A short message processing method, device and equipment and readable storage medium

By verifying the APP through PP-DOWNLOAD type SMS received on the terminal, it can determine whether there are known vulnerabilities or whether the SIM card is on the whitelist, thus solving the problem of SIM card vulnerability and achieving effective protection of information security.

CN115866606BActive Publication Date: 2026-03-27XI AN FIBOCOM WIRELESS SOFTWARE INC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-25
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

In existing technologies, SIM cards are vulnerable to attacks, especially by taking over devices and leaking user information through specific text messages. Furthermore, operators' interception measures are not timely or have omissions, resulting in information security not being effectively guaranteed.

Method used

After receiving a PP-DOWNLOAD type SMS message on the terminal, the security policy is verified by the verification APP to determine whether there are any known vulnerabilities or whether the message is on the whitelist. If it passes the verification, the message is sent to the SIM card; otherwise, the SMS message is discarded.

Benefits of technology

Effectively prevent SIM card attacks and ensure information security by improving the terminal's security protection capabilities for SIM cards through real-time updates to the vulnerability database and whitelist mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115866606B_ABST
    Figure CN115866606B_ABST
Patent Text Reader

Abstract

The application discloses a short message processing method, device and equipment and a readable storage medium. The method comprises the following steps: receiving and buffering a target short message of a PP-DOWNLOAD type; reporting the target short message to a verification APP of an upper layer; verifying the target short message based on a current security strategy configured by the verification APP; if the verification is passed, sending the target short message to a SIM card; and if the verification is not passed, discarding the target short message. For the target short message of the PP-DOWNLOAD type, the verification is performed in the verification APP based on the current security strategy configured, and the target short message is sent to the SIM card only when it is determined that the verification is passed, and the target short message is discarded if the verification is not passed, so that the short message cannot reach the SIM card, and thus, the SIM card can be prevented from being attacked.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of security assurance, in particular to a short message processing method and device, equipment and readable storage medium. BACKGROUND

[0002] In the intelligent SIM (Subscriber Identification Module) card, an application program STK (SIM Application Toolkit) also runs. The STK is fixed in the SIM card and contains a series of interactive instructions of the mobile phone and the SIM card. At present, the security protection of the operating system is generally concerned while the security protection of the SIM card is ignored. Hackers have targeted the application program in the SIM card and are looking for vulnerabilities to attack.

[0003] Attackers only need to send a specific short message to the target user's mobile phone number to take over the device and retrieve the positioning information, call records or short message records. During the attack, the user is completely unaware of being attacked and the information is leaked. Since it does not depend on the mobile phone system but is built into the SIM card, Internet devices with SIM cards can be attacked, and after being invaded, no traces are left.

[0004] For this type of attack means, mainly rely on the operator to configure filtering measures to intercept those illegal binary short message content. That is, the current preventive means depends on the interception deployed by the operator, and the interception deployed by the operator may not be timely or missed, and the interception deployed by the operator for the vulnerability may not be timely. Therefore, there will still be a situation of being attacked.

[0005] In summary, how to effectively solve the problem of SIM card attack and utilization is a technical problem that needs to be solved by the technical personnel in the field at present. SUMMARY

[0006] The purpose of the present application is to provide a short message processing method, device, equipment and readable storage medium, which can check the short message in the terminal, so that the short message with attack attribute cannot reach the SIM card, thereby protecting the user information security.

[0007] To solve the above technical problems, the present application provides the following technical solutions:

[0008] A short message processing method, comprising:

[0009] Receiving and caching a target short message of PP-DOWNLOAD type;

[0010] Reporting the target short message to a verification APP of an upper layer, and verifying the target short message based on a currently configured security policy by using the verification APP.

[0011] If the verification passes, the target short message is sent to the SIM card.

[0012] If the verification fails, the target short message is discarded.

[0013] Preferably, the target short message is verified by the verification APP based on a currently configured security policy, comprising:

[0014] It is determined by the verification APP whether the target short message corresponds to a known vulnerability.

[0015] If yes, it is determined that the verification fails.

