WO2013123716A1 - 一种监控终端行为异常的方法和系统 - Google Patents

一种监控终端行为异常的方法和系统 Download PDF

Info

Publication number
WO2013123716A1
WO2013123716A1 PCT/CN2012/074591 CN2012074591W WO2013123716A1 WO 2013123716 A1 WO2013123716 A1 WO 2013123716A1 CN 2012074591 W CN2012074591 W CN 2012074591W WO 2013123716 A1 WO2013123716 A1 WO 2013123716A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
monitoring
hss
signaling
mtc
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2012/074591
Other languages
English (en)
French (fr)
Inventor
吴昊
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
ZTE Corp
Original Assignee
ZTE Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by ZTE Corp filed Critical ZTE Corp
Publication of WO2013123716A1 publication Critical patent/WO2013123716A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/02Processing of mobility data, e.g. registration information at HLR [Home Location Register] or VLR [Visitor Location Register]; Transfer of mobility data, e.g. between HLR, VLR or external networks

Definitions

  • the present invention relates to the field of machine type communication (MTC) technology, and in particular, to a method and system for monitoring abnormal behavior of a terminal.
  • MTC machine type communication
  • the existing cellular wireless communication system is composed of a core network (CN, Core Network), an access network (RAN, Radio Access Network), and a terminal, as shown in FIG.
  • the CN is responsible for non-access stratum transactions, such as terminal location update, and the CN is an anchor point of the user plane
  • the RAN is composed of a base station, or is composed of a base station and a base station controller, and the RAN is responsible for access layer transactions, such as management of radio resources.
  • a user equipment (UE, User Equipment) refers to various devices that can communicate with a cellular wireless communication network, such as a mobile terminal, a notebook computer, and the like.
  • the Mobility Management Entity (MME) or the Serving GPRS Support Node (SGSN) is the unit responsible for managing terminal access control, location information update, and handover in the core network.
  • the Home Subscriber Server (HSS) or the Home Location Register (HLR) is an entity in the core network that is responsible for storing subscription data, identity information, authentication information, and authorization information of the terminal device.
  • the HSS or HLR can be used to store the identity information of the user, and the binding information of the user and the terminal device, or only the identity information of the user (the binding information of the user and the terminal device can be saved by the gateway), or directly save the terminal.
  • the HSS or HLR is also responsible for the user's subscription database, as well as the execution user. Authentication and authorization, etc.
  • the service platform can query user or terminal information from the HSS or HLR.
  • the MTC Interoperability Function Entity is a connection entity between the mobile communication network and the external public network, which can implement functions such as protocol conversion, address query, and information storage.
  • the interworking function entity is connected to the MTC server, and can be connected to the mobile communication network element such as HSS/HLR or MME/SGSN.
  • the main object of the present invention is to provide a method and system for monitoring abnormal behavior of a terminal, so as to implement detection and up-and-down of abnormal behavior of the terminal.
  • the present invention provides a method for monitoring abnormal behavior of a terminal, the method comprising:
  • the mobility management unit monitors the behavior of the terminal, and sends an event report to the machine type communication interoperation function entity MTC IWF when detecting the occurrence of the monitoring event;
  • the MTC IWF sends an information query request signaling to the home subscriber server HSS, and receives the information query feedback signaling returned by the HSS;
  • the MTC IWF sends a monitoring event report to the information in the information query feedback signaling.
  • the mobility management unit monitors the behavior of the terminal, specifically:
  • the mobility management unit acquires subscription data of the terminal from the HSS or the home subscriber location register HLR, where the subscription data includes a monitoring event parameter;
  • the mobility management unit performs behavior on the terminal according to the acquired monitoring event parameter. Monitoring. After receiving the attach request signaling or the tracking area update request signaling from the terminal, the mobility management unit sends an update location request signaling to the HSS or the HLR;
  • the HSS or HLR sends update location approval signaling to the mobility management unit, and the update location approval signaling includes subscription data of the terminal.
  • the event report sent by the mobility management unit includes an international mobile subscriber identity code IMSI of the terminal, and a monitoring event.
  • the information query request signaling sent by the MTC IWF includes the IMSI of the terminal.
  • the information in the information query feedback signaling sent by the HSS includes: an external identifier of the terminal, and an identifier or address of the MTC server.
  • the monitoring event sent by the MTC IWF includes an external identifier and a monitoring event of the terminal.
  • the present invention also provides a system for monitoring abnormal behavior of a terminal, the system comprising: a mobility management unit, a machine type communication interoperation function entity MTC IWF and a home subscriber server HSS, the mobility management unit, configured to be used by the terminal The behavior is monitored, and an event report is sent to the MTC IWF when a monitoring event is detected;
  • the MTC IWF is configured to send information query request signaling to the HSS, and receive information query feedback signaling returned by the HSS; send a monitoring event report to the MTC server according to the information in the information query feedback signaling;
  • the HSS is configured to return information query feedback signaling to the MTC IWF after receiving the information query request signaling from the MTC IWF.
  • the mobility management unit is further configured to acquire subscription data of the terminal from the HSS or the home location register HLR, where the subscription data includes a monitoring event parameter, and monitor the behavior of the terminal according to the acquired monitoring event parameter.
  • the subscription data of the terminal obtained from the HSS or the HLR is specifically: After receiving the attach request signaling or tracking area update request signaling from the terminal, the mobility management unit sends an update location request signaling to the HSS or HLR, and receives an update sent by the HSS or HLR.
  • the location approval signaling includes the subscription data of the terminal in the update location approval signaling.
  • the event report sent by the mobility management unit includes an international mobile subscriber identity code IMSI of the terminal, and a monitoring event.
  • the information query request signaling sent by the MTC IWF includes the IMSI of the terminal.
  • the information in the information query feedback signaling sent by the HSS includes: an external identifier of the terminal, and an identifier or address of the MTC server.
  • the monitoring event sent by the MTC IWF includes an external identifier and a monitoring event of the terminal.
