Authenticity query method and terminal device thereof

By automatically reading and displaying the network access permission information in the terminal device and verifying it with the server, the problems of aesthetics, cost and operational difficulties caused by paper labels are solved, and convenient and accurate device authenticity query is achieved.

CN113196262BActive Publication Date: 2025-09-26HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN201880100352.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2018-12-22
Publication Date
2025-09-26
Estimated Expiration
2038-12-22

AI Technical Summary

Technical Problem

In the prior art, the network access permission mark of telecommunication equipment is affixed in paper form, which affects the appearance of the equipment, has high transportation and inspection costs, and is easily damaged and lost, making the authenticity verification operation difficult and the user experience poor.

Method used

A terminal device that automatically reads network access permission information is used, which displays and sends an authenticity query request to the server through the user interface, obtains and displays the authenticity query result, and stores the network access permission information in the terminal device to prevent loss. It also supports QR code query and operating system setup wizard verification.

Benefits of technology

It improves the convenience and accuracy of terminal device authenticity query, reduces the risk of damage to paper labels, eliminates the need for users to manually enter information, ensures that the authenticity of the device can be checked at any time, and reduces transportation and inspection costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113196262B_ABST
    Figure CN113196262B_ABST
Patent Text Reader

Abstract

The present disclosure relates to an authenticity query method and a terminal device thereof. The network access permission information of a terminal device is automatically read and a first user interface including the network access permission information and an authenticity query interactive element is displayed; when an input is received from a user selecting an authenticity query interactive element, an authenticity query request carrying the above network access permission information is sent to an authenticity verification server, and an authenticity query result corresponding to the above network access permission information is received from the authenticity verification server and the authenticity query result is displayed. Through the solution provided by the present application, the user can intuitively see the network access permission information of the device and conveniently query the authenticity of the terminal device through the user interface of the terminal device, thereby significantly improving the convenience of authenticity query of the terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of intelligent terminals, and more particularly, to an authenticity query method and a terminal device thereof. Background Art

[0002] China implements a network access licensing system for telecommunications terminal equipment, radio communication equipment, and telecommunications equipment used to access public telecommunications networks. Telecommunications equipment subject to the network access licensing system must obtain a network access license issued by the Ministry of Industry and Information Technology of China.

[0003] Telecommunications equipment manufacturers must affix the network access permission mark to their network access-permitted telecommunications equipment. This mark, uniformly printed and issued by the Ministry of Industry and Information Technology, serves as a quality mark. Telecommunications equipment that has not obtained a network access permission or whose network access permission has expired must not be affixed with the network access permission mark. The network access permission mark contains information such as the network access permission number, device model, and scrambling code. Users can verify the information on the network access permission mark through the website to verify the authenticity of the equipment.

[0004] However, the network access permission mark is affixed to the device housing in the form of a paper label, which detracts from the device's aesthetics. Furthermore, the paper label delivery, transportation, storage, affixing, and inspection processes are costly. Paper labels are difficult to preserve, and if the label information is damaged or lost, subsequent authenticity verification cannot be performed. Furthermore, verifying the device's legitimacy requires users to manually log in to a website and enter the paper network access permission mark information, resulting in a poor user experience. Summary of the Invention

[0005] This article describes a method for authenticity query and its terminal device, which can provide a convenient and fast authenticity query method for terminal devices.

[0006] To achieve the above objectives, the embodiments of the present application adopt the following technical solutions:

[0007] In the first aspect, the present application provides a method for querying the authenticity of a terminal device. The authenticity query method includes: automatically reading network access permission information, where the network access permission information includes one or any combination of the following items: network access permission number, terminal device model, scrambling code, international mobile terminal equipment identity (IMEI), mobile terminal equipment identity (MEID), network access permission application unit, terminal device name, network access permission certificate validity period or issuance date; displaying a first user interface, where the first user interface includes the above-mentioned network access permission information and an authenticity query interactive element; obtaining a first touch input for selecting the authenticity query interactive element; in response to the first touch input, sending an authenticity query request to an authenticity verification server, where the authenticity query request includes the above-mentioned network access permission information; receiving an authenticity query result corresponding to the network access permission information from the authenticity verification server; and displaying the authenticity query result.

[0008] In the above-mentioned authenticity verification method, users can intuitively view network access permit information through the user interface, trigger authenticity verification requests through the user interface, and display authenticity verification results. Compared with the previous paper network access permit mark, this method can improve the authenticity verification rate of terminal devices for two reasons: first, users no longer need to manually enter the network access permit number; second, the risk of losing the paper network access permit mark is eliminated, and users can verify the authenticity of the terminal device at any time after purchasing it.

[0009] In some possible implementations, the network access permission information is stored in a non-volatile memory (e.g., read-only memory (ROM) or flash memory) of the terminal device. This ensures that the stored network access permission information is not lost when the terminal device is powered off, and the user can view the network access permission information of the terminal device at any time upon powering it on.

[0010] In some possible implementations, the network access permission information displayed on the first user interface is recorded in a quick response matrix code (Quick Response Code).

[0011] In some possible implementations, the quick response matrix code also records an authenticity query website (e.g., https: / / www.tenaa.com.cn). Thus, a user can scan the quick response matrix code displayed in the first user interface using a second terminal device (different from the terminal device displaying the first user interface) to obtain the network access permission information and the authenticity query website recorded in the quick response matrix code. The second terminal device accesses the authenticity query website to access the authenticity verification server (i.e., an authenticity query website is deployed on the authenticity verification server). The second terminal device then sends the network access permission information to the authenticity verification server (e.g., by sending the network access permission information to the authenticity verification server via HTTP POST). The second terminal device then receives an authenticity query result corresponding to the network access permission information from the authenticity verification server. The second terminal device then displays the authenticity query result.

[0012] In the above implementation, a user can verify the authenticity of a terminal device with the assistance of a second terminal device. For example, if a user's newly purchased terminal device (e.g., a smartwatch) is unable to connect to the Internet, the user can verify the authenticity of the terminal device by scanning the quick response matrix code displayed on the terminal device with a second terminal device (e.g., a smartphone).

[0013] In some possible implementations, the terminal device authenticity query method further includes starting an operating system setting wizard, and the first user interface is presented during the operating system setting wizard process.

[0014] In the above implementation, after the terminal device is powered on for the first time, the terminal device launches the operating system setup wizard and, during the operating system setup wizard, displays the first user interface containing the network access permission information. This allows the user to verify the authenticity of the terminal device and obtain the verification result promptly when the user powers on the device for the first time after purchasing it, thus avoiding the risk of fraud.

[0015] In some possible implementations, the step of sending an authenticity query request to an authenticity verification server includes: generating a Uniform Resource Locator (URL) containing the above-mentioned network access permission information; and accessing the resource identified by the Uniform Resource Locator in the authenticity verification server through a web browser application.

[0016] In some possible implementations, the authenticity verification server verifies whether the terminal device is genuine by querying the network access permission information database to see whether there is network access permission information corresponding to the terminal device. If there is corresponding network access permission information, it means that the terminal device is legal; if there is no corresponding network access permission information, it means that the terminal device is illegal.

[0017] In the second aspect, an embodiment of the present application provides a terminal device, comprising: a processor, a memory, a bus and a communication interface; the memory is used to store computer execution instructions, the processor is connected to the memory through the bus, and when the terminal device is running, the processor executes the computer execution instructions stored in the memory, so that the terminal device executes any of the above-mentioned terminal device authenticity query methods.

[0018] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, which stores instructions. When the instructions are executed on any of the above-mentioned terminal devices, the terminal device executes any of the above-mentioned terminal device authenticity query methods.

[0019] In a fourth aspect, an embodiment of the present application provides a computer program product comprising instructions, which, when executed on any of the above-mentioned terminal devices, enables the terminal device to execute any of the above-mentioned terminal device authenticity query methods.

[0020] In addition, the technical effects brought about by any design method in the second to fourth aspects can refer to the technical effects brought about by the different design methods in the above-mentioned first aspect, and will not be repeated here.

[0021] In a fifth aspect, an embodiment of the present application provides another method for querying the authenticity of a terminal device, the authenticity query method comprising: the terminal device receives an authenticity query instruction sent by an authenticity verification device; the terminal device initiates an authentication process for the terminal device in response to the authenticity query instruction; when the terminal device is authenticated, the terminal device automatically reads the network access permission information, the network access permission information including one or any combination of the following items: network access permission number, terminal device model, scrambling code, international mobile terminal equipment identity code (IMEI), mobile terminal equipment identification code (MEID), network access permission application unit, terminal device name, network access permission certificate validity period or issuance date; the terminal device sends the above-mentioned network access permission information to the authenticity verification device, so that the authenticity verification device obtains the authenticity query result corresponding to the network access permission information.

[0022] This authenticity query method is primarily targeted at counterfeit terminals produced by counterfeit terminal manufacturers. For example, a counterfeit terminal may display a user interface similar to the first aspect described above, displaying forged network access permission information and an authenticity query interactive element. When a user selects the authenticity query interactive element, the counterfeit terminal directly displays a query result such as "The identification information you are querying is authentic and corresponds to the product serial number." In reality, the network access permission information displayed by the counterfeit terminal is fake, appearing only to resemble the network access permission information displayed by a legitimate terminal device (for example, the counterfeit terminal also displays a QR code and information such as the terminal device model, network access permission number, and scrambling code). When a user selects the authenticity query interactive element, the counterfeit terminal does not send an authenticity query request to the authenticity verification server, but instead directly displays a query result stating "The identification information you are querying is authentic and corresponds to the product serial number," misleading the user into believing they have purchased a genuine product. In this case, the counterfeit terminal does not access the authenticity verification server at all, but instead uses the forged network access permission information and forged authenticity query results to mislead the user into believing they have purchased a genuine product.

[0023] In the authenticity verification method of the fifth aspect, the authenticity verification device may be an authenticity testing device provided by the Ministry of Industry and Information Technology. If a user suspects that a purchased terminal device is counterfeit, they may send the terminal device to a professional testing agency approved by the Ministry of Industry and Information Technology for verification using the aforementioned authenticity verification method. If, after the aforementioned authenticity verification, the authenticity verification device indicates that the terminal device is authentic, the user has purchased a genuine product.

[0024] In some possible implementations, authentication of the terminal device is performed between the terminal device and the authenticity verification device using an asymmetric key encryption algorithm. For example, the terminal device and the authenticity verification device each store an asymmetric key pair (i.e., a public key and a private key). One party (e.g., the terminal device) uses the private key to encrypt specific data (e.g., a random number), while the other party (e.g., the authenticity verification device) decrypts the data using the public key. If the decryption is successful, the terminal device is considered authenticated. After successful authentication of the terminal device, the terminal device reads the network access permission information and transmits it to the authenticity verification device. The authenticity verification device queries whether the network access permission information is stored in a network access permission information database. If so, the terminal device is authenticated. In one implementation, the authenticity verification device locally stores the network access permission information database. In another implementation, the network access permission information database is stored on an authenticity verification server, and the authenticity verification device accesses the network access permission information database stored on the authenticity verification server to determine the authenticity of the terminal device.

[0025] In some possible implementations, after the terminal device is successfully authenticated, in addition to sending the network access permission information to the authenticity verification device, the terminal device also sends the product serial number of the terminal device (IMEI, MEID or other unique identifier of the terminal device (for example, hardware serial number)) to the authenticity verification device. After obtaining the serial number, the authenticity verification device queries whether the serial number matches the stored serial number delivered by the terminal device manufacturer. If they match, it means that the terminal device is authentic.