[0016] If no, it is determined that the verification passes.

[0017] Preferably, determining whether the target short message corresponds to a known vulnerability comprises:

[0018] It is determined whether the target short message has code content corresponding to the known vulnerability.

[0019] If yes, it is determined that the target short message corresponds to the known vulnerability.

[0020] Preferably, it further comprises:

[0021] New vulnerability information is received.

[0022] The known vulnerability is updated by using the new vulnerability information.

[0023] Preferably, before the target short message is sent to the SIM card, it further comprises:

[0024] If the whitelist function is turned on, it is determined whether the sending number of the target short message is in the whitelist.

[0025] If yes, it is determined to execute the step of sending the target short message to the SIM card.

[0026] If no, the target short message is discarded.

[0027] Preferably, it further comprises:

[0028] Whitelist information is received.

[0029] The whitelist is updated by using the whitelist information.

[0030] Preferably, if the verification fails, the target short message is discarded, comprising:

[0031] If the verification fails, a discard reminder information is outputted, and a processing instruction is obtained.

[0032] if the processing instruction is discard, discarding the target short message;

[0033] if the processing instruction is keep, sending the target short message to the SIM card.

[0034] A short message processing device, comprising:

[0035] a short message cache module, configured to receive and cache a target short message of a PP-DOWNLOAD type;

[0036] a verification module, configured to report the target short message to a verification APP of an upper layer, and perform verification on the target short message based on a currently configured security policy by using the verification APP;

[0037] a short message sending module, configured to send the target short message to a SIM card if the verification passes;

[0038] a short message discarding module, configured to discard the target short message if the verification fails.

[0039] An electronic device, comprising:

[0040] a memory, configured to store a computer program;

[0041] a processor, configured to implement the steps of the short message processing method when executing the computer program.

[0042] A readable storage medium, having a computer program stored thereon, the computer program being executed by a processor to implement the steps of the short message processing method.

[0043] By using the method provided in the application, a target short message of a PP-DOWNLOAD type is received and cached, the target short message is reported to a verification APP of an upper layer, and verification is performed on the target short message based on a currently configured security policy by using the verification APP; if the verification passes, the target short message is sent to a SIM card; and if the verification fails, the target short message is discarded.

[0044] When a terminal with a SIM card receives a target short message of a PP-DOWNLOAD type, the target short message is first cached. Then, the target short message is reported to a verification APP of an upper layer, and verification is performed on the target short message based on a currently configured security policy by using the verification APP. After the verification passes, the target short message is sent to the SIM card, otherwise the target short message is discarded. That is, for a target short message of a PP-DOWNLOAD type, verification is performed in the verification APP based on a currently configured security policy, and only in the case where it is determined that the verification passes, the target short message is sent to the SIM card, and if the verification fails, the target short message is discarded, so that the short message cannot reach the SIM card, and thus the SIM card can be prevented from being attacked.

[0045] Correspondingly, the embodiment of the present application further provides a short message processing device, equipment and readable storage medium corresponding to the short message processing method, which have the above technical effects, and details are not described herein. BRIEF DESCRIPTION OF DRAWINGS

[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the drawings needed to be used in the embodiments or the related art description will be briefly introduced. Obviously, the drawings in the following description only some embodiments of the present application, and for those skilled in the art, other drawings can be obtained without creative labor on the basis of these drawings.

[0047] Figure 1 The flowchart of the short message processing method in the embodiment of the present application is shown in the figure.

[0048] Figure 2 The specific implementation schematic diagram of the short message processing method in the embodiment of the present application is shown in the figure.

[0049] Figure 3 The structure schematic diagram of the short message processing device in the embodiment of the present application is shown in the figure.

[0050] Figure 4 The structure schematic diagram of the electronic equipment in the embodiment of the present application is shown in the figure.