  • the present invention provides a method and system for monitoring abnormal behavior of a terminal.
  • the MTC IWF can obtain the identity or address of the correct MTC server from the HSS/HLR, and obtain the external identifier of the terminal that can be identified in the MTC server; thus, MTC The IWF can send monitoring event reports to the correct MTC server, and the MTC server can correctly identify the terminal that has an abnormal event.
  • DRAWINGS can obtain the identity or address of the correct MTC server from the HSS/HLR, and obtain the external identifier of the terminal that can be identified in the MTC server; thus, MTC The IWF can send monitoring event reports to the correct MTC server, and the MTC server can correctly identify the terminal that has an abnormal event.
  • FIG. 1 is a schematic structural diagram of a conventional cellular wireless communication system
  • FIG. 1 is a flowchart of a method for monitoring abnormal behavior of a terminal according to the present invention
  • FIG. 3 is a flowchart of a method for monitoring abnormal behavior of a terminal according to Embodiment 1 of the present invention
  • FIG. 4 is a flowchart of a method for monitoring abnormal behavior of a terminal according to Embodiment 2 of the present invention. detailed description
  • a method for monitoring abnormal behavior of a terminal provided by the present invention mainly includes the following steps: Step 201: The terminal sends an attach request signaling or a tracking area update request signaling to a mobility management unit (MME or SGSN).
  • MME mobility management unit
  • Step 202 The mobility management unit sends an update location request signaling to the HSS or the HLR.
  • Step 204 The mobility management unit monitors the behavior of the terminal according to the monitoring event parameter in the subscription data.
  • Step 205 After detecting the monitoring event, the mobility management unit sends an event report to the MTC IWF, where the report includes: an International Mobile Subscriber Identification Number (IMSI) of the terminal, and a monitoring event.
  • IMSI International Mobile Subscriber Identification Number
  • Step 206 The MTC IWF sends an information query request signaling to the HSS, where the terminal includes the IMSL.
  • Step 207 The HSS sends the information query feedback signaling to the MTC IWF, where: the external identifier of the terminal, and the identifier or address of the MTC server.
  • Step 208 The MTC IWF sends a monitoring event report to the MTC server according to the information in the information query feedback signaling, where the monitoring event report includes the external identifier of the terminal and the monitoring event.
  • the operator when the terminal enters the network, the operator needs to monitor the terminal device and the Universal Integrated Circuit Card (UICC) to change the event service, and monitor whether the user illegally steals the UICC card. .
  • UICC Universal Integrated Circuit Card
  • the user of the terminal wants the network to send a warning and report it to the MTC server, so that the user of the terminal can view the relevant event warning information on the MTC server.
  • Monitor event code or event description;
  • Monitor event A terminal device and UICC card association change
  • IMEI International Mobile Equipment Identity
  • the monitoring event parameter is saved in the HSS as the contract data of the terminal, and the following parameters are also saved in the HSS:
  • MTC Mobility Management Entity
  • the specific process includes:
  • Step 301 After the terminal is powered on, sending the attach request signaling to the MME, where the attach request signaling includes the internal identifier IMSI of the terminal in the mobile communication network;
  • Step 302 After receiving the attach request signaling of the terminal, the MME reads the IMSI therein, and sends the IMSI to the HSS in the update location request signaling.
  • Step 303 After receiving the update location request signaling sent by the MME, the HSS reads the
  • the IMSI queries the local database according to the IMSI to obtain the subscription data of the terminal, which includes: monitoring the event parameter; the HSS sends the update location approval signaling to the MME, and includes the subscription data of the terminal in the update location approval signaling, and the subscription data of the terminal. Includes: Monitoring event parameters.
  • the storage format is shown in the following table:
  • the MME After receiving the subscription data, if the MTC subscription data includes the monitoring event parameter, the MME reads the parameter: the monitoring event code and the device number.
  • the monitoring event code is set to monitor the event, indicating that it is necessary to monitor the event that the terminal device is associated with the UICC card.
  • the behavior of the terminal is monitored according to this, that is, whether the monitoring terminal is associated with the UICC card is changed.
  • Step 305 The MME sends control signaling to the terminal, requesting the terminal to report its own device number, that is, IMEI.
  • Step 306 After receiving the control signaling of the MME, the terminal includes its own IMEI in the feedback signaling and sends the information to the MME.
  • Step 307 After receiving the IMEI fed back by the terminal, the MME compares it with the device number in the subscription data. If the two are the same, it is considered that no monitoring event A is detected, and no subsequent operations are performed; if the two are different, Then, it is considered that the monitoring event A is detected, the MME generates an event report, and sends the event report to the MTC IWF.
  • Step 308 After receiving the event report sent by the MME, the MTC IWF reads the content in the event report, and the IMSI is included in the information query signaling and sent to the HSS.
  • Step 309 After receiving the information query signaling, the HSS reads the IMSI, and queries the local database according to the received IMSI to obtain the external identifier (ExID) of the terminal corresponding to the IMSI and the identifier or address of the MTC server (MTC— Server— A ), then send a message to query the feedback letter To the MTC IWF, the information contained in the information query signaling is shown in the following table:
  • Step 310 After receiving the information query feedback signaling sent by the HSS, the MTC IWF reads the information therein.
  • the identifier or address of the MTC server may be a serial number used to identify the MTC server, or may be an IP address of the MTC server. Based on the obtained serial number or IP address, the MTC IWF sends a monitoring event report to the corresponding MTC server.
  • the monitoring event report contains the following information:
  • the service contract with the operator needs to monitor the service of the terminal location change event, and is used to monitor whether someone illegally steals the terminal.
  • the user of the terminal wants the network to send a warning and report it to the MTC server, so that the user of the terminal can view the relevant event warning information on the MTC server.
  • monitoring event B The operator defines this event as monitoring event B and sets the corresponding monitoring event parameters as follows: Monitoring event code (or event description): Monitoring event B (terminal location change); Terminal location: Tracking area A
  • Monitoring event code or event description
  • Monitoring event B terminal location change
  • Terminal location Tracking area A
  • the monitoring event parameter is stored in the HSS as the subscription data of the terminal, and the following parameters are also saved in the HSS:
