送给所述eSIM模块;以及
    业务主站,在所述网络连接请求通过所述eSIM模块的安全审查并与移动网络成功连接的情况下,通过所述远程通信模块与所述主控终端建立通 信。
  6. 一种安全审计方法,包括:
    根据预先存储的审计规则,对接收的网络连接请求进行安全审查;
    若通过安全审查,则确认该网络连接请求为合法请求,则允许发起所述网络连接请求的主控终端进行移动网络连接;
    若未通过安全审查,则确认该网络连接请求为非法请求,禁止发起所述网络连接请求的主控终端进行移动网络连接。
  7. 如权利要求6所述的安全审计方法,其中,所述方法还包括:
    对非法请求信息进行记录。
  8. 如权利要求7所述的安全审计方法,其中,所述方法还包括:
    将记录的非法请求信息进行上传。
  9. 如权利要求8所述的安全审计方法,其中,所述方法还包括:
    接收配置的所述审计规则和上传规则;
    根据所述审计规则对所述网络连接请求进行安全审查;
    根据所述上传规则将记录的非法请求信息进行上传。
  10. 如权利要求6所述的安全审计方法,其中,所述方法还包括:
    接收由远程通信模块转发的所述主控终端发起的所述网络连接请求,其中所述主控终端插入有所述远程通信模块;
    在所述网络连接请求通过安全审查、所述主控终端与移动网络成功连接的情况下,所述主控终端通过所述远程通信模块与业务主站进行通信。
PCT/CN2019/098469 2018-08-27 2019-07-30 安全审计系统及方法 Ceased WO2020042856A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US16/969,736 US11184773B2 (en) 2018-08-27 2019-07-30 Security auditing system and method

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201810980737.2A CN109246704A (zh) 2018-08-27 2018-08-27 用于远程连接的安全审计系统及方法
CN201810980737.2 2018-08-27

Publications (1)

Publication Number Publication Date
WO2020042856A1 true WO2020042856A1 (zh) 2020-03-05

Family

ID=65068366

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/098469 Ceased WO2020042856A1 (zh) 2018-08-27 2019-07-30 安全审计系统及方法

Country Status (3)

Country Link
US (1) US11184773B2 (zh)
CN (1) CN109246704A (zh)
WO (1) WO2020042856A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115208593A (zh) * 2021-03-26 2022-10-18 南宁富联富桂精密工业有限公司 安全性监测方法、终端及计算机可读存储介质
CN116915503A (zh) * 2023-09-08 2023-10-20 成都卓拙科技有限公司 一种违规外联检测方法及装置、存储介质及电子设备

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109246704A (zh) 2018-08-27 2019-01-18 北京智芯微电子科技有限公司 用于远程连接的安全审计系统及方法
CN114786170B (zh) * 2022-05-09 2023-06-23 中国联合网络通信集团有限公司 上链数据安全处理实体切换方法、终端、usim及系统

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105141621A (zh) * 2015-09-16 2015-12-09 北京星网锐捷网络技术有限公司 网络访问的监控方法及装置
CN106131090A (zh) * 2016-08-31 2016-11-16 北京力鼎创软科技有限公司 一种web认证下的用户访问网络的方法和系统
US9949113B1 (en) * 2017-06-02 2018-04-17 Apple Inc. Updating profiles for secondary wireless devices
CN108024243A (zh) * 2017-12-05 2018-05-11 恒宝股份有限公司 一种eSIM卡入网通信方法及其系统
CN109246704A (zh) * 2018-08-27 2019-01-18 北京智芯微电子科技有限公司 用于远程连接的安全审计系统及方法

Family Cites Families (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6918038B1 (en) * 1996-08-13 2005-07-12 Angel Secure Networks, Inc. System and method for installing an auditable secure network
US6532543B1 (en) * 1996-08-13 2003-03-11 Angel Secure Networks, Inc. System and method for installing an auditable secure network
CN1859114A (zh) * 2006-01-18 2006-11-08 华为技术有限公司 利用数据卡进行互联网访问的方法
US8844040B2 (en) * 2009-03-20 2014-09-23 Citrix Systems, Inc. Systems and methods for using end point auditing in connection with traffic management
EP2299631A1 (en) * 2009-09-17 2011-03-23 Gemalto SA Mechanism to detect that a portable security device configured a communication device
US8990560B2 (en) * 2011-06-17 2015-03-24 The Boeing Company Multiple independent levels of security (MILS) host to multilevel secure (MLS) offload communications unit
KR20130006258A (ko) * 2011-07-08 2013-01-16 주식회사 케이티 동적 키 생성 기반의 내장 sim의 mno 변경방법 및 그를 위한 내장 sim과 기록매체
CN102711089B (zh) * 2012-06-13 2015-08-26 中兴通讯股份有限公司 对移动终端进行锁网锁卡的方法及装置
CN104581721A (zh) * 2013-10-25 2015-04-29 北京旅信顺捷软件科技有限公司 基于双卡结构的移动业务数据处理方法、系统和移动终端
CN105320873B (zh) * 2014-07-02 2019-06-07 中国移动通信集团公司 一种终端应用的解锁方法、装置、终端及sim卡
CN107613487A (zh) * 2017-11-07 2018-01-19 恒宝股份有限公司 一种eSIM卡及其工作方法
CN108040044B (zh) * 2017-12-07 2019-06-07 恒宝股份有限公司 一种实现eSIM卡安全认证的管理方法及系统