[0051] Figure 5 The specific structure schematic diagram of the electronic equipment in the embodiment of the present application is shown in the figure. DETAILED DESCRIPTION

[0052] In order to make the person in the art better understand the present application, the present application will be further described in detail below in combination with the drawings and specific embodiments. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0053] Please refer to Figure 1 , Figure 1 The flowchart of the short message processing method in the embodiment of the present application is shown in the figure, which can be applied to the terminal with SIM card, and the method comprises the following steps:

[0054] S101, receiving and buffering the target short message of PP-DOWNLOAD type.

[0055] After receiving the short message, the short message type of the short message can be determined first.

[0056] Short message is a kind of telecom service generated along with digital mobile communication system, which transmits short information in text or number through signaling channel and signaling network of mobile communication system.

[0057] When the terminal receives the short message, the target short message can be decoded to determine the short message type of the target short message.

[0058] In the present application, the target short message of PP-DOWNLOAD type is checked, and the processing is performed based on the checking result.

[0059] In one specific embodiment of the present application, the target short message is received, and the short message type of the target short message is determined, comprising:

[0060] Step one, receiving and decoding the target short message to obtain the short message format;

[0061] Step two, determining the short message type of the target short message by using the short message format.

[0062] For convenience of description, the above two steps will be described in combination.

[0063] When the target short message is received, it is first decoded to determine the short message format of the target short message. Different short message types correspond to different short message formats, so the short message type of the target short message can be determined based on the decoded short message format. For example, it is determined whether the target short message receiver corresponds to a SIM card.

[0064] If the short message type is PP-DOWNLOAD type, the short message is confirmed as the target short message. Then it is cached.

[0065] In the embodiment of the present application, the SIM is protected, so the target short message of PP-DOWNLOAD type, specifically the target short message of (U)SIM Data download type, is checked. Since the short message format is fixed and the attack code is specific, the SIM can be effectively protected according to the specific short message type and whether the known vulnerability is corresponding in the embodiment.

[0066] Among them, the short message of (U)SIM Data download type is different from the ordinary short message, and the target of this kind of short message is not sent to the user, but sent to the SIM card. It is a kind of data transmission based on short message, which transmits data to the SIM card transparently through envelop instruction. Among them, (U) means user terminal (terminal), and SIM Data download (SIM card data download).

[0067] If it is determined that the short message type is the SIM Datadownload type, it is indicated that the target short message may have an attack threat, and step S102 can be performed.

[0068] S102, report the target short message to a verification APP of an upper layer, and perform verification on the target short message based on a currently configured security policy by using the verification APP.

[0069] In the embodiments of the present application, a verification APP can be specially set to verify the target short message to determine whether the target short message has a threat.

[0070] Specifically, different security policies can be configured in the verification APP. After receiving and buffering the target short message, the target short message can be reported to the verification APP of the upper layer. After receiving the target short message, the verification APP can perform verification on the target short message based on the currently configured security policy.

[0071] In a specific embodiment of the present application, performing verification on the target short message based on the currently configured security policy by using the verification APP includes:

[0072] Step one, determining, by using the verification APP, whether the target short message corresponds to a known vulnerability;

[0073] Step two, if yes, determining that the verification fails;

[0074] Step three, if no, determining that the verification passes.

[0075] For ease of description, the above three steps are combined for description.

[0076] The known vulnerability can be specifically from a new SIM card security vulnerability published by a vulnerability publishing platform, and new vulnerability data can be pushed to a terminal by a server.

[0077] For example, the vulnerability is named Simjacker, and exists in an S@T (SIM alliance Toolbox Browser) browser of a SIM application tool kit (STK). The S@T is a bit browser, also known as a mobile browser, and is used for a mobile device, especially a mobile phone supporting a wireless application protocol (WAP).

[0078] The S@T browser allows a user to access network applications such as emails, stock prices, news, and the like by using an executable application stored in a SIM card. An attacker only needs to send a specific short message to a target user's mobile phone number to take over the device and retrieve positioning information, call records, or short message records.

[0079] Specifically, whether the target short message corresponds to the known vulnerability can be determined according to whether the format and content of the target short message are consistent with the characteristics of the known vulnerability.

[0080] In an embodiment of the present application, whether the target short message corresponds to the known vulnerability is determined by:

[0081] Step 1: determining whether the target short message has the code content corresponding to the known vulnerability;

[0082] Step 2: if yes, determining that the target short message corresponds to the known vulnerability.