  • MTC Mobility Management Entity
  • the specific process includes:
  • Step 401 After the terminal moves to the new cell, reads the tracking area information in the cell broadcast information, compares the tracking area information of the new cell with the locally saved tracking area information, and finds that the two do not match, and the terminal sends the tracking.
  • the area update request signaling is sent to the new MME, and the tracking area update request signaling includes the temporary internal identifier (GUTI) of the original MME, and the identifier includes the identifier of the original MME.
  • GUI temporary internal identifier
  • Step 402 After receiving the tracking area update request signaling of the terminal, the MME reads the GUTI, obtains the identifier of the original MME, and sends data request signaling to the original MME. After the original MME receives the data request signaling, the MME sends the data request signaling. The IMSI is sent to the new MME, and the new MME sends the IMSI to the HSS in the update location request signaling.
  • Step 403 After receiving the update location request signaling sent by the MME, the HSS reads the IMSI, and queries the local database according to the IMSI to obtain the subscription data of the terminal, where: the monitoring event parameter is included; the HSS sends the update location approval signaling to The MME includes the subscription data of the terminal in the update location approval signaling, and the subscription data of the terminal includes: a monitoring event parameter.
  • the storage format is as shown in Table 1 above.
  • the MME After receiving the subscription data, if the MTC subscription data includes the monitoring event parameters, the MME reads the parameters therein: the monitoring event code and the terminal location.
  • the monitoring event code is set to monitor event B, indicating that the terminal location change event needs to be monitored, and the terminal location is tracking area A.
  • each MME belongs to a fixed tracking area and will be its own
  • the tracking area information of the genus is saved in the local database.
  • the tracking area to which the new MME belongs is the tracking area B.
  • Step 405 After reading the terminal location in the terminal subscription data, the MME compares the tracking area information saved by the local database with the terminal location information. If the two are the same, it is considered that no monitoring event B is detected, and no subsequent execution is performed. Operation; if the two are different, it is considered that the monitoring event B is detected, the MME generates an event report, and sends the event report to the MTC IWF.
  • Step 406 After receiving the event report sent by the MME, the MTC IWF reads the content in the event report, and the IMSI is included in the information query signaling and sent to the HSS.
  • Step 407 After receiving the information query signaling, the HSS reads the IMSI, and queries the local database according to the received IMSI to obtain the external identifier (ExID) of the terminal corresponding to the IMSI and the identifier or address of the MTC server (MTC— Server-A), then, sends information query feedback signaling to the MTC IWF, and the information contained in the information query signaling is as shown in Table 3 above.
  • ExID external identifier
  • MTC— Server-A MTC— Server-A
  • Step 408 After receiving the information query feedback signaling sent by the HSS, the MTC IWF reads the information therein.
  • the identifier or address of the MTC server may be a serial number used to identify the MTC server, or may be an IP address of the MTC server. Based on the obtained serial number or IP address, the MTC IWF sends a monitoring event report to the corresponding MTC server.
  • the information contained in the monitoring event report is shown in the following table: Information element note
  • Protocol identification information Used by the MTC server to identify the received signaling class, set here as "event report”
  • the external ID of the terminal is set to ExID
  • Monitoring event B Event occurrence location Set to tracking area B
  • the present invention further provides a system for monitoring terminal behavior abnormalities, which mainly includes: a mobility management unit, an MTC IWF, and an HSS,
  • the mobility management unit is configured to monitor the behavior of the terminal, and send an event report to the MTC IWF when detecting the occurrence of the monitoring event;
  • the MTC IWF is configured to send an information query request signaling to the HSS, and receive the information query feedback signaling returned by the HSS; send a monitoring event report according to the information in the information query feedback signaling.
  • the HSS is configured to return the information query feedback signaling to the MTC IWFo after receiving the information query request signaling from the MTC IWF.
  • the mobility management unit is further configured to acquire the subscription data of the terminal from the HSS or the HLR, where the subscription data includes a monitoring event parameter, and is further configured to monitor the behavior of the terminal according to the acquired monitoring event parameter.
  • the acquiring the subscription data of the terminal from the HSS or the HLR is specifically: after receiving the attach request signaling or the tracking area update request signaling from the terminal, the mobility management unit sends the update location request signaling to the HSS or the HLR, and receives the The update location approval signaling sent by the HSS or the HLR includes the subscription data of the terminal in the update location approval signaling.
  • the event report sent by the mobility management unit includes the IMSI and the monitoring event of the terminal;
  • the information query request signaling sent by the MTC IWF includes the IMSI of the terminal;
  • the information in the information query feedback signaling sent by the HSS includes: an external identifier of the terminal, and The ID or address of the MTC server;
  • the monitoring event report sent by the MTC IWF includes the external identifier of the terminal and the monitoring event.
  • the monitoring event is: the monitoring terminal is associated with the universal integrated circuit card UICC, and correspondingly, the mobility management unit monitors the behavior of the terminal according to the acquired monitoring event parameter, specifically:
  • the mobility management unit sends control signaling to the terminal, and the requesting terminal reports the device number; the mobility management unit receives the device number sent by the terminal through the feedback signaling;
  • the mobility management unit compares the device number in the feedback signaling with the device number in the subscription data of the terminal. If the two are the same, it is determined that no monitoring event is detected; if the two are different, it is determined that the monitoring event is detected. .
  • the monitoring event is: monitoring the location change of the terminal, and correspondingly, the mobility management unit monitors the behavior of the terminal according to the acquired monitoring event parameter, specifically:
  • the mobility management unit reads the terminal location in the subscription data of the terminal, and compares the terminal location in the subscription data with the tracking area information saved in the local database. If the two are the same, it is determined that no monitoring event occurs; If it is different, it is judged that a monitoring event is detected.