[0026] By using any of the design methods in the fifth aspect above, users can use the authenticity verification equipment provided by professional authentication agencies to verify the authenticity of the terminal device, which can prevent counterfeit and shoddy products from entering the market to a certain extent. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 This is an architecture diagram of a network access license management system provided by an embodiment of the present application;

[0028] Figure 2 This is a schematic diagram of a method for managing network access permits provided in an embodiment of the present application;

[0029] Figure 3 This is a schematic diagram of the structure of a terminal device provided in an embodiment of the present application;

[0030] Figure 4A This is a schematic diagram of the architecture of a terminal device authenticity verification system provided by an embodiment of the present application;

[0031] Figure 4B Schematic diagram of various electronic signs for network access permission provided in the embodiments of the present application;

[0032] Figure 5 This is a schematic diagram of querying the authenticity of a terminal device in an operating system setup wizard provided by an embodiment of the present application;

[0033] Figure 6A This is an exemplary user interface for querying the authenticity of a terminal device provided in an embodiment of the present application;

[0034] Figure 6B This is an exemplary user interface for a terminal device authenticity query result provided by an embodiment of the present application;

[0035] Figure 7 This is another exemplary user interface for querying authenticity information of a terminal device provided in an embodiment of the present application;

[0036] Figure 8A 8B, 8C, and 8D show another exemplary user interface for authenticity query of a terminal device provided in an embodiment of the present application;

[0037] Figure 9 This is a flowchart of an exemplary method for querying the authenticity of a terminal device provided in an embodiment of the present application;

[0038] Figure 10 This is a schematic diagram of the structure of another terminal device provided in an embodiment of the present application;

[0039] Figure 11 This is a structural diagram of another terminal device provided in an embodiment of the present application;

[0040] Figure 12 This is a schematic diagram of a terminal device authenticity query system provided by an embodiment of the present application;

[0041] Figure 13 This is another exemplary process diagram for checking the authenticity of a terminal device provided in an embodiment of the present application;

[0042] Figure 14 This is another exemplary process diagram for querying the authenticity of a terminal device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0043] The technical solutions in the embodiments of the present disclosure will be described below with reference to the accompanying drawings in the embodiments of the present disclosure.

[0044] Figure 1An architectural diagram of a network access license management system 100 according to various examples is shown. In some examples, the system 100 can implement functions such as application acceptance and issuance of network access licenses, and monitoring of the use of network access licenses. The term "network access license" refers to a network access license issued by a network access license management organization (for example, the Ministry of Industry and Information Technology of China). Only communication equipment that has obtained a network access license is allowed to access the public communication network for use and sale. The term "network access license electronic mark" refers to a quality mark stored in the form of electronic data on a communication device that has obtained a network access license (this is a name relative to the paper network access license label in the prior art). The network access license electronic mark records the network access license information of the device.

[0045] like Figure 1 As shown, in some examples, the network access license management system 100 includes a network access license management server 102, a network access license data management client 104 of a device vendor (e.g., a terminal device manufacturer), a network access license import device 106, and a terminal device 108 (e.g., Figure 1 The device vendor's network access permit data management client 104 and the network access permit management server 102 can communicate via one or more networks 110 according to a client-server model.

[0046] The network access license management server 102 is provided, managed, and maintained by a network access license management organization (e.g., an official organization such as the Ministry of Industry and Information Technology of China or another third-party network access license management organization). The network access license data management server 102 can provide server-side functions for the network access license data management client 104 of terminal device manufacturers, such as facilitating the application and issuance of network access licenses by various device manufacturers and monitoring their use.

[0047] The device manufacturer (e.g., a mobile phone or smartwatch manufacturer) provides, manages, and maintains the device vendor's network access permit data management client 104. The device manufacturer's network access permit data management client 104 provides client-side functions such as network access permit application and network access permit usage reporting for the device manufacturer, as well as communication with the network access permit data management server.

[0048] The network access license importing device 106 can be a production device on the production line of the equipment manufacturer's production workshop. It is responsible for obtaining the network access license from the equipment manufacturer's network access license data management client 104 and importing the network access license information to the terminal device 108. In some embodiments, the network access license importing device 106 obtains three parameters from the network access license data management client 104: the network access license number, the terminal device model, and the scrambling code. These three parameters are separated by commas in sequence and concatenated into a string "NAL" (where NAL stands for (Network Access License), and the comma-concatenated NAL string can be "Network Access License Number, Terminal Device Model, Scrambling Code"). In one example, the NAL string can be "02-5043-163526, MHA-AL00, 9YP24PAA2C152TA". The above string is then written into the terminal device (for example, stored in non-volatile memory). In some implementations, a digital signature of the aforementioned string (for example, by performing a hash operation on the "NAL" string to obtain a hash value, and then encrypting the hash value with the private key of an asymmetric encryption algorithm as a signature) can be written into the terminal device. Finally, the network access license importing device 106 reads the written "NAL" string from the terminal device 108 to determine whether the string was written correctly. If the string read from the terminal device 108 matches the string initially written, the network access permission information is successfully written. In some implementations, if the "NAL" string and the signature information are stored together in the terminal device, after reading the signature information, the network access license importing device 106 can decrypt the signature using the public key to obtain the "NAL" string, and then determine whether the "NAL" string matches the written "NAL" string.

[0049] The network access license importing device 106 also notifies the equipment vendor's network access license usage status for the production line (e.g., a table of correspondences between terminal device product serial numbers (such as International Mobile Equipment Identity (IMEI) or Mobile Equipment Identifier (MEID) or other unique terminal device identifiers (e.g., hardware serial numbers)) and network access license information, where the network access license information corresponds one-to-one with the terminal device product serial numbers) to the network access license data management client 104, and ultimately transmits the information to the network access license management server 102. The network access license information includes one or any combination of the following items: network access license number, terminal device model, scrambling code, International Mobile Equipment Identity (IMEI), Mobile Equipment Identifier (MEID), network access license application unit, terminal device name, and network access license certificate validity period or issuance date. The scrambling code is a unique number for each terminal device and is as unique as the International Mobile Equipment Identity (IMEI) or Mobile Equipment Identifier (MEID).

[0050] In some examples, the network access license management server 102 may include a client-oriented external I / O interface 112, one or more processing modules 114, and a storage module 116. The client-oriented external I / O interface 112 can communicate with the equipment vendor's network access license data management client 104 via one or more networks 110. The one or more processing modules 114 can process the equipment vendor's network access license application, network access license issuance, and network access license usage monitoring of the network access license data management client 104. In addition, the one or more processing modules 114 generate network access licenses based on information such as the number of devices and device models reported by the equipment vendor. The storage module 116 is used to store data and instructions. Among them, the storage module 116 can store equipment vendor network access license application data (such as network access license application form, equipment vendor enterprise information, device information, equipment quality inspection report, etc.), or network access license information usage data. In some embodiments, the network access permission information usage data may be a table of correspondences between terminal device product serial numbers (such as the International Mobile Equipment Identity (IMEI) or the Mobile Equipment Identifier (MEID) or other unique identifiers of terminal devices (e.g., hardware serial numbers)) reported monthly by the device vendor and network access permission information, wherein the network access permission information corresponds one-to-one with the terminal device product serial numbers. In some embodiments, the network access permission information usage data may also be a table of correspondences between terminal device product serial numbers and network access permission information serial numbers (the network access permission information serial number may also be referred to as the network access permission electronic identification serial number). The network access permission management server 102 assigns a corresponding serial number to each piece of network access permission information.

[0051] In some examples, the device vendor network access license data management client 104 may include a server-facing external I / O interface 118, one or more processing modules 120, and a storage module 122. The server-facing external I / O interface 118 may communicate with the network access license management server 102 via one or more networks 110. The one or more processing modules 120 may apply for a network access license from the network access license management server 102 via the external I / O interface 118 and transmit network access license usage information. Furthermore, the one or more processing modules 120 may transmit device quantity and model information to the network access license management server 102 via the external I / O interface 118 to apply for a network access license. The storage module 122 is configured to store data and instructions. The storage module 122 may store device vendor network access license application data (e.g., device model, device name, device quantity, device quality certification information, etc.) and network access license information usage data (e.g., a table recording the correspondence between terminal device product serial numbers (IMEI or MEID) and network access license information, where network access license information corresponds one-to-one with terminal device product serial numbers). Of course, the network access permission information usage data may also be a correspondence table between terminal device product serial numbers and network access permission information serial numbers, wherein the network access license management server 102 assigns a corresponding serial number to each piece of network access permission information.

[0052] The terminal device 108 can be any suitable electronic device (its structure can be referred to below). Figure 3 The electronic device 300 described in the foregoing description may be a mobile phone or other portable multi-function device (e.g., a laptop or tablet computer). In addition, in some examples, the terminal device 108 may be a non-portable multi-function device. Specifically, the terminal device 108 may be a desktop computer, a game console, a television, or a TV set-top box. In some examples, the terminal device 108 may include a touch-sensitive surface (e.g., a touch screen display and / or a touchpad). In addition, the terminal device 108 may optionally include one or more other physical user interface devices, such as a physical keyboard, a mouse, and / or a joystick. In some examples, the terminal device 108 may be a wearable electronic device, such as a smart watch, a smart bracelet, etc.

[0053] Examples of the communication network 110 may include a local area network (LAN) and a wide area network (WAN), such as the Internet. The communication network 110 may be implemented using any known network protocol, including various wired or wireless protocols, such as, for example, Ethernet, Universal Serial Bus (USB), Global System for Mobile Communications (GSM), Enhanced Data GSM Environment (EDGE), Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Long Term Evolution (LTE), Bluetooth, Wireless Fidelity (Wi-Fi), or any other suitable communication protocol.

[0054] The network access license management server system 100 can be implemented on one or more independent data processing devices or a distributed network. In some examples, the server system 100 can also use various virtual devices and / or services of third-party service providers (e.g., third-party cloud service providers) to provide potential computing resources and / or infrastructure resources of the server system 100.

[0055] Figure 2 A schematic diagram of a network access permit management method according to various examples is shown.

[0056] In step 202, before producing a terminal device, the device vendor sends a network access license acquisition request to the network access license management server 102 via the device vendor network access license data management client 104. The network access license acquisition request carries one or any combination of the following parameters: device manufacturer, device name, device model, device quantity, or device quality inspection report.

[0057] In step 204, the network access license management server 102 verifies the network access license acquisition request submitted by the equipment vendor's network access license data management client 104. If the network access license management server 102 verifies that the request meets the requirements, it generates a network access license and sends network access license information to the equipment vendor's network access license data management client 104. The network access license information includes one or any combination of the following items: network access license number, terminal device model, scrambling code, International Mobile Equipment Identity (IMEI), Mobile Equipment Identity (MEID), network access license applicant, terminal device name, and network access license certificate validity period or issuance date.

[0058] In some implementations, in order to record the number of network access permission information sent, the network access permission management server 102 may also send a serial number corresponding to the network access permission information (this serial number may also be called a network access permission electronic mark serial number) to the network access device vendor license data management client 104 in step 204. In this way, the network access permission management server 102 can easily count the number of network access permission electronic marks issued based on the serial number.

[0059] In step 206 , the network access license management server 102 transmits the network access license information to the equipment vendor network access license data management client 104 . The equipment vendor network access license data management client 104 then stores the network access license information in the storage module 122 and transmits it to the network access license importing device 106 in step 208 .

