A communication method and device based on IMS data channel

Through the collaborative work of the certificate management server and the key management server, the generation and distribution of reliable data channel application certificates is solved, and the problem of network loss in the IMS data channel is realized, and reliable communication process supervision and terminal security are achieved.

CN114079650BActive Publication Date: 2025-08-08HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010803406.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-08-11
Publication Date
2025-08-08
Estimated Expiration
2040-08-11

AI Technical Summary

Technical Problem

The security certificate of the IMS data channel is generated or installed by the terminal itself, causing the network to lose its control and supervision capabilities of communication content, affecting communication reliability.

Method used

The certificate management server receives encrypted tickets and application identification information, verifies it to the key management server and generates a data channel application certificate, and sends it to the terminal by the application server to ensure the reliability of the certificate and network supervision capabilities.

Benefits of technology

Reliable IMS data channel communication is realized, ensuring the network's supervision of the communication process and terminal security, and improving the reliability of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114079650B_ABST
    Figure CN114079650B_ABST
Patent Text Reader

Abstract

The present application provides a communication method and device based on an IMS data channel. The method may include: a certificate management server receives an encrypted ticket and identification information of a first application from an AS; the certificate management server sends the encrypted ticket and identification information of the first application to a KMS; the certificate management server receives a first key; the certificate management server sends a data channel application certificate corresponding to the first key to the first terminal of the AS, and the data channel application certificate is used for the first application to perform IMS data channel services with the second application of the second terminal. In the present application, the certificate management server issues a reliable data channel application certificate to the first terminal, and the IMS network is able to obtain the data channel application certificate, thereby avoiding the first terminal manually installing / replacing a third-party (non-communication network provided) certificate and using an unreliable self-signed certificate, thereby providing reliable IMS data channel communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of wireless communications, and in particular to a communication method and device based on an IMS data channel. Background Art

[0002] The Internet Protocol Multimedia Subsystem (IMS) data channel is a new concept emerging in the industry. Its key technical feature is the overlay of fifth-generation wireless systems (5G) data channels on top of voice over long-term evolution (VoLTE) voice services. This upgrades IMS-based real-time audio and video communications to real-time interaction, enriching the business scenarios enabled by IMS.

[0003] Currently, IMS data channels can be considered a new media type, using the Stream Control Transmission Protocol over Datagram Transport Layer Security over User Datagram Protocol (SCTP over DTLS over UDP), which is used in Web Real Time Communication (WebRTC), as the bearer protocol. This means that the security mechanism of IMS data channels differs from that used by audio and video services. The former uses SCTP over DTLS over UDP, while the latter uses Secure Real-Time Transport Protocol (SRTP). SCTP over DTLS over UDP requires a security certificate, while SRTP only requires a key. If the security certificate used by the IMS data channel is generated or installed by the terminal or application itself, the network loses control and supervision over the communication content of the IMS data channel, affecting communication reliability. Summary of the Invention

[0004] The present application provides a communication method and device based on an IMS data channel to provide reliable IMS data channel communication.

[0005] In a first aspect, the present application provides a communication method based on an IMS data channel, which can be applied to a certificate management server in a communication network. In the communication network, the certificate management server can communicate with a corresponding terminal (such as a first terminal) through network elements of the IMS network, such as an application server (AS) and a call session control function (CSCF). When a first application on a first terminal is about to conduct an IMS data channel service with a second application on a second terminal, first, the certificate management server receives an encrypted ticket (ticket) and identification information of the first application used to identify the first application forwarded by the AS from the first terminal. Then, the certificate management server sends the encrypted ticket and the identification information of the first application to the key management server (KMS), so that the KMS verifies the first application based on the encrypted ticket and the identification information of the first application, and notifies the certificate management server of the verification result; then, after the first application is successfully verified, the certificate management server receives the first key from the KMS and generates a corresponding data channel application certificate based on the first key. Finally, the certificate management server sends the data channel application certificate to the first terminal via the AS, so that the first application can conduct IMS data channel service with the second application based on the data channel application certificate.

[0006] In this application, the certificate management server issues a reliable data channel application certificate to the first terminal, and the IMS network is able to obtain the data channel application certificate, avoiding the first terminal manually installing / replacing a third-party (non-communication network provided) certificate and using an unreliable self-signed certificate, thereby providing reliable IMS data channel communication.

[0007] In some possible implementations, the first terminal may further send the address of the KMS to the certificate management server. In this way, the certificate management server may send the encrypted ticket and identification information of the first application to the corresponding KMS according to the address of the KMS.

[0008] In other possible implementations, the certificate management server can send the data channel application certificate and the identification information of the first application to the first terminal through the AS. In this way, the first terminal can know that the received data channel application certificate is assigned to the first application, and then associate the data channel application certificate with the identification information of the first application and save it.

[0009] In some other possible implementations, the identification information of the first application may include: a terminal identification of the first terminal; or a terminal identification of the first terminal and an application identification of the first application.

[0010] Optionally, the terminal identifier of the first terminal includes: a device identifier of the first terminal or a user identifier of a user using the first terminal.

[0011] In this application, the above-mentioned terminal identifier can be a device identifier used for the terminal, such as an international mobile subscriber identity (IMSI), an international mobile equipment identity (IMEI), etc., and can also be a user identifier of a user using the terminal, such as an Internet Protocol Multimedia Public Identity (IMPU); the application identifier can be an application identifier (AID).

[0012] In some other possible implementations, the encrypted ticket may include identification information of the first application. For example, the encrypted ticket may be implemented in the form of a MIKEY (multimedia internet keying) ticket.

[0013] Furthermore, in order to improve reliability, the encrypted ticket may further include: a key index of a second key, the second key matches the first key, and the second key is allocated by the KMS to the first application.

[0014] In the present application, the key index of the second key can be the second key itself, or the first key corresponding to the second key, or the identifier of the second key, etc. Of course, the key index can also be in other forms, as long as the second key can be uniquely determined by the key index of the second key.

[0015] In the second aspect, the present application provides a communication method based on the IMS data channel, including: KMS obtains a first encrypted ticket and identification information of a first application from a certificate management server, and the identification information of the first application is used to identify the first application of the first terminal; KMS decrypts the first encrypted ticket to obtain the identification information in the first encrypted ticket; KMS verifies the first application based on the identification information and the identification information of the first application; if the verification of the first application is successful, KMS sends a first key to the certificate management server, and the first key matches the second key assigned by KMS to the first application. The first key is used by the certificate management server to generate a data channel application certificate for the first application, and the data channel application certificate is used for the first application to perform IMS data channel services with the second application of the second terminal.

[0016] In some possible implementations, the KMS may determine whether the identification information matches the identification information of the first application, where if the identification information matches the identification information of the first application, it indicates that the verification of the first application is successful; if the identification information does not match the identification information of the first application, it indicates that the verification of the first application has failed.

[0017] In this application, by determining whether the identification information matches the identification information of the first application, it is verified whether the identification information in the encrypted ticket is consistent with the identification information of the first application that sent the encrypted ticket, thereby verifying whether the first application is legal.

[0018] Furthermore, to improve reliability, the first encrypted ticket may further include a key index; accordingly, the KMS may verify the first application based on the identification information, the key index, and the identification information of the first application.

[0019] In other possible implementations, the KMS may determine whether the identification information matches the identification information of the first application; if the identification information matches the identification information of the first application, the KMS determines whether the key index matches the second key; wherein, if the key index matches the second key, it indicates that the verification of the first application is successful; if the key index does not match the second key, it indicates that the verification of the first application has failed.

[0020] In other possible implementations, before the KMS obtains the first encryption ticket and identification information of the first application from the certificate management server, the above method may also include: the KMS receives a key request from the first terminal; the KMS responds to the key request and allocates a second key and a second encryption ticket to the first application, where the second encryption ticket includes: identification information of the first application, or identification information of the first application and a key index of the second key; the KMS sends the second key and the second encryption ticket to the first terminal.

[0021] In some other possible implementations, the identification information of the first application includes: a terminal identification of the first terminal; or a terminal identification of the first terminal and an application identification of the first application.

[0022] In some other possible implementations, the terminal identifier of the first terminal includes: a device identifier of the first terminal or a user identifier of a user using the first terminal.

[0023] In some other possible implementations, the above method may further include: the KMS and the first terminal establishing a communication channel using a generic bootstrapping architecture (GBA).

[0024] In the third aspect, the present application provides a communication method based on the IMS data channel, including: the first terminal sends an encrypted ticket and identification information of a first application to a certificate management server via an AS, where the identification information of the first application is used to identify the first application of the first terminal; the first terminal receives a data channel application certificate sent by the certificate management server via the AS, where the data channel application certificate is sent by the certificate management server after successfully verifying the first application based on the encrypted ticket and the identification information of the first application; the first terminal performs IMS data channel services with the second application of the second terminal based on the data channel application certificate.

[0025] In some possible implementations, the above method may further include: the first terminal sending the address of the KMS to the certificate management server via the AS, where the address of the KMS is used to instruct the certificate management server to communicate with the KMS.

[0026] In some other possible implementations, the identification information of the first application includes: a terminal identification of the first terminal; or a terminal identification of the first terminal and an application identification of the first application.

[0027] In some other possible implementations, the terminal identifier of the first terminal includes: a device identifier of the first terminal or a user identifier of a user using the first terminal.

[0028] In some other possible implementations, before the first terminal sends the encrypted ticket and the identification information of the first application to the certificate management server, the above method may also include: the first terminal requests the key and the ticket from the KMS; the first terminal receives the second key and the encrypted ticket allocated by the KMS to the first application, and the encrypted ticket includes: the identification information of the first application, or the identification information of the first application and the key index of the second key.