[0083] For the convenience of description, the above two steps will be described together.

[0084] The target short message can be decoded to obtain the short message content, and then the obtained short message content is compared with the code content corresponding to the known vulnerability, so as to determine whether the target short message has the code content corresponding to the known vulnerability. If the target short message has the code content corresponding to the known vulnerability, it is determined that the target short message corresponds to the known vulnerability, otherwise, it is determined that the target short message does not correspond to the known vulnerability.

[0085] In an embodiment of the present application, the known vulnerability can also be updated, and the specific updating method includes:

[0086] Step 1: receiving new vulnerability information;

[0087] Step 2: updating the known vulnerability by using the new vulnerability information.

[0088] That is, the known vulnerability can be updated by receiving new vulnerability information, so that the new known vulnerability can be protected.

[0089] After determining whether the target short message corresponds to the known vulnerability, it can be determined whether the verification is passed.

[0090] After obtaining the verification result, the subsequent steps can be determined according to different results. Specifically, if the verification is passed, step S103 is executed, and if the verification is not passed, step S104 is executed.

[0091] S103: sending the target short message to the SIM card.

[0092] After it is determined that the target short message passes the verification, it means that the target short message does not exist threat, and thus the target short message can be sent to the SIM card.

[0093] In one specific embodiment of the present application, the short message sent to the SIM card can also be effectively screened. Specifically, before sending the target short message to the SIM card, the following steps are also performed:

[0094] Step one, if the whitelist function is turned on, determine whether the sending number of the target short message is in the whitelist;

[0095] Step two, if yes, determine to perform the step of sending the target short message to the SIM card;

[0096] Step three, if no, discard the target short message.

[0097] For ease of description, the above three steps will be described in combination.

[0098] First, it is determined whether the whitelist function is turned on. If yes, it is further determined whether the sending number of the target short message is in the whitelist. If yes, it is determined to send the target short message to the SIM card; otherwise, the target short message will also be discarded. Of course, for the case where the whitelist function is not turned on, the target short message can be directly sent to the SIM card after it is determined that the target short message is not a threat.

[0099] The whitelist can be manually added by the user, can be published by the operator, or can be collected by the present network test.

[0100] In one specific embodiment of the present application, the whitelist can also be updated, and the specific process includes:

[0101] Step one, receive the whitelist information;

[0102] Step two, update the whitelist using the whitelist information.

[0103] The whitelist information can be specifically input by the user or sent by a server or the like. After obtaining the whitelist information, the whitelist can be updated in the form of addition, deletion, or modification based on the whitelist information.

[0104] S104, discard the target short message.

[0105] After it is determined that the target short message belongs to a known vulnerability, it is indicated that the target short message can be a threat. At this time, the target short message can be directly discarded. In this way, the target short message cannot reach the SIM card, and the SIM card will not be attacked.

[0106] In one specific embodiment of the present application, if the verification fails, the target short message is discarded, including:

[0107] Step one, if the verification fails, output a discard reminder information and obtain a processing instruction;

[0108] Step two, if the processing instruction is discard, discard the target short message;

[0109] Step three, if the processing instruction is keep, send the target short message to the SIM card.

[0110] For the convenience of description, the above three steps are combined for description.

[0111] When it is determined that the target short message is threatening, in order to avoid false deletion, a discard reminder information can be outputted, so as to prompt the user that the target short message received currently can be threatening, and receive the processor instruction fed back by the user. For example, the user does not respond in time, which can be set as discard or keep (which can be set or adjusted according to specific requirements); if the user selects discard, it is determined that the processing instruction is discard, and if the user selects keep, it is determined that the processing instruction is keep. After obtaining the processing instruction, the target short message is processed based on the specific processing instruction, so as to avoid directly discarding the target short message and affecting the normal use of the user.