Landscapes

  • Engineering & Computer Science (AREA)
  • Databases & Information Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)

Abstract

本发明公开了一种监控终端行为异常的方法和系统,方法包括:移动性管理单元对终端的行为进行监控,并在检测到监控事件发生时发送事件报告给机器类型通信互操作功能实体(MTC IWF);MTC IWF发送信息查询请求信令给归属用户服务器(HSS),并接收HSS返回的信息查询反馈信令;MTC IWF根据信息查询反馈信令中的信息,发送监控事件报告给MTC服务器。通过本发明,实现了对终端行为异常的检测和上报。

Description

一种监控终端行为异常的方法和系统 技术领域
本发明涉及机器类型通信(MTC, Machine Type Communication )技术 领域, 尤其涉及一种监控终端行为异常的方法和系统。 背景技术
现有的蜂窝无线通信系统如图 1所示,由核心网(CN, Core Network ), 接入网 (RAN, Radio Access Network )和终端组成。 其中, CN负责非接 入层事务, 例如终端位置更新等, 且 CN是用户面的锚点; RAN由基站、 或者由基站和基站控制器组成, RAN负责接入层事务, 例如无线资源的管 理, 基站之间可以根据实际情况存在物理或逻辑上的连接, 如图 1 中的基 站 1与基站 2、或者基站 3之间的连接, 并且每个基站可以与一个或者一个 以上的 CN节点连接; 终端即用户设备 ( UE , User Equipment )是指可以与 蜂窝无线通信网络通信的各种设备, 如移动终端、 笔记本电脑等。
移动性管理单元(移动性管理实体( MME, Mobility Management Entity ) 或者服务 GPRS支持节点(SGSN, Serving GPRS Support Node ) )是核心网 中负责管理终端接入控制、 位置信息更新以及切换的单元, 负责核心网到 终端的非接入层信令控制和将终端注册到网络。
归属用户服务器(HSS, Home Subscriber Server )或归属用户位置寄存 器( HLR, Home Location Register )是核心网中负责保存终端设备的签约数 据、身份信息、认证信息和授权信息等的实体。根据不同情况, HSS或 HLR 可用于保存用户的身份信息、 及用户和终端设备的绑定信息, 或只保存用 户的身份信息(可由网关保存用户和终端设备的绑定信息), 或直接保存终 端设备的身份信息。 HSS或 HLR还负责用户的签约数据库, 以及执行用户 的身份验证和授权等。 业务平台可从 HSS或 HLR查询用户或终端信息。
MTC互操作功能实体( MTC IWF )是在移动通信网和外部公网之间的 一个连接实体, 能够实现协议转换、 地址查询、 信息保存等功能。 互操作 功能实体对外连接 MTC服务器,对内可以连接到 HSS/HLR、或 MME/SGSN 等移动通信网络网元。
在实际应用中, 用户通常需要能对其终端进行监控, 比如: 一些固定 放置的终端是否被人非法移动、 或者是否被人非法调换用户身份识别模块
( SIM, Subscriber Identity Module )卡等等。 这就需要一些网元能监控终端 的行为, 并能在发生终端行为异常后报告给 MTC服务器。 然而, 现有技术 还无法提供解决上述问题的方法。 发明内容
有鉴于此, 本发明的主要目的在于提供一种监控终端行为异常的方法 和系统, 以实现对终端行为异常的检测和上才艮。
为达到上述目的, 本发明的技术方案是这样实现的:
本发明提供了一种监控终端行为异常的方法, 该方法包括:
移动性管理单元对终端的行为进行监控, 并在检测到监控事件发生时 发送事件报告给机器类型通信互操作功能实体 MTC IWF;
所述 MTC IWF发送信息查询请求信令给归属用户服务器 HSS,并接收 所述 HSS返回的信息查询反馈信令;
所述 MTC IWF根据信息查询反馈信令中的信息,发送监控事件报告给
MTC服务器。
所述移动性管理单元对终端的行为进行监控, 具体为:
所述移动性管理单元从 HSS或归属用户位置寄存器 HLR获取终端的签 约数据, 所述签约数据中包括监控事件参数;
所述移动性管理单元根据获取的监控事件参数对所述终端的行为进行 监控。 所述移动性管理单元接收到来自所述终端的附着请求信令或跟踪区更 新请求信令后, 向所述 HSS或 HLR发送更新位置请求信令;
所述 HSS或 HLR发送更新位置认可信令给所述移动性管理单元,所述 更新位置认可信令中包括所述终端的签约数据。
所述移动性管理单元发送的事件报告中包括所述终端的国际移动用户 识别码 IMSI、 监控事件。
所述 MTC IWF发送的信息查询请求信令中包含所述终端的 IMSI。
所述 HSS发送的信息查询反馈信令中的信息包括: 所述终端的外部标 识、 以及 MTC 良务器的标识或地址。
所述 MTC IWF发送的监控事件 4艮告中包括所述终端的外部标识、监控 事件。
本发明还提供了一种监控终端行为异常的系统, 该系统包括: 移动性 管理单元、机器类型通信互操作功能实体 MTC IWF和归属用户服务器 HSS, 所述移动性管理单元, 用于对终端的行为进行监控, 并在检测到监控 事件发生时发送事件报告给所述 MTC IWF;
所述 MTC IWF, 用于发送信息查询请求信令给所述 HSS, 并接收所述 HSS 返回的信息查询反馈信令; 根据信息查询反馈信令中的信息, 发送监 控事件报告给 MTC服务器;
所述 HSS,用于在收到来自所述 MTC IWF的信息查询请求信令后,返 回信息查询反馈信令给所述 MTC IWF。
所述移动性管理单元还用于,从 HSS或归属用户位置寄存器 HLR获取 终端的签约数据, 所述签约数据中包括监控事件参数; 根据获取的监控事 件参数对所述终端的行为进行监控。
所述从 HSS或 HLR获取终端的签约数据具体为: 所述移动性管理单元在接收到来自所述终端的附着请求信令或跟踪区 更新请求信令后, 向所述 HSS或 HLR发送更新位置请求信令,并接收所述 HSS或 HLR发送的更新位置认可信令, 所述更新位置认可信令中包括所述 终端的签约数据。
所述移动性管理单元发送的事件报告中包括所述终端的国际移动用户 识别码 IMSI、 监控事件。