[0029] In other possible implementations, the data channel application certificate is generated by the certificate management server based on the first key, and the first key matches the second key; accordingly, when the second terminal successfully verifies the first application, the first terminal verifies the data channel application certificate through the cooperation of the first key and the second key.

[0030] In some other possible implementations, the above method may further include: the first terminal and the KMS establishing a communication channel using GBA.

[0031] In a fourth aspect, the present application provides a communication method based on an IMS data channel, including: AS receives an encrypted ticket and identification information of a first application from a first terminal, where the identification information of the first application is used to identify the first application of the first terminal; AS sends the encrypted ticket and the identification information of the first application to a certificate management server; AS receives a first data channel application certificate from the certificate management server, where the first data channel application certificate is allocated by the certificate management server to the first application, and the first data channel application certificate is used for the first application to perform IMS data channel services with the second application of the second terminal; AS saves the first data channel application certificate and sends the first data channel application certificate to the first terminal.

[0032] In this application, when the first terminal initiates an IMS data channel service, the IMS network can refuse to use data channel application certificates generated by non-IMS networks by checking whether the fingerprint information of the certificate exchanged during the DTLS handshake is the data channel application certificate issued by the certificate management server. This ensures secure communication of the terminal while enabling the communicating IMS network to supervise the reliability of the communication process.

[0033] In some possible implementations, the above method may also include: the AS receives a second data channel application certificate allocated by the certificate management server to the second application, the second data channel application certificate is used for the second application to perform IMS data channel services with the first application; the AS saves the second data channel application certificate and sends the second data channel application certificate to the second terminal.

[0034] In other possible implementations, the above method may also include: AS obtains a data channel application certificate from the first terminal and a data channel application certificate from the second terminal during the DTLS handshake process; AS matches the data channel application certificate from the first terminal with the first data channel application certificate; AS matches the data channel application certificate from the second terminal with the second data channel application certificate; if the data channel application certificate from the first terminal matches the first data channel application certificate, and the data channel application certificate from the second terminal matches the second data channel application certificate, allowing the first application to establish an IMS data channel with the second application; if the data channel application certificate from the first terminal does not match the first data channel application certificate, and / or the data channel application certificate from the second terminal does not match the second data channel application certificate, prohibiting the first application from establishing an IMS data channel with the second application.

[0035] In a fifth aspect, the present application provides a communication device, which can be a chip or system on chip in a certificate management server, or a functional module in a certificate management server for implementing the method described in the first aspect or any possible implementation method of the first aspect. For example, the communication device includes: a first communication module for receiving an encrypted ticket and identification information of a first application from an AS, the identification information of the first application is used to identify the first application of a first terminal; a second communication module for sending an encrypted ticket and identification information of the first application to a KMS, the encrypted ticket and identification information of the first application are used by the KMS to verify the first application; receiving a first key, the first key is sent by the KMS after successfully verifying the first application; the first communication module is also used to send a data channel application certificate corresponding to the first key to the AS, the data channel application certificate is used for the first application to perform IMS data channel services with the second application of the second terminal.

[0036] In some possible implementations, the first communication module is further configured to obtain an address of a KMS; and the second communication module is further configured to send the encrypted ticket and identification information of the first application to the KMS according to the address of the KMS.

[0037] In some other possible implementations, the first communication module is further configured to send the data channel application certificate and identification information of the first application to the AS.

[0038] In some other possible implementations, the identification information of the first application includes: a terminal identification of the first terminal; or a terminal identification of the first terminal and an application identification of the first application.

[0039] In some other possible implementations, the terminal identifier of the first terminal includes: a device identifier of the first terminal or a user identifier of a user using the first terminal.

[0040] In some other possible implementations, the encrypted ticket includes: identification information of the first application.

[0041] In some other possible implementations, the encrypted ticket further includes: a key index of a second key, the second key matches the first key, and the second key is allocated by the KMS to the first application.

[0042] In the sixth aspect, the present application provides a communication device, which can be a chip or system on chip in the KMS, or a functional module in the KMS for implementing the method described in the second aspect or any possible implementation method of the second aspect. For example, the communication device includes: a third communication module for obtaining the first encrypted ticket and the identification information of the first application from the certificate management server, the identification information of the first application is used to identify the first application of the first terminal; a first processing module for decrypting the first encrypted ticket and obtaining the identification information in the first encrypted ticket; verifying the first application according to the identification information and the identification information of the first application; the third communication module is also used to send a first key to the certificate management server if the verification of the first application is successful, the first key matches the second key assigned by the KMS to the first application, the first key is used by the certificate management server to generate a data channel application certificate for the first application, and the data channel application certificate is used for the first application to perform IMS data channel services with the second application of the second terminal.

[0043] In some possible implementations, the first processing module is used to determine whether the identification information matches the identification information of the first application, wherein if the identification information matches the identification information of the first application, it indicates that the verification of the first application is successful; if the identification information does not match the identification information of the first application, it indicates that the verification of the first application has failed.

[0044] In some other possible implementations, the first encrypted ticket further includes: a key index; and a first processing module configured to verify the first application based on the identification information, the key index, and the identification information of the first application.

[0045] In other possible implementations, the first processing module is used to determine whether the identification information matches the identification information of the first application; if the identification information matches the identification information of the first application, then determine whether the key index matches the second key; wherein, if the key index matches the second key, it indicates that the verification of the first application is successful; if the key index does not match the second key, it indicates that the verification of the first application has failed.

[0046] In other possible embodiments, the above-mentioned communication device also includes a fourth communication module, which is used to receive a key request from the first terminal before the third communication module obtains the first encrypted ticket and identification information of the first application from the certificate management server; the first processing module is also used to respond to the key request and allocate a second key and a second encrypted ticket to the first application, and the second encrypted ticket includes: identification information of the first application, or identification information of the first application and a key index of the second key; the fourth communication module is also used to send the second key and the second encrypted ticket to the first terminal.

[0047] In some other possible implementations, the identification information of the first application includes: a terminal identification of the first terminal; or a terminal identification of the first terminal and an application identification of the first application.

[0048] In some other possible implementations, the terminal identifier of the first terminal includes: a device identifier of the first terminal or a user identifier of a user using the first terminal.

[0049] In some other possible implementations, the fourth communication module is further configured to establish a communication channel with the first terminal using GBA.

[0050] In a seventh aspect, the present application provides a communication device, which may be a chip or system on chip in a first terminal, or a functional module in the first terminal for implementing the method described in the third aspect or any possible implementation method of the third aspect. For example, the communication device includes: a fifth communication module for sending an encrypted ticket and identification information of a first application to an AS, where the identification information of the first application is used to identify the first application of the first terminal; receiving a data channel application certificate sent by the AS, where the data channel application certificate is sent by a certificate management server after successfully verifying the first application based on the encrypted ticket and the identification information of the first application; and a sixth communication module for performing an IMS data channel service with a second application of a second terminal based on the data channel application certificate.

[0051] In some possible implementations, the fifth communication module is further configured to send the address of the KMS to the AS, where the address of the KMS is used to instruct the certificate management server to communicate with the KMS.

[0052] In some other possible implementations, the identification information of the first application includes: a terminal identification of the first terminal; or a terminal identification of the first terminal and an application identification of the first application.

[0053] In some other possible implementations, the terminal identifier of the first terminal includes: a device identifier of the first terminal or a user identifier of a user using the first terminal.

[0054] In other possible implementations, the above-mentioned communication device may further include: a seventh communication module, which is also used to request a key and a ticket from the KMS before the fifth communication module sends the encrypted ticket and the identification information of the first application to the AS; receive the second key and encrypted ticket allocated by the KMS to the first application, the encrypted ticket including: the identification information of the first application, or the identification information of the first application and the key index of the second key.

[0055] In some other possible implementations, the first terminal and the KMS establish a communication channel using GBA.

[0056] In other possible implementations, the data channel application certificate is generated by the certificate management server based on the first key, and the first key matches the second key; the sixth communication module is also used to verify the data channel application certificate through the cooperation of the first key and the second key when the second terminal successfully verifies the first application.

[0057] In an eighth aspect, the present application provides a communication device, which may be a chip or system on chip in an AS, or a functional module in an AS for implementing the method described in the fourth aspect or any possible implementation method of the fourth aspect. For example, the communication device includes: an eighth communication module for receiving an encrypted ticket and identification information of a first application from a first terminal, the identification information of the first application being used to identify the first application of the first terminal; a ninth communication module for sending the encrypted ticket and the identification information of the first application to a certificate management server; receiving a first data channel application certificate from the certificate management server, the first data channel application certificate being allocated by the certificate management server to the first application, and the first data channel application certificate being used for the first application to perform IMS data channel services with the second application of the second terminal; a second processing module for storing the first data channel application certificate; and the eighth communication module is further used to send the first data channel application certificate to the first terminal.

[0058] In some possible implementations, the ninth communication module is further used to receive a second data channel application certificate allocated by the certificate management server to the second application, and the second data channel application certificate is used for the second application to perform IMS data channel services with the first application; the second processing module is further used to save the second data channel application certificate; the eighth communication module is further used to send the second data channel application certificate to the second terminal.

[0059] In other possible implementations, the eighth communication module is further used to obtain a data channel application certificate from the first terminal and a data channel application certificate from the second terminal during the DTLS handshake process; the second processing module is further used to match the data channel application certificate from the first terminal with the first data channel application certificate; match the data channel application certificate from the second terminal with the second data channel application certificate; if the data channel application certificate from the first terminal matches the first data channel application certificate, and the data channel application certificate from the second terminal matches the second data channel application certificate, then allow the first application to establish an IMS data channel with the second application; if the data channel application certificate from the first terminal does not match the first data channel application certificate, and / or the data channel application certificate from the second terminal does not match the second data channel application certificate, then prohibit the first application from establishing an IMS data channel with the second application.

