User identity authentication method, information transmission method, device and equipment
Patent Information
- Application Number
- CN202111025106.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-02
- Publication Date
- 2026-09-11
- Estimated Expiration
- 2041-09-02
AI Technical Summary
[0004]本发明的目的在于提供一种用户身份认证方法、信息传输方法、装置及设备,以解决现有用户通过5G消息系统访问第三方服务页面时,用户操作效率与用户业务数据安全性无法兼得的问题
Smart Images

Figure CN115767528B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and in particular to a user authentication method, information transmission method, apparatus, and device. Background Technology
[0002] 5G messaging opens external pages through a browser via URLs (Uniform Resource Locators). These external pages are typically developed by third-party service providers, and the two are relatively independent, weakly connected systems. Therefore, 5G messaging's own account authentication information cannot be directly transmitted to external HTML (Hypertext Markup Language) pages.
[0003] When users need to access third-party service pages within the 5G messaging system, if they wish to log in using their 5G messaging account, they must manually enter user information and a login password (or SMS verification code) to confirm their identity. This process is cumbersome, reducing user efficiency and service experience. Existing solutions that eliminate manual operation all carry certain risks. Currently, there is no convenient, secure, and terminal-unmodified authentication and open mechanism suitable for users to access external services within the 5G messaging system without manual operation. Summary of the Invention
[0004] The purpose of this invention is to provide a user authentication method, information transmission method, apparatus, and device to solve the problem that user operation efficiency and user business data security cannot be simultaneously achieved when users access third-party service pages through existing 5G messaging systems.
[0005] To achieve the above objectives, the present invention provides a user authentication method, applied to a network-side device, comprising:
[0006] The system receives a first request message sent by a third-party server. The first request message is used to request user authentication for the target terminal attempting to access an external service page. The external service page is a page provided to the first terminal by the third-party server.
[0007] A second request message is sent to the first user identity recognition module SIM card of the first terminal. The second request message is used to request the first terminal to confirm whether to allow access to the external service page.
[0008] If a second reply message is received from the first SIM card of the first terminal in response to the second request message, and the second reply message satisfies the first condition, the target terminal attempting to access the external service page is determined to be the first terminal. The first condition is used to determine that the terminal that is confirmed to allow access to the external service page is the first terminal.
[0009] Send a first reply message indicating successful user authentication to the third-party server.
[0010] The first condition is:
[0011] The second reply message includes a reply message from the first terminal confirming permission to access the external service page and the card information of the first SIM card. The identification information of the terminal corresponding to the card information of the first SIM card is the identification information of the first terminal. The identification information of the terminal corresponding to the card information of the first SIM card is determined based on the pre-stored correspondence between the card information of the SIM card and the identification information of the terminal.
[0012] The first request message includes an application identifier corresponding to the third-party server, a first serial number, and the identifier information of the first terminal, all encrypted using a public key by the third-party server. The first serial number is generated based on the identifier information of the first terminal and includes the application identifier corresponding to the third-party server.
[0013] The process of sending a second request message to the first user identification module SIM card of the first terminal includes:
[0014] The first request message is decrypted using a private key to obtain the application identifier, the first serial number, and the identifier information of the first terminal corresponding to the third-party server.
[0015] Based on the identification information of the first terminal, a second request message is sent to the first SIM card of the first terminal via data SMS. The second request message carries the first serial number.
[0016] Before sending a second request message to the first SIM card of the first terminal via data SMS based on the identification information of the first terminal, the method further includes:
[0017] Based on the application identifier corresponding to the third-party server, it is determined that the third-party server has authentication access permissions.
[0018] The second reply message also includes a second serial number, which is the serial number obtained by encrypting the first serial number using a symmetric encryption algorithm on the first SIM card.
[0019] The method further includes, after receiving a second reply message from the first SIM card of the first terminal in response to the second request message:
[0020] The second serial number is decrypted using a symmetric encryption algorithm to obtain the first serial number;
[0021] Based on the first sequence number, it is determined that the second request message is a request initiated by a network-side device.
[0022] This invention also provides an information transmission method applied to a terminal, wherein the terminal is a first terminal, comprising:
[0023] The first terminal receives a second request message sent by the network-side device after receiving a first request message from a third-party server via the first user identity recognition module SIM card. The first request message is used to request user identity authentication for the target terminal attempting to access an external service page, where the external service page is a page provided to the first terminal by the third-party server. The second request message is used to request the first terminal to confirm whether to allow access to the external service page.
[0024] A second response message is sent to the network-side device in response to the second request message, so that the network-side device determines that the target terminal attempting to access the external service page is the first terminal if the second response message meets a first condition, wherein the first condition is used to determine that the terminal that is confirmed to be allowed to access the external service page is the first terminal.
[0025] Wherein, the first user identity recognition module SIM card receiving network-side device of the first terminal, after receiving the first request message sent by the third-party server, sends a second request message, including:
[0026] The network-side device receives a second request message after receiving a first request message from a third-party server via data SMS. The second request message carries a first sequence number, which is generated based on the identification information of the first terminal and includes the application identifier corresponding to the third-party server.
[0027] The process of sending a second response message to the network-side device in response to the second request message includes:
[0028] If the first terminal confirms permission to access the external service page based on the second request information, the card information of the first SIM card is extracted;
[0029] A second reply message is sent to the network-side device. The second reply message contains a reply message confirming that the first terminal is allowed to access the external service page and the card information of the first SIM card.
[0030] Before sending a second reply message to the network-side device in response to the second request message, the method further includes:
[0031] The first serial number is encrypted using a symmetric encryption algorithm to obtain a second serial number, and the second reply message also includes the second serial number.
[0032] The method further includes:
[0033] This displays the external service page pushed by the third-party server after confirming successful user authentication.
[0034] This invention also provides a user authentication device, comprising:
[0035] The first receiving module is configured to receive a first request message sent by a third-party server. The first request message requests user authentication for a target terminal attempting to access an external service page, wherein the external service page is a page provided by the third-party server to the first terminal.
[0036] The first sending module is used to send a second request message to the first user identity recognition module SIM card of the first terminal. The second request message is used to request the first terminal to confirm whether to allow access to the external service page.
[0037] The identity authentication module is used to determine that the target terminal attempting to access the external service page is the first terminal when it receives a second reply message sent by the first SIM card of the first terminal in response to the second request message, and the second reply message satisfies a first condition. The first condition is used to determine that the terminal that is confirmed to be allowed to access the external service page is the first terminal.
[0038] The second sending module is used to send a first reply message indicating successful user authentication to the third-party server.
[0039] This invention also provides a network-side device, including a processor and a transceiver, wherein the transceiver receives and transmits data under the control of the processor, and the processor is configured to perform the following operations:
[0040] The system receives a first request message sent by a third-party server. The first request message is used to request user authentication for the target terminal attempting to access an external service page. The external service page is a page provided to the first terminal by the third-party server.
[0041] A second request message is sent to the first user identity recognition module SIM card of the first terminal. The second request message is used to request the first terminal to confirm whether to allow access to the external service page.
[0042] If a second reply message is received from the first SIM card of the first terminal in response to the second request message, and the second reply message satisfies the first condition, the target terminal attempting to access the external service page is determined to be the first terminal. The first condition is used to determine that the terminal that is confirmed to allow access to the external service page is the first terminal.
[0043] Send a first reply message indicating successful user authentication to the third-party server.
[0044] The first condition is:
[0045] The second reply message includes a reply message from the first terminal confirming permission to access the external service page and the card information of the first SIM card. The identification information of the terminal corresponding to the card information of the first SIM card is the identification information of the first terminal. The identification information of the terminal corresponding to the card information of the first SIM card is determined based on the pre-stored correspondence between the card information of the SIM card and the identification information of the terminal.
[0046] The first request message includes an application identifier corresponding to the third-party server, a first serial number, and the identifier information of the first terminal, all encrypted using a public key by the third-party server. The first serial number is generated based on the identifier information of the first terminal and includes the application identifier corresponding to the third-party server.