[0112] By applying the method provided in the embodiment of the application, the target short message of the PP-DOWNLOAD type is received and cached; the target short message is reported to the verification APP of the upper layer, and the verification APP is used to verify the target short message based on the currently configured security policy; if the verification passes, the target short message is sent to the SIM card; if the verification fails, the target short message is discarded.

[0113] When the terminal with the SIM card receives the target short message of the PP-DOWNLOAD type, the target short message is first cached. Then, the target short message is reported to the verification APP of the upper layer, and the verification APP is used to verify the target short message based on the currently configured security policy. After the verification passes, the target short message is sent to the SIM card, otherwise the target short message is discarded. That is, for the target short message of the PP-DOWNLOAD type, the verification is performed in the verification APP based on the currently configured security policy, and only in the case that it is determined that the verification passes, the target short message is sent to the SIM card, and if the verification fails, the target short message is discarded, so that the short message cannot reach the SIM card, and thus the SIM card can be protected from attack.

[0114] For the convenience of the person skilled in the art to better connect the short message processing method provided in the embodiment of the application, the short message processing method is described in detail below by taking specific scenarios as examples.

[0115] When the terminal receives a target short message of the PP-DOWNLOAD type, a modem buffers the short message, reports it to an upper-layer special APP, and then checks it based on a currently-configured security policy. If the short message passes the check, the modem releases it, and sends it to a SIM card. If the short message does not pass the check, the modem discards it, and notifies the APP to record the short message in the APP and notify a user of relevant interception information. If the user confirms that the short message is mis-intercepted, the short message can be sent to the SIM card again.

[0116] The security policy configured by the APP can be updated in a timely manner according to relevant vulnerability release platforms and announcements of security organizations. The security policy configured by the APP can also be preset with a security white list of legal PP-DOWNLOAD short message sending numbers of all operators in a current delivery country. Meanwhile, a switch for the security function is set.

[0117] The processing flow is described in detail in the following. Figure 2 , Figure 2 The following is a specific implementation schematic diagram of a short message processing method in the embodiment of the application.

[0118] Step 1: A modem receives a PP-DOWNLOAD short message, and judges whether a SIM card security protection function is currently turned on. If the function is turned off, the modem directly sends the short message to the SIM card. Otherwise, the process goes to Step 2.

[0119] Step 2: The modem reports the short message to an upper-layer APP (terminal).

[0120] Step 3: The APP checks the short message based on a currently-configured security policy.

[0121] Step 4: Whether the short message is a published vulnerability is checked based on a vulnerability code. If the short message is a published vulnerability, the process goes to Step 8. Otherwise, the process goes to Step 5.

[0122] Step 5: Whether a white list matching mechanism is turned on is checked. If the mechanism is turned on, the process goes to Step 6. Otherwise, the process goes to Step 7.

[0123] Step 6: Whether a sender of the short message is a legal short message sending number of an operator in a current country is checked. If the sender is a legal short message sending number, the process goes to Step 7. Otherwise, the process goes to Step 8.

[0124] Step 7: The modem is notified to release the PP-DOWNLOAD short message, and the process ends.

[0125] Step 8: The modem is notified to discard the PP-DOWNLOAD short message, and the APP is notified to record the short message in the APP and notify a user of relevant interception information.

[0126] Step 9: If the user confirms that the short message is mis-intercepted, the short message can be sent to the SIM card again, and the process goes to Step 7. Otherwise, the APP discards the short message.

[0127] Therefore, by applying the short message processing method provided in the embodiments of the present application, the security check of the short message of the (U)SIM Data download type can be deployed on the terminal side, and the security protection capability of the terminal against the vulnerability attack of the SIM card is improved. The system vulnerability library is updated in real time and online, the suspicious short message is intercepted in the first time, the white list protection mechanism is added, and the undiscovered vulnerability is prevented. The interception reminder is added, and the short message that is mistakenly intercepted can be manually recovered by the user.

[0128] Corresponding to the above method embodiments, the embodiments of the present application also provide a short message processing device. The short message processing device described below can be referred to in correspondence with the short message processing method described above.

[0129] Referring to Figure 3 The device includes the following modules:

[0130] The short message cache module 101 is configured to receive and cache the target short message of the PP-DOWNLOAD type.