[0060] In a ninth aspect, the present application provides a certificate management server comprising: a processor and a memory; the processor is coupled to the memory, and the processor is configured to read and execute instructions in the memory to implement the communication method based on the IMS data channel as described in the first aspect and any possible implementation method thereof.

[0061] In a tenth aspect, the present application provides a KMS comprising: a processor and a memory; the processor is coupled to the memory, and the processor is configured to read and execute instructions in the memory to implement the communication method based on the IMS data channel as described in the second aspect and any possible implementation method thereof.

[0062] In an eleventh aspect, the present application provides a terminal comprising: a processor and a memory; the processor is coupled to the memory, and the processor is configured to read and execute instructions in the memory to implement the communication method based on the IMS data channel as described in the third aspect and any possible implementation manner thereof.

[0063] In the twelfth aspect, the present application provides an AS, comprising: a processor and a memory; the processor is coupled to the memory, and the processor is configured to read and execute instructions in the memory to implement the communication method based on the IMS data channel as described in the fourth aspect and any possible implementation method thereof.

[0064] In the thirteenth aspect, the present application provides a communication system, comprising: a certificate management server, a KMS and an AS; wherein the certificate management server is configured to execute the communication method based on the IMS data channel as described in the first aspect and any possible implementation manner thereof; the KMS is configured to execute the communication method based on the IMS data channel as described in the second aspect and any possible implementation manner thereof; the AS is configured to execute the communication method based on the IMS data channel as described in the fourth aspect and any possible implementation manner thereof.

[0065] In a fourteenth aspect, the present application provides a computer-readable storage medium, which stores instructions. When the instructions are executed on a computer, the computer-readable storage medium is used to execute the communication method based on the IMS data channel as described in the first aspect, the second aspect, the third aspect or the fourth aspect and any possible implementation manner thereof.

[0066] In a fifteenth aspect, the present application provides a computer program or a computer program product. When the computer program or the computer program product is executed on a computer, the computer implements the communication method based on the IMS data channel as described in the first aspect, the second aspect, the third aspect or the fourth aspect above and any possible implementation manner thereof.

[0067] It should be understood that the fifth to fifteenth aspects of this application are consistent with the technical solutions of the first to fourth aspects of this application, and the beneficial effects achieved by each aspect and the corresponding feasible implementation methods are similar, so they will not be repeated. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments of the present application or the background technology will be described below.

[0069] Figure 1 Schematic diagram of the WebRTC protocol stack in an embodiment of the present application;

[0070] Figure 2 Schematic diagram of secure transmission protocols for different data types in the IMS in an embodiment of the present application;

[0071] Figure 3 Schematic diagram of the architecture of the communication system in an embodiment of the present application;

[0072] Figure 4 A schematic diagram of a bill request process in an embodiment of the present application;

[0073] Figure 5 A schematic diagram of the certificate request process in an embodiment of the present application;

[0074] Figure 6 Schematic diagram of the flow of the communication method of the IMS data channel in the embodiment of the present application;

[0075] Figure 7 A schematic structural diagram of a communication device in an embodiment of the present application;

[0076] Figure 8 Another structural diagram of the communication device in the embodiment of the present application

[0077] Figure 9 This is another structural diagram of the communication device in the embodiment of the present application.

[0078] Figure 10 This is a hardware diagram of the communication device in an embodiment of the present application. DETAILED DESCRIPTION

[0079] The embodiments of the present application are described below in conjunction with the drawings in the embodiments of the present application. In the following description, reference is made to the drawings that form a part of this application and illustrate specific aspects of the embodiments of the present application or specific aspects of the embodiments of the present application that can be used. It should be understood that the embodiments of the present application can be used in other aspects and may include structural or logical changes not depicted in the drawings. For example, it should be understood that the disclosure in conjunction with the described method can also be applied to the corresponding device or system for performing the method, and vice versa. For example, if one or more specific method steps are described, the corresponding device can include one or more units such as functional units to perform the one or more method steps described (for example, one unit performs one or more steps, or multiple units, each of which performs one or more of the multiple steps), even if such one or more units are not explicitly described or illustrated in the drawings. On the other hand, for example, if a specific device is described based on one or more units such as functional units, the corresponding method can include a step to perform the functionality of one or more units (for example, one step performs the functionality of one or more units, or multiple steps, each of which performs the functionality of one or more units in the multiple units), even if such one or more steps are not explicitly described or illustrated in the drawings. Further, it should be understood that, unless explicitly stated otherwise, features of the various exemplary embodiments and / or aspects described herein may be combined with each other.

[0080] As we all know, browsers don't support direct communication channels between each other; they all communicate through servers. For example, if there are two clients, A and B, and they want to communicate, they first need to establish a channel between A and the server, and between B and the server. When A sends a message to B, A first sends the message to the server, which then forwards A's message to B, and vice versa. Thus, a single message between A and B must pass through two channels, and communication efficiency is limited by the bandwidth of both channels. Furthermore, such channels are not suitable for transmitting data streams. Establishing point-to-point communication between browsers has long been a challenge for developers, leading to the emergence of web real-time communication (WebRTC).

[0081] WebRTC is a technology that enables web browsers to conduct real-time voice and video conversations. It aims to provide a simple interface for browsers to facilitate real-time communication (RTC). Simply put, WebRTC uses a series of signaling commands to establish a peer-to-peer communication channel between browsers. This channel can send any data without passing through a server, enabling high-performance, low-latency, and point-to-point communication. Figure 1 This is a schematic diagram of the WebRTC protocol stack in the embodiment of the present application, see Figure 1As shown in the figure, the protocol stack used by WebRTC data channel is the stream control transmission protocol over datagram transport layer security over interactive connectivity establishment or user datagram protocol (SCTP over DTLS over ICE / UDP). The underlying UDP implements low-latency communication, the middle DTLS implements data channel secure communication, and finally the high-level SCTP supports the establishment of multiple streams with different reliability in a single SCTP connection.

[0082] With the development of technology, a new concept has emerged: the Internet Protocol Multimedia Subsystem (IMS) data channel. Its main technical feature is to superimpose the fifth-generation communication technology data channel (5G data channel) on the voice call of long-term evolution (VoLTE) bearer. This upgrades the real-time audio and video communication based on IMS to real-time interaction, enriching the business scenarios enabled by IMS. Technically, the IMS data channel can be regarded as a new media type, and can adopt SCTP over DTLS over UDP used in WebRTC as the bearer protocol. Figure 2 This is a schematic diagram of the secure transmission protocol for different data types in the IMS in the embodiment of the present application, see Figure 2 As shown in the figure, the IMS data channel uses SCTP over DTLS over UDP, the audio (voice) service uses the secure real time transport protocol (SRTP), and the video (video) service also uses SRTP. Among them, SCTP over DTLS overUDP uses a security certificate verification mechanism, and SRTP uses a security key verification mechanism.

[0083] However, if the security certificate used by the IMS data channel is generated or installed by the terminal or the IMS data channel application, the network side will lose the ability to control and supervise the communication content in the IMS data channel, affecting communication reliability.

[0084] In order to solve the above problems, an embodiment of the present application provides a communication method based on an IMS data channel. The method can be applied to a communication system that can be used for real-time audio and video communication. Figure 3 This is a schematic diagram of the architecture of the communication system in the embodiment of the present application, see Figure 3 As shown by the solid line, the communication system 300 may include: a terminal 301 , a key management system (KMS) 302 , a certificate management server 303 , and an application server (AS) 304 .

[0085] Among them, the first terminal in terminal 301 can be used to send an encrypted ticket (also referred to as a first encrypted ticket) and identification information of the first application to AS 304. The encrypted ticket and identification information of the first application are used by the certificate management server 303 to verify the first application; receive the data channel application certificate sent by AS 304. The data channel application certificate is sent by the certificate management server 303 after successfully verifying the first application; send the data channel application certificate to the second terminal in terminal 301. The data channel application certificate is used for the first application to perform IMS data channel services with the second application of the second terminal in terminal 301;

[0086] The second terminal can be used to verify the first application based on the data channel application certificate; if the verification of the first application is successful, an IMS data channel is established between the second terminal and the first terminal; a first key is obtained based on the data channel application certificate, and the data channel application certificate of the first application is verified by combining the first key with the second key allocated by KMS to the first application, so that the first application and the second application communicate with the first application in the IMS data channel; if the verification of the first terminal fails, the process ends.

[0087] KMS 302 can be used to obtain the encrypted ticket and identification information of the first application from the certificate management server 303; decrypt the encrypted ticket to obtain the application identification in the encrypted ticket; verify the first application based on the application identification in the encrypted ticket and the identification information of the first application sent by the certificate management server; if the verification is successful, send a first key to the certificate management server 303. The first key matches the second key assigned by KMS 302 to the first application. The first key is used by the certificate management server 303 to generate a corresponding data channel application certificate (also referred to as a first data channel application certificate). The data channel application certificate can be used for the first application to perform IMS data channel services with the second application.

[0088] The certificate management server 303 can be used to send the encrypted ticket and the identification information of the first application to AS 304. The encrypted ticket and the identification information of the first application are used by KMS 302 to verify the first application; receive the first key, which is sent by KMS 302 after successfully verifying the first application 301; and send the data channel application certificate corresponding to the first key to AS 304. The data channel application certificate is used for the first application and the second application to perform IMS data channel services.