[0047] The transceiver is also used for:
[0048] The first request message is decrypted using a private key to obtain the application identifier, the first serial number, and the identifier information of the first terminal corresponding to the third-party server.
[0049] Based on the identification information of the first terminal, a second request message is sent to the first SIM card of the first terminal via data SMS. The second request message carries the first serial number.
[0050] The processor is also used to perform the following processes:
[0051] Based on the application identifier corresponding to the third-party server, it is determined that the third-party server has authentication access permissions.
[0052] The second reply message also includes a second serial number, which is the serial number obtained by encrypting the first serial number using a symmetric encryption algorithm on the first SIM card.
[0053] The processor is also used to perform the following processes:
[0054] The second serial number is decrypted using a symmetric encryption algorithm to obtain the first serial number;
[0055] Based on the first sequence number, it is determined that the second request message is a request initiated by a network-side device.
[0056] This invention also provides a network-side device, including a memory, a processor, and a program stored in the memory and executable on the processor; when the processor executes the program, it implements the user authentication method as described in the above embodiments.
[0057] This invention also provides an information transmission device, comprising:
[0058] The second receiving module is configured to enable the first user identity recognition module SIM card of the first terminal to receive the second request message sent by the network-side device after receiving the first request message sent by the third-party server. The first request message is used to request user identity authentication for the target terminal attempting to access an external service page, where the external service page is a page provided to the first terminal by the third-party server. The second request message is used to request the first terminal to confirm whether to allow access to the external service page.
[0059] The third sending module is used to send a second reply message to the network-side device in response to the second request message, so that the network-side device determines the target terminal attempting to access the external service page as the first terminal when the second reply message meets a first condition, wherein the first condition is used to determine that the terminal that confirms permission to access the external service page is the first terminal.
[0060] This invention also provides a terminal, which is a first terminal, including a processor and a transceiver. The transceiver receives and sends data under the control of the processor, and the transceiver is used to perform the following process:
[0061] The first user identity recognition module SIM card of the first terminal receives a second request message sent by the network-side device after receiving a first request message sent by a third-party server. The first request message is used to request user identity authentication for the target terminal attempting to access an external service page, where the external service page is a page provided to the first terminal by the third-party server. The second request message is used to request the first terminal to confirm whether to allow access to the external service page.
[0062] A second response message is sent to the network-side device in response to the second request message, so that the network-side device determines that the target terminal attempting to access the external service page is the first terminal if the second response message meets a first condition, wherein the first condition is used to determine that the terminal that is confirmed to be allowed to access the external service page is the first terminal.
[0063] The transceiver is used to perform the following process:
[0064] The network-side device receives a second request message after receiving a first request message from a third-party server via data SMS. The second request message carries a first sequence number, which is generated based on the identification information of the first terminal and includes the application identifier corresponding to the third-party server.
[0065] The transceiver is used to perform the following process:
[0066] If the first terminal confirms permission to access the external service page based on the second request information, the card information of the first SIM card is extracted;
[0067] A second reply message is sent to the network-side device. The second reply message contains a reply message confirming that the first terminal is allowed to access the external service page and the card information of the first SIM card.
[0068] The processor is further configured to:
[0069] The first serial number is encrypted using a symmetric encryption algorithm to obtain a second serial number, and the second reply message also includes the second serial number.
[0070] The processor is further configured to:
[0071] This displays the external service page pushed by the third-party server after confirming successful user authentication.
[0072] This invention also provides a terminal, including a memory, a processor, and a program stored in the memory and executable on the processor; when the processor executes the program, it implements the information transmission method as described in the above embodiments.
[0073] This invention also provides a computer-readable storage medium storing a computer program thereon, characterized in that, when executed by a processor, the program implements the steps in the user authentication method as described in the above embodiments, or implements the steps in the information transmission method as described in the above embodiments.
[0074] The above-described technical solution of the present invention has at least the following beneficial effects:
[0075] In this embodiment of the invention, a first request message is received from a third-party server. This first request message requests user authentication for a target terminal attempting to access an external service page, where the external service page is a page provided to the first terminal by the third-party server. A second request message is sent to the first user identification module (SIM card) of the first terminal. This second request message requests the first terminal to confirm whether access to the external service page is permitted. Upon receiving a second reply message from the first SIM card of the first terminal in response to the second request message, and if the second reply message satisfies a first condition, the target terminal attempting to access the external service page is determined to be the first terminal. The first condition is used to determine that the terminal confirming permission to access the external service page is the first terminal. A first reply message indicating successful user authentication is sent to the third-party server. Thus, when a user accesses an external service page provided by a third-party server through a 5G messaging system, the introduction of a terminal SIM card verification process enables user authentication without manual operation, improving user efficiency. Furthermore, it prevents users without SIM cards from accessing the user's account information, thereby ensuring the security of user business data. Attached Figure Description
[0076] Figure 1 A flowchart illustrating the user authentication method according to an embodiment of the present invention;
[0077] Figure 2 A flowchart illustrating the information transmission method according to an embodiment of the present invention;
[0078] Figure 3 A schematic diagram illustrating the process of implementing the method of the present invention between devices;
[0079] Figure 4 A schematic diagram of the modules of a user authentication device according to an embodiment of the present invention;
[0080] Figure 5A schematic diagram illustrating the structure of a network-side device according to an embodiment of the present invention;
[0081] Figure 6 A schematic diagram of the information transmission device according to an embodiment of the present invention;
[0082] Figure 7 A schematic diagram illustrating the structure of a terminal according to an embodiment of the present invention. Detailed Implementation
[0083] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.
[0084] Building upon RCS (Rich Communication Suite), 5G messaging introduces MaaP (Messaging as a Platform) capabilities. This upgrades the interaction between third-party service providers and end-users from simple text- and link-based SMS notifications and confirmations to a comprehensive display and interactive capability based on audio and video, geolocation, rich media cards, and features such as floating menus, fixed menus, and link navigation. This transforms messaging products from a business endpoint (SMS notifications) to a business starting point (user interaction), greatly enriching the application space and commercial value of industry messaging.
[0085] 5G messaging offers advantages such as native terminal entry, rich media display, strong user reach, and lightweight interaction; however, its message-based interaction mode dictates that it is primarily suitable for simple and quick application scenarios. For scenarios requiring complex content display and interaction logic (such as displaying detailed bills or filling out forms), it is necessary to use a third-party service provider (such as a bank app's server) to send links (such as suggested action buttons) within the message to redirect to an external HTML page to complete the business logic processing.
[0086] 5G Messaging opens external pages via URLs in browsers. These external pages are typically developed by third-party service providers, and the two are relatively independent, weakly connected systems. Therefore, 5G Messaging's own account authentication information cannot be directly passed to external HTML pages. When a user needs to access a third-party service page within the 5G Messaging system, if they need to log in using their 5G Messaging account (such as a mobile phone number IMPU), they must manually enter user information and a login password (or SMS verification code) to confirm their identity. This process is cumbersome, reducing user efficiency and service experience.
[0087] For scenarios with low business security requirements, third-party service providers can generate a unique link for each user when pushing links to users, thus eliminating the need for users to manually enter identity verification information. However, if a user mistakenly forwards the link to another user, or if someone else steals the link address, there is a data security risk that the user's identity may be stolen, their personal privacy data may be viewed, and their business may be processed by other users.
[0088] Among existing solutions that eliminate the need for manual operation, i.e., do not require users to manually enter identity verification information, the following two methods are commonly used:
[0089] 1) Terminal security zone authentication method
[0090] The system consists of a network service provider offering specific network services and user terminal devices. The user terminal devices require separate environments, consisting of an insecure zone based on an open operating system and a secure zone based on a secure operating system. Users access network services through a web browser running in the insecure zone, sending an open identifier to the network service provider. The network service provider then redirects the user to the secure zone of the user terminal device for user authentication. However, this solution requires modifications to user terminal devices to support the secure zone and its corresponding processing logic. Furthermore, the large-scale modification of existing user terminals is complex, difficult to implement, and time-consuming, making it difficult to quickly and comprehensively implement the open authentication mechanism.