[0131] The check module 102 is configured to report the target short message to the check APP of the upper layer, and check the target short message based on the current configured security policy by using the check APP.

[0132] The short message sending module 103 is configured to send the target short message to the SIM card if the check passes.

[0133] The short message discarding module 104 is configured to discard the target short message if the check fails.

[0134] By applying the device provided in the embodiments of the present application, the target short message of the PP-DOWNLOAD type is received and cached. The target short message is reported to the check APP of the upper layer, and the target short message is checked based on the current configured security policy by using the check APP. If the check passes, the target short message is sent to the SIM card. If the check fails, the target short message is discarded.

[0135] When the terminal with the SIM card receives the target short message of the PP-DOWNLOAD type, the target short message is first cached. Then, the target short message is reported to the check APP of the upper layer, and the target short message is checked based on the current configured security policy by using the check APP. After the check passes, the target short message is sent to the SIM card, otherwise the target short message is discarded. That is, for the target short message of the PP-DOWNLOAD type, the check is performed in the check APP based on the current configured security policy, and only in the case where it is determined that the check passes, the target short message is sent to the SIM card, and the target short message is discarded if the check fails, so that the short message cannot reach the SIM card, and thus the SIM card can be protected from attack.

[0136] In an embodiment of the present application, the checking module 102 is specifically configured to determine whether the target short message corresponds to a known vulnerability by using the checking APP.

[0137] If yes, it is determined that the checking fails.

[0138] If no, it is determined that the checking passes.

[0139] In an embodiment of the present application, the checking module 102 is specifically configured to determine whether the target short message has code content corresponding to a known vulnerability.

[0140] If yes, it is determined that the target short message corresponds to a known vulnerability.

[0141] In an embodiment of the present application, the application further comprises a vulnerability updating module configured to receive new vulnerability information.

[0142] The known vulnerability is updated by using the new vulnerability information.

[0143] In an embodiment of the present application, the application further comprises a screening module configured to, before the target short message is sent to the SIM card, if the whitelist function is turned on, determine whether the sending number of the target short message is in the whitelist.

[0144] If yes, it is determined to execute the step of sending the target short message to the SIM card.

[0145] If no, the target short message is discarded.

[0146] In an embodiment of the present application, the application further comprises a whitelist updating module configured to receive whitelist information.

[0147] The whitelist is updated by using the whitelist information.

[0148] In an embodiment of the present application, the short message discarding module 104 is specifically configured to, if the checking fails, output a discarding prompt information and acquire a processing instruction.

[0149] If the processing instruction is discarding, the target short message is discarded.

[0150] If the processing instruction is keeping, the target short message is sent to the SIM card.

[0151] Corresponding to the above method embodiment, the embodiments of the present application further provide an electronic device. The electronic device described below can be mutually referred to the short message processing method described above.

[0152] Referring to Figure 4 As shown in the figure, the electronic device comprises:

[0153] The memory 332 is configured to store a computer program.

[0154] The processor 322 is configured to execute the computer program and implement the steps of the short message processing method according to the above method embodiments.

[0155] Specifically, refer to Figure 5 A specific structural diagram of an electronic device according to the embodiment is provided, and the electronic device can have great differences due to different configurations or performances, and can include one or more processors (central processing units, CPU) 322 (for example, one or more processors) and a memory 332, and the memory 332 stores one or more computer programs 342 or data 344. The memory 332 can be temporary storage or persistent storage. The program stored in the memory 332 can include one or more modules (not shown in the figure), and each module can include a series of instruction operations in the data processing device. Further, the central processing unit 322 can be configured to communicate with the memory 332 and execute the series of instruction operations in the memory 332 on the electronic device 301.

[0156] The electronic device 301 can further include one or more power supplies 326, one or more wired or wireless network interfaces 350, one or more input / output interfaces 358, and / or one or more operating systems 341.

[0157] The steps of the short message processing method described above can be implemented by the structure of the electronic device.