[0089] It should be noted that the first terminal and / or the second terminal in the embodiment of the present application is a terminal device with wireless communication function, which can be deployed on land, including indoors or outdoors, handheld, wearable or vehicle-mounted; can also be deployed on the water surface (such as ships, etc.); can also be deployed in the air (for example, on airplanes, balloons and satellites, etc.). The above-mentioned terminal device can be a mobile phone, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. The terminal device can also be a handheld device with wireless communication function, a vehicle-mounted device, a wearable device, a computing device or other processing device connected to a wireless modem. In different networks, terminal devices may be referred to by different names, such as terminal device, access terminal, subscriber unit, subscriber station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device, cellular phone, cordless phone, Session Initiation Protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), terminal device in 5G network or future evolution network, etc. In actual application, browser applications need to be installed in the first terminal and the second terminal. In this way, the first terminal and the second terminal can achieve real-time audio and video interaction through the IMS data channel between the browser applications.

[0090] The above KMS can be deployed on a network application function (NAF) or on a third-party server. KMS can use a generic bootstrapping architecture (GBA) to authenticate the terminal 301 and communicate securely with the terminal 301 after the terminal 301 passes the authentication. For example, if KMS 302 is deployed on NAF, the terminal 301 is connected to the NAF via the Ua interface, see Figure 3 As shown by the dotted line, the terminal 301 is connected to the bootstrapping server function (BSF) 305 in the network to which it belongs through the Ub interface, the KMS 302 is connected to the BSF 305 in the network to which it belongs through the Zn interface, and the above-mentioned BSF305 is connected to the home subscriber server (HSS) 306 through the Zh interface.

[0091] In some possible implementations, see Figure 3 As shown by the dashed line, the communication network may further include a call session control function (CSCF) 307 in the IMS network. Terminal 301 may be connected to CSCF 307, which may be connected to AS 304 via an IMS service control (ISC) interface. AS 304 may be connected to certificate management server 303. Terminal 301 may send messages to certificate management server 303 via CSCF 307 and AS 304. CSCF 307 and AS 304 may interact via the standard Session Initiation Protocol (SIP).

[0092] In practical applications, CSCF can be divided into P-CSCF (Proxy CSCF) and S-CSCF (Serving CSCF).

[0093] The communication method based on the IMS data channel provided in the embodiment of the present application is described below in conjunction with the structure of the above communication system.

[0094] Figure 4 This is a schematic diagram of the bill request process in the embodiment of this application, see Figure 4 As shown, the method may include:

[0095] S401: The first terminal requests a key and a ticket from the KMS;

[0096] When a first application on a first terminal, such as a live broadcast application or a video call application, needs to communicate with a second application on a second terminal through an IMS data channel, the first terminal can first send a REQUEST_INIT message to the KMS to request the key and ticket corresponding to the first application. The REQUEST_INIT message can carry the identification information of the first application.

[0097] In some possible implementations, the identification information of the first application can uniquely identify the first application of the first terminal, so the identification information of the first application can include the terminal identification of the first terminal, or the terminal identification of the first terminal and the application identification of the first application. For example, if there is only one application (i.e., the first application) in the first terminal requesting keys and tickets from the KMS at the same time, the REQUEST_INIT message can carry the terminal identification of the first terminal (such as #UE A); if there are multiple applications including the first application in the first terminal requesting keys and tickets from the KMS at the same time, the REQUEST_INIT message can carry the terminal identification of the first terminal (such as #UE A) and the application identification of one application (such as the first application) among the multiple applications (such as #APP A), or the REQUEST_INIT message can carry the terminal identification of the first terminal (such as #UE A) and the application identification of each application among the multiple applications (such as #APP 1, #APP 2, ..., #APPn, etc.).

[0098] In practical applications, the terminal identifier mentioned in the embodiment of the present application can be a device identifier for the terminal, such as an international mobile subscriber identity (IMSI), an international mobile equipment identity (IMEI), etc., and can also be a user identifier of a user using the terminal, such as an Internet Protocol Multimedia Public Identity (IMPU); the application identifier can be an application identifier (AID). Of course, other forms of identifiers may exist, and the embodiment of the present application does not specifically limit them.

[0099] In some possible implementations, before S401 , the method may further include: the first terminal and the KMS establishing a communication channel using GBA.

[0100] First, the first terminal initiates a GBA initialization request to the BSF; the BSF obtains the first terminal's authentication information from the HSS and generates a shared key Ks and the first terminal's transaction identifier; the BSF sends the first terminal's authentication information and transaction identifier to the first terminal, which processes and stores them accordingly; the first terminal initiates an authentication request to the KMS (i.e., NAF) with the transaction identifier; the KMS checks whether it has a valid key stored. If not, it requests Ks from the BSF with the transaction identifier. The KMS and the first terminal authenticate Ks. After successful authentication, the first terminal obtains Ks. Furthermore, the first terminal derives the key Ks_NAF for accessing the KMS from the first terminal based on Ks. Subsequent communications between the first terminal and the KMS can be encrypted and protected using Ks_NAF.

[0101] S402: The KMS allocates key A (i.e., the second key) and encryption ticket A to the first application;

[0102] The KMS receives the REQUEST_INIT message (carrying the identification information of the first application) from the first terminal, responds to the REQUEST_INIT message, and allocates the corresponding key A and encryption ticket A to the first application based on the identification information of the first application. Among them, the encryption mechanism of encryption ticket A is only known to the KMS.

[0103] Here, the key A can be used to encrypt the communication between the first application and the second application in the IMS data channel. Optionally, the key A can be a private key.

[0104] The encrypted note A is used by other network elements in the communication network to verify the first application. Optionally, the encrypted note A may include: identification information of the first application.

[0105] Furthermore, to improve reliability, encrypted note A may further include a key index of key A. In some possible implementations, the key index of key A may be key A itself, key B (public key) corresponding to key A, or an identifier of key A. Of course, the key index may also be in other forms, as long as key A can be uniquely identified by its key index. This embodiment of the present application does not impose any specific limitations thereon.

[0106] S403: The KMS sends key A and encrypted ticket A to the first terminal.

[0107] The KMS sends a REQUEST_RESP message to the first terminal, and the REQUEST_RESP message carries the key A and the encryption note A.

[0108] The above is the ticket request process.

[0109] In some possible implementations, when a first application needs to communicate with a second application through an IMS data channel for encryption, the first terminal must first establish an IMS data channel between it and the second terminal. Before establishing the data channel, the first terminal needs to apply to the certificate management server for a data channel application certificate for the IMS data channel service.

[0110] So, Figure 5 This is a schematic diagram of the certificate request process in the embodiment of this application, see Figure 5 As shown, after S401 to S403, the method may include:

[0111] S501: The first terminal sends the encrypted note B and identification information of the first application to the AS;

[0112] The first terminal can send a SIP message to the AS, which can carry the identification information of encrypted note B and the first application. The AS then sends the encrypted note B and the identification information of the first application in a Hypertext Transfer Protocol over Secure Socket Layer (HTTPS) message to the certificate management server. It is understandable that since the first terminal has not yet been verified, encrypted note B can be the same as encrypted note A (i.e., the first application is valid) or different from encrypted note A (i.e., the first application is invalid).

[0113] It should be noted that in the embodiment of the present application, the identification information of the first application is sent as plain text.

[0114] Optionally, the identification information of the first application may include: a terminal identification of the first terminal, such as the IMSI of the first terminal; and may also include an application identification of the first application, such as an AID. In this case, the identification information of the first application may be a combination of the IMSI and the AID.

[0115] It should be noted that, in the embodiments of the present application, the legality of the first application refers to the legality of the first application with respect to the IMS data channel between the first and second applications, and the first application can reliably conduct encrypted IMS data channel communication with the second application through the IMS data channel. Similarly, the illegality of the first application refers to the illegality of the first application with respect to the IMS data channel between the first and second applications, and the first application cannot conduct encrypted IMS data channel communication with the second application. However, at the same time, the first application can be legal with respect to other IMS data channels between the first terminal and the second terminal. Thus, for different applications, their legality is relative to the IMS data channel, which ensures the reliability of encrypted communication on each IMS data channel.

[0116] In actual applications, S501 may include: the first terminal sending a certificate request to the AS, where the AS may include the identification information of the first application in a field of the certificate request forwarded to the certificate management server. In this case, the first terminal may omit the step of sending the identification information of the first application. In other words, the first terminal may only send the encrypted ticket B to the AS, and the AS will send the encrypted ticket B and the identification information of the first application to the certificate management server. In this case, the first terminal is already registered in the IMS network.

[0117] Specifically, the first terminal can first send the encrypted note B to the S-CSCF, which then forwards it to the AS. The AS then forwards the identification information of the first application (such as the terminal identification of the first terminal) and the encrypted note B to the certificate management server.

[0118] For example, the first terminal may send the encrypted ticket B to the S-CSCF through the following MESSAGE request message:

[0119] MESSAGE sip:as.home1.net SIP / 2.0

[0120] Via:SIP / 2.0 / UDP[5555::aaa:bbb:ccc:ddd]:1357;comp=sigcomp;Branch=z9hG4b-Knashds7

[0121] Max-Forwards:70

[0122] Route:<sip:pcscf1.visited1.net:7531;lr;comp=sigcomp> ,<sip:orig@scscf1.home1.net;lr>

[0123] P-Preferred-Identity:"John Doe"<sip:user1_public1@home1.net>

[0124] From:<sip:user1_public1@home1.net> ;tag=171828

[0125] To:<sip:as.home1.net.net>

[0126] Call-ID:cb03a0s09a2sdfglkj490333

[0127] Cseq:666MESSAGE

[0128] Content-Type:application / vnd.3gpp.certificate / / Indicates certificate request

[0129] Content-Length: <length>

[0130] TICKET:TICKET / / Encrypted ticket B parsed from REQUEST_RESP

[0131] KMS URI: kms.operator.example:1234 / / KMS address

[0132] S502: The AS sends the encrypted note B and the identification information of the first application to the certificate management server;

[0133] Furthermore, the first terminal may also send a KMS address to the AS, and the AS forwards the KMS address to the certificate management server, so that the certificate management server can communicate with the corresponding KMS based on the KMS address. Optionally, the above certificate request may also carry a KMS address.