[0091] 2) Method based on association between user IP and user ID
[0092] This method introduces a support device on the network side to receive and store the mapping relationship between user IP addresses and user IDs. Upon receiving an IP address query request from a third party, the stored mapping relationship is used to verify the identity of the user accessing the third-party service. However, since IP addresses and port numbers remain unchanged for a long time, and are easily intercepted by other users during the process of sending data from the user's terminal device to the third-party service, there is still a security risk that other terminals may use stolen IP addresses to access private data and process related business with a genuine user identity.
[0093] In summary, there is currently no convenient, secure, and terminal-unmodifiable authentication and access mechanism that can be applied to a solution for users to access external services without manual intervention within a 5G messaging system.
[0094] To address the aforementioned issues, embodiments of the present invention provide a user authentication method, an information transmission method, an apparatus, and a device. The method and apparatus are based on the same application concept. Since the methods and apparatus solve problems in similar principles, their implementations can be mutually referenced, and repeated details will not be elaborated further.
[0095] like Figure 1The diagram shown is a flowchart of a user authentication method provided in an embodiment of the present invention. This method is applied to a network-side device and includes:
[0096] Step 101: Receive a first request message sent by a third-party server. The first request message is used to request user authentication for the target terminal attempting to access an external service page. The external service page is a page provided by the third-party server to the first terminal.
[0097] Here, the network-side device in this embodiment of the invention can be a server in a 5G messaging system, which has open identity authentication capabilities.
[0098] Prior to this step, the target terminal receives a push message sent by a third-party server. The push message includes a link instructing the terminal to access an external service page. The link carries a first serial number, which includes a serial number identifying the first terminal and an application identifier corresponding to the third-party server.
[0099] Here, the serial number identifying the first terminal is generated based on the identification information of the first terminal, or optionally, it can be generated based on the user number (such as a mobile phone number) of the first terminal.
[0100] It should be noted that different terminals will use different links to access the same external service page. The third-party server will store the correspondence between the first serial number and the identification information of the first terminal.
[0101] Subsequently, the target terminal receives user input for the link (usually through a click) and attempts to access an external service page through that link. Then, the third-party server matches the first terminal's identification information (such as the first terminal's user number, like a mobile phone number) with the first serial number carried in the link instructing the terminal to access the external service page. This facilitates the subsequent sending of a second request message to the first terminal's SIM card.
[0102] Finally, a first request message is sent to the network-side device, which corresponds to receiving the first request message sent by the third-party server in this step.
[0103] It should be noted that external service pages are pages provided to the first terminal by a third-party server. However, the target terminal attempting to access an external service page is not necessarily the first terminal. It could be the first terminal or another terminal that has stolen the link. Therefore, in order to ensure the security of user business data, it is necessary to determine the user identity of the target terminal.
[0104] Step 102: Send a second request message to the first user identity recognition module SIM card of the first terminal. The second request message is used to request the first terminal to confirm whether to allow access to the external service page.
[0105] The purpose of this step is to verify with the first terminal whether it is attempting to access an external service page. Sending a second request message through the first terminal's first SIM card utilizes the SIM's authentication and authorization capabilities to achieve automatic authentication of the user's identity, eliminating the need for cumbersome manual authentication steps.
[0106] Step 103: Upon receiving a second reply message from the first SIM card of the first terminal in response to the second request message, and if the second reply message satisfies the first condition, the target terminal attempting to access the external service page is determined to be the first terminal. The first condition is used to determine that the terminal that is confirmed to allow access to the external service page is the first terminal.
[0107] This step corresponds to the situation where the first terminal confirms that access to the external service page is permitted, which indirectly indicates that the first terminal confirms that the target terminal attempting to access the external service page is itself.
[0108] Step 104: Send a first reply message indicating successful user authentication to the third-party server.
[0109] It should be noted that when the third-party server learns from the first reply message that the first terminal is attempting to access the external service page, it will push the external service page to the first terminal for display.
[0110] The authentication method of this invention involves receiving a first request message from a third-party server, which requests user authentication for a target terminal attempting to access an external service page (the external service page being a page provided to the first terminal by the third-party server); sending a second request message to the first user identification module (SIM card) of the first terminal, which requests confirmation from the first terminal regarding whether access to the external service page is permitted; receiving a second response message from the first SIM card of the first terminal in response to the second request message, provided that the second response message meets a first condition, determining that the target terminal attempting to access the external service page is the first terminal, where the first condition is used to confirm that the terminal authorized to access the external service page is the first terminal; and sending a first response message indicating successful user authentication to the third-party server. Thus, when a user accesses an external service page provided by a third-party server through a 5G messaging system, the introduction of a terminal SIM card verification process enables user authentication without manual intervention, improving user efficiency. Furthermore, it prevents users without SIM cards from accessing the user's account information, thereby ensuring the security of user business data.
[0111] Optionally, the first condition is:
[0112] The second reply message includes a reply message from the first terminal confirming permission to access the external service page and the card information of the first SIM card. The identification information of the terminal corresponding to the card information of the first SIM card is the identification information of the first terminal. The identification information of the terminal corresponding to the card information of the first SIM card is determined based on the pre-stored correspondence between the card information of the SIM card and the identification information of the terminal.
[0113] Here, the card information of the first SIM card is generally the ICCID (Integrated Circuit Card Identity) of the first SIM card, which is the card number of the first SIM card. It is equivalent to the identification information of the first terminal (generally the user number of the first terminal, such as a mobile phone number).
[0114] It should be noted that the second reply message includes the card information of the first SIM card, indicating that the first SIM card has provided its own card information. Specifically, the first SIM card can be triggered to retrieve its own card information in the following two ways.
[0115] Method 1: If the network-side device does not require user confirmation, the first SIM card directly extracts its own card information.
[0116] It should be noted that whether the network-side device requires user confirmation can be determined based on the negotiation between the network-side device and the third-party server.
[0117] Method 2: If the network-side device requires user confirmation, the first SIM card sends an active command (such as launch Browser, display text, etc.) to the first terminal, requesting the user to manually confirm whether to allow access to the external service page (i.e. whether to authorize login to the corresponding third-party server).
[0118] Then, by clicking the confirmation button in the system prompt box, the first SIM card receives a confirmation response from the user, and then the first SIM card retrieves its own card information.
[0119] It should be noted that if, based on the pre-stored correspondence between the SIM card information and the terminal identification information, it is determined that the terminal identification information corresponding to the first SIM card information is the identification information of the first terminal, it can be further verified that the terminal allowed to access the external service page is the first terminal.
[0120] Optionally, the first request message includes an application identifier corresponding to the third server, a first serial number, and the identifier information of the first terminal, which are encrypted using a public key by the third-party server. The first serial number is generated based on the identifier information of the first terminal and includes the application identifier corresponding to the third server.
[0121] It should be noted that the content included in the first request message is all encrypted with a public key. The purpose of this is to ensure the reliability of message transmission. Even if the request message is intercepted by other devices, since it is encrypted with a public key, other devices do not have the private key corresponding to the public key and cannot decrypt it, thereby avoiding the leakage of the application identifier, first serial number and identifier information of the third server and the first terminal.
[0122] Based on this, as an optional implementation, method step 102 of this embodiment of the invention sends a second request message to the first user identity recognition module SIM card of the first terminal, including:
[0123] The first request message is decrypted using a private key to obtain the application identifier, the first serial number, and the identifier information of the first terminal corresponding to the third-party server.
[0124] Here, the private key corresponds to the public key mentioned above.
[0125] It should be noted that after decrypting the first request message, the application identifier, the first serial number, and the identifier information of the first terminal corresponding to the third-party server are obtained. The purpose is to enable the network-side device to know that the first request message is related to the application corresponding to the third-party server and the first terminal. At the same time, the network-side device can also perform the following steps based on the identifier information of the first terminal.
