Network security management method, and apparatus

    公开(公告)号:US11895157B2

    公开(公告)日:2024-02-06

    申请号:US17939637

    申请日:2022-09-07

    IPC分类号: H04L9/40 H04W76/10

    CPC分类号: H04L63/20 H04L63/08 H04W76/10

    摘要: Embodiments of this application provide a network security management method and an apparatus. The method includes: receiving, by a first network device, a session request sent by a terminal device, where the session request is used to request establishment of a first session with a first data network, the session request includes first authentication information for the first session, and the first authentication information includes identifier information of the first data network; obtaining, by the first network device, second authentication information for a second session of the terminal device, where the second authentication information includes identifier information of a second data network to which the second session is connected; and if the identifier information of the first data network is the same as the identifier information of the second data network, authorizing the terminal device to establish the first session with the first data network.

    Blacklist management method for IBC-based distributed authentication framework

    公开(公告)号:US10581860B2

    公开(公告)日:2020-03-03

    申请号:US16372668

    申请日:2019-04-02

    摘要: A system for managing and distributing a blacklist of User Equipment IDs (UE IDs) in a network. The system comprises a number of groups of networks, each of the groups of networks comprise a blacklist server and a number of authentication servers. The system further comprises a Package Key Generator (PKG). The blacklist server is configured to: store a blacklist containing UE IDs that are not allowed to gain access to the network; transmit the blacklist to the plurality of authentication servers in the same group; receive a message; determine a content in the message is an order to add a new revoked UE ID to the blacklist; update the blacklist to include the new revoked UE ID; and send an update blacklist message to the plurality of authentication servers in the same group.

    NETWORK SECURITY MANAGEMENT METHOD, AND APPARATUS

    公开(公告)号:US20240223613A1

    公开(公告)日:2024-07-04

    申请号:US18415304

    申请日:2024-01-17

    IPC分类号: H04L9/40 H04W76/10

    CPC分类号: H04L63/20 H04L63/08 H04W76/10

    摘要: Embodiments of this application provide a network security management method and an apparatus. The method includes: receiving, by a first network device, a session request sent by a terminal device, where the session request is used to request establishment of a first session with a first data network, the session request includes first authentication information for the first session, and the first authentication information includes identifier information of the first data network; obtaining, by the first network device, second authentication information for a second session of the terminal device, where the second authentication information includes identifier information of a second data network to which the second session is connected; and if the identifier information of the first data network is the same as the identifier information of the second data network, authorizing the terminal device to establish the first session with the first data network.

    Network security management method, and apparatus

    公开(公告)号:US11477242B2

    公开(公告)日:2022-10-18

    申请号:US16746479

    申请日:2020-01-17

    IPC分类号: H04L9/40 H04W76/10

    摘要: Embodiments of this application provide a network security management method and an apparatus. The method includes: receiving, by a first network device, a session request sent by a terminal device, where the session request is used to request establishment of a first session with a first data network, the session request includes first authentication information for the first session, and the first authentication information includes identifier information of the first data network; obtaining, by the first network device, second authentication information for a second session of the terminal device, where the second authentication information includes identifier information of a second data network to which the second session is connected; and if the identifier information of the first data network is the same as the identifier information of the second data network, authorizing the terminal device to establish the first session with the first data network.

    Session processing method and device

    公开(公告)号:US11425202B2

    公开(公告)日:2022-08-23

    申请号:US16659334

    申请日:2019-10-21

    摘要: Embodiments of a session processing method and a device relating to a data network are provided. The method includes a data-network network element in the data network receiving a data network access request sent by a session management function (SMF) network element of the data network, where the data network access request includes an identifier of user equipment UE and a session address to be used by the UE. The data-network network element sends a response message to the SMF, where the response message instructs the SMF to allow the UE to access the data network, so that the SMF establishes a data packet unit session of the UE. The data-network network element detects, based on the session address or the identifier of the UE, that the data packet unit session of the UE needs to be processed, generates a session processing request, and instructs, by using the session processing request, the SMF to process the data packet unit session of the UE.