[0134] S503: The certificate management server sends the encrypted note B and the identification information of the first application to the KMS;

[0135] In some possible implementations, the certificate management server may send the encrypted ticket B and the identification information of the first application to the corresponding KMS according to the address of the KMS sent by the first terminal.

[0136] In actual application, the certificate management server sends a decryption request to the KMS, and the decryption request may carry the above-mentioned encrypted ticket B and identification information of the first application.

[0137] S504: The KMS decrypts the encrypted note B and obtains the identification information in the encrypted note B;

[0138] Here, the identification information in encrypted note B may include a terminal identifier, or a terminal identifier and an application identifier. It is understood that since encrypted note B is the note to be verified, the terminal identifier may or may not be the terminal identifier of the first terminal; similarly, the application identifier in encrypted note B may or may not be the application identifier of the first application.

[0139] S505: The KMS verifies the first application based on the identification information in the encrypted ticket B and the identification information of the first application. If the verification of the first application succeeds, the process proceeds to S506. If the verification of the first application fails, the process ends.

[0140] After KMS decrypts the encrypted note B, it obtains identification information, such as the terminal identification. Then, KMS can match the terminal identification with the terminal identification of the first terminal in the identification information of the first application sent by the certificate management server to verify whether the terminal identification in the encrypted note B is consistent with the terminal identification of the first terminal that sent the encrypted note B. If the two are consistent (or match), it indicates that the verification of the first application is successful, that is, the first application is legal. Otherwise, if the two are inconsistent (or do not match), it indicates that the verification of the first application has failed, that is, the first application is illegal.

[0141] Of course, after KMS decrypts the encrypted note B, the obtained identification information can also include the terminal identification and application identification. Then, KMS matches the terminal identification and application identification with the terminal identification of the first terminal and the application identification of the first application in the identification information of the first application, respectively, to verify whether the terminal identification in the encrypted note B is consistent with the identification information of the first application that sends the encrypted note B. If the two are consistent (or match), it indicates that the verification of the first application is successful, that is, the first application is legal. On the contrary, if the two are inconsistent (or do not match), it indicates that the verification of the first application has failed, that is, the first application is illegal.

[0142] In an embodiment of the present application, in order to further improve the reliability of communication, the encrypted note B may also include a key index. Then, S505 may include: KMS verifies the first application based on the identification information, key index and identification information of the first application in the encrypted note B.

[0143] The KMS first matches the identification information in encrypted note B with the identification information of the first application. If the two are consistent (or match), the KMS matches the key index in encrypted note B with the key A assigned to the first application in S402. For example, assuming that the key index is the key itself, the KMS compares the key with key A to determine whether the two are consistent. Alternatively, assuming that the key index is the identifier corresponding to the key, the KMS determines whether the key corresponding to the identifier is key A. If the two are consistent (or match), the first application is successfully verified, that is, the first application is legal. Conversely, if the two are inconsistent (or do not match), the first application verification fails, that is, the first application is illegal.

[0144] Of course, the encrypted note B may also include other information, which is not specifically limited in the embodiment of the present application.

[0145] In some possible implementations, after S504 , if the verification of the first application fails, the KMS considers the first application to be illegal, and then the KMS notifies the certificate management server so that the certificate management server rejects the certificate request of the first terminal.

[0146] S506: The KMS sends key B (i.e., the first key) to the certificate management server;

[0147] Here, key B matches key A allocated by KMS to the first application in S402. It can be understood that if key A is a private key, key B can be a matching public key.

[0148] S507: The certificate management server generates a data channel application certificate based on key B;

[0149] S508: The certificate management server sends the data channel application certificate to the AS;

[0150] S509: The AS sends the data channel application certificate to the first terminal;

[0151] The certificate management server sends the generated data channel application certificate and the identification information of the first application to the AS. The AS then sends the data channel application certificate and the identification information of the first application to the first terminal. In this way, the first terminal can know that the received data channel application certificate is assigned to the first application and then associate the data channel application certificate with the identification information of the first application and save it. In actual applications, the AS first forwards the data channel application certificate and the identification information of the first application to the S-CSCF, which then forwards them to the first terminal.

[0152] For example, the AS may forward the data channel application certificate to the S-CSCF via the following 200 (OK) response message:

[0153] SIP / 2.0 200OK

[0154] Via:

[0155] From:

[0156] Call-ID:

[0157] Content-Type:application / vnd.3gpp.certificate / / indicates certificate response

[0158] Content-Length: <length>

[0159] CERTIFICATE:certificate / / certificate

[0160] It should be noted that in S508, after receiving the data channel application certificate from the certificate management server, the AS can save the data channel application certificate and the association between the data channel application certificate and the application for subsequent determination of whether to allow the first application and the second application to establish an IMS data channel.

[0161] S510: The first terminal uses the data channel application certificate to perform an IMS data channel service with a second application of the second terminal.

[0162] It should be noted that the above-mentioned IMS data channel service may be: one or more services related to the IMS data channel between the first application and the second application, such as verifying the first application, determining whether the establishment of an IMS data channel between the first application and the second application is allowed, establishing an IMS data channel between the first application and the second application, and performing encrypted communication between the first application and the second application on the IMS data channel. Of course, other services may also be included, which are not specifically limited in the embodiments of the present application.

[0163] For example, in S510, after obtaining the data channel application certificate through S507, the first terminal may send the data channel application certificate to the second terminal. After receiving the data channel application certificate, the second terminal may verify the data channel application certificate based on key A and key B. After the verification is successful, the second terminal may conduct encrypted communication with the first terminal on the IMS data channel to verify whether the first application is allowed to use the IMS data channel for encrypted communication. If the verification of the first application is successful and the second terminal determines that the first application is legal, then the second terminal establishes an IMS data channel between the first application and the second application with the first terminal and conducts encrypted communication on the IMS data channel. Conversely, if the verification of the first application fails and the second terminal determines that the first application is illegal, then the second terminal may refuse to establish the IMS data channel between the first application and the second application with the first terminal.

[0164] At this point, the certificate application process is completed.

[0165] For example, suppose that, at the same time, APP1 (first application) of UE A (first terminal) wants to conduct IMS data channel services with APP2 of UE B (second terminal). Here, APP1 and APP2 can be the same application on different terminals. In this case, the application identifiers of APP1 and APP2 are the same, that is, #APP1. For example, APP1 is a video call application, and APP2 is the same video call application. Alternatively, APP1 and APP2 can also be mutually matching applications on different terminals. For example, APP1 is a host-side application, and APP2 is a client-side application. In this case, the application identifiers of APP1 and APP2 can have at least the same part. For example, the application identifier of APP1 can be #X-APP1, and the application identifier of APP2 can be #X-APP2. The following takes the case where APP1 and APP2 have the same application identifier #APP1 as an example.

[0166] In the first step, UE A and UE B each request a key and encryption ticket from the KMS. The KMS assigns Key A (private key) and Encryption Ticket A to APP1.

[0167] Step 2: UE A sends a certificate request to the AS. The certificate request carries the encryption ticket A, the KMS address, and the application identifier of APP1 (#APP 1). Since UE A is already registered in the IMS network, the AS forwards the certificate request to the certificate management server after receiving it. The certificate request carries the encryption ticket A, the KMS address, the UE's terminal identifier (#UE A), and #APP 1.

[0168] Step 3: After receiving the certificate request, the certificate management server sends a parsing request to the KMS according to the KMS address, requesting the KMS to parse the encrypted note A. The parsing request carries the encrypted note A, #UE A, and #APP 1.

[0169] Step 4: After receiving the resolution request, KMS resolves the encrypted note A and obtains #UE A and #APP 1 in the encrypted note A. KMS then compares #UE A and #APP 1 in the encrypted note A with #UE A and #APP 1 carried in the resolution request. If the two are consistent, KMS sends the key B corresponding to #UE A and #APP 1 (i.e., the public key of key A) to the certificate management server.

[0170] Step 5: The certificate management server may generate a data channel application certificate corresponding to the first application based on key B, and then send the data channel application certificate corresponding to the first application, #UE A, and #APP 1 to the AS;

[0171] Step 6: The AS saves the data channel application certificate, #UE A, and #APP 1 corresponding to the first application, and forwards it to the UEA.

[0172] Furthermore, the above steps 1 to 6 are also performed on UE B. The AS saves the data channel application certificate, #UE B and #APP 1 corresponding to the second application, and forwards them to UE B.

[0173] Step 7: UE A sends the SDP Offer or the SIP message MESSAGE A with the SDP Offer attached to the AS. MESSAGE A carries #UE A and #APP 1.

[0174] Step 8. The AS obtains #UE A and #APP 1 from the MESSAGE A. Based on #UE A and #APP 1, the AS determines whether to allow UE A to transmit APP 1 data on the IMS data channel. If allowed, the AS forwards the MESSAGE A to UE B and instructs UE B to allow UE A to transmit APP 1 data on the IMS data channel. Conversely, if prohibited, the AS deletes #APP 1 when forwarding the MESSAGE A to UE B.