[0126] Based on the identification information of the first terminal, a second request message is sent to the first SIM card of the first terminal via data SMS. The second request message carries the first serial number.
[0127] In this step, the network-side device sends a data SMS to the first SIM card of the first terminal based on the identification information of the first terminal (generally the user number of the first terminal, such as a mobile phone number). The data SMS includes a second request message.
[0128] Here, the purpose of carrying the first sequence number in the second request message is to enable the network-side device to determine that the network-side device initiated the second request message after receiving the second reply message in response to the second request message. This helps the network-side device distinguish which request messages were initiated by itself and which were not.
[0129] Based on this, as an optional implementation, before sending a second request message to the first SIM card of the first terminal via data SMS according to the identification information of the first terminal, the method of this embodiment further includes:
[0130] Based on the application identifier corresponding to the third-party server, it is determined that the third-party server has authentication access permissions.
[0131] In other words, after the third-party server has the authorization to authenticate, it sends a second request message to the first SIM card of the first terminal via SMS.
[0132] Optionally, the second reply message may also include a second serial number, which is the serial number obtained by encrypting the first serial number using a symmetric encryption algorithm on the first SIM card.
[0133] It should be noted that the purpose of encrypting the first sequence number using a symmetric encryption algorithm is to enable the network-side device to verify that the second request message corresponding to the second reply message was initiated by the network-side device itself.
[0134] Based on this, further, after receiving the second reply message sent by the first SIM card of the first terminal in response to the second request message, the method further includes:
[0135] The second serial number is decrypted using a symmetric encryption algorithm to obtain the first serial number;
[0136] Based on the first sequence number, it is determined that the second request message is a request initiated by a network-side device.
[0137] It should be noted that in this embodiment, the network-side device can verify whether the second request message corresponding to the second reply message was initiated by the network-side device itself by decrypting the second serial number. If so, it can verify the card information of the first SIM card in the second reply message to obtain the terminal identifier corresponding to the card information of the first SIM card, making the verification of the network-side device more targeted.
[0138] The authentication method of this invention involves receiving a first request message from a third-party server, which requests user authentication for a target terminal attempting to access an external service page (the external service page being a page provided to the first terminal by the third-party server); sending a second request message to the first user identification module (SIM card) of the first terminal, which requests confirmation from the first terminal regarding whether access to the external service page is permitted; receiving a second response message from the first SIM card of the first terminal in response to the second request message, provided that the second response message meets a first condition, determining that the target terminal attempting to access the external service page is the first terminal, where the first condition is used to confirm that the terminal authorized to access the external service page is the first terminal; and sending a first response message indicating successful user authentication to the third-party server. Thus, when a user accesses an external service page provided by a third-party server through a 5G messaging system, the introduction of a terminal SIM card verification process enables user authentication without manual intervention, improving user efficiency. Furthermore, it prevents users without SIM cards from accessing the user's account information, thereby ensuring the security of user business data.
[0139] like Figure 2 The diagram shown is a flowchart illustrating an information transmission method provided in an embodiment of the present invention. This method is applied to a terminal, which is a first terminal. The method may include:
[0140] Step 201: Through the first user identity recognition module SIM card of the first terminal, receive the second request message sent by the network side device after receiving the first request message sent by the third-party server. The first request message is used to request user identity authentication of the target terminal attempting to access an external service page. The external service page is a page provided to the first terminal by the third-party server. The second request message is used to request the first terminal to confirm whether to allow access to the external service page.
[0141] Here, the network-side device in this embodiment of the invention can be a server in a 5G messaging system, which has open identity authentication capabilities.
[0142] It should be noted that the first SIM card of the first terminal receives the second request message sent by the network-side device, the purpose of which is to inform the first terminal that the first terminal is attempting to access an external service page.
[0143] If it is indeed the first terminal attempting to access the external service page, then the first SIM card is triggered to use the SIM's authentication and authorization capabilities to automatically authenticate the user's identity, eliminating the need for cumbersome manual authentication steps. Specifically, a second response message is sent to the network-side device in response to the second request message. This second response message includes a reply message from the first terminal confirming that access to the external service page is permitted.
[0144] If the first terminal is not attempting to access the external service page itself, a second response message is sent to the network-side device in response to the second request message. This second response message includes a response message from the first terminal denying access to the external service page, thus ensuring the security of user service data.
[0145] Step 202: Send a second response message to the network-side device in response to the second request message, so that the network-side device determines the target terminal attempting to access the external service page as the first terminal if the second response message meets the first condition. The first condition is used to determine that the terminal that is confirmed to be allowed to access the external service page is the first terminal.
[0146] Here, the second reply message is the basis for the network-side device to perform user authentication. This step corresponds to the network-side device when the user authentication is successful.
[0147] If authentication fails, meaning the network-side device determines that the target terminal attempting to access the external service page is not the first terminal when the second reply message does not meet the first condition, then the target terminal cannot access the external service page, thus ensuring the security of user business data.
[0148] The information transmission method of this invention, through a first user identification module SIM card of a first terminal, receives a second request message sent by a network-side device after receiving a first request message from a third-party server. The first request message requests user authentication for a target terminal attempting to access an external service page, where the external service page is a page provided to the first terminal by the third-party server. The second request message requests the first terminal to confirm whether access to the external service page is permitted. A second response message is sent to the network-side device in response to the second request message, so that if the second response message meets a first condition, the network-side device determines that the target terminal attempting to access the external service page is the first terminal. The first condition is used to confirm that the terminal authorized to access the external service page is the first terminal. Thus, when a user accesses an external service page provided by a third-party server through a 5G messaging system, the introduction of a terminal SIM card verification process enables user authentication without manual operation, improving user efficiency. Furthermore, it prevents users without SIM cards from accessing the user's account information, thereby ensuring the security of user business data.
[0149] As an optional implementation, method step 201 of this embodiment of the invention may include:
[0150] The network-side device receives a second request message after receiving a first request message from a third-party server via data SMS. The second request message carries a first sequence number, which is generated based on the identification information of the first terminal and includes the application identifier corresponding to the third-party server.
[0151] In this step, the second request message carries the first sequence number. This is to enable the network-side device to determine that the network-side device initiated the second request message after receiving the second reply message in response to the second request message. This helps the network-side device distinguish which request messages were initiated by itself and which were not.
[0152] As an optional implementation, method step 202 of this embodiment of the invention, sending a second response message to the network-side device in response to the second request message, includes:
[0153] If the first terminal confirms permission to access the external service page based on the second request information, the card information of the first SIM card is extracted;
[0154] Here, based on the second request information, obtaining the reply message from the first terminal confirming permission to access the external service page may specifically include:
[0155] If the network-side device does not require user confirmation, it directly obtains the reply message from the first terminal confirming permission to access the external service page based on the second request information.
[0156] This method corresponds to Figure 1 The method shown is one of two ways to trigger the first SIM card to extract its own card information in the network-side device.
[0157] If the network-side device requires user confirmation, then according to the second request message, the first SIM card sends an active command (such as launch Browser, display text, etc.) to the first terminal, requesting the user to manually confirm whether to allow access to the external service page (i.e. whether to authorize login to the corresponding third-party server).
[0158] Then, by clicking the confirmation button in the system prompt box, the first SIM card receives a confirmation response from the user, that is, the first terminal confirms that access to the external service page is allowed.
[0159] This method corresponds to Figure 1 The method shown is the second of two ways to trigger the first SIM card to extract its own card information in the network-side device.
[0160] A second reply message is sent to the network-side device. The second reply message contains a reply message confirming that the first terminal is allowed to access the external service page and the card information of the first SIM card.
[0161] As an optional implementation, before sending a second reply message to the network-side device in response to the second request message, the method of this embodiment further includes:
[0162] The first serial number is encrypted using a symmetric encryption algorithm to obtain a second serial number, and the second reply message also includes the second serial number.