[0060] In step 208, the network access license importing device 106 sends the network access license information to the terminal device 108. For example, the license importing device 106 in the equipment manufacturer's production line sends the network access license information to the terminal device 108 via an AT command or a Diag command. The terminal device 108 then stores the network access license information, for example, in the manufacturer information (e.g., Original Equipment Manufacturer (OEM) Information) in the non-volatile memory of the terminal device 108. Also stored with the network access license information is a corresponding signature used to verify the identity of the requester requesting access to the network access license information. The terminal device 108 can then call a series of interfaces to access the network access license information. For example, in the case of a terminal device 108 running the Android operating system, an application in the application layer of the terminal device 108 (e.g., a settings application or an operating system setup wizard application) obtains the network access license information stored by the terminal device 108 through the corresponding interface for obtaining network access license information in the framework layer. The framework layer verifies the permissions of the application requesting access to the network access permission information. If malicious access by an illegal application is detected, its access request will be denied. If the application requesting access to the network access permission information has access permissions, it will be allowed to access the network access permission information.

[0061] At step 210, the license importing device 106 provides feedback to the device vendor's network access license data management client 104 on the usage of the network access license information. Specifically, the license importing device 106 provides a table of correspondences between mobile terminal device identification codes, terminal device product serial numbers (IMEI numbers or MEID numbers), and corresponding network access license information, based on the actual number of devices produced and used. There is a one-to-one correspondence between the network access license information and the terminal device product serial numbers of the terminal devices 108.

[0062] In some implementations, in step 210, the format of the correspondence table provided by the device vendor to the network access license management server 102 is "product serial number, network access license information serial number." If the terminal device has multiple product serial numbers (for example, multiple IMEI numbers when the terminal device supports multiple SIM cards), the number of entries in the correspondence table provided by the device vendor to the network access license management server 102 is "product serial number 1, product serial number 2, network access license information serial number." For example, taking a terminal device with two IMEIs and two MEIDs as an example, the correspondence provided is "IMEI1, IMEI2, MEID1, MEID2, network access license information serial number."

[0063] In step 212, the equipment vendor's network access license data management client 104 provides feedback on the usage of the network access license information to the network access license management server 102. For example, the equipment vendor's network access license data management client 104 provides feedback to the network access license management server 102 on a table of correspondences between terminal device product serial numbers (IMEI numbers and / or MEID numbers) and corresponding network access license information.

[0064] Now, an implementation scheme of a terminal device having network access permission information or a network access permission electronic mark is introduced. Figure 3 An embodiment according to the present disclosure is shown Figure 1 The terminal device 108 is a schematic diagram of the structure of the terminal device 108. Figure 3 The electronic device 300 is shown as an example for description.

[0065] The electronic device 300 may include a processor 310, an external memory interface 320, an internal memory 321, a universal serial bus (USB) interface 330, a charging management module 340, a power management module 341, a battery 342, an antenna 1, an antenna 2, a mobile communication module 350, a wireless communication module 360, an audio module 370, a speaker 370A, a receiver 370B, a microphone 370C, an earphone interface 370D, a sensor module 380, a button 390, a motor 391, an indicator 392, a camera 393, a display screen 394, and a subscriber identification module (SIM) card interface 395, etc. The sensor module 380 may include a pressure sensor 380A, a gyroscope sensor 380B, an air pressure sensor 380C, a magnetic sensor 380D, an acceleration sensor 380E, a distance sensor 380F, a proximity light sensor 380G, a fingerprint sensor 380H, a temperature sensor 380J, a touch sensor 380K, an ambient light sensor 380L, a bone conduction sensor 380M, etc.

[0066] It should be understood that the structure illustrated in the embodiments of the present application does not constitute a specific limitation on the electronic device 300. In other embodiments of the present application, the electronic device 300 may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0067] The processor 310 may include one or more processing units. For example, the processor 310 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). The different processing units may be independent devices or integrated into one or more processors.

[0068] The controller can generate operation control signals according to the instruction operation code and timing signal to complete the control of instruction fetching and execution.

[0069] Processor 310 may also include a memory for storing instructions and data. In some embodiments, the memory in processor 310 is a cache memory. This memory can store instructions or data that have just been used or are being recycled by processor 310. If processor 310 needs to use the same instruction or data again, it can directly access the memory. This avoids duplicate accesses, reduces processor 310 latency, and thus improves system efficiency.

[0070] In some embodiments, the processor 310 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface.

[0071] The I2C interface is a bidirectional synchronous serial bus that includes a serial data line (SDA) and a serial clock line (SCL). In some embodiments, the processor 310 may include multiple I2C busses. The processor 310 may be coupled to the touch sensor 380K, the charger, the flash, the camera 393, and the like via different I2C bus interfaces. For example, the processor 310 may be coupled to the touch sensor 380K via the I2C interface, enabling communication between the processor 310 and the touch sensor 380K via the I2C bus interface, thereby enabling the touch function of the electronic device 300.

[0072] The I2S interface can be used for audio communication. In some embodiments, the processor 310 can include multiple I2S buses. The processor 310 can be coupled to the audio module 370 via the I2S bus to enable communication between the processor 310 and the audio module 370. In some embodiments, the audio module 370 can transmit audio signals to the wireless communication module 360 ​​via the I2S interface, enabling the function of answering calls through a Bluetooth headset.

[0073] The PCM interface can also be used for audio communication, sampling, quantizing, and encoding analog signals. In some embodiments, the audio module 370 and the wireless communication module 360 ​​can be coupled via a PCM bus interface. In some embodiments, the audio module 370 can also transmit audio signals to the wireless communication module 360 ​​via the PCM interface, enabling the function of answering calls via a Bluetooth headset. Both the I2S interface and the PCM interface can be used for audio communication.

[0074] The UART interface is a universal serial data bus used for asynchronous communication. This bus can be a bidirectional communication bus. It converts the data to be transmitted between serial communication and parallel communication. In some embodiments, the UART interface is typically used to connect the processor 310 and the wireless communication module 360. For example, the processor 310 communicates with the Bluetooth module in the wireless communication module 360 ​​via the UART interface to implement Bluetooth functionality. In some embodiments, the audio module 370 can transmit audio signals to the wireless communication module 360 ​​via the UART interface, enabling the function of playing music through Bluetooth headphones.

[0075] The MIPI interface can be used to connect the processor 310 to peripheral devices such as the display screen 394 and the camera 393. MIPI interfaces include the camera serial interface (CSI) and the display serial interface (DSI). In some embodiments, the processor 310 and the camera 393 communicate via the CSI interface to implement the camera function of the electronic device 300. The processor 310 and the display screen 394 communicate via the DSI interface to implement the display function of the electronic device 300.

[0076] The GPIO interface can be configured through software. The GPIO interface can be configured as a control signal or a data signal. In some embodiments, the GPIO interface can be used to connect the processor 310 to the camera 393, the display 394, the wireless communication module 360, the audio module 370, the sensor module 380, etc. The GPIO interface can also be configured as an I2C interface, an I2S interface, a UART interface, a MIPI interface, etc.

[0077] USB interface 330 is an interface that complies with USB standards and specifications, and may be a Mini USB interface, a Micro USB interface, a USB Type-C interface, or the like. USB interface 330 can be used to connect a charger to charge electronic device 300, or to transfer data between electronic device 300 and peripheral devices. It can also be used to connect headphones to play audio. This interface can also be used to connect other electronic devices, such as AR devices.

[0078] It is understood that the interface connection relationship between the modules illustrated in the embodiment of the present application is merely an illustrative illustration and does not constitute a structural limitation on the electronic device 300. In other embodiments of the present application, the electronic device 300 may also adopt a different interface connection method from the above embodiment, or a combination of multiple interface connection methods.

[0079] The charging management module 340 is configured to receive charging input from a charger. The charger can be either a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 340 can receive charging input from the wired charger via the USB interface 330. In some wireless charging embodiments, the charging management module 340 can receive wireless charging input via the wireless charging coil of the electronic device 300. While charging the battery 342, the charging management module 340 can also provide power to the electronic device via the power management module 341.

[0080] The power management module 341 is used to connect the battery 342, the charging management module 340, and the processor 310. The power management module 341 receives input from the battery 342 and / or the charging management module 340 and provides power to the processor 310, the internal memory 321, the display 394, the camera 393, and the wireless communication module 360. The power management module 341 can also be used to monitor parameters such as battery capacity, battery cycle count, and battery health status (leakage, impedance). In some other embodiments, the power management module 341 can also be set in the processor 310. In other embodiments, the power management module 341 and the charging management module 340 can also be set in the same device.

[0081] The wireless communication function of the electronic device 300 can be implemented through the antenna 1, the antenna 2, the mobile communication module 350, the wireless communication module 360, the modem processor and the baseband processor.

[0082] Antenna 1 and Antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 300 can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In other embodiments, the antennas can be used in conjunction with a tuning switch.

[0083] The mobile communication module 350 can provide solutions for wireless communications including 2G / 3G / 4G / 5G applied to the electronic device 300. The mobile communication module 350 may include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 350 can receive electromagnetic waves from the antenna 1, and filter, amplify, and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 350 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. In some embodiments, at least some of the functional modules of the mobile communication module 350 can be set in the processor 310. In some embodiments, at least some of the functional modules of the mobile communication module 350 can be set in the same device as at least some of the modules of the processor 310.

[0084] The modem processor may include a modulator and a demodulator. The modulator is used to modulate the low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After being processed by the baseband processor, the low-frequency baseband signal is passed to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 370A, the receiver 370B, etc.) or displays an image or video through the display screen 394. In some embodiments, the modem processor may be an independent device. In other embodiments, the modem processor may be independent of the processor 310 and be provided in the same device as the mobile communication module 350 or other functional modules.

[0085] The wireless communication module 360 ​​can provide wireless communication solutions including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR), etc., which are applied to the electronic device 300. The wireless communication module 360 ​​can be one or more devices integrating at least one communication processing module. The wireless communication module 360 ​​receives electromagnetic waves via the antenna 2, frequency modulates and filters the electromagnetic wave signals, and sends the processed signals to the processor 310. The wireless communication module 360 ​​can also receive the signal to be sent from the processor 310, frequency modulate it, amplify it, and convert it into electromagnetic waves for radiation through the antenna 2.

[0086] In some embodiments, antenna 1 of electronic device 300 is coupled to mobile communication module 350, and antenna 2 is coupled to wireless communication module 360, so that electronic device 300 can communicate with a network and other devices via wireless communication technology. The wireless communication technology may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology. The GNSS may include a global positioning system (GPS), a global navigation satellite system (GLONASS), a Beidou navigation satellite system (BDS), a quasi-zenith satellite system (QZSS) and / or a satellite based augmentation system (SBAS).

[0087] Electronic device 300 implements display functionality through a GPU, display screen 394, and an application processor. A GPU is a microprocessor for image processing that connects display screen 394 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. Processor 310 may include one or more GPUs that execute program instructions to generate or modify display information.

[0088] Display screen 394 is used to display images, videos, etc. Display screen 394 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a MiniLED, a MicroLED, a Micro-oLed, or a quantum dot light-emitting diode (QLED). In some embodiments, electronic device 300 may include one or N display screens 394, where N is a positive integer greater than one.

[0089] The electronic device 300 can realize the shooting function through the ISP, camera 393, video codec, GPU, display screen 394 and application processor.

[0090] The ISP processes data fed back by camera 393. For example, when taking a photo, the shutter is opened, and light is transmitted through the lens to the camera's photosensitive element. The light signal is converted into an electrical signal, which is then passed to the ISP for processing and converted into a visible image. The ISP can also perform algorithmic optimization on image noise, brightness, and skin tone. The ISP can also optimize parameters such as exposure and color temperature of the captured scene. In some embodiments, the ISP can be located within camera 393.