所述 MTC IWF发送的信息查询请求信令中包含所述终端的 IMSI。 所述 HSS发送的信息查询反馈信令中的信息包括: 所述终端的外部标 识、 以及 MTC 良务器的标识或地址。
所述 MTC IWF发送的监控事件 4艮告中包括所述终端的外部标识、监控 事件。
本发明所提供的一种监控终端行为异常的方法和系统, MTC IWF能从 HSS/HLR获取正确的 MTC服务器的标识或地址,以及获取能在 MTC服务 器被识别的终端的外部标识; 从而, MTC IWF能将监控事件报告发送到正 确的 MTC服务器, 并且 MTC服务器能正确的识别发生异常事件的终端。 附图说明
图 1为现有的蜂窝无线通信系统的结构示意图;
图 1为本发明一种监控终端行为异常的方法流程图;
图 3为本发明实施例一的监控终端行为异常的方法流程图;
图 4为本发明实施例二的监控终端行为异常的方法流程图。 具体实施方式
下面结合附图和具体实施例对本发明的技术方案进一步详细阐述。 本发明所提供的一种监控终端行为异常的方法, 如图 2所示, 主要包 括以下步驟: 步驟 201,终端发送附着请求信令或跟踪区更新请求信令给移动性管理 单元( MME或 SGSN )。
步驟 202, 移动性管理单元向 HSS或 HLR发送更新位置请求信令。 步驟 203 , HSS或 HLR发送更新位置认可信令给移动性管理单元, 在 更新位置认可信令中包含终端的签约数据, 终端的签约数据中包括: 监控 事件参数。
步驟 204,移动性管理单元根据签约数据中的监控事件参数对终端的行 为进行监控。
步驟 205, 移动性管理单元检测到监控事件后, 发送事件报告给 MTC IWF,报告中包含: 终端的国际移动用户识别码( IMSI, International Mobile Subscriber Identification Number )、 监控事件。
步驟 206, MTC IWF发送信息查询请求信令给 HSS, 其中包含终端的 IMSL
步驟 207, HSS发送信息查询反馈信令给 MTC IWF, 其中包含: 终端 的外部标识、 以及 MTC 良务器的标识或地址。
步驟 208, MTC IWF根据信息查询反馈信令中的信息, 发送监控事件 报告给 MTC服务器, 监控事件报告中包含终端的外部标识、 监控事件。
下面结合具体实施例对本发明的监控终端行为异常的方法进一步详细 阐述。
在本发明的实施例一中, 终端在入网时, 与运营商签约需要监控终端 设备与通用集成电路卡( UICC, Universal Integrated Circuit Card )关联变更 事件的服务,用于监控是否有人非法盗用 UICC卡。一旦有人非法盗用 UICC 卡, 在其他终端上使用, 终端的使用者希望网络能发送警告并报告给 MTC 服务器,这样终端的使用者就可以在 MTC服务器上查看到相关的事件警告 信息。
运营商将该事件定义为监控事件 A,并设置相应的监控事件参数如下: 监控事件代码 (或事件描述;): 监控事件 A (终端设备与 UICC卡关联 变更);
设备号:为终端的国际移动电话设备识别码( IMEI , International Mobile Equipment Identity )。
该监控事件参数作为该终端的签约数据保存在 HSS中,同时,还在 HSS 中保存下列参数:
终端的外部标识: ExID;
MTC服务器的标识或地址: MTC— Server— A, 用于使 MTC IWF能够根 据该标识将监控报告发送到正确的 MTC服务器。
具体流程包括:
步驟 301 , 终端开机后, 发送附着请求信令给 MME, 附着请求信令中 包含终端在移动通信网络的内部标识 IMSI;
步驟 302 , MME在接收到终端的附着请求信令后, 读取其中的 IMSI , 并将 IMSI包含在更新位置请求信令中发送给 HSS。
步驟 303 , HSS接收到 MME发送的更新位置请求信令后, 读取其中的
IMSI, 根据 IMSI查询本地数据库, 获得该终端的签约数据, 其中包括: 监 控事件参数; HSS发送更新位置认可信令给 MME, 在更新位置认可信令中 包含终端的签约数据, 终端的签约数据中包括: 监控事件参数。 储格式如下表所示:
Figure imgf000008_0001
表 1 MME在接收到签约数据后, 如果其中的 MTC签约数据中包含监控事 件参数,则 ΜΜΕ读取其中的参数:监控事件代码和设备号。在本实施例中, 监控事件代码设置为监控事件 Α,表示需要监控终端设备与 UICC卡关联变 更的事件。 在读取监控事件参数后, ΜΜΕ依此对终端的行为进行监控, 即 监控终端与 UICC卡关联是否变更。
步驟 305 , MME发送控制信令给终端, 请求终端报告自己的设备号、 即 IMEI。
步驟 306, 终端接收到 MME的控制信令后, 将自身的 IMEI包含在反 馈信令中发送给 MME。
步驟 307, MME接收到终端反馈的 IMEI后, 将其与签约数据中的设 备号进行比较, 如果两者相同, 则认为没有检测到监控事件 A发生, 不再 执行后续操作; 如果两者不同, 则认为检测到监控事件 A发生, MME生成 事件报告, 并将事件报告发送给 MTC IWF。
事件报告的内容如下表所示:
Figure imgf000009_0001
表 2
步驟 308, MTC IWF接收到 MME发送的事件报告后, 读取事件报告 中的内容, 将 IMSI包含在信息查询信令中发送给 HSS。
步驟 309, HSS接收到信息查询信令后, 读取其中的 IMSI, 根据接收 到的 IMSI查询本地数据库,获得与该 IMSI对应的终端的外部标识( ExID ) 和 MTC服务器的标识或地址( MTC— Server— A ), 然后发送信息查询反馈信 令给 MTC IWF, 信息查询信令中包含的信息如下表所示:
Figure imgf000010_0001
表 3
步驟 310, MTC IWF接收到 HSS发送的信息查询反馈信令后, 读取其 中的信息, 这里 MTC服务器的标识或地址可以是用于识别 MTC服务器的 串号,也可以是 MTC服务器的 IP地址。根据所获得的串号或 IP地址, MTC IWF将监控事件报告发送到相应的 MTC服务器。 其中,监控事件报告包含 的信息如下表所示:
Figure imgf000010_0002
表 4