[0163] It should be noted that the purpose of encrypting the first sequence number using a symmetric encryption algorithm is to enable the network-side device to verify that the second request message corresponding to the second reply message was initiated by the network-side device itself.
[0164] As an optional implementation, the method in this embodiment of the invention may further include:
[0165] This displays the external service page pushed by the third-party server after confirming successful user authentication.
[0166] Here, if the third-party server determines that the user's identity authentication is successful, it means that the first terminal is allowed to access the external service page, and the external service page pushed by the third-party server is displayed on the screen of the first terminal.
[0167] The following is an example, with reference to Figure 3 The implementation process of the method of the present invention will be specifically described from the perspective of device interaction.
[0168] S1: The third-party server generates a unique serial number for the user number of the first terminal, and the serial number and the application identifier corresponding to the third-party server constitute the first serial number;
[0169] It should be noted that the third-party server will generate a unique serial number for each user number on each terminal, and then save the correspondence between the serial number and the user number.
[0170] S2: A third-party server sends a push message to the first terminal;
[0171] It should be noted that the third-party server will send push messages to each terminal; this example only uses the first terminal.
[0172] Here, the push message includes a link instructing the terminal to access an external service page (a page provided by an application on a third-party server), the link carrying a first serial number.
[0173] S3: The user clicks the link;
[0174] Here, it's uncertain whether the user is the primary user; they may or may not be. In other words, the target user attempting to access an external service page is not necessarily the primary user.
[0175] S4: Open this link in your browser;
[0176] In this step, the user clicks the link, opens the link (such as a third-party URL) through a browser, and sends an access request to the third-party server through the browser. This access request includes the link.
[0177] S5: The third-party server matches the user number of the corresponding first terminal based on the first serial number carried in the link.
[0178] It should be noted that the third-party server uses this first serial number to find the authorized user number for the link, which can be an MSISDN.
[0179] S6: The third-party server sends a user authentication request to the open authentication module, carrying the application identifier APP_ID corresponding to the third-party server, the first serial number SN, and the user number MSISDN of the first terminal, which are encrypted using the public key.
[0180] Here, the 5G messaging system includes the 5G messaging application on the terminal, the SIM card, and the network-side equipment, among which the open authentication module is a module in the network-side equipment.
[0181] It should be noted that the user authentication request is used to request user authentication for the target terminal attempting to access an external service page.
[0182] S7: The open authentication module sends a user confirmation request to the SIM card corresponding to the user number of the first terminal via push data SMS;
[0183] Here, the open authentication module decrypts the user authentication request using a private key to obtain the APP_ID, SN, and MSISDN. Then, after verifying that the third-party server has authentication access permissions using the APP_ID, it sends a user confirmation request to the SIM card corresponding to the MSISDN via push SMS.
[0184] It should be noted that the user confirmation request is used to request the first terminal to confirm whether access to the external service page is permitted.
[0185] Here, the user authentication request carries the first serial number (SN).
[0186] It should be noted that if the open authentication module requires user confirmation, then S8 to S10 (optional steps) should be executed before S11; if the open authentication module requires user confirmation, then S11 should be executed.
[0187] S8: The SIM card of the first terminal sends an active command to the first terminal;
[0188] Here, proactive commands can be things like "launch Browser" or "display text." Proactive commands are used to request the user to manually confirm whether to allow the first terminal to access external service pages, that is, to request the user to manually confirm whether to authorize login to the corresponding third-party server application.
[0189] S9: User confirmation;
[0190] Here, the user can click the confirmation button in the system prompt on the first terminal's screen. In other words, the user manually confirms that the first terminal is allowed to access the external service page.
[0191] S10: The SIM card of the first terminal receives the user confirmation response.
[0192] S11: The SIM card information of the first terminal is extracted, and the first serial number SN is encrypted using a symmetric encryption algorithm to obtain the second serial number SN. ’ ;
[0193] Here, the SIM card information of the first terminal can be the ICCID.
[0194] S12: The SIM card of the first terminal sends a user confirmation response to the open authentication module. This user confirmation response carries the ICCID and SN. ’ ;
[0195] S13: The open authentication module uses a symmetric encryption algorithm to authenticate the SN. ’ The SN is obtained by decryption, confirming that the user confirmation request corresponding to the user confirmation response was initiated by the open authentication module; then, the open authentication module obtains the user number corresponding to the SIM card of the first terminal based on the correspondence between card information and user number;
[0196] It should be noted that the correspondence between card information and user number can be pre-stored within the open authentication module or obtained externally.
[0197] Here, if the user number corresponding to the SIM card of the first terminal is the same as the user number of the first terminal, then the target terminal attempting to access the external service page via the link is the first terminal, indicating successful user authentication. If the user number corresponding to the SIM card of the first terminal is not the user number of the first terminal, then the target terminal attempting to access the external service page via the link is not the first terminal, indicating that user authentication has failed. In other words, the target terminal cannot open the external service page through a browser.
[0198] S14: The open authentication module sends a user authentication response to the third-party server;
[0199] If the user authentication response indicates that the user authentication was successful, then proceed with the next steps.
[0200] S15: The third-party server determines that the user's identity authentication was successful based on the user authentication response;
[0201] S16: The third-party server returns the external service page after login to the first terminal.
[0202] In other words, the external service page after logging in is displayed on the first terminal.
[0203] like Figure 4 As shown, this embodiment of the invention also provides a user authentication device, which includes:
[0204] The first receiving module 401 is configured to receive a first request message sent by a third-party server. The first request message is used to request user authentication for a target terminal attempting to access an external service page. The external service page is a page provided by the third-party server to the first terminal.
[0205] The first sending module 402 is used to send a second request message to the first user identity recognition module SIM card of the first terminal. The second request message is used to request the first terminal to confirm whether to allow access to the external service page.
[0206] The identity authentication module 403 is used to determine that the target terminal attempting to access the external service page is the first terminal when it receives a second reply message sent by the first SIM card of the first terminal in response to the second request message, and the second reply message satisfies a first condition. The first condition is used to determine that the terminal that is confirmed to be allowed to access the external service page is the first terminal.
[0207] The second sending module 404 is used to send a first reply message indicating successful user authentication to the third-party server.
[0208] Optionally, the first condition is:
[0209] The second reply message includes a reply message from the first terminal confirming permission to access the external service page and the card information of the first SIM card. The identification information of the terminal corresponding to the card information of the first SIM card is the identification information of the first terminal. The identification information of the terminal corresponding to the card information of the first SIM card is determined based on the pre-stored correspondence between the card information of the SIM card and the identification information of the terminal.
[0210] Optionally, the first request message includes the application identifier of the third-party server, the first serial number, and the identifier information of the first terminal, which are encrypted using a public key by the third-party server. The first serial number is generated based on the identifier information of the first terminal and includes the application identifier of the third-party server.
[0211] Optionally, the first transmitting module 402 may include:
[0212] The decryption unit is used to decrypt the first request message using a private key to obtain the application identifier, the first serial number, and the identifier information of the first terminal corresponding to the third-party server.
[0213] The first sending unit is configured to send a second request message to the first SIM card of the first terminal via data SMS, based on the identification information of the first terminal, wherein the second request message carries the first serial number.
[0214] Optionally, the apparatus in embodiments of the present invention may further include:
[0215] The first processing module is used to determine whether the third-party server has authentication access permissions based on the application identifier corresponding to the third-party server.
[0216] Optionally, the second reply message may also include a second serial number, which is the serial number obtained by encrypting the first serial number using a symmetric encryption algorithm on the first SIM card.
[0217] Optionally, the apparatus in embodiments of the present invention may further include:
[0218] The decryption module is used to decrypt the second serial number using a symmetric encryption algorithm to obtain the first serial number;
[0219] The second processing module is used to determine, based on the first sequence number, that the second request message is a request initiated by a network-side device.
[0220] It should be noted that this user authentication device can correspond to the above. Figure 3 The open authentication module in the illustrated embodiment.