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105141621A (zh) * 2015-09-16 2015-12-09 北京星网锐捷网络技术有限公司 网络访问的监控方法及装置
CN106131090A (zh) * 2016-08-31 2016-11-16 北京力鼎创软科技有限公司 一种web认证下的用户访问网络的方法和系统
US9949113B1 (en) * 2017-06-02 2018-04-17 Apple Inc. Updating profiles for secondary wireless devices
CN108024243A (zh) * 2017-12-05 2018-05-11 恒宝股份有限公司 一种eSIM卡入网通信方法及其系统
CN109246704A (zh) * 2018-08-27 2019-01-18 北京智芯微电子科技有限公司 用于远程连接的安全审计系统及方法

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115208593A (zh) * 2021-03-26 2022-10-18 南宁富联富桂精密工业有限公司 安全性监测方法、终端及计算机可读存储介质
CN115208593B (zh) * 2021-03-26 2023-08-18 南宁富联富桂精密工业有限公司 安全性监测方法、终端及计算机可读存储介质
CN116915503A (zh) * 2023-09-08 2023-10-20 成都卓拙科技有限公司 一种违规外联检测方法及装置、存储介质及电子设备
CN116915503B (zh) * 2023-09-08 2023-11-14 成都卓拙科技有限公司 一种违规外联检测方法及装置、存储介质及电子设备

Also Published As

Publication number Publication date
US20200404487A1 (en) 2020-12-24
CN109246704A (zh) 2019-01-18
US11184773B2 (en) 2021-11-23

Similar Documents

Publication Publication Date Title
CN110602096B (zh) 区块链网络中的数据处理方法、装置、存储介质和设备
CN110708336B (zh) 视频终端的认证方法及装置、电子设备、存储介质
CN110855777B (zh) 一种基于区块链的节点管理方法及装置
CN110602216B (zh) 多终端使用单账号的方法、装置、云服务器及存储介质
WO2020042856A1 (zh) 安全审计系统及方法
CN104767713A (zh) 账号绑定的方法、服务器及系统
CN113672894B (zh) 针对验证码请求的数据处理方法、装置、设备及存储介质
US20160105417A1 (en) Computer network security management system and method
US20220272538A1 (en) Classifier-based message routing in a telecommunications network
US20150220726A1 (en) Authentication Method, Authentication Apparatus and Authentication Device
CN105933886A (zh) 一种esim号码的写入方法、安全系统、esim号码服务器及终端
JP2019169880A (ja) 異常トラヒック分析装置、異常トラヒック分析方法及び異常トラヒック分析プログラム
CN103518205A (zh) 限制操作权限的方法及自动化设备
KR20070104633A (ko) 코어 네트워크를 보호하는 방법 및 장치
CN103428370B (zh) 手机的多用户控制方法及手机
KR101059058B1 (ko) 위치 기반 서비스 접근 제어 장치, 방법 및 시스템
JP7025098B2 (ja) 異常トラヒック分析装置、異常トラヒック分析方法及び異常トラヒック分析プログラム
CN111209574B (zh) 访问控制与访问行为识别方法、系统、设备及存储介质
CN119449463A (zh) 基于IPv6技术的网络权限控制方法、装置、设备及介质
CN115529156B (zh) 接入认证方法及装置、存储介质、计算机设备
JP7006882B2 (ja) 端末装置、通信制御システム及びプログラム
US11153877B2 (en) Method for bonding a plurality of radio connections in a wireless network
WO2022243956A1 (en) Method, mobile equipment, and system for vulnerability detection in a sim
US20220295259A1 (en) Conditional message routing in a telecommunications network
CN106131237A (zh) 容器间通信控制方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19853692

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19853692

Country of ref document: EP

Kind code of ref document: A1