[0091] The camera 393 is used to capture still images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, and then passes the electrical signal to the ISP to be converted into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV or other format. In some embodiments, the electronic device 300 may include 1 or N cameras 393, where N is a positive integer greater than 1.

[0092] The digital signal processor is used to process digital signals. In addition to processing digital image signals, it can also process other digital signals. For example, when the electronic device 300 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy.

[0093] Video codecs are used to compress or decompress digital video. Electronic device 300 may support one or more video codecs. This allows electronic device 300 to play or record videos in various encoding formats, such as Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, and MPEG4.

[0094] The NPU is a neural network (NN) computing processor. Drawing on the structure of biological neural networks, such as the transmission patterns between neurons in the human brain, it rapidly processes input information and can continuously self-learn. The NPU enables intelligent cognitive applications in electronic device 300, such as image recognition, face recognition, speech recognition, and text comprehension.

[0095] The external memory interface 320 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 300. The external memory card communicates with the processor 310 via the external memory interface 320 to implement data storage functions. For example, files such as music and videos can be stored on the external memory card.

[0096] The internal memory 321 can be used to store computer executable program codes, which include instructions. The internal memory 321 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc. The data storage area may store data created during the use of the electronic device 300 (such as audio data, a phone book, etc.), etc. In addition, the internal memory 321 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc. The processor 310 executes various functional applications and data processing of the electronic device 300 by running instructions stored in the internal memory 321 and / or instructions stored in a memory provided in the processor.

[0097] The electronic device 300 can implement audio functions such as music playback and recording through the audio module 370, the speaker 370A, the receiver 370B, the microphone 370C, the headphone jack 370D, and the application processor.

[0098] The audio module 370 is used to convert digital audio information into analog audio signal output, and is also used to convert analog audio input into digital audio signals. The audio module 370 can also be used to encode and decode audio signals. In some embodiments, the audio module 370 can be provided in the processor 310, or some functional modules of the audio module 370 can be provided in the processor 310.

[0099] The speaker 370A, also called a "speaker", is used to convert audio electrical signals into sound signals. The electronic device 300 can listen to music or listen to hands-free calls through the speaker 370A.

[0100] The receiver 370B, also called a "handset", is used to convert audio electrical signals into sound signals. When the electronic device 300 receives a call or a voice message, the user can place the receiver 370B close to the ear to hear the voice.

[0101] Microphone 370C, also known as "microphone" or "microphone", is used to convert sound signals into electrical signals. When making a call or sending a voice message, the user can speak by putting their mouth close to the microphone 370C to input the sound signal into the microphone 370C. The electronic device 300 can be provided with at least one microphone 370C. In other embodiments, the electronic device 300 can be provided with two microphones 370C, which can not only collect sound signals but also realize noise reduction function. In other embodiments, the electronic device 300 can also be provided with three, four or more microphones 370C to collect sound signals, reduce noise, identify the source of sound, realize directional recording function, etc.

[0102] The headphone jack 370D is used to connect a wired headphone. The headphone jack 370D can be a USB interface 330 or a 3.5mm open mobile terminal platform (OMTP) standard interface or a cellular telecommunications industry association of the USA (CTIA) standard interface.

[0103] Pressure sensor 380A is used to sense pressure signals and convert them into electrical signals. In some embodiments, pressure sensor 380A can be located on display screen 394. There are many types of pressure sensors 380A, such as resistive, inductive, and capacitive. A capacitive pressure sensor can include at least two parallel plates made of conductive material. When force is applied to pressure sensor 380A, the capacitance between the electrodes changes. Electronic device 300 determines the intensity of the pressure based on this change in capacitance. When a touch operation is applied to display screen 394, electronic device 300 detects the intensity of the touch operation based on pressure sensor 380A. Electronic device 300 can also calculate the location of the touch based on the detection signal from pressure sensor 380A. In some embodiments, touch operations applied to the same touch location but with different touch intensities can correspond to different operation instructions. For example, when a touch operation with an intensity less than a first pressure threshold is applied to a short message application icon, a command to view short messages is executed. When a touch operation with an intensity greater than or equal to the first pressure threshold is applied to a short message application icon, a command to create a new short message is executed.

[0104] The gyroscope sensor 380B can be used to determine the motion posture of the electronic device 300. In some embodiments, the angular velocity of the electronic device 300 around three axes (i.e., x, y, and z axes) can be determined by the gyroscope sensor 380B. The gyroscope sensor 380B can be used for anti-shake shooting. For example, when the shutter is pressed, the gyroscope sensor 380B detects the angle of the electronic device 300 shaking, calculates the distance that the lens module needs to compensate based on the angle, and allows the lens to offset the shaking of the electronic device 300 through reverse movement to achieve anti-shake. The gyroscope sensor 380B can also be used for navigation and somatosensory game scenes.

[0105] The air pressure sensor 380C is used to measure air pressure. In some embodiments, the electronic device 300 calculates the altitude using the air pressure value measured by the air pressure sensor 380C to assist in positioning and navigation.

[0106] The magnetic sensor 380D includes a Hall sensor. The electronic device 300 can use the magnetic sensor 380D to detect the opening and closing of the flip cover. In some embodiments, when the electronic device 300 is a flip phone, the electronic device 300 can detect the opening and closing of the flip cover using the magnetic sensor 380D. Based on the detected opening and closing status of the leather case or flip cover, features such as automatic unlocking of the flip cover can be configured.

[0107] Accelerometer 380E can detect the magnitude of acceleration of electronic device 300 in all directions (generally three axes). When electronic device 300 is stationary, it can detect the magnitude and direction of gravity. It can also be used to identify the electronic device's posture, enabling applications such as switching between landscape and portrait modes and pedometers.

[0108] The distance sensor 380F is used to measure distance. The electronic device 300 can measure distance using infrared or laser. In some embodiments, when shooting a scene, the electronic device 300 can use the distance sensor 380F to measure distance to achieve fast focusing.

[0109] The proximity light sensor 380G may include, for example, a light emitting diode (LED) and a light detector, such as a photodiode. The light emitting diode may be an infrared light emitting diode. The electronic device 300 emits infrared light outward through the light emitting diode. The electronic device 300 uses a photodiode to detect infrared reflected light from nearby objects. When sufficient reflected light is detected, it can be determined that there is an object near the electronic device 300. When insufficient reflected light is detected, the electronic device 300 can determine that there is no object near the electronic device 300. The electronic device 300 can use the proximity light sensor 380G to detect when the user holds the electronic device 300 close to the ear to talk, so as to automatically turn off the screen to save power. The proximity light sensor 380G can also be used in leather case mode and pocket mode to automatically unlock and lock the screen.

[0110] Ambient light sensor 380L is used to sense ambient light brightness. Electronic device 300 can adaptively adjust the brightness of display screen 394 based on the perceived ambient light. Ambient light sensor 380L can also be used to automatically adjust white balance when taking photos. Ambient light sensor 380L can also work with proximity light sensor 380G to detect whether electronic device 300 is in a pocket to prevent accidental touches.

[0111] The fingerprint sensor 380H is used to collect fingerprints. The electronic device 300 can use the collected fingerprint characteristics to achieve fingerprint unlocking, access application locks, fingerprint photography, fingerprint answering calls, etc.

[0112] The temperature sensor 380J is used to detect temperature. In some embodiments, the electronic device 300 uses the temperature detected by the temperature sensor 380J to implement a temperature processing strategy. For example, when the temperature reported by the temperature sensor 380J exceeds a threshold, the electronic device 300 reduces the performance of the processor located near the temperature sensor 380J to reduce power consumption and implement thermal protection. In other embodiments, when the temperature is lower than another threshold, the electronic device 300 heats the battery 342 to prevent the electronic device 300 from shutting down abnormally due to low temperature. In other embodiments, when the temperature is lower than another threshold, the electronic device 300 boosts the output voltage of the battery 342 to prevent abnormal shutdown due to low temperature.

[0113] The touch sensor 380K is also called a "touch panel." The touch sensor 380K can be disposed on the display screen 394. The touch sensor 380K and the display screen 394 form a touch screen, also called a "touch screen." The touch sensor 380K is used to detect touch operations applied thereto or in the vicinity thereof. The touch sensor can transmit the detected touch operations to the application processor to determine the type of touch event. Visual output related to the touch operations can be provided via the display screen 394. In other embodiments, the touch sensor 380K can also be disposed on the surface of the electronic device 300, at a location different from that of the display screen 394.

[0114] The bone conduction sensor 380M can acquire vibration signals. In some embodiments, the bone conduction sensor 380M can acquire vibration signals from the vibrating bones of the human body's vocal cords. The bone conduction sensor 380M can also contact the human pulse to receive blood pressure signals. In some embodiments, the bone conduction sensor 380M can also be set in headphones to form bone conduction headphones. The audio module 370 can parse out voice signals based on the vibration signals of the vibrating bones of the vocal cords acquired by the bone conduction sensor 380M to implement voice functions. The application processor can parse heart rate information based on the blood pressure signals acquired by the bone conduction sensor 380M to implement heart rate detection functions.

[0115] The buttons 390 include a power button, a volume button, and the like. The buttons 390 may be mechanical buttons or touch buttons. The electronic device 300 may receive key inputs and generate key signal inputs related to user settings and function control of the electronic device 300.

[0116] Motor 391 can generate vibration prompts. Motor 391 can be used for incoming call vibration prompts, and can also be used for touch vibration feedback. For example, touch operations acting on different applications (such as taking pictures, audio playback, etc.) can correspond to different vibration feedback effects. For touch operations acting on different areas of the display screen 394, motor 391 can also correspond to different vibration feedback effects. Different application scenarios (for example: time reminders, receiving messages, alarm clocks, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also support customization.

[0117] Indicator 392 can be an indicator light, which can be used to indicate charging status, power changes, messages, missed calls, notifications, etc.

[0118] The SIM card interface 395 is used to connect a SIM card. The SIM card can be connected to and disconnected from the electronic device 300 by inserting it into or removing it from the SIM card interface 395. The electronic device 300 can support 1 or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 395 can support Nano SIM cards, Micro SIM cards, SIM cards, and the like. Multiple cards can be inserted into the same SIM card interface 395 at the same time. The types of the multiple cards can be the same or different. The SIM card interface 395 can also be compatible with different types of SIM cards. The SIM card interface 395 can also be compatible with external memory cards. The electronic device 300 interacts with the network through the SIM card to implement functions such as calls and data communications. In some embodiments, the electronic device 300 uses an eSIM, i.e., an embedded SIM card. The eSIM card can be embedded in the electronic device 300 and cannot be separated from the electronic device 300.

[0119] In the embodiment of the present application, the processor 310 can execute the program instructions stored in the memory 340 to implement the method executed by the terminal device in the following embodiment.

[0120] The network access permit electronic mark or network access permit information is a quality mark set on terminal devices that have obtained a network access permit. Terminal devices can use the authenticity query function of the authenticity verification system provided by the network access permit management organization to query and verify all network access permit information. Figure 4A A schematic diagram of the architecture of a terminal device authenticity verification system 400 according to various examples is shown.