[0175] Step 9. The AS receives the SDP Answer from UE B, or the SIP message MESSAGE B attached to the SDP Answer. #MESSAGE B carries #UE B and #APP1. The AS then forwards MESSAGE B and instructs UE A whether to allow UE A to transmit APP1 data over the IMS data channel. Furthermore, the AS establishes an IMS data channel between UE A's APP1 and UE B's APP2.

[0176] Step 10: UE A determines whether to allow UE A to transmit APP1 data on the IMS data channel according to the instruction. If allowed, UE A sends the encrypted APP1 data to UE B on the IMS data channel.

[0177] Step 11: UE B obtains the data of APP1 through decryption.

[0178] In an embodiment of the present application, the certificate management server issues a reliable data channel application certificate to the first terminal, and the IMS network is able to obtain the data channel application certificate, thereby avoiding the first terminal manually installing / replacing a third-party (non-communication network provided) certificate and using an unreliable self-signed certificate, thereby providing reliable IMS data channel communication.

[0179] In some possible embodiments, after the first terminal obtains the data channel application certificate through S501 to S510 above, it can use the certificate to initiate an IMS data channel service. In this process, the IMS network wants to supervise the IMS data channel services of the first terminal and the second terminal to prevent the first terminal and the second terminal from communicating independently by bypassing the IMS network. Then, Figure 6 This is a flow chart of the communication method of the IMS data channel in the embodiment of the present application, see Figure 6 As shown, after the above S508, the method may include:

[0180] S601: The AS obtains the data channel application certificate of the first application;

[0181] Here, through S501 to S508, the certificate management server allocates a data channel application certificate to the first application and sends it to the first terminal via the AS. During this process, the AS saves the data channel application certificate of the first application.

[0182] S602: The AS obtains the data channel application certificate of the second application;

[0183] Here, through S501 to S508, the certificate management server allocates a data channel application certificate for the second application and sends it to the second terminal via the AS. During this process, the AS saves the data channel application certificate of the second application.

[0184] It should be noted that the data channel application certificate of the first application and / or the data channel application certificate of the second application are used for the first application and the second application to perform IMS data channel services.

[0185] S603: The AS obtains the data channel application certificate exchanged between the first terminal and the second terminal during the DTLS handshake process;

[0186] Here, during the DTLS handshake process, the first terminal and the second terminal will each send a data channel application certificate to the AS to exchange certificates. In this case, the data channel application certificate exchanged can be the data channel application certificate obtained by the first application and the second application through S501 to S510, or it can be a data channel application certificate provided by a third party (non-communication network).

[0187] S604: The AS calculates first fingerprint information and second fingerprint information corresponding to the data channel application certificate exchanged between the first terminal and the second terminal;

[0188] The AS obtains the data channel application certificate exchanged between the first terminal and the second terminal through the DTLS process, such as the data channel application certificate from the first terminal and the data channel application certificate from the second terminal, and then calculates the fingerprint information of the two certificates respectively to obtain the first fingerprint information and the second fingerprint information.

[0189] S605: The AS matches the first fingerprint information with the data channel application certificate of the first application, and matches the second fingerprint information with the data channel application certificate of the second application. If the first fingerprint information matches the data channel application certificate of the first application, and the second fingerprint information matches the data channel application certificate of the second application, the user of the IMS data channel is confirmed to be a legitimate user, and S606 is executed. If the first fingerprint information does not match the data channel application certificate of the first application, and / or the second fingerprint information does not match the data channel application certificate of the second application, S607 is executed.

[0190] S606: The AS allows the first application to establish an IMS data channel with the second application;

[0191] S607: The AS prohibits the first application from establishing an IMS data channel with the second application.

[0192] Furthermore, in S605, the AS matches the fingerprint information with the data channel application certificate, which may include: the AS calculates the fingerprint information corresponding to the data channel application certificate, and then compares the calculated fingerprint information with the fingerprint information corresponding to the data channel application certificate exchanged during the DTLS handshake process to determine whether the two are consistent. If the two are consistent, it indicates that the two match; otherwise, if the two are inconsistent, it indicates that the two do not match.

[0193] It should be noted that the fingerprint information may be summary information obtained by applying the certificate to the data channel.

[0194] In an embodiment of the present application, when the first terminal initiates an IMS data channel service, the IMS network can refuse to use data channel application certificates generated by non-IMS networks by checking whether the fingerprint information of the certificate exchanged during the DTLS handshake is the data channel application certificate issued by the certificate management server, thereby ensuring the secure communication of the terminal while enabling the communicating IMS network to supervise the reliability of the communication process.

[0195] Based on the same inventive concept, an embodiment of the present application provides a communication device, which can be a chip or system on chip in a certificate management server, or a functional module in a certificate management server used in the method described in any of the above possible implementations. For example, Figure 7 This is a schematic diagram of the structure of the communication device in the embodiment of the present application, see Figure 7 As shown, the communication device 700 includes: a communication module 701, which is used to receive the encryption ticket and identification information of the first application from the AS, and the identification information of the first application is used to identify the first application of the first terminal; a communication module 702, which is used to send the encryption ticket and identification information of the first application to the KMS, and the encryption ticket and identification information of the first application are used by the KMS to verify the first application; receive the first key, and the first key is sent by the KMS after the first application is successfully verified; the communication module 701 is also used to send the data channel application certificate corresponding to the first key to the AS, and the data channel application certificate is used for the first application to perform IMS data channel services with the second application of the second terminal.

[0196] In some possible implementations, the communication module 701 is further configured to obtain the address of the KMS; and the second communication module is further configured to send the encrypted ticket and identification information of the first application to the KMS according to the address of the KMS.

[0197] In some other possible implementations, the communication module 701 is further configured to send the data channel application certificate and identification information of the first application to the AS.

[0198] In some other possible implementations, the identification information of the first application includes: a terminal identification of the first terminal; or a terminal identification of the first terminal and an application identification of the first application.

[0199] In some other possible implementations, the terminal identifier of the first terminal includes: a device identifier of the first terminal or a user identifier of a user using the first terminal.

[0200] In some other possible implementations, the encrypted ticket includes: identification information of the first application.

[0201] In some other possible implementations, the encrypted ticket further includes: a key index of a second key, the second key matches the first key, and the second key is allocated by the KMS to the first application.

[0202] Based on the same inventive concept, an embodiment of the present application provides a communication device, which can be a chip or system on chip in a KMS, or a functional module in a KMS for implementing the method described in any of the above possible implementations. For example, Figure 8 This is another structural diagram of the communication device in the embodiment of the present application, see Figure 8 As shown, the communication device 800 may include: a communication module 801, used to obtain the first encrypted ticket and identification information of the first application from the certificate management server, the identification information of the first application is used to identify the first application of the first terminal; a processing module 802, used to decrypt the first encrypted ticket and obtain the identification information in the first encrypted ticket; verify the first application according to the identification information and the identification information of the first application; the communication module 801 is also used to send a first key to the certificate management server if the verification of the first application is successful, the first key matches the second key assigned by the KMS to the first application, the first key is used by the certificate management server to generate a data channel application certificate for the first application, and the data channel application certificate is used for the first application to perform IMS data channel services with the second application of the second terminal.

[0203] In some possible implementations, the processing module 802 is used to determine whether the identification information matches the identification information of the first application, wherein if the identification information matches the identification information of the first application, it indicates that the verification of the first application is successful; if the identification information does not match the identification information of the first application, it indicates that the verification of the first application has failed.

[0204] In some other possible implementations, the first encrypted ticket further includes: a key index; and a first processing module configured to verify the first application based on the identification information, the key index, and the identification information of the first application.

[0205] In other possible implementations, the processing module 802 is used to determine whether the identification information matches the identification information of the first application; if the identification information matches the identification information of the first application, then determine whether the key index matches the second key; wherein, if the key index matches the second key, it indicates that the verification of the first application is successful; if the key index does not match the second key, it indicates that the verification of the first application has failed.

[0206] In some other possible implementations, see Figure 8 As shown, the above-mentioned communication device 800 also includes: a communication module 803, which is used to receive a key request from the first terminal before the communication module 801 obtains the first encryption ticket and the identification information of the first application from the certificate management server; the processing module 802 is also used to respond to the key request and allocate a second key and a second encryption ticket to the first application, and the second encryption ticket includes: the identification information of the first application, or the identification information of the first application and the key index of the second key; the communication module 803 is also used to send the second key and the second encryption ticket to the first terminal.

[0207] In some other possible implementations, the identification information of the first application includes: a terminal identification of the first terminal; or a terminal identification of the first terminal and an application identification of the first application.

[0208] In some other possible implementations, the terminal identifier of the first terminal includes: a device identifier of the first terminal or a user identifier of a user using the first terminal.

[0209] In some other possible implementations, the communication module 803 is further configured to establish a communication channel with the first terminal using GBA.

[0210] Based on the same inventive concept, an embodiment of the present application provides a communication device, which can be a chip or system on chip in a first terminal, or a functional module in the first terminal for implementing the method described in any of the above possible implementations. For example, Figure 9 This is another structural diagram of the communication device in the embodiment of the present application, see Figure 9 As shown by the solid line in the middle, the communication device 900 includes: a communication module 901, which is used to send an encrypted ticket and identification information of the first application to the AS, where the identification information of the first application is used to identify the first application of the first terminal; receiving a data channel application certificate sent by the AS, where the data channel application certificate is sent by the certificate management server after successfully verifying the first application based on the encrypted ticket and the identification information of the first application; and a communication module 902, which is used to perform IMS data channel services with the second application of the second terminal based on the data channel application certificate.