在本发明的实施例二中, 终端在入网时, 与运营商签约需要监控终端 位置变更事件的服务, 用于监控是否有人非法盗用终端。 一旦有人非法盗 用终端, 将终端带离原来固定的位置, 终端的使用者希望网络能发送警告 并报告给 MTC服务器, 这样终端的使用者可以在 MTC服务器上查看到相 关的事件警告信息。
运营商将该事件定义为监控事件 B,并设置相应的监控事件参数如下: 监控事件代码(或事件描述): 监控事件 B (终端位置变更); 终端位置: 跟踪区 A 该监控事件参数作为该终端的签约数据保存在 HSS中,同时,还在 HSS 中保存下列参数:
终端的外部标识: ExID;
MTC服务器的标识或地址: MTC— Server— A, 用于使 MTC IWF能够根 据该标识将监控报告发送到正确的 MTC服务器。
具体流程包括:
步驟 401 , 当终端移动到新的小区,读取小区广播信息中的跟踪区信息 后, 将新的小区的跟踪区信息与本地保存的跟踪区信息对比后发现两者不 匹配, 则终端发送跟踪区更新请求信令给新的 MME, 跟踪区更新请求信令 中包含原 MME 为终端分配的临时内部标识 ( GUTI , Global Unique Temporary Identity ), 该标识中包含有原 MME的标识。
步驟 402, MME在接收到终端的跟踪区更新请求信令后, 读取其中的 GUTI, 获得原 MME的标识, 向原 MME发送数据请求信令, 原 MME接 收到数据请求信令后, 将该终端的 IMSI发送给新的 MME, 新的 MME将 IMSI包含在更新位置请求信令中发送给 HSS。
步驟 403 , HSS接收到 MME发送的更新位置请求信令后, 读取其中的 IMSI, 根据 IMSI查询本地数据库, 获得该终端的签约数据, 其中包括: 监 控事件参数; HSS发送更新位置认可信令给 MME, 在更新位置认可信令中 包含终端的签约数据, 终端的签约数据中包括: 监控事件参数。 储格式如前述表 1所示。
MME在接收到签约数据后, 如果其中的 MTC签约数据中包含监控事 件参数, 则 MME读取其中的参数: 监控事件代码和终端位置。在本实施例 中, 监控事件代码设置为监控事件 B, 表示需要监控终端位置变更事件, 终端位置为跟踪区 A。
需要说明的是,通常每个 MME都属于一个固定的跟踪区,并将自己所 属的跟踪区信息保存在本地数据库。在本实施例中,新的 MME所属的跟踪 区为 艮踪区 B。
步驟 405 , 在读取终端签约数据中的终端位置后, MME将本地数据库 保存的跟踪区信息与终端位置信息做比较, 如果两者相同, 则认为没有检 测到监控事件 B发生, 不再执行后续操作; 如果两者不同, 则认为检测到 监控事件 B发生, MME生成事件报告, 并将事件报告发送给 MTC IWF。
事件报告的内容如下表所示:
Figure imgf000012_0001
表 5
步驟 406 , MTC IWF接收到 MME发送的事件报告后, 读取事件报告 中的内容, 将 IMSI包含在信息查询信令中发送给 HSS。
步驟 407, HSS接收到信息查询信令后, 读取其中的 IMSI, 根据接收 到的 IMSI查询本地数据库,获得与该 IMSI对应的终端的外部标识( ExID ) 和 MTC服务器的标识或地址(MTC— Server— A ), 然后, 发送信息查询反馈 信令给 MTC IWF , 信息查询信令中包含的信息如前述表 3所示。
步驟 408 , MTC IWF接收到 HSS发送的信息查询反馈信令后, 读取其 中的信息, 这里 MTC服务器的标识或地址可以是用于识别 MTC服务器的 串号,也可以是 MTC服务器的 IP地址。根据所获得的串号或 IP地址, MTC IWF将监控事件报告发送到相应的 MTC服务器。 其中,监控事件报告包含 的信息如下表所示: 信息元 备注
协议识别信息 用于 MTC server识别接收到的信令类别, 这里设 置为 "事件报告"
终端的外部标识 设置为 ExID
监控事件 检测到的监控事件, 在这里设置为: 监控事件 B 事件发生位置 设置为跟踪区 B
表 6
对应上述监控终端行为异常的方法, 本发明还提供了一种监控终端行 为异常的系统, 主要包括: 移动性管理单元、 MTC IWF和 HSS,
其中, 移动性管理单元, 用于对终端的行为进行监控, 并在检测到监 控事件发生时发送事件报告给 MTC IWF;
MTC IWF, 用于发送信息查询请求信令给 HSS, 并接收 HSS返回的信 息查询反馈信令; 根据信息查询反馈信令中的信息, 发送监控事件报告给
MTC服务器;
HSS, 用于在收到来自 MTC IWF的信息查询请求信令后, 返回信息查 询反馈信令给 MTC IWFo
较佳的,移动性管理单元还用于,从 HSS或 HLR获取终端的签约数据, 该签约数据中包括监控事件参数; 还用于根据获取的监控事件参数对终端 的行为进行监控。
其中,从 HSS或 HLR获取终端的签约数据具体为: 移动性管理单元在 接收到来自终端的附着请求信令或跟踪区更新请求信令后, 向 HSS或 HLR 发送更新位置请求信令, 并接收 HSS或 HLR发送的更新位置认可信令, 更 新位置认可信令中包括终端的签约数据。
其中,移动性管理单元发送的事件报告中包括终端的 IMSI、监控事件;
MTC IWF发送的信息查询请求信令中包含终端的 IMSI;
HSS发送的信息查询反馈信令中的信息包括: 终端的外部标识、 以及 MTC服务器的标识或地址;
MTC IWF发送的监控事件报告中包括终端的外部标识、 监控事件。 较佳的,监控事件为: 监控终端与通用集成电路卡 UICC关联变更, 相 应的, 移动性管理单元根据获取的监控事件参数对终端的行为进行监控, 具体为:
移动性管理单元发送控制信令给终端 , 请求终端报告设备号; 移动性管理单元接收终端通过反馈信令发送的设备号;
移动性管理单元将反馈信令中的设备号与终端的签约数据中的设备号 进行比较, 如果两者相同, 则判断没有检测到监控事件发生; 如果两者不 同, 则判断检测到监控事件发生。
较佳的, 监控事件为: 监控终端位置变更, 相应的, 移动性管理单元 根据获取的监控事件参数对终端的行为进行监控, 具体为:
移动性管理单元读取终端的签约数据中的终端位置, 并将签约数据中 的终端位置与本地数据库保存的跟踪区信息进行比较, 如果两者相同, 则 判断没有检测到监控事件发生; 如果两者不同, 则判断检测到监控事件发 生。
以上所述, 仅为本发明的较佳实施例而已, 并非用于限定本发明的保 护范围。