[0121] See also Figure 4A The terminal device authenticity verification system 400 may include an authenticity query client 408 executed on a terminal device 402, and an authenticity verification server 404. The authenticity query client-side portion 408 may communicate with the authenticity verification server 404 via one or more networks 406. The authenticity query client 402 may provide client-side functions, such as providing an authenticity query interface, receiving user query input, sending authenticity query requests, and displaying authenticity query results. The authenticity query client 402 may store the IP address of the authenticity verification server 404 to establish a communication connection with the authenticity verification server 404. In some embodiments, the authenticity query client 402 may also store the website address of the authenticity query server 404, access the website address of the authenticity verification server 404 through a browser, and query the IP address corresponding to the website address of the authenticity verification server 404 through the Domain Name System (DNS) to establish a communication connection with the authenticity verification server 404. The authenticity verification server 404 may provide server-side functions for the authenticity query clients 408 from multiple terminal devices.

[0122] In some examples, the terminal device 402 can also communicate with the authenticity verification server 404 via the second terminal device 410. The second terminal device 410 can be similar to or the same as the terminal device 402. For example, the second terminal device 410 can be similar to the above Figure 3 The electronic device 300 described above. The second terminal device 410 can store the address of the authenticity verification server 404. The second terminal device 410 can also obtain the IP address of the authenticity verification server 404 from the terminal device 402 to establish a communication connection with the authenticity verification server 404. In some embodiments, the second terminal device 410 can store the authenticity query website corresponding to the authenticity verification server 404. Of course, the second terminal device 410 can also obtain the authenticity query website corresponding to the authenticity verification server 404 from the terminal device 402, and query the IP address corresponding to the authenticity query website of the authenticity verification server 404 through the Domain Name System (DNS) to establish a communication connection with the authenticity verification server 404. The second terminal device 410 queries the authenticity of the terminal device 402 by accessing the authenticity verification server 404. The terminal device 402 can be configured to communicate with the second terminal device 410 via a direct communication connection (such as Bluetooth, near field communication (NFC), etc.) or via a wired or wireless network (such as a wireless fidelity (Wi-Fi) network). In some examples, the second terminal device 410 may be configured to act as a proxy between the terminal device 402 and the authenticity verification server 404. For example, the authenticity query client 408 of the terminal device 108 may be configured to transmit information (e.g., an authenticity query request received at the terminal device 402) to the authenticity verification server 404 via the second terminal device 408. The authenticity verification server 404 may process the information and return relevant data (e.g., a query result in response to the user's authenticity query request) to the terminal device 402 via the second terminal device 410.

[0123] In some examples, terminal device 402 can display network access permission information (or an electronic network access permission logo). The network access permission information can be presented using any of the following: a Quick Response Code (QR code), a two-dimensional barcode, a one-dimensional barcode, or a serial number. Second terminal device 410 uses a camera to scan the QR code, two-dimensional barcode, or one-dimensional barcode provided by terminal device 402 to obtain the network access permission information. Using the network access permission information, second terminal device 410 generates a complete authenticity query request and transmits it to authenticity verification server 404. Figure 4AThe illustrated system architecture can advantageously verify the authenticity of a terminal device 402 using a second terminal device 410 (e.g., a mobile phone, laptop, tablet, etc.). If terminal device 402 is newly purchased by a user and is temporarily unable to access the network, but second terminal device 410 stores the IP address of an authentication server 404, it can establish a communication connection with the authentication server 404. The user can then use second terminal device 410 to send the network access permission information of terminal device 402 to the authentication server 404 and verify the authenticity of terminal device 402.

[0124] In some implementations, the presentation format of the network access permission information can refer to Figure 4B . Figure 4B Figure 4 shows three presentation formats for network access permission information. Terminal device 402 can display the network access permission information in any of these formats. 420 represents the network access permission information presented solely in a quick response matrix code. Quick response matrix code 420 can contain both the network access permission information and, of course, the URL of an authenticity verification website (e.g., https: / / www.tenaa.com.cn). In some embodiments, when a user uses a second terminal device to scan the authenticity verification QR code displayed on the terminal device's screen, the user can automatically access the authenticity verification website to verify the terminal device's authenticity and receive the authenticity verification result. In 422, in addition to the network access permission information recorded in the quick response matrix code, the corresponding text recording the network access permission information is also displayed (for example, the text shown in 422 includes the network access license number "02-5043-163526", the device model "MHA-AL00", the device product serial number SN "A123456789012345", the scrambling code "9YP24PAA2C152TA" and the authenticity query website "https:\\www.tenaa.com.cn"). In addition to the network access permission information recorded in the quick response matrix code, 424 also displays the corresponding text recording the network access permission information (for example, the text shown in 426 includes the network access license number "02-5043-163526", the device model "MHA-AL00", the scrambling code "9YP24PAA2C152TA" and the authenticity query website "https:\\www.tenaa.com.cn"), as well as the terminal device product serial number ("A123456789012345") shown in barcode 428. The terminal device product serial number can be IMEI or MEID.

[0125] In some embodiments, the error correction level (Error Correction Code Level) of the network access permission information QR code is at least level L, and the QR code size is at least 80 pixels x 80 pixels. If the QR code is printed, the error correction level (Error Correction Code Level) of the network access permission information QR code is at least level Q. This ensures the accuracy of the QR code when it is scanned.

[0126] The authenticity verification server 404 can query the license information database to verify whether the terminal device is authentic. In some implementations, the authenticity verification server 404 can be Figure 1 The network access license management server 102 in the embodiment stores the network access license information corresponding to each terminal device (for example, a table of one-to-one correspondence between network access license information and terminal device product serial numbers). In other implementations, the authenticity verification server 404 may establish a connection with the terminal device. Figure 1 The authentication server 404 establishes a communication connection with the network access permit management server 102 and then accesses the network access permit information database of the network access permit management server. In this way, the authenticity verification server 404 verifies whether the terminal device is genuine by querying the network access permit information database to determine whether the terminal device has corresponding network access permit information. If the corresponding network access permit information exists, the terminal device is legitimate; if the corresponding network access permit information does not exist, the terminal device is illegal (or counterfeit).

[0127] although Figure 4A Only two terminal devices 402 and 410 are shown in FIG. 4 , but it should be understood that the system 400 may include any number and type of terminal devices configured to communicate with the authenticity verification server 404 .

[0128] Users typically check the authenticity of newly purchased terminal devices, but the query rate for paper network access permits is low. This is due to two factors: first, users need to manually enter the network access permit number, making it inconvenient to query; second, the network access permit label affixed to telecommunications equipment that has obtained network access permits is easily lost by users, and when they want to verify the authenticity, they find that they have already discarded the label. Therefore, a new method for verifying the authenticity of terminal devices during the out-of-box experience (OOBE) is needed. According to some embodiments of the present application, when a terminal device is first unpacked and powered on, or after a system reset, the computing device's operating system setup wizard (e.g., an Android / iOS setup wizard) is launched, and the authenticity of the terminal device is checked during the operating system setup wizard. The operating system setup wizard will go through the standard operating system setup process, which may include steps such as setting the operating system language, downloading operating system updates and bug fixes, and requesting the user to enter a WiFi password to set up the network. The operating system setup wizard will provide an authenticity query interface through which the user can verify the authenticity of the terminal device.

[0129] Figure 5 An exemplary process diagram 500 is shown for verifying the authenticity of a terminal device using an operating system setup wizard at the terminal device. Process diagram 500 begins when an operating system setup wizard 502 is launched. For example, when the terminal device is first unpacked and powered on, or after a system reset, the operating system setup wizard (boot wizard) 502 begins to set up the operating system. The operating system setup wizard 502 displays a language selection screen, WLAN settings, password / fingerprint settings, or other customization interfaces. Figure 5 In step 504, the operating system setup wizard 502 first presents a manufacturer-specific welcome interface. For example, the manufacturer-specific welcome interface may include the manufacturer's logo and the word "Welcome" on the screen. The manufacturer-specific welcome interface may also include a prompt for any information the manufacturer has for the user, such as confirmation of the user's service plan.

[0130] The operating system setup wizard 502 then presents the WLAN setup interface at step 506, requiring the user device to connect to Wi-Fi. If the user sees the name of a router, they can click the router's name on the Wi-Fi connection interface of the terminal device, enter the router's Wi-Fi password, and then click Connect to connect to the Wi-Fi network. Once connected to the Wi-Fi network, the user can then verify the device's authenticity or perform download operations. If the user chooses to skip step 506 of connecting to Wi-Fi, the user device will need to connect to a mobile network before verifying the device's authenticity or downloading software updates, which may consume a large amount of mobile data.

[0131] The operating system setup wizard 502 then presents an authenticity query interface at step 508. The authenticity query interface may display network access permission information and provide authenticity query interactive elements (eg, an authenticity query button, etc.) for the user to query the authenticity of the device.

[0132] Next, the operating system setup wizard 502 presents a user account addition interface in step 510, requesting the user to add a user account, such as a username and password for cloud storage. If the user already has an account, they can enter their account name and password and click Next. If the user does not have an account, they can click Create a New Account and fill in the relevant account information.

[0133] The operating system setup wizard 502 then provides a fingerprint scanning entry interface in step 512, which can provide a high level of security for the terminal device. If the user wants to use it, click Set Fingerprint to start the fingerprint entry process, and the user can also add multiple fingerprints.

[0134] Those skilled in the art will appreciate that, in addition to the manufacturer welcome interface, WLAN setup interface, authenticity query interface, user account addition interface, and fingerprint scanning entry interface mentioned above, the operating system setup wizard 502 may present more or fewer interfaces or processes than those shown in the figure, and the present embodiment of the application does not limit this. Moreover, the manufacturer welcome interface, WLAN setup interface, authenticity query interface, user account addition interface, and fingerprint scanning entry interface may be presented in any predetermined order. Figure 5 The example shown in FIG. 1 is just one example. In some cases, the authenticity query interface may be displayed after the manufacturer welcome interface. Furthermore, the user may select the back button to return to the previous interface for operation, for example, the user may return to the WLAN settings interface from the authenticity query interface.

[0135] Figure 6A Shown according to Figure 5 A user interface 600 for authenticity query is described. Similar user interfaces can be found in Figure 3 Implementation on the electronic device 300. Figure 6A As shown, in some embodiments, the user interface 600 includes the following elements or a subset thereof: a network access license information QR code 602 (the QR code in the figure contains the letters "NAL", which stands for Network Access License); a network access license number 604; an applicant 606 (A terminal device manufacturer); a device name 608; a device model 610; and an authenticity query button 612.

[0136] It should be pointed out that Figure 6AThe information in the authenticity query interface shown in FIG is only exemplary. For example, in some embodiments, the user interface 600 may further include other elements, such as a scrambling code or a terminal device serial number (a terminal device serial number includes an IMEI, MEID, or a product serial number SN).

[0137] In some embodiments, the user interface 600 may only display the network access permission information QR code 602, which may be encoded by one or any combination of the following items: network access permission number, terminal device model, scrambling code, IMEI, MEID, product serial number, authenticity query website, International Mobile Terminal Equipment Identity (IMEI), Mobile Terminal Equipment Identity (MEID), network access permission application unit, terminal device name, network access permission certificate validity period or issuance date. The user uses a second terminal device (for example, Figure 4A The second terminal device 410 in FIG. 4 ) scans the QR code 602. The second terminal device decodes the QR code to obtain the network access permission information encoded in the QR code, such as the network access permission number, the terminal device model, the scrambling code, IMEI, MEID, the international mobile terminal equipment identity code (IMEI), the mobile terminal equipment identification code (MEID), the network access permission application unit, the terminal device name, the validity period of the network access permission certificate or at least one of the issuance date. The second terminal device can use the IP address of the authenticity verification server stored therein to establish a communication connection with the authenticity verification server 404, and send the parsed network access permission information (for example, the network access permission number, the device model, and information such as the scrambling code) to the authenticity verification server (for example, the authenticity verification server 404 in FIG. 4 ). The user can use the camera on the second terminal device to scan the QR code for the authenticity query displayed on the screen of the terminal device. For example, the user can open a website or a mobile application for authenticity query (for example, Figure 4A The second terminal device can install QR code reading software to capture and decode the captured QR code. For example, the second terminal device displays a QR code scanning interface and prompts the user to align the second terminal device with the QR code displayed on the terminal device screen. The decoded network access permission information can be sent to the authenticity verification server to obtain the authenticity of the terminal device. The second terminal device can also encrypt the network access permission information and pass Figure 4A The network 406 in the embodiment sends the encrypted network access permission information to the authenticity verification server, thereby improving the security of communication transmission. The authenticity verification server can call the license information database to verify whether the device is authentic.