[0221] The user authentication device of this invention receives a first request message from a third-party server, which requests user authentication for a target terminal attempting to access an external service page, wherein the external service page is a page provided by the third-party server to the first terminal; sends a second request message to the first user identification module SIM card of the first terminal, which requests the first terminal to confirm whether access to the external service page is permitted; upon receiving a second reply message from the first SIM card of the first terminal in response to the second request message, and provided that the second reply message satisfies a first condition, determines that the target terminal attempting to access the external service page is the first terminal, wherein the first condition is used to determine that the terminal confirming permission to access the external service page is the first terminal; and sends a first reply message indicating successful user authentication to the third-party server. Thus, when a user accesses an external service page provided by a third-party server through a 5G messaging system, the introduction of a terminal SIM card verification process enables user authentication to be performed without manual operation, improving user efficiency. Furthermore, it prevents users without SIM cards from accessing the user's account information, thereby ensuring the security of user business data.
[0222] To better achieve the above objectives, such as Figure 5 As shown, this embodiment of the invention also provides a network-side device, including a processor 500 and a transceiver 510, wherein the processor is used to perform the following process:
[0223] The system receives a first request message sent by a third-party server. The first request message is used to request user authentication for the target terminal attempting to access an external service page. The external service page is a page provided to the first terminal by the third-party server.
[0224] A second request message is sent to the first user identity recognition module SIM card of the first terminal. The second request message is used to request the first terminal to confirm whether to allow access to the external service page.
[0225] If a second reply message is received from the first SIM card of the first terminal in response to the second request message, and the second reply message satisfies the first condition, the target terminal attempting to access the external service page is determined to be the first terminal. The first condition is used to determine that the terminal that is confirmed to allow access to the external service page is the first terminal.
[0226] Send a first reply message indicating successful user authentication to the third-party server.
[0227] Optionally, the first condition is:
[0228] The second reply message includes a reply message from the first terminal confirming permission to access the external service page and the card information of the first SIM card. The identification information of the terminal corresponding to the card information of the first SIM card is the identification information of the first terminal. The identification information of the terminal corresponding to the card information of the first SIM card is determined based on the pre-stored correspondence between the card information of the SIM card and the identification information of the terminal.
[0229] Optionally, the first request message includes the application identifier of the third-party server, the first serial number, and the identifier information of the first terminal, which are encrypted using a public key by the third-party server. The first serial number is generated based on the identifier information of the first terminal and includes the application identifier of the third-party server.
[0230] Optionally, the transceiver 510 is further configured to:
[0231] The first request message is decrypted using a private key to obtain the application identifier, the first serial number, and the identifier information of the first terminal corresponding to the third-party server.
[0232] Based on the identification information of the first terminal, a second request message is sent to the first SIM card of the first terminal via data SMS. The second request message carries the first serial number.
[0233] Optionally, the processor 500 is further configured to perform the following process:
[0234] Based on the application identifier corresponding to the third-party server, it is determined that the third-party server has authentication access permissions.
[0235] Optionally, the second reply message may also include a second serial number, which is the serial number obtained by encrypting the first serial number using a symmetric encryption algorithm on the first SIM card.
[0236] Optionally, the processor 500 is further configured to perform the following process:
[0237] The second serial number is decrypted using a symmetric encryption algorithm to obtain the first serial number;
[0238] Based on the first sequence number, it is determined that the second request message is a request initiated by a network-side device.
[0239] The network-side device of this invention receives a first request message from a third-party server, which requests user authentication for a target terminal attempting to access an external service page, wherein the external service page is a page provided to the first terminal by the third-party server; sends a second request message to the first user identification module SIM card of the first terminal, which requests the first terminal to confirm whether access to the external service page is permitted; upon receiving a second reply message from the first SIM card of the first terminal in response to the second request message, and provided that the second reply message satisfies a first condition, determines that the target terminal attempting to access the external service page is the first terminal, wherein the first condition is used to determine that the terminal confirming permission to access the external service page is the first terminal; and sends a first reply message indicating successful user authentication to the third-party server. Thus, when a user accesses an external service page provided by a third-party server through a 5G messaging system, the introduction of a terminal SIM card verification process enables user authentication to be performed without manual operation, improving user efficiency. Furthermore, it prevents users without SIM cards from accessing the user's account information, thereby ensuring the security of user business data.
[0240] This invention also provides a network-side device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the various processes in the user authentication method embodiments described above and achieves the same technical effect. To avoid repetition, these will not be repeated here.
[0241] This invention also provides a computer-readable storage medium storing a computer program. When executed by a processor, this program implements the various processes described in the user authentication method embodiments above, achieving the same technical effects. To avoid repetition, it will not be described again here. The computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0242] like Figure 6 As shown, this embodiment of the invention also provides an information transmission device, which includes:
[0243] The second receiving module 601 is configured to enable the first user identity recognition module SIM card of the first terminal to receive a second request message sent by the network-side device after receiving a first request message sent by a third-party server. The first request message is used to request user identity authentication for the target terminal attempting to access an external service page, where the external service page is a page provided to the first terminal by the third-party server. The second request message is used to request the first terminal to confirm whether to allow access to the external service page.
[0244] The third sending module 602 is used to send a second reply message to the network-side device in response to the second request message, so that the network-side device determines the target terminal attempting to access the external service page as the first terminal when the second reply message meets a first condition, wherein the first condition is used to determine that the terminal that confirms permission to access the external service page is the first terminal.
[0245] Optionally, the second receiving module 601 may include:
[0246] The first receiving unit is configured to receive, via data SMS, a second request message sent by the network-side device after receiving a first request message sent by a third-party server. The second request message carries a first sequence number, which is generated based on the identification information of the first terminal and includes the application identifier corresponding to the third-party server.
[0247] Optionally, the third sending module 602 may include:
[0248] The information extraction unit is used to extract the card information of the first SIM card when the first terminal confirms permission to access the external service page based on the second request information.
[0249] The second sending unit is used to send a second reply message to the network-side device. The second reply message contains a reply message confirming that the first terminal has permission to access the external service page and card information of the first SIM card.
[0250] Optionally, the apparatus in this embodiment of the invention further includes:
[0251] An encryption module is used to encrypt the first serial number using a symmetric encryption algorithm to obtain a second serial number, and the second reply message also includes the second serial number.
[0252] Optionally, the apparatus in this embodiment of the invention further includes:
[0253] The display module is used to display the external service page pushed by the third-party server after confirming that the user's identity authentication is successful.
[0254] The information transmission device of this invention receives a second request message from a network-side device after receiving a first request message from a third-party server, via a first user identification module SIM card of a first terminal. The first request message requests user authentication for a target terminal attempting to access an external service page, where the external service page is a page provided to the first terminal by the third-party server. The second request message requests the first terminal to confirm whether access to the external service page is permitted. A second response message is sent to the network-side device in response to the second request message, so that the network-side device determines the target terminal attempting to access the external service page as the first terminal if the second response message meets a first condition. The first condition determines that the terminal authorized to access the external service page is the first terminal. Thus, when a user accesses an external service page provided by a third-party server through a 5G messaging system, the introduction of a terminal SIM card verification process eliminates manual operation for user authentication, improving user efficiency. Furthermore, it prevents users without SIM cards from accessing the user's account information, thereby ensuring the security of user business data.
[0255] To better achieve the above objectives, such as Figure 7 As shown, this embodiment of the invention also provides a terminal, which is a first terminal, including a processor 700 and a transceiver 710. The terminal also includes a user interface 720, and the transceiver is used to perform the following process:
[0256] The first user identity recognition module SIM card of the first terminal receives a second request message sent by the network-side device after receiving a first request message sent by a third-party server. The first request message is used to request user identity authentication for the target terminal attempting to access an external service page, where the external service page is a page provided to the first terminal by the third-party server. The second request message is used to request the first terminal to confirm whether to allow access to the external service page.