Claims

权利要求书
1、 一种监控终端行为异常的方法, 其特征在于, 该方法包括: 移动性管理单元对终端的行为进行监控, 并在检测到监控事件发生 时发送事件报告给机器类型通信互操作功能实体 MTC IWF;
所述 MTC IWF发送信息查询请求信令给归属用户服务器 HSS,并接 收所述 HSS返回的信息查询反馈信令;
所述 MTC IWF根据信息查询反馈信令中的信息,发送监控事件报告 给 MTC服务器。
2、 根据权利要求 1所述监控终端行为异常的方法, 其特征在于, 所 述移动性管理单元对终端的行为进行监控, 具体为:
所述移动性管理单元从 HSS或归属用户位置寄存器 HLR获取终端的 签约数据, 所述签约数据中包括监控事件参数;
所述移动性管理单元根据获取的监控事件参数对所述终端的行为进 行监控。
3、 根据权利要求 2所述监控终端行为异常的方法, 其特征在于, 所 所述移动性管理单元接收到来自所述终端的附着请求信令或跟踪区 更新请求信令后, 向所述 HSS或 HLR发送更新位置请求信令;
所述 HSS或 HLR发送更新位置认可信令给所述移动性管理单元,所 述更新位置认可信令中包括所述终端的签约数据。
4、 根据权利要求 1、 2或 3所述监控终端行为异常的方法, 其特征 在于, 所述移动性管理单元发送的事件报告中包括所述终端的国际移动 用户识别码 IMSI、 监控事件。
5、 根据权利要求 4所述监控终端行为异常的方法, 其特征在于, 所 述 MTC IWF发送的信息查询请求信令中包含所述终端的 IMSI。
6、 根据权利要求 5所述监控终端行为异常的方法, 其特征在于, 所 述 HSS发送的信息查询反馈信令中的信息包括: 所述终端的外部标识、 以及 MTC服务器的标识或地址。
7、 根据权利要求 6所述监控终端行为异常的方法, 其特征在于, 所 述 MTC IWF发送的监控事件报告中包括所述终端的外部标识、监控事件。
8、 一种监控终端行为异常的系统, 其特征在于, 该系统包括: 移动 性管理单元、机器类型通信互操作功能实体 MTC IWF和归属用户服务器 HSS,
所述移动性管理单元, 用于对终端的行为进行监控, 并在检测到监 控事件发生时发送事件报告给所述 MTC IWF;
所述 MTC IWF, 用于发送信息查询请求信令给所述 HSS, 并接收所 述 HSS返回的信息查询反馈信令; 根据信息查询反馈信令中的信息, 发 送监控事件报告给 MTC服务器;
所述 HSS, 用于在收到来自所述 MTC IWF的信息查询请求信令后, 返回信息查询反馈信令给所述 MTC IWF。
9、 根据权利要求 8所述监控终端行为异常的系统, 其特征在于, 所 述移动性管理单元还用于,从 HSS或归属用户位置寄存器 HLR获取终端 的签约数据, 所述签约数据中包括监控事件参数; 根据获取的监控事件 参数对所述终端的行为进行监控。
10、 根据权利要求 9 所述监控终端行为异常的系统, 其特征在于, 所述从 HSS或 HLR获取终端的签约数据具体为:
所述移动性管理单元在接收到来自所述终端的附着请求信令或跟踪 区更新请求信令后, 向所述 HSS或 HLR发送更新位置请求信令,并接收 所述 HSS或 HLR发送的更新位置认可信令,所述更新位置认可信令中包 括所述终端的签约数据。
11、根据权利要求 8、 9或 10所述监控终端行为异常的系统, 其特征 在于, 所述移动性管理单元发送的事件报告中包括所述终端的国际移动 用户识别码 IMSI、 监控事件。
12、 根据权利要求 11所述监控终端行为异常的系统, 其特征在于, 所述 MTC IWF发送的信息查询请求信令中包含所述终端的 IMSI。
13、 根据权利要求 12 所述监控终端行为异常的系统, 其特征在于, 所述 HSS发送的信息查询反馈信令中的信息包括:所述终端的外部标识、 以及 MTC服务器的标识或地址。
14、 根据权利要求 13 所述监控终端行为异常的系统, 其特征在于, 所述 MTC IWF发送的监控事件报告中包括所述终端的外部标识、监控事 件。
PCT/CN2012/074591 2012-02-24 2012-04-24 一种监控终端行为异常的方法和系统 Ceased WO2013123716A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN2012100443941A CN103297946A (zh) 2012-02-24 2012-02-24 一种监控终端行为异常的方法和系统
CN201210044394.1 2012-02-24