[0138] In some embodiments, the QR code 602 records the URL of the authenticity query website (for example, https: / / www.tenaa.com.cn). In some embodiments, when the user uses the second terminal device to scan the authenticity query QR code displayed on the screen of the terminal device, the authenticity query website can be automatically accessed to query the authenticity of the terminal device and receive the authenticity query result. In other embodiments, when the user uses the second terminal device to scan the authenticity query QR code displayed on the screen of the terminal device, the authenticity query website can be automatically opened, and the user can enter the network access permission information (for example, license number, device model, scrambling code, etc.) on the website to query the authenticity of the terminal device.

[0139] In some embodiments, the user interface 600 may not include the network access permission information QR code 602 (for example, the screen resolution of the terminal device cannot support the display of the complete network access permission information QR code). In this case, one or any combination of the following items may be displayed in text: network access permission number, terminal device model, scrambling code, IMEI, MEID, International Mobile Equipment Identity (IMEI), Mobile Equipment Identity (MEID), network access permission application unit, terminal device name, and network access permission certificate validity period or issuance date. In some embodiments, after the user clicks the authenticity query button 612, the terminal device uses the stored address of the authenticity verification server to establish a connection with the authenticity verification server (or accesses the authenticity verification server through the stored authenticity verification website URL), and then sends an authenticity query request (the authenticity query request may include any one or any combination of the following parameters: network access license number, terminal device model, scrambling code, international mobile terminal equipment identity code (IMEI), mobile terminal equipment identity code (MEID), network access license application unit, terminal device name, network access license certificate validity period or issuance date) to the authenticity verification server, thereby obtaining the authenticity of the terminal device and presenting the authenticity query result on the user interface of the terminal device. In some embodiments, the terminal device can use the POST request method of the HTTP protocol to submit the network access permission information to the authenticity query server. The terminal device can use the "JSON" structure to transmit the network access permission information. For example, the authenticity query request represented by the "JSON" structure is as follows:

[0140] {"BizCode":"VLD",

[0141] "L":"02-5043-163526",

[0142] "M":"MHA-AL00",

[0143] "R":"9YP24PAA2C152TA",

[0144] "C":"861234567890123,A0FFFFFF000000F"}

[0145] Among them, "BizCode" represents the business identifier, the default value is "VLD", "L" represents the network access license number, "M" represents the device model, "R" represents the scrambling code of the terminal device, and "C" represents the serial number of the terminal device. If there are multiple serial numbers (for example, the serial numbers "861234567890123" and "A0FFFFFF000000F" shown above), the serial numbers are separated by commas.

[0146] The query results returned by the authenticity verification server can also be transmitted using the "JSON" structure. For example, the authenticity query results expressed in the "JSON" structure are as follows:

[0147] {"RspCode":"0000",

[0148] "Result": "The flag information you queried is true and corresponds to the product serial number. This device supports TD-LTE / LTEFDD / TD-SCDMA / WCDMA / cdma2000 / CDMA 1X / GSM standards."}

[0149] Among them, "RspCode" represents the processing result identifier returned by the authenticity verification server, 0000 represents success, and 0001 represents failure. "Result" represents the query result information (for example, "The mark information you queried is true and corresponds to the product serial number. The device supports TD-LTE / LTE FDD / TD-SCDMA / WCDMA / cdma2000 / CDMA 1X / GSM standards." shown above). The query result information includes the authenticity information of the device's network access license electronic mark and the network standards supported by the device. Figure 6B An example page of authenticity query results is shown, which includes the query result "The mark information you queried is true and corresponds to the product serial number. The device supports TD-LTE / LTE FDD / TD-SCDMA / WCDMA / cdma2000 / CDMA 1X / GSM standards."

[0150] In some embodiments, the user can also click the authenticity query button 612. The terminal device uses the network access permission information (for example, the network access permission number, terminal device model, scrambling code, International Mobile Equipment Identity (IMEI), Mobile Equipment Identity (MEID), network access permission application unit, terminal device name, at least one of the validity period or issuance date of the network access permission certificate) to create an authenticity query link. By accessing the authenticity query link, the authenticity query page corresponding to the authenticity query link can be displayed, thereby obtaining the authenticity of the terminal device.

[0151] In one exemplary embodiment, after the user clicks the authenticity check button 612, the terminal device automatically obtains one or any combination of the network access license number (SN), device model (MODEL), scrambling code (SCRAMBLE), and terminal device serial number (e.g., International Mobile Equipment Identity (IMEI)), and concatenates the above information into a uniform resource locator (URL) for authenticity check. For example, if the terminal device's network access license number is 02-5043-163526, the device model is MHA-AL00, the scrambling code is 9YP24PAA2C152TA, and the IMEI is A123456789012345, the concatenated uniform resource locator (URL) is:

[0152] http: / / www.tenaa.com.cn / WSFW / FlagValidate_test.aspx?SN=02-5043-163526&MODEL=MHA-AL00&SCRAMBLE=9YP24PAA2C152TA&IMEI=A123456789012345

[0153] It can be seen that the network access license number (SN), device model (MODEL), scrambling code (SCRAMBLE), and IMEI are spliced ​​together to form a uniform resource locator (URL) for authenticity query. In response to the touch event of the authenticity query request button 612, the terminal device automatically opens the browser application and accesses the above URL. Examples of browsers include Internet Explorer, Mozilla, FireFox, Netscape, Chrome, etc. When the authenticity verification server of the Ministry of Industry and Information Technology receives the user's browser access with the above link, it automatically parses the above four parameters (SN, MODEL, SCRAMBLE, IMEI) and returns the authenticity query page. Figure 7As shown, after the terminal device opens the browser and accesses the above URL, the terminal device displays the telecommunications equipment network management authenticity information query page 700. The four parameters (SN, MODEL, SCRAMBLE, IMEI) appear in the corresponding query boxes (702, 704, 706, 708) respectively, and the user clicks the verification button 710 to perform the verification. The display interface of the verification result and Figure 6B Similarly, for example, the page contains the query result "The logo information you queried is true and corresponds to the product serial number. This device supports TD-LTE / LTE FDD / TD-SCDMA / WCDMA / cdma2000 / CDMA 1X / GSM standards."

[0154] The above describes a method for verifying the authenticity of a terminal device during the out-of-box experience (OOBE). Users need to verify the authenticity of a device not only when turning it on for the first time, but also during daily use. Figures 8A-8D An exemplary user interface for authenticity query on a terminal device according to some other embodiments is shown. Figures 8A-8D The user interface shown can be found in Figure 3 It is implemented on the electronic device 300 in.

[0155] See also Figure 8A , the user clicks Figure 8A Click the settings icon 802 in the menu to enter the settings interface, which includes basic adjustments to various terminal device attributes and function switches. Settings is the most convenient entry point for users to customize electronic devices (such as mobile phones) according to their personal preferences and is also one of the most frequently used modules in daily life.

[0156] The settings interface includes modules such as Wireless and Network (mainly responsible for WLAN management, mobile network management and SIM card management, etc.), User and Account (responsible for managing accounts and synchronization, cloud services, etc.), Display, Storage, Battery, System (including system updates, about the phone, language and input method, etc.). Users click System to enter Figure 8B The system information interface is displayed, and then click Figure 8B Click the 804 button in About Phone to enter Figure 8C The About Mobile Phone interface shows a Network Access Permission option 806. The user clicks on the Network Access Permission option 806 to enter the Figure 8D The authenticity query page shown. Figure 6A similar, Figure 8D The user interface shown includes the following elements or a subset thereof: network access permission information QR code 808, network access permit number 810, applicant 812, device name 814, device model 816, authenticity check button 818. The user can also Figure 8D Click the authenticity check button 818 on the page shown to check the authenticity of the terminal device. The specific method is as follows Figure 6A , 6B and Figure 7 Similar to what is shown in Figure 6A , 6B and Figure 7 For example, a user uses a second terminal device (eg, Figure 4A The second terminal device 410 in the QR code scans the QR code 808. The second terminal device decodes the QR code to obtain the network access license number, device model, and at least one of the information such as the scrambling code, the applicant unit, or the device name encoded in the QR code. The second terminal device can send the parsed network access permission information (e.g., the network access license number, device model, and information such as the scrambling code) to the authenticity verification server (e.g., Figure 4A For example, after the user clicks the authenticity query button 818, it enters a similar Figure 7 The authenticity query webpage shown in the figure can be used to query the authenticity of the terminal device.

[0157] Of course, in some implementations, the network access permission information can also be viewed through special program software installed on the terminal device (for example, program software provided by the Ministry of Industry and Information Technology) to verify the authenticity of the terminal device.

[0158] Figure 9 A flowchart 900 of an exemplary method for checking the authenticity of a terminal device is shown. For example, process 900 may be initiated when a user first starts the terminal device, resets the terminal device system, or enters the authenticity check function entry through the settings icon.

[0159] like Figure 9 As shown, process 900 begins at step 910 by automatically reading network access permission information. The network access permission information includes one or any combination of the following items: network access permission number, terminal device model, scrambling code, International Mobile Equipment Identity (IMEI), Mobile Equipment Identity (MEID), network access permission application unit, terminal device name, and network access permission certificate validity period or issuance date.

[0160] In some embodiments, the network access permission information is stored in a non-volatile memory of the terminal device. In this way, when the terminal device is powered on for the first time, the stored network access permission information can be automatically read and accessed through Figure 6A The interface shown presents the network access permission information.

[0161] In some embodiments, the terminal device receives a first touch input from the user. In response to the first touch input, the terminal device automatically reads the network access permission information. For example, Figure 8CAfter the first touch input of selecting the network access permission option 806 in the user interface shown in FIG, the network access permission information is obtained and displayed as shown in FIG. Figure 8D Of course, input methods other than touch input may also be used, for example, other types of gesture inputs may be included, such as 3D gestures or gesture inputs involving movement of the terminal device.

[0162] In step 920, a first user interface is displayed, where the first user interface includes the network access permission information (or the network access permission electronic mark).

[0163] Specifically, in some embodiments, after the terminal device is started for the first time or the terminal device system is reset, the terminal device executes the operating system setup wizard. For example, Figure 5 The operating system setting wizard 502 shown in FIG. 5 displays the WLAN setting interface in step 506, and after receiving the user's first touch input on the WLAN setting interface (for example, clicking a button such as "Next" or "Skip" in the WLAN setting interface), the first user interface (for example, the authenticity query interface) is displayed. In other embodiments, the user enters the setting interface similar to that shown in FIG. 8 through the setting icon, and then enters the following steps: Figure 8C The mobile phone interface shown in FIG. 10 obtains the first touch input of the user on the mobile phone interface (for example, the user clicks Figure 8C After the network access permission option 806 is displayed, the first user interface (eg, Figure 8D Authenticity query interface shown).