[0211] In some possible implementations, the communication module 901 is further configured to send the address of the KMS to the AS, where the address of the KMS is used to instruct the certificate management server to communicate with the KMS.

[0212] In some other possible implementations, the identification information of the first application includes: a terminal identification of the first terminal; or a terminal identification of the first terminal and an application identification of the first application.

[0213] In some other possible implementations, the terminal identifier of the first terminal includes: a device identifier of the first terminal or a user identifier of a user using the first terminal.

[0214] In some other possible implementations, see Figure 9 As shown by the dotted line, the above-mentioned communication device may also include: a communication module 903, which is also used to request a key and a ticket from the KMS before the communication module 901 sends the encryption ticket and the identification information of the first application to the AS; receive the second key and encryption ticket allocated by the KMS to the first application, the encryption ticket including: the identification information of the first application, or the identification information of the first application and the key index of the second key.

[0215] In some other possible implementations, the communication module 903 is further configured to establish a communication channel with the KMS using GBA.

[0216] In other possible implementations, the data channel application certificate is generated by the certificate management server based on the first key, and the first key matches the second key; the communication module 902 is also used to verify the data channel application certificate through the cooperation of the first key and the second key when the second terminal successfully verifies the first application.

[0217] Based on the same inventive concept, an embodiment of the present application provides a communication device, which can be a chip or system on chip in an AS, or a functional module in an AS for implementing the method described in any of the above possible implementations. Figure 8 As shown, the communication device includes: a communication module 801, which is used to receive an encrypted ticket and identification information of a first application from a first terminal, where the identification information of the first application is used to identify the first application of the first terminal; a communication module 803, which is used to send the encrypted ticket and the identification information of the first application to a certificate management server; receiving a first data channel application certificate from the certificate management server, where the first data channel application certificate is allocated by the certificate management server to the first application, and the first data channel application certificate is used for the first application to perform IMS data channel services with the second application of the second terminal; a processing module 802, which is used to save the first data channel application certificate; and the communication module 801 is also used to send the first data channel application certificate to the first terminal.

[0218] In some possible implementations, the communication module 803 is further used to receive a second data channel application certificate allocated by the certificate management server to the second application, where the second data channel application certificate is used by the second application to perform IMS data channel services with the first application; the second processing module is further used to save the second data channel application certificate; and the communication module 801 is further used to send the second data channel application certificate to the second terminal.

[0219] In other possible implementations, the communication module 801 is further used to obtain a data channel application certificate from the first terminal and a data channel application certificate from the second terminal during the DTLS handshake process; the processing module 802 is further used to match the data channel application certificate from the first terminal with the first data channel application certificate; and match the data channel application certificate from the second terminal with the second data channel application certificate; if the data channel application certificate from the first terminal matches the first data channel application certificate, and the data channel application certificate from the second terminal matches the second data channel application certificate, then allowing the first application to establish an IMS data channel with the second application; if the data channel application certificate from the first terminal does not match the first data channel application certificate, and / or the data channel application certificate from the second terminal does not match the second data channel application certificate, then prohibiting the first application from establishing an IMS data channel with the second application.

[0220] It should be noted that the above-mentioned communication module 701, communication module 702, communication module 801, communication module 803, communication module 901, communication module 902 and communication module 903 can be transceiver circuits, transceiver interfaces, transceivers, etc.; the processing module 802 can be one or more processors.

[0221] Based on the same inventive concept, the embodiments of the present application also provide a terminal, a certificate management server, a KSM and an AS, which are consistent with the terminal, certificate management server, KSM or AS described in one or more of the above embodiments. Figure 10 This is a hardware diagram of the communication device in the embodiment of the present application, see Figure 10 As shown, the communication device 1000 provided in the embodiment of the present application, such as a terminal, a certificate management server, a KSM and an AS, all adopt general computer hardware, including a processor 1001, a memory 1002, a bus 1003, an input device 1004 and an output device 1005.

[0222] In some possible implementations, the memory 1002 may include computer storage media in the form of volatile and / or non-volatile memory, such as read-only memory and / or random access memory. The memory 1002 may store an operating system, application programs, other program modules, executable code, program data, user account registration data, user subscription data, etc.

[0223] An input device 1004, such as a keyboard or pointing device, such as a mouse, trackball, touchpad, microphone, joystick, game pad, satellite TV dish, scanner, or similar device, can be used to input commands and information to the communication device 1000. These input devices can be connected to the processor 1001 via the bus 1003.

[0224] The output device 1005 can be used for the communication device 1000 to output information. In addition to the monitor, the output device 1005 can also be other peripheral output devices, such as speakers and / or printing devices. These output devices can also be connected to the processor 1001 through the bus 1003.

[0225] The communication device 1000 can be connected to a network, such as a local area network (LAN), via the network interface 1006. In a networked environment, the computer-executable instructions stored in the communication device 1000 can be stored in a remote storage device, rather than being limited to local storage.

[0226] When the processor 1001 in the terminal executes the executable code or application stored in the memory 1002, the terminal executes the terminal-side method steps in the above embodiment, such as executing S401, S501, S510, etc. The specific execution process is referred to the above embodiment and will not be repeated here.

[0227] When the processor 1001 in the certificate management server executes the executable code or application stored in the memory 1002, the terminal executes the terminal-side method steps in the above embodiment, such as executing S503, S507, S508, etc. The specific execution process is referred to the above embodiment and will not be repeated here.

[0228] When the processor 1001 in the KMS executes the executable code or application stored in the memory 1002, the terminal executes the terminal-side method steps in the above embodiment, such as executing S402 to S403, S504 to S506, etc. The specific execution process is referred to the above embodiment and will not be repeated here.

[0229] When the processor 1001 in the AS executes the executable code or application stored in the memory 1002, the terminal executes the terminal-side method steps in the above embodiment, such as executing S503, S509, S601 to S607, etc. The specific execution process is referred to the above embodiment and will not be repeated here.

[0230] In addition, the memory 1002 stores the Figures 7 to 9 Computer-executable instructions for the functions of communication modules 701, 702, 801, 803, 901, 902, 903 and processing module 802. Figures 7 to 9 The functions / implementation processes of the communication modules 701, 702, 801, 803, 901, 902, 903 and the processing module 802 can be realized by Figure 10 The processor 1001 in the memory 1002 calls the computer execution instructions stored in the memory 1002 to implement it. For the specific implementation process and functions, please refer to the above-mentioned related embodiments.

[0231] Based on the same inventive concept, the embodiment of the present application provides a communication system, which is the above-mentioned Figure 1 The network side of the communication system shown may include: a certificate management server, a KMS and an AS; wherein the certificate management server, the KMS and / or the AS are respectively configured to execute the communication method based on the IMS data channel as described in any possible implementation method described above.

[0232] Based on the same inventive concept, an embodiment of the present application provides a computer-readable storage medium, which stores instructions. When the instructions are executed on a computer, they are used to execute the communication method based on the IMS data channel as described in the above embodiment and any possible implementation methods thereof.

[0233] Based on the same inventive concept, an embodiment of the present application provides a computer program or a computer program product. When the computer program or the computer program product is executed on a computer, the computer implements the communication method based on the IMS data channel as described in the above embodiment and any possible implementation manner thereof.

[0234] Those skilled in the art will appreciate that the functions described in conjunction with the various illustrative logic blocks, modules, and algorithm steps disclosed herein can be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions described in the various illustrative logic blocks, modules, and steps can be stored or transmitted as one or more instructions or codes on a computer-readable medium and executed by a hardware-based processing unit. Computer-readable media can include computer-readable storage media, which corresponds to tangible media, such as data storage media, or communication media including any media that facilitates the transfer of computer programs from one place to another (e.g., according to a communication protocol). In this manner, computer-readable media can generally correspond to (1) non-transitory tangible computer-readable storage media, or (2) communication media, such as signals or carrier waves. Data storage media can be any available media that can be accessed by one or more computers or one or more processors to retrieve instructions, codes, and / or data structures for implementing the techniques described in this application. A computer program product can include computer-readable media.

[0235] By way of example, and not limitation, such computer-readable storage media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage, flash memory, or any other medium that can be used to store desired program code in the form of instructions or data structures and that can be accessed by a computer. Furthermore, any connection is properly referred to as a computer-readable medium. For example, if instructions are transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwaves, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwaves are included in the definition of medium. However, it should be understood that computer-readable storage media and data storage media do not include connections, carrier waves, signals, or other transient media, but are actually directed to non-transitory tangible storage media. As used herein, disk and disc include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), and Blu-ray disc, where disks typically reproduce data magnetically, while discs reproduce data optically using lasers. Combinations of the above should also be included within the scope of computer-readable media.

[0236] Instructions may be executed by one or more processors, such as one or more digital signal processors (DSPs), general-purpose microprocessors, application-specific integrated circuits (ASICs), field-programmable logic arrays (FPGAs), or other equivalent integrated or discrete logic circuits. Thus, the term "processor," as used herein, may refer to any of the aforementioned structures or any other structure suitable for implementing the techniques described herein. Additionally, in some aspects, the functionality described by the various illustrative logical blocks, modules, and steps described herein may be provided within dedicated hardware and / or software modules configured for encoding and decoding, or incorporated into a combined codec. Furthermore, the techniques may be fully implemented in one or more circuits or logic elements.