Publications (1)

Publication Number Publication Date
WO2013123716A1 true WO2013123716A1 (zh) 2013-08-29

Family

ID=49004960

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2012/074591 Ceased WO2013123716A1 (zh) 2012-02-24 2012-04-24 一种监控终端行为异常的方法和系统

Country Status (2)

Country Link
CN (1) CN103297946A (zh)
WO (1) WO2013123716A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110969265A (zh) * 2019-12-04 2020-04-07 国网河南省电力公司南阳供电公司 一种输电线路监督方法、装置和计算机可读存储介质

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105338615B (zh) * 2014-08-12 2019-12-03 中兴通讯股份有限公司 用户设备的注册方法、实体及系统
CN106981104B (zh) * 2017-03-24 2020-04-21 北京悦畅科技有限公司 一种收费监控方法、装置、服务器和系统
CN115426653B (zh) * 2018-11-02 2025-03-25 华为技术有限公司 类别信息的确定方法及装置

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102056140A (zh) * 2009-11-06 2011-05-11 中兴通讯股份有限公司 机器类通讯终端信息的获取方法和系统
CN102202270A (zh) * 2010-03-24 2011-09-28 中兴通讯股份有限公司 基于机器类通信的消息传输方法及互通功能实体
CN102238517A (zh) * 2010-04-26 2011-11-09 中兴通讯股份有限公司 机器类通信事件上报方法、装置及系统
CN102238617A (zh) * 2010-04-30 2011-11-09 中兴通讯股份有限公司 机器类通信事件上报方法及系统

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102158835B (zh) * 2010-02-12 2014-11-05 华为技术有限公司 机器类型通信信息传输方法和设备及系统
CN103781015A (zh) * 2012-10-17 2014-05-07 中兴通讯股份有限公司 一种机器类型通信设备事件的监控方法、系统和网络侧

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102056140A (zh) * 2009-11-06 2011-05-11 中兴通讯股份有限公司 机器类通讯终端信息的获取方法和系统
CN102202270A (zh) * 2010-03-24 2011-09-28 中兴通讯股份有限公司 基于机器类通信的消息传输方法及互通功能实体
CN102238517A (zh) * 2010-04-26 2011-11-09 中兴通讯股份有限公司 机器类通信事件上报方法、装置及系统
CN102238617A (zh) * 2010-04-30 2011-11-09 中兴通讯股份有限公司 机器类通信事件上报方法及系统

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110969265A (zh) * 2019-12-04 2020-04-07 国网河南省电力公司南阳供电公司 一种输电线路监督方法、装置和计算机可读存储介质
CN110969265B (zh) * 2019-12-04 2024-04-02 国网河南省电力公司南阳供电公司 一种输电线路监督方法、装置和计算机可读存储介质

Also Published As

Publication number Publication date
CN103297946A (zh) 2013-09-11

Similar Documents

Publication Publication Date Title
CN103209402B (zh) 终端组可及性确定方法及系统
EP2824967B1 (en) Device discovery method, device, and system
CN102404825B (zh) 一种通过nas信令触发终端的方法和系统
CN103188616B (zh) 一种终端组的管理方法和系统
CN102075909A (zh) 一种imsi与imei绑定关系的校验方法和装置
CN103024719B (zh) 终端组的移动性管理实体选择方法及系统
WO2012113178A1 (zh) 检测终端连接丢失的方法及装置
CN103024810B (zh) 一种触发消息发送方法及系统
WO2013123716A1 (zh) 一种监控终端行为异常的方法和系统
EP3086580B1 (en) Accessibility management method and device for m2m terminal/terminal peripheral
CN102869015B (zh) 一种mtc设备触发的方法和系统
CN102858026B (zh) 一种触发特定位置终端的方法、系统和终端
WO2013139073A1 (zh) 一种发送终端监控报告的方法及系统
CN102868995B (zh) 终端接入方法及系统
EP2725830B1 (en) Method and system for triggering response of terminal, terminal and network side
CN102932748B (zh) 一种触发终端组的方法及系统
CN103108305B (zh) 一种终端触发消息有效时间控制方法及系统
CN103037502A (zh) 一种处理终端触发消息的方法及系统
CN102448168B (zh) 一种触发离线状态mtc设备的方法和系统
CN100372427C (zh) 一种向请求端提供用户设备位置信息的处理方法
CN102958036B (zh) 一种终端触发的方法及系统
CN102857899B (zh) 一种mtc设备的接入控制方法和系统
CN103249012B (zh) 触发消息的发送方法、装置及系统
CN103179542A (zh) 终端触发消息处理方法、系统及相关网元
WO2013082919A1 (zh) 一种机器类型通信设备的连接控制方法及系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12869460

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 12869460

Country of ref document: EP

Kind code of ref document: A1