[0164] In some embodiments, the first user interface also includes an authenticity query interactive element. The first interface can also use text to display information such as the terminal device's International Mobile Terminal Equipment Identity (IMEI), Mobile Terminal Equipment Identity (MEID), the network access license application unit, the terminal device name, the network access license certificate validity period or issuance date. The authenticity query interactive element can be Figure 6A Authenticity check button 612 or Figure 8D Authenticity query button 818 in.

[0165] In some embodiments, the network access permission information may be recorded in a quick response matrix code, or in the form of text or images.

[0166] In step 930, a first touch input is received to select the authenticity query interactive element. In some embodiments, the user selection is obtained. Figure 6A Authenticity check button 612 or Figure 8D The first touch input of the authenticity query button 818 in Figure 6A Authenticity check button 612 or Figure 8D Authenticity query button 818).

[0167] In step 940, in response to the first touch input, an authenticity query request is sent to the authenticity query request server, and the authenticity query request includes the network access permission information. In some embodiments, the authenticity query request (e.g., HTTP GET request) can be sent to the authenticity query request server via a browser. For example, the user selects Figure 6A Authenticity check button 612 or Figure 8D The first touch input of the authenticity query button 818 in Figure 6A Authenticity check button 612 or Figure 8D After clicking the authenticity query button 818 in the terminal device, the terminal device uses the network access permission information (for example, at least one of the network access license number, device model, scrambling code or terminal device serial number) to assemble an authenticity query link (for example, a uniform resource locator (URL)). When accessing the authenticity query link through a web browser, an authenticity query page corresponding to the authenticity query link (for example, Figure 7 ), obtain the user's input when clicking the authenticity query button on the authenticity query page (for example, the user clicks Figure 7 ), and sends an authenticity query request to the authenticity verification server.

[0168] In other embodiments, in response to a user selecting Figure 6A Authenticity check button 612 or Figure 8D The first touch input of the authenticity query button 818 in Figure 6A Authenticity check button 612 or Figure 8D The authenticity query button 818 in the browser) can send an authenticity query request to the authenticity verification server without calling the browser (for example, the terminal device stores the network address of the authenticity verification server, through Figure 4A One or more networks 406 in the network send an authenticity query request to the authenticity verification server 404), and receive a query result from the authenticity verification server.

[0169] In step 950, the authenticity query result corresponding to the network access permission information is received from the authenticity query request server. The authenticity verification server processes the authenticity query request, obtains the network access permission information from the authenticity query request, and queries the license information database to verify the authenticity of the terminal device.

[0170] In step 960, the authenticity query result is displayed.

[0171] Through the method of the embodiments of the present application, users can intuitively view the device's network access permission information through the terminal device's user interface and conveniently check the terminal device's authenticity through the authenticity query interface. Compared to previous paper network access permission marks, this method can improve the authenticity verification rate of terminal devices, and users can check the authenticity of terminal devices at any time after purchasing the terminal device.

[0172] The embodiment of the present application can divide the functional modules of the terminal device according to the above method example. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. In actual implementation, there may be other division methods.

[0173] In the case of dividing each functional module into corresponding functional modules, such as Figure 10 As shown, the embodiment of the present application provides a terminal device 1000, which includes a first reading unit 1001, a first display unit 1002, a first receiving unit 1003, a sending unit 1004, a second receiving unit 1005 and a second display unit 1006. The relevant actions of these functional modules can be referred to Figure 9 For example, the first reading unit 1001 is used to perform step 910, the first display unit 1002 is used to perform step 920, the first receiving unit 1003 is used to perform step 930, the sending unit is used to perform step 940, the second receiving unit 1005 is used to perform step 950, and the second display unit 1006 is used to perform step 960.

[0174] In the case of integrated units, such as Figure 11 , which shows another possible structural diagram of the terminal device involved in the above embodiment, including a processing module 1101 , a communication module 1102 , an input / output module 1103 and a storage module 1104 . Figure 11 The terminal device shown is used to execute the above method embodiment (for example, Figure 9 ) is a terminal device authenticity verification method described in .

[0175] The processing module 1101 is used to control and manage the terminal device's operations. The communication module 1102 is used to support communication between the terminal device and other network entities. The input / output module 1103 is used to receive information input by the user or output information provided to the user and various terminal menus. The storage module 904 is used to store the terminal device's program code and data.

[0176] When the processing module 1101 is a processor (such as Figure 3 The processor 310 shown in FIG. 1 is a processor 310 shown in FIG. 1 , and the communication module Figure 3 The mobile communication module 350 or wireless communication module 360 ​​shown in FIG. 1 , the storage module 1104 is a memory (such as Figure 3 The memory 321 shown in FIG. 110 is a display screen (such as FIG. Figure 3 When the display screen 394 is shown, the terminal device provided by this application can be Figure 3 The electronic device 300 shown in FIG. 1 includes the processor, communication module, display screen, and memory that can be coupled together via a bus.

[0177] The embodiment of the present application further provides a terminal device, including a processor and a memory, wherein the memory is used to store computer program code, and the computer program code includes computer instructions. When the processor executes the computer instructions, the method embodiment (for example, Figure 9 ) is a terminal device authenticity verification method described in .

[0178] The embodiment of the present application further provides a computer storage medium in which computer program code is stored. When the processor executes the computer program code, the device executes Figure 9 The relevant method steps in implement the method in the above embodiment.

[0179] The present application also provides a computer program product that, when executed on a computer, enables the computer to execute Figure 9 The relevant method steps in implement the method in the above embodiment.

[0180] In some cases, counterfeit terminals produced by counterfeit terminal manufacturers can also display similar Figure 6A or Figure 8D The user interface shown displays forged network access permission information and provides similar authenticity query interaction elements. When the user selects the authenticity query interaction element displayed by the counterfeit terminal, the counterfeit terminal directly displays a query result such as "The logo information you queried is authentic and corresponds to the product serial number." In fact, when the user selects the authenticity query interaction element, the counterfeit terminal does not send an authenticity query request to the authenticity verification server. Instead, it directly displays the query result "The logo information you queried is authentic and corresponds to the product serial number," misleading the user into believing that the product they purchased is authentic. In this case, the counterfeit terminal does not access the authenticity verification server at all, but simply uses forged network access permission information and forged authenticity query results to mislead the user into believing that the product they purchased is authentic.

[0181] In response to the above situation where counterfeit terminals mislead consumers, the embodiments of the present application also provide another terminal device authenticity query system.

[0182] See also Figure 12 , Figure 12 The device includes an authenticity verification device 1202 and a terminal device 1204. The authenticity verification device 1202 can detect the authenticity of the terminal device 1204. The authenticity verification device 1202 can be provided by the Ministry of Industry and Information Technology (MIIT) or a third-party authentication agency, and can detect the authenticity of the terminal device 1204. If a user suspects that the terminal device they purchased is counterfeit, they can submit the terminal device to a professional testing agency approved by the MIIT and verify it using the authenticity verification device 1202. If the terminal device passes the authenticity verification test, it indicates that the user has purchased an authentic product.

[0183] The authenticity verification device 1202 and the terminal device 1204 can establish a connection 1212 via a wired connection, for example, via a USB Type C or micro USB cable. Of course, the authenticity verification device 1202 and the terminal device 1204 can be connected via other methods (such as a wireless connection or other wired connection methods), which is not limited in this embodiment of the present application.

[0184] The authenticity verification device 1202 displays a device manufacturer configuration interface element 1204 and a device model configuration interface element 1208. The device manufacturer configuration interface element 1204 is used to configure the manufacturer of the terminal device to be verified, and the user can select the manufacturer of the terminal device (for example, the H manufacturer shown in the figure) through the drop-down button shown in 1210. The device model configuration interface element 1208 is used to configure the model of the terminal device to be verified, and the user can select the model of the terminal device (for example, the "MHA-AL00" shown in the figure) through the drop-down button 1214. Of course, the authenticity verification device 1202 can also display other detection parameter configuration interface elements, which are not limited in the embodiments of the present application. After the detection parameters such as the device manufacturer and device model are configured, the "Start Verification" button 1216 can receive the selection input of the detection personnel to start the authenticity verification process. If the terminal device 1204 passes the authenticity verification test, the authenticity verification device 1202 can display a verification result such as "The logo information you queried is true and corresponds to the product serial number. The device supports TD-LTE / LTE FDD / TD-SCDMA / WCDMA / cdma2000 / CDMA 1X / GSM standards."

[0185] Figure 13 Shown for Figure 12 An exemplary authenticity query process diagram of a terminal device authenticity system is shown.

[0186] In step 1302, the terminal device receives the authenticity query instruction sent by the authenticity verification device; for example, the inspection personnel selects Figure 12 The "Start Verification" button 1216 is shown, and the authenticity verification device sends an authenticity query instruction to the terminal device to start the authenticity verification process.

[0187] At step 1304, the terminal device initiates an authentication process for the terminal device in response to the authenticity query instruction;

[0188] In some embodiments, authentication between the terminal device and the authenticity verification device is performed using an asymmetric key encryption algorithm. The terminal device and the authenticity verification device store at least one key pair for authentication (the key pair includes a private key and a public key). For example, the terminal device stores the public key and the authenticity verification device stores the private key; or alternatively, the terminal device stores the private key and the authenticity verification device stores the public key. If one party encrypts data using the public key, the other party can only decrypt it using the corresponding private key. If one party encrypts data using the private key, the other party can only decrypt it using the corresponding public key.

[0189] For example, the terminal device uses a private key to encrypt specific data (such as a random number or the terminal device's unique identifier), while the authentication device uses a public key to decrypt the data. If decryption is successful, the terminal device is considered authenticated. After successful authentication, the terminal device reads the network access permission information and transmits it to the authentication device. The authentication device checks whether the network access permission information is stored in the network access permission information database. If so, the terminal device is authenticated.

[0190] In some embodiments, the authenticity verification device may also obtain the certificate of the terminal device and send the certificate to the CA (Certificate Authority) management server of the terminal device manufacturer to verify the certificate. If the verification passes, it indicates that the authentication of the terminal device is successful.

[0191] In step 1306, after the terminal device is authenticated, the terminal device automatically reads the network access permission information, which includes one or any combination of the following items: network access permission number, terminal device model, scrambling code, international mobile terminal equipment identity code (IMEI), mobile terminal equipment identification code (MEID), network access permission application unit, terminal device name, network access permission certificate validity period or issuance date; the terminal device sends the above-mentioned network access permission information to the authenticity verification device, so that the authenticity verification device obtains the authenticity query result corresponding to the network access permission information.

[0192] In some embodiments, in step 1306, after the terminal device is authenticated, in addition to sending the network access permission information to the authenticity verification device, the terminal device also sends the product serial number of the terminal device (the unique identifier of the terminal device, such as IMEI, MEID or hardware serial number) to the authenticity verification device. After obtaining the product serial number, the authenticity verification device queries whether the serial number matches the stored serial number delivered by the terminal device manufacturer. If they match, it means that the terminal device is authentic.

[0193] Figure 14 Another exemplary process diagram 1400 for verifying the authenticity of a terminal device is shown.