[0257] A second response message is sent to the network-side device in response to the second request message, so that the network-side device determines that the target terminal attempting to access the external service page is the first terminal if the second response message meets a first condition, wherein the first condition is used to determine that the terminal that is confirmed to be allowed to access the external service page is the first terminal.
[0258] Optionally, the transceiver 710 is configured to perform the following process:
[0259] The network-side device receives a second request message after receiving a first request message from a third-party server via data SMS. The second request message carries a first sequence number, which is generated based on the identification information of the first terminal and includes the application identifier corresponding to the third-party server.
[0260] Optionally, the transceiver 710 is configured to perform the following process:
[0261] If the first terminal confirms permission to access the external service page based on the second request information, the card information of the first SIM card is extracted;
[0262] A second reply message is sent to the network-side device. The second reply message contains a reply message confirming that the first terminal is allowed to access the external service page and the card information of the first SIM card.
[0263] Optionally, the processor 700 is further configured to:
[0264] The first serial number is encrypted using a symmetric encryption algorithm to obtain a second serial number, and the second reply message also includes the second serial number.
[0265] Optionally, the processor 700 is further configured to:
[0266] The external service page pushed by the third-party server after successful user authentication is displayed through user interface 720.
[0267] In this embodiment of the invention, the terminal receives a second request message from a network-side device after receiving a first request message from a third-party server, via a first user identification module SIM card of the first terminal. The first request message requests user authentication for the target terminal attempting to access an external service page, where the external service page is a page provided to the first terminal by the third-party server. The second request message requests the first terminal to confirm whether access to the external service page is permitted. The terminal then sends a second response message to the network-side device in response to the second request message. If the second response message satisfies a first condition, the network-side device determines that the target terminal attempting to access the external service page is the first terminal. The first condition determines that the terminal authorized to access the external service page is the first terminal. Thus, when a user accesses an external service page provided by a third-party server through a 5G messaging system, the introduction of a terminal SIM card verification process eliminates the need for manual user authentication, improving user efficiency. Furthermore, it prevents users without SIM cards from accessing the user's account information, thereby ensuring the security of user business data.
[0268] This invention also provides a terminal, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the various processes in the information transmission method embodiments described above and achieves the same technical effect. To avoid repetition, these will not be repeated here.
[0269] This invention also provides a computer-readable storage medium storing a computer program. When executed by a processor, this program implements the various processes described in the information transmission method embodiments above, achieving the same technical effects. To avoid repetition, it will not be described again here. The computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc.
[0270] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-readable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0271] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 A device for one or more processes and / or the functions specified in one or more boxes.
[0272] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce a paper article including an instruction means, the instruction means being implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0273] These computer program instructions can also be loaded onto a computer or other programmable data processing equipment, causing the computer or other programmable equipment to perform a series of operational steps to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0274] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A user authentication method, applied to network-side devices, characterized in that, include: The system receives a first request message sent by a third-party server. The first request message is used to request user authentication for a target terminal attempting to access an external service page. The external service page is a page provided to the first terminal by the third-party server. The first request message includes an application identifier corresponding to the third-party server, a first serial number, and the identifier information of the first terminal, all encrypted by the third-party server using a public key. The first serial number is generated based on the identifier information of the first terminal and includes the application identifier corresponding to the third-party server. A second request message is sent to the first user identity recognition module SIM card of the first terminal. The second request message is used to request the first terminal to confirm whether to allow access to the external service page. If a second reply message is received from the first SIM card of the first terminal in response to the second request message, and the second reply message satisfies the first condition, the target terminal attempting to access the external service page is determined to be the first terminal. The first condition is used to determine that the terminal that is confirmed to allow access to the external service page is the first terminal. Send a first reply message indicating successful user authentication to the third-party server; The first condition is: The second reply message includes a reply message from the first terminal confirming permission to access the external service page and the card information of the first SIM card, and the identification information of the terminal corresponding to the card information of the first SIM card is the identification information of the first terminal. The identification information of the terminal corresponding to the card information of the first SIM card is determined based on the pre-stored correspondence between the card information of the SIM card and the identification information of the terminal. Send a second request message to the first user identification module SIM card of the first terminal, including: Based on the identification information of the first terminal, a second request message is sent to the first SIM card of the first terminal via data SMS, the second request message carrying a first serial number; The second reply message also includes a second serial number, which is the serial number obtained by encrypting the first serial number using a symmetric encryption algorithm on the first SIM card; After receiving a second reply message from the first SIM card of the first terminal in response to the second request message, the method further includes: The second serial number is decrypted using a symmetric encryption algorithm to obtain the first serial number; Based on the first sequence number, it is determined that the second request message is a request initiated by a network-side device.
2. The method of claim 1, wherein, Before sending the second request message to the first user identity recognition module SIM card of the first terminal, the method further includes: The first request message is decrypted using a private key to obtain the application identifier, the first serial number, and the identifier information of the first terminal corresponding to the third-party server.
3. The method according to claim 1, characterized in that, Before sending a second request message to the first SIM card of the first terminal via data SMS based on the identification information of the first terminal, the method further includes: Based on the application identifier corresponding to the third-party server, it is determined that the third-party server has authentication access permissions.
4. An information transmission method applied to a terminal, wherein the terminal is a first terminal, characterized in that, include: The first terminal receives a second request message from the network-side device after receiving a first request message from a third-party server via its first user identity recognition module SIM card. The first request message requests user authentication for the target terminal attempting to access an external service page, where the external service page is a page provided to the first terminal by the third-party server. The second request message requests the first terminal to confirm whether access to the external service page is permitted. The first request message includes an application identifier corresponding to the third-party server, a first serial number, and the identification information of the first terminal, all encrypted using a public key by the third-party server. The second request message carries a first serial number, which is generated based on the identification information of the first terminal and includes the application identifier corresponding to the third-party server. A second response message is sent to the network-side device in response to the second request message, so that the network-side device determines, if the second response message meets a first condition, that the target terminal attempting to access the external service page is the first terminal. The first condition is used to determine that the terminal authorized to access the external service page is the first terminal. The first condition is: The second reply message includes a reply message from the first terminal confirming permission to access the external service page and the card information of the first SIM card, and the identification information of the terminal corresponding to the card information of the first SIM card is the identification information of the first terminal. The identification information of the terminal corresponding to the card information of the first SIM card is determined based on the pre-stored correspondence between the card information of the SIM card and the identification information of the terminal. Before sending a second response message to the network-side device in response to the second request message, the method further includes: The first serial number is encrypted using a symmetric encryption algorithm to obtain a second serial number, and the second reply message also includes the second serial number.
5. The method according to claim 4, characterized in that, The first user identification module SIM card receiving network-side device of the first terminal, after receiving the first request message sent by the third-party server, sends a second request message, including: The network device receives a second request message after receiving a first request message from a third-party server via data SMS.
6. The method according to claim 4, characterized in that, Sending a second response message to the network-side device in response to the second request message, including: If the first terminal confirms permission to access the external service page based on the second request message, the card information of the first SIM card is extracted; A second reply message is sent to the network-side device. The second reply message contains a reply message confirming that the first terminal is allowed to access the external service page and the card information of the first SIM card.
7. The method according to claim 5, characterized in that, The method further includes: This displays the external service page pushed by the third-party server after confirming successful user authentication.