[0158] According to the above method embodiments, the embodiment of the present application further provides a readable storage medium, and the readable storage medium described below can be correspondingly referred to the short message processing method described above.

[0159] A readable storage medium, and the readable storage medium stores a computer program, and the computer program is executed by the processor to implement the steps of the short message processing method according to the above method embodiments.

[0160] The readable storage medium can be a U disk, a mobile hard disk, a read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), a magnetic disk or an optical disk, and various readable storage media that can store program codes.

[0161] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware, computer software or a combination of both, and the general description of the components and steps of each example has been described above in order to clarify the interchangeability of hardware and software. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

Claims

1. A method for processing short messages, characterized by The application comprises the following steps: receiving and buffering a target short message of PP-DOWNLOAD type; wherein the type of the PP-DOWNLOAD short message is (U)SIM Data download, and the target short message is used to transmit data to the SIM card in a transparent manner through the envelop instruction based on the short message data transmission mode; reporting the target short message to a check APP in the upper layer, and checking the target short message based on the current security policy configured by the check APP; if the check is passed, sending the target short message to the SIM card; if the check is not passed, discarding the target short message, recording the target short message in the APP, notifying the user of the relevant interception information, and if the user confirms the false interception, sending the target short message to the SIM card; wherein the checking of the target short message based on the current security policy configured by the check APP comprises the following steps: using the check APP to determine whether the target short message corresponds to a known vulnerability; if yes, determining that the check is not passed; if no, determining that the check is passed; wherein the determination of whether the target short message corresponds to a known vulnerability comprises the following steps: determining whether the target short message has the code content corresponding to the known vulnerability; if yes, determining that the target short message corresponds to the known vulnerability; receiving new vulnerability information; updating the known vulnerability based on the new vulnerability information.

2. The short message processing method of claim 1, wherein, Before the target short message is sent to the SIM card, the following steps are further included: if the whitelist function is turned on, determining whether the sending number of the target short message is in the whitelist; if yes, determining to execute the step of sending the target short message to the SIM card; if no, discarding the target short message.

3. The short message processing method of claim 2, wherein, The application further comprises the following steps: receiving whitelist information; updating the whitelist based on the whitelist information.

4. The short message handling method according to any one of claims 1 to 3, characterized by, if the check is not passed, discarding the target short message comprises the following steps: if the check is not passed, outputting a discard reminder information and obtaining a processing instruction; if the processing instruction is discard, discarding the target short message; if the processing instruction is keep, sending the target short message to the SIM card.

5. A short message processing apparatus characterized by comprising: The application comprises the following steps: a short message buffering module is configured to receive and buffer a target short message of PP-DOWNLOAD type; wherein the type of the PP-DOWNLOAD short message is (U)SIM Data download, and the target short message is used to transmit data to the SIM card in a transparent manner through the envelop instruction based on the short message data transmission mode; a check module is configured to report the target short message to a check APP in the upper layer, and check the target short message based on the current security policy configured by the check APP; a short message sending module is configured to send the target short message to the SIM card if the check is passed; a short message discarding module is configured to discard the target short message if the check is not passed, record the target short message in the APP, notify the user of the relevant interception information, and send the target short message to the SIM card if the user confirms the false interception. The check module is specifically configured to determine whether the target short message corresponds to a known vulnerability by using the check APP; if yes, it is determined that the check fails; if no, it is determined that the check passes; wherein determining whether the target short message corresponds to a known vulnerability comprises: determining whether the target short message has code content corresponding to the known vulnerability; if yes, it is determined that the target short message corresponds to the known vulnerability; receiving new vulnerability information; and updating the known vulnerability by using the new vulnerability information.

6. An electronic device, comprising: The method comprises the following steps: a memory for storing a computer program; a processor for executing the computer program to realize the steps of the short message processing method according to any one of claims 1 to 4.

7. A readable storage medium characterized by, The computer program is stored on the readable storage medium, and the computer program is executed by the processor to realize the steps of the short message processing method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • A method for mobile phone SMS filtering

    CN101170776A

  • Method, device, user terminal and system supporting multiple imsi

    CN102668689B