[0194] like Figure 14 As shown, the process 1400 starts at step 1402, where the authenticity verification device 1202 sends an authenticity query instruction to the terminal device 1204. For example, an operator of a third-party authentication agency or the Ministry of Industry and Information Technology can use the operation interface (e.g., Figure 12 The "Start Verification" button 1216 on the user interface presented by the authentication verification device 1202 (shown in FIG. 1 ) initiates the authentication verification process. The user interface presented by the authentication verification device 1202 can be configured with terminal device manufacturer information (e.g., manufacturer name) or terminal device model information. In response to receiving input from the operator selecting the "Start Verification" button, the authentication verification device transmits an authenticity query instruction to the terminal device 1204.

[0195] In step 1404 , the terminal device 1204 generates a random number in response to the authenticity query instruction; for example, the terminal device 1204 generates the random number using a random number generator and some random number generation algorithm.

[0196] In step 1406, terminal device 1204 encrypts the random number. The encryption algorithm may be an asymmetric encryption algorithm, such as RSA, ECC (Elliptic Curves Cryptography), or DSA (Digital Signature Algorithm). Terminal device 1204 and authentication device 1202 store at least one key pair for authentication (a key pair includes a private key and a public key). For example, terminal device 1204 stores the public key and authentication device 1202 stores the private key; alternatively, terminal device 1204 stores the private key and authentication device 1202 stores the public key. If one party encrypts data using the public key, the other party can only decrypt it using the corresponding private key. If one party encrypts data using the private key, the other party can only decrypt it using the corresponding public key. In step 1406, terminal device 1204 may use the public key (or private key) of the first key pair to encrypt the random number.

[0197] At step 1408, the encrypted random number is transmitted to the authenticity verification device 1202;

[0198] In step 1410, the authenticity verification device 1202 decrypts the encrypted random number; in step 1406, if the terminal device 1204 uses the public key in the first key pair to perform encryption of the random number, the authenticity verification device 1202 can use the private key in the saved first key pair to decrypt the encrypted random number.

[0199] In step 1412, the authentication verification device 1202 re-encrypts the decrypted random number. In step 1412, the authentication verification device 1202 may use the public key (or private key) of the second key pair to encrypt the random number. In some embodiments, the second key pair may be different from the first key pair.

[0200] In step 1414 , the authenticity verification device 1202 transmits the re-encrypted random number to the terminal device 1202 .

[0201] In step 1416, the terminal device 1204 decrypts the re-encrypted random number. If, in step 1412, the authenticity verification device 1202 used the public key of the second key pair to encrypt the random number, the terminal device 1204 can decrypt the encrypted random number using the stored private key of the second key pair.

[0202] In step 1418, the terminal device compares the random number decrypted in step 1416 with the random number generated in step 1404 to see if they are the same. If they are the same, step 1420 is executed. If the verification in step 1418 fails, the terminal device is proven to be an illegal device, and the authenticity verification process ends.

[0203] In step 1420, the terminal device returns a successful authentication result to the authenticity verification device; steps 1402 to 1420 only illustrate one authentication process for the terminal device 1204. The authenticity verification device 1202 can perform various authentication operations on the terminal device 1204 to ensure the legitimacy of the identity of the terminal device 1204. For example, in some embodiments, the authenticity verification device 1202 can also obtain the terminal device's certificate after step 1420 and send the certificate to the terminal device manufacturer's CA (Certificate Authority) management server to verify the certificate. If the verification passes, it indicates that the authentication of the terminal device 1204 is successful. For example, in step 1422, the authenticity verification device 1202 obtains the device certificate from the terminal device 1204;

[0204] At step 1424, the authentication device 1202 verifies the legitimacy of the device certificate, which is used to authenticate the terminal device. The authentication device 1202 can send the certificate to the terminal device manufacturer's CA (Certificate Authority) management server for verification. If the device certificate is legitimate, the process proceeds to step 1426. If not, the terminal device is deemed illegitimate, and the authentication process ends.

[0205] In step 1426 , the authenticity verification device 1202 obtains the network access permission information from the terminal device 1204 , and in step 1428 , the authenticity verification device 1202 verifies whether the network access permission information is legitimate.

[0206] If the network access permission information is valid, step 1430 is executed; if the network access permission information is invalid, the authenticity verification process ends. The authenticity verification device stores the network access permission information of the terminal device, and the authenticity verification device compares the obtained network access permission information with the stored device network access permission information to determine whether the terminal device is valid.

[0207] In addition to sending the network access permission information to the authenticity verification device, the terminal device can also send the product serial number of the terminal device (the unique identifier of the terminal device, such as IMEI, MEID or hardware serial number) to the authenticity verification device in step 1430. After obtaining the product serial number, the authenticity verification device will query whether the serial number matches the stored serial number delivered by the terminal device manufacturer. If they match, it means that the terminal device is authentic.

[0208] In step 1230, the authenticity verification device obtains the device serial number from the terminal device, and in step 1232, the authenticity verification device verifies whether the device serial number (the device serial number can be the terminal device product serial number (such as the International Mobile Equipment Identity (IMEI) or the Mobile Equipment Identifier (MEID))) is legal. If the device serial number is legal, step 1230 is executed; if the network access permission information is illegal, the authenticity verification process ends. Among them, the authenticity verification device stores the device serial number of the terminal device, and the authenticity verification device compares the obtained network access permission information with the stored device serial number to determine whether the terminal device is legal.

[0209] Figure 14 The illustrated authentication method verifies the legitimacy of a terminal device through four authentication methods: random number authentication, device certificate authentication, network access permission information authentication, and device serial number authentication. Failure to pass any of these authentication steps indicates that the terminal device is illegitimate, significantly increasing the difficulty of counterfeiting terminal devices and thereby protecting the legitimate rights and interests of terminal device manufacturers and consumers. Of course, in some embodiments, any one or a combination of these four authentication methods may be selected to verify the legitimacy of a terminal device.

[0210] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using a software program, it can appear in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD) or a semiconductor medium (e.g., a solid-state drive (SSD)).

[0211] The above description is only a specific implementation method of the present application, but the protection scope of the present application is not limited thereto. Any changes or replacements within the technical scope disclosed in the present application should be included in the protection scope of the present application.

Claims

1. A method for checking the authenticity of a terminal device, characterized in that: The method is applied to a terminal device, wherein the terminal device includes an interface for obtaining network access permission information, and the method includes: Obtaining network access permission information by calling the interface, the network access permission information including one or any combination of the following items: network access permission number, terminal device model, scrambling code, international mobile terminal equipment identity code, mobile terminal equipment identity code, network access permission application unit, terminal device name, network access permission certificate validity period or issuance date; Displaying a first user interface, wherein the first user interface includes the network access permission information and an authenticity query interaction element; receiving a first touch input for selecting the authenticity query interactive element; In response to the first touch input, sending an authenticity query request to an authenticity verification server, wherein the authenticity query request includes the network access permission information, and the authenticity verification server is managed by a network access permission management organization; receiving an authenticity query result corresponding to the network access permission information from the authenticity verification server; The authenticity query result is displayed.

2. The method according to claim 1, characterized in that Before obtaining the network access permission information, the method further includes: Verifying the permission of the application requesting access to the network access permission information; In a case where the application has permission to access the network access permission information, the application is allowed to access the network access permission information.

3. The method according to claim 2, characterized in that The application includes a setup application or an operating system setup wizard application.

4. The method according to claim 2, characterized in that The application is located in the application layer of the operating system of the terminal device.

5. The method according to claim 1, wherein The interface is located in the framework layer of the operating system of the terminal device.

6. The method according to claim 1, wherein The authenticity query result includes query result information, and the displaying of the authenticity query result specifically includes: The query result information in the authenticity query result is displayed.

7. The method according to claim 6, characterized in that The authenticity query result also includes a processing result identifier, and the processing result identifier is used to indicate success or failure.

8. The method according to claim 6 or 7, characterized in that The authenticity query result is transmitted in a JSON structure.

9. The method according to claim 1, characterized in that The authenticity query request is transmitted in a JSON structure.

10. The method according to claim 1, wherein The network access permission information is stored in the non-volatile memory of the terminal device.

11. The method according to claim 1 or 10, wherein: The network access permission information displayed on the first user interface is recorded in a quick response matrix code.

12. The method according to claim 1, wherein The method further comprises: An operating system setup wizard is started, wherein the first user interface is presented during the operating system setup wizard process.

13. The method according to claim 1, wherein The sending of the authenticity query request to the authenticity verification server includes: generating a uniform resource locator including the network access permission information; The resource identified by the uniform resource locator in the authenticity verification server is accessed through a web browser.

14. A terminal device comprising a memory, one or more processors, a plurality of application programs, and one or more programs; wherein the one or more programs are stored in the memory; characterized in that The terminal device includes an interface for obtaining network access permission information, and when the one or more processors execute the one or more programs, the terminal device performs the following steps: Obtaining network access permission information by calling the interface, the network access permission information including one or any combination of the following items: network access permission number, terminal device model, scrambling code, international mobile terminal equipment identity code, mobile terminal equipment identity code, network access permission application unit, terminal device name, network access permission certificate validity period or issuance date; Displaying a first user interface, wherein the first user interface includes the network access permission information and an authenticity query interaction element; receiving a first touch input for selecting the authenticity query interactive element; In response to the first touch input, sending an authenticity query request to an authenticity verification server, wherein the authenticity query request includes the network access permission information, and the authenticity verification server is managed by a network access permission management organization; receiving an authenticity query result corresponding to the network access permission information from the authenticity verification server; The authenticity query result is displayed.

15. The terminal device according to claim 14, wherein: When executing the one or more programs, the one or more processors further cause the terminal device to perform the following steps: Verifying the permission of the application requesting access to the network access permission information; In a case where the application has permission to access the network access permission information, the application is allowed to access the network access permission information.

16. The terminal device according to claim 15, wherein: The application includes a setup application or an operating system setup wizard application.

17. The terminal device according to claim 15, characterized in that The application is located in the application layer of the operating system of the terminal device.

18. The terminal device according to claim 14, wherein: The interface is located in the framework layer of the operating system of the terminal device.

19. The terminal device according to claim 14, wherein: The authenticity query result includes query result information. When the one or more processors execute the one or more programs, the terminal device further executes the following steps: The query result information in the authenticity query result is displayed.

20. The terminal device according to claim 19, wherein: The authenticity query result also includes a processing result identifier, and the processing result identifier is used to indicate success or failure.

21. The terminal device according to claim 19 or 20, characterized in that: The authenticity query result is transmitted in a JSON structure.

22. The terminal device according to claim 14, wherein: The authenticity query request is transmitted in a JSON structure.

23. The terminal device according to claim 14, wherein: The network access permission information is stored in the non-volatile memory of the terminal device.

24. The terminal device according to claim 14 or 23, characterized in that: The network access permission information displayed on the first user interface is recorded in a quick response matrix code.

25. The terminal device according to claim 14, wherein: When executing the one or more programs, the one or more processors further cause the terminal device to perform the following steps: An operating system setup wizard is started, wherein the first user interface is presented during the operating system setup wizard process.

26. The terminal device according to claim 14, wherein: The sending of the authenticity query request to the authenticity verification server includes: generating a uniform resource locator including the network access permission information; The resource identified by the uniform resource locator in the authenticity verification server is accessed through a web browser.

27. A computer program product comprising instructions, characterized in that When the computer program product is run on a terminal device, the terminal device is caused to execute the method according to any one of claims 1 to 13.

28. A computer-readable storage medium comprising instructions, characterized in that: When the instruction is executed on a terminal device, the terminal device is caused to execute the method according to any one of claims 1 to 13.

Citation Information

Patent Citations

  • System and method for antifake and counting marketing-information of hand-set based on short message

    CN1581189A