8. A user authentication device, characterized in that, include: The first receiving module is configured to receive a first request message sent by a third-party server. The first request message is used to request user authentication for a target terminal attempting to access an external service page. The external service page is a page provided by the third-party server to the first terminal. The first request message includes an application identifier corresponding to the third-party server, a first serial number, and the identifier information of the first terminal, all encrypted by the third-party server using a public key. The first serial number is generated based on the identifier information of the first terminal and includes the application identifier corresponding to the third-party server. The first sending module is used to send a second request message to the first user identity recognition module SIM card of the first terminal. The second request message is used to request the first terminal to confirm whether to allow access to the external service page. The identity authentication module is configured to, upon receiving a second response message from the first SIM card of the first terminal in response to the second request message, and provided that the second response message satisfies a first condition, determine that the target terminal attempting to access the external service page is the first terminal. The first condition is used to confirm that the terminal authorized to access the external service page is the first terminal. The first condition is: The second reply message includes a reply message from the first terminal confirming permission to access the external service page and the card information of the first SIM card, and the identification information of the terminal corresponding to the card information of the first SIM card is the identification information of the first terminal. The identification information of the terminal corresponding to the card information of the first SIM card is determined based on the pre-stored correspondence between the card information of the SIM card and the identification information of the terminal. The second sending module is used to send a first reply message indicating successful user authentication to the third-party server; The first sending module includes: a first sending unit, configured to send a second request message to a first SIM card of the first terminal via data SMS based on the identification information of the first terminal, wherein the second request message carries a first serial number; The second reply message also includes a second serial number, which is the serial number obtained by encrypting the first serial number using a symmetric encryption algorithm on the first SIM card; The device further includes: The decryption module is used to decrypt the second serial number using a symmetric encryption algorithm to obtain the first serial number; The second processing module is used to determine, based on the first sequence number, that the second request message is a request initiated by a network-side device.
9. A network-side device, comprising a processor and a transceiver, wherein the transceiver receives and transmits data under the control of the processor, characterized in that, The processor is used to perform the following operations: The system receives a first request message sent by a third-party server. The first request message is used to request user authentication for a target terminal attempting to access an external service page. The external service page is a page provided to the first terminal by the third-party server. The first request message includes an application identifier corresponding to the third-party server, a first serial number, and the identifier information of the first terminal, all encrypted by the third-party server using a public key. The first serial number is generated based on the identifier information of the first terminal and includes the application identifier corresponding to the third-party server. A second request message is sent to the first user identity recognition module SIM card of the first terminal. The second request message is used to request the first terminal to confirm whether to allow access to the external service page. Upon receiving a second response message from the first SIM card of the first terminal in response to the second request message, and if the second response message satisfies a first condition, the target terminal attempting to access the external service page is determined to be the first terminal. The first condition is used to determine that the terminal authorized to access the external service page is the first terminal. The first condition is: The second reply message includes a reply message from the first terminal confirming permission to access the external service page and the card information of the first SIM card, and the identification information of the terminal corresponding to the card information of the first SIM card is the identification information of the first terminal. The identification information of the terminal corresponding to the card information of the first SIM card is determined based on the pre-stored correspondence between the card information of the SIM card and the identification information of the terminal. Send a first reply message indicating successful user authentication to the third-party server; The first condition is: The second reply message includes a reply message from the first terminal confirming permission to access the external service page and the card information of the first SIM card, and the identification information of the terminal corresponding to the card information of the first SIM card is the identification information of the first terminal. The identification information of the terminal corresponding to the card information of the first SIM card is determined based on the pre-stored correspondence between the card information of the SIM card and the identification information of the terminal. The transceiver is also used for: Based on the identification information of the first terminal, a second request message is sent to the first SIM card of the first terminal via data SMS, the second request message carrying a first serial number; The second reply message also includes a second serial number, which is the serial number obtained by encrypting the first serial number using a symmetric encryption algorithm on the first SIM card; The processor is also used to perform the following processes: The second serial number is decrypted using a symmetric encryption algorithm to obtain the first serial number; Based on the first sequence number, it is determined that the second request message is a request initiated by a network-side device.
10. The network-side device according to claim 9, characterized in that, The transceiver is also used for: The first request message is decrypted using a private key to obtain the application identifier, the first serial number, and the identifier information of the first terminal corresponding to the third-party server.
11. The network-side device according to claim 9, characterized in that, The processor is also used to perform the following processes: Based on the application identifier corresponding to the third-party server, it is determined that the third-party server has authentication access permissions.
12. A network-side device, comprising a memory, a processor, and a program stored in the memory and executable on the processor; characterized in that, When the processor executes the program, it implements the user authentication method as described in any one of claims 1 to 3.
13. An information transmission device, characterized in that, include: The second receiving module is configured to enable the first user identification module SIM card of the first terminal to receive a second request message sent by the network-side device after receiving a first request message sent by a third-party server. The first request message requests user authentication for the target terminal attempting to access an external service page, where the external service page is a page provided to the first terminal by the third-party server. The second request message requests the first terminal to confirm whether access to the external service page is permitted. The first request message includes an application identifier corresponding to the third-party server, a first serial number, and the identification information of the first terminal, all encrypted using a public key by the third-party server. The second request message carries a first serial number, which is generated based on the identification information of the first terminal and includes the application identifier corresponding to the third-party server. The third sending module is configured to send a second reply message to the network-side device in response to the second request message, so that the network-side device, upon the second reply message satisfying a first condition, determines that the target terminal attempting to access the external service page is the first terminal. The first condition is used to determine that the terminal authorized to access the external service page is the first terminal. The first condition is: The second reply message includes a reply message from the first terminal confirming permission to access the external service page and the card information of the first SIM card, and the identification information of the terminal corresponding to the card information of the first SIM card is the identification information of the first terminal. The identification information of the terminal corresponding to the card information of the first SIM card is determined based on the pre-stored correspondence between the card information of the SIM card and the identification information of the terminal. The device further includes: An encryption module is used to encrypt the first serial number using a symmetric encryption algorithm to obtain a second serial number, and the second reply message also includes the second serial number.
14. A terminal, said terminal being a first terminal, comprising a processor and a transceiver, said transceiver receiving and transmitting data under the control of the processor, characterized in that, The transceiver is used to perform the following process: The first user identification module SIM card of the first terminal receives a second request message sent by the network-side device after receiving a first request message from a third-party server. The first request message requests user authentication for the target terminal attempting to access an external service page, where the external service page is a page provided to the first terminal by the third-party server. The second request message requests the first terminal to confirm whether access to the external service page is permitted. The first request message includes an application identifier corresponding to the third-party server, a first serial number, and the identification information of the first terminal, all encrypted using a public key by the third-party server. The second request message carries the first serial number, which is generated based on the identification information of the first terminal and includes the application identifier corresponding to the third-party server. A second response message is sent to the network-side device in response to the second request message, so that the network-side device determines, if the second response message meets a first condition, that the target terminal attempting to access the external service page is the first terminal. The first condition is used to determine that the terminal authorized to access the external service page is the first terminal. The first condition is: The second reply message includes a reply message from the first terminal confirming permission to access the external service page and the card information of the first SIM card, and the identification information of the terminal corresponding to the card information of the first SIM card is the identification information of the first terminal. The identification information of the terminal corresponding to the card information of the first SIM card is determined based on the pre-stored correspondence between the card information of the SIM card and the identification information of the terminal. The processor is also used for: The first serial number is encrypted using a symmetric encryption algorithm to obtain a second serial number, and the second reply message also includes the second serial number.
15. The terminal according to claim 14, characterized in that, The transceiver is used to perform the following process: The network device receives a second request message after receiving a first request message from a third-party server via data SMS.
16. The terminal according to claim 14, characterized in that, The transceiver is used to perform the following process: If the first terminal confirms permission to access the external service page based on the second request message, the card information of the first SIM card is extracted; A second response message is sent to the network-side device. The second response message includes a response message from the first terminal confirming permission to access the external service page and the card information of the first SIM card.
17. The terminal according to claim 15, characterized in that, The processor is also used for: This displays the external service page pushed by the third-party server after confirming successful user authentication.
18. A terminal, comprising a memory, a processor, and a program stored in the memory and executable on the processor; characterized in that, When the processor executes the program, it implements the information transmission method as described in any one of claims 4 to 7.
19. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the program implements the steps of the user authentication method as described in any one of claims 1 to 3, or the steps of the information transmission method as described in any one of claims 4 to 7.
Citation Information
Patent Citations
Identity authentication method and authentication server
CN106130971A