[0237] The techniques of this application can be implemented in a variety of devices or apparatuses, including wireless handsets, integrated circuits (ICs), or a set of ICs (e.g., a chipset). Various components, modules, or units are described herein to emphasize functional aspects of devices for performing the disclosed techniques, but they do not necessarily require implementation by different hardware units. In fact, as described above, the various units may be combined in a codec hardware unit in conjunction with appropriate software and / or firmware, or provided by interoperating hardware units (including one or more processors as described above).

[0238] In the above embodiments, the description of each embodiment has different emphases. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0239] The above description is merely an exemplary embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.< / length> < / length>

Claims

1. A communication method based on an Internet Protocol Multimedia Subsystem (IMS) data channel, characterized in that: include: The certificate management server receives the encrypted ticket and identification information of the first application from the application server AS, where the identification information of the first application is used to identify the first application of the first terminal; The certificate management server sends the encrypted ticket and identification information of the first application to the key management server KMS; The certificate management server receives a first key; The certificate management server sends a data channel application certificate corresponding to the first key to the AS, where the data channel application certificate is used for the first application to perform an IMS data channel service with a second application of the second terminal.

2. The method according to claim 1, characterized in that The method further comprises: The certificate management server obtains the address of the KMS; The certificate management server sends the encrypted ticket and identification information of the first application to the key management server KMS, including: The certificate management server sends the encrypted ticket and identification information of the first application to the KMS according to the address of the KMS.

3. The method according to claim 1 or 2, characterized in that The certificate management server sends the data channel application certificate corresponding to the first key to the AS, including: The certificate management server sends the data channel application certificate and identification information of the first application to the AS.

4. The method according to claim 1 or 2, characterized in that The identification information of the first application includes: the terminal identification of the first terminal; or the terminal identification of the first terminal and the application identification of the first application.

5. The method according to claim 4, characterized in that The terminal identification of the first terminal includes: a device identification of the first terminal or a user identification of a user using the first terminal.

6. The method according to claim 1, wherein The encrypted ticket includes: identification information of the first application.

7. The method according to claim 6, characterized in that The encrypted ticket also includes a key index of a second key, the second key matches the first key, and the second key is allocated by the KMS to the first application.

8. A communication method based on an Internet Protocol Multimedia Subsystem (IMS) data channel, characterized in that: include: The key management server KMS obtains the first encryption ticket and identification information of the first application from the certificate management server, where the identification information of the first application is used to identify the first application of the first terminal; The KMS decrypts the first encrypted ticket to obtain identification information in the first encrypted ticket; The KMS verifies the first application based on the identification information in the first encrypted ticket and the identification information of the first application; If the verification of the first application is successful, the KMS sends a first key to the certificate management server. The first key is used by the certificate management server to generate a data channel application certificate for the first application. The data channel application certificate is used by the first application to perform IMS data channel services with the second application of the second terminal.

9. The method according to claim 8, characterized in that The KMS verifies the first application according to the identification information in the first encrypted ticket and the identification information of the first application, including: The KMS determines whether the identification information in the first encrypted ticket matches the identification information of the first application. If the identification information in the first encrypted ticket matches the identification information of the first application, verification of the first application is successful. If the identification information in the first encrypted ticket does not match the identification information of the first application, verification of the first application fails.

10. The method according to claim 8 or 9, characterized in that The first encrypted ticket also includes: a key index; The KMS verifies the first application according to the identification information in the first encrypted ticket and the identification information of the first application, including: The KMS verifies the first application according to the identification information in the first encryption ticket, the key index, and the identification information of the first application.

11. The method according to claim 10, characterized in that The KMS verifies the first application according to the identification information in the first encryption ticket, the key index, and the identification information of the first application, including: The KMS determines whether the identification information in the first encrypted ticket matches the identification information of the first application; If the identification information in the first encrypted ticket matches the identification information of the first application, the KMS determines whether the key index matches a second key, where the second key is allocated by the KMS to the first application; If the key index matches the second key, it indicates that the verification of the first application is successful; if the key index does not match the second key, it indicates that the verification of the first application fails.

12. The method according to claim 11, characterized in that Before the KMS obtains the first encrypted ticket and the identification information of the first application from the certificate management server, the method further includes: The KMS receives a key request from the first terminal; In response to the key request, the KMS allocates the second key and a second encryption ticket to the first application, where the second encryption ticket includes: identification information of the first application, or identification information of the first application and a key index of the second key; The KMS sends the second key and the second encrypted ticket to the first terminal.

13. The method according to any one of claims 8 to 9, 11 to 12, characterized in that The identification information of the first application includes: the terminal identification of the first terminal; or the terminal identification of the first terminal and the application identification of the first application.

14. The method according to claim 13, characterized in that The terminal identification of the first terminal includes: a device identification of the first terminal or a user identification of a user using the first terminal.

15. The method according to any one of claims 8 to 9, 11 to 12, and 14, characterized in that: The method further comprises: The KMS and the first terminal establish a communication channel using a general authentication mechanism GBA.

16. A communication method based on an Internet Protocol Multimedia Subsystem (IMS) data channel, characterized in that: include: The first terminal sends the encrypted ticket and identification information of the first application to the application server AS, where the identification information of the first application is used to identify the first application of the first terminal; The first terminal receives the data channel application certificate sent by the AS; The first terminal performs an IMS data channel service with the second application of the second terminal according to the data channel application certificate.

17. The method according to claim 16, characterized in that The method further comprises: The first terminal sends the address of the key management server KMS to the AS, where the address of the KMS is used to instruct the certificate management server to communicate with the KMS.

18. The method according to claim 16 or 17, characterized in that The identification information of the first application includes: the terminal identification of the first terminal; or the terminal identification of the first terminal and the application identification of the first application.

19. The method according to claim 18, characterized in that The terminal identification of the first terminal includes: a device identification of the first terminal or a user identification of a user using the first terminal.

20. The method according to any one of claims 16 to 17 and 19, characterized in that: Before the first terminal sends the encrypted ticket and the identification information of the first application to the AS, the method further includes: The first terminal requests a key and a ticket from the KMS; The first terminal receives a second key and an encryption ticket allocated by the KMS to the first application, where the encryption ticket includes: identification information of the first application, or identification information of the first application and a key index of the second key.

21. The method according to claim 17, wherein The data channel application certificate is generated by the certificate management server according to the first key, and the first key matches the second key; The first terminal performing an IMS data channel service with a second application of the second terminal according to the data channel application certificate, including: When the second terminal successfully authenticates the first application, the first terminal authenticates the data channel application certificate by using the first key and the second key in combination.

22. The method according to claim 17, wherein The method further comprises: The first terminal and the KMS establish a communication channel using a general authentication mechanism GBA.

23. A communication method based on Internet Protocol Multimedia Subsystem IMS data channel, characterized in that: include: The application server AS receives the encrypted ticket and identification information of the first application from the first terminal, where the identification information of the first application is used to identify the first application of the first terminal; The AS sends the encrypted ticket and the identification information of the first application to the certificate management server; The AS receives a first data channel application certificate from the certificate management server, where the first data channel application certificate is allocated by the certificate management server to the first application, and the first data channel application certificate is used for the first application to perform an IMS data channel service with a second application of the second terminal; The AS saves the first data channel application certificate and sends the first data channel application certificate to the first terminal.

24. The method according to claim 23, wherein The method further comprises: The AS receives a second data channel application certificate allocated by the certificate management server to the second application, where the second data channel application certificate is used for the second application to perform an IMS data channel service with the first application; The AS saves the second data channel application certificate and sends the second data channel application certificate to the second terminal.

25. The method according to claim 24, characterized in that The method further comprises: The AS obtains the data channel application certificate from the first terminal and the data channel application certificate from the second terminal during the datagram transport layer security DTLS handshake process; The AS matches the data channel application certificate from the first terminal with the first data channel application certificate; The AS matches the data channel application certificate from the second terminal with the second data channel application certificate; If the data channel application certificate from the first terminal matches the first data channel application certificate, and the data channel application certificate from the second terminal matches the second data channel application certificate, allowing the first application to establish an IMS data channel with the second application; If the data channel application certificate from the first terminal does not match the first data channel application certificate, and / or the data channel application certificate from the second terminal does not match the second data channel application certificate, the first application is prohibited from establishing an IMS data channel with the second application.

26. A certificate management server, characterized in that: include: processor and memory; The processor is coupled to the memory, and is configured to read and execute instructions in the memory to implement the communication method based on the Internet Protocol Multimedia Subsystem IMS data channel according to any one of claims 1 to 7.

27. A key management server KMS, characterized in that: include: processor and memory; The processor is coupled to the memory, and is configured to read and execute instructions in the memory to implement the communication method based on the Internet Protocol Multimedia Subsystem IMS data channel according to any one of claims 8 to 15.

28. A terminal, characterized in that: include: processor and memory; The processor is coupled to the memory, and is configured to read and execute instructions in the memory to implement the communication method based on the Internet Protocol Multimedia Subsystem (IMS) data channel according to any one of claims 16 to 22.

29. An application server AS, characterized in that: include: processor and memory; The processor is coupled to the memory, and is configured to read and execute instructions in the memory to implement the communication method based on the Internet Protocol Multimedia Subsystem IMS data channel according to any one of claims 23 to 25.

30. A communication system, characterized in that: include: Certificate management server, key management server KMS and application server AS; among them, The certificate management server is configured to execute the communication method based on the IMS data channel according to any one of claims 1 to 7; The KMS is configured to execute the communication method based on the IMS data channel according to any one of claims 8 to 15; The AS is configured to execute the communication method based on the IMS data channel according to any one of claims 23 to 25.

Citation Information

Patent Citations

  • Audio-video data monitoring method and system

    CN107294968A

  • Methods and arrangements for binding a device application to a web service

    CN109792433A