Security authentication method and device, computer device and storage medium
By verifying the digital signature of the application client on the SIM card, its legitimacy is ensured, thus solving the problem of SIM card information leakage during the GBA authentication process and achieving security protection of SIM card information and enhanced security of operator networks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER
- Filing Date
- 2023-07-06
- Publication Date
- 2026-08-04
AI Technical Summary
In existing technologies, when application clients negotiate GBA authentication with servers, there is a risk of SIM card information leakage during the process of obtaining information from the SIM card, which may also pose a security threat to the operator's network.
Before an application client requests SIM card information, the SIM card verifies the application client's digital signature using the operator's public key to ensure its legitimacy. SIM card information is only provided to legitimate application clients, while requests from illegitimate application clients are rejected.
It effectively reduces the risk of SIM card information leakage, enhances the security of SIM cards and BSF network elements, prevents illegal applications from stealing SIM card information, and reduces the security risks of terminal devices.
Smart Images

Figure CN117062073B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of mobile communication technology, and in particular to a security authentication method, apparatus, computer equipment, and storage medium. Background Technology
[0002] GBA (General Bootstrapping Architecture) is a lightweight security infrastructure defined by 3GPP based on mobile communication networks. It can provide unified security authentication services for application layer services of application clients. It uses the AKA (Authentication and Key Agreement) authentication mechanism to establish a secure channel key between the application client and the application server, and then uses the secure channel key to establish a secure channel between the application client and the application server for identity authentication and secure communication.
[0003] When an application client negotiates with a server to use the GBA authentication method, the application client obtains SIM card information from the SIM (Subscriber Identity Module) card and then sends a GBA authentication request message to the operator's BSF (Bootstrapping Server Function) network element. During this process, the application client only needs to pass the terminal system's signature authentication to obtain SIM card information. However, if the application client is malicious, there is a risk of SIM card information leakage.
[0004] Therefore, how to reduce the risk of SIM card information leakage has become an urgent technical problem to be solved. Summary of the Invention
[0005] Therefore, it is necessary to provide a secure authentication method, device, computer equipment, and storage medium that can reduce the risk of SIM card information leakage in response to the above-mentioned technical problems.
[0006] Firstly, this application provides a security authentication method. The method includes:
[0007] A first request message is sent to the SIM card of the user identification module; wherein the first request message contains a digital signature of the application client to be authenticated, and the digital signature is used by the SIM card to perform security authentication of the application client.
[0008] In one embodiment, the method further includes:
[0009] Receive a first response message sent by the SIM card; the first response message is sent when the SIM card determines that the application client has passed security authentication.
[0010] In one embodiment, the first response message includes the identification information of the SIM card and information about the Bootstrap Service Function (BSF) network element, and the method further includes:
[0011] Based on the identification information of the SIM card and the information of the BSF network element, a General Authentication Mechanism (GBA) authentication request is sent to the BSF network element; wherein, the GBA authentication request is used to instruct the BSF network element to initiate the GBA authentication process.
[0012] In one embodiment, a first request message is sent to the SIM card (User Identification Module), including:
[0013] Send a second request message to the NAF (network application function) network element; wherein the second request message is used to instruct the NAF network element to determine the authentication method;
[0014] If a second response message is received from the NAF network element, a first request message is sent to the SIM card according to the GBA authentication method carried in the second response message.
[0015] Secondly, this application provides a security authentication method applied to a SIM card. The method includes:
[0016] Receive a first request message sent by a terminal device; wherein the first request message contains the digital signature of the application client to be authenticated;
[0017] The application client is authenticated based on its digital signature.
[0018] In one embodiment, the step of performing security authentication on the application client based on the application client's digital signature includes:
[0019] The digital signature within the application client is verified using the management key to obtain the security authentication result of the application client.
[0020] In one embodiment, the management key is an operator public key.
[0021] In one embodiment, the method further includes:
[0022] If the application client passes security authentication, a first response message is sent to the terminal device.
[0023] In one embodiment, the first response message includes the identification information of the SIM card and the information of the BSF network element; the first response message is used for the terminal device to send a GBA authentication request to the BSF network element based on the identification information of the SIM card and the information of the BSF network element; the GBA authentication request is used to instruct the BSF network element to initiate the GBA authentication process.
[0024] In one embodiment, before receiving the first request message sent by the terminal device, the method further includes:
[0025] The application client that has signed up for the GBA authentication service is signed based on the operator's private key.
[0026] Thirdly, this application also provides a security authentication system. The device includes:
[0027] A terminal device is configured to send a first request message to a user identification module (SIM card); wherein the first request message contains a digital signature of the application client to be authenticated;
[0028] The SIM card is used to perform security authentication on the application client based on the application client's digital signature.
[0029] Fourthly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to perform the following steps:
[0030] A first request message is sent to the SIM card of the user identification module; wherein the first request message contains a digital signature of the application client to be authenticated, and the digital signature is used by the SIM card to perform security authentication of the application client.
[0031] Alternatively, the processor may execute the computer program by performing the following steps:
[0032] Receive a first request message sent by a terminal device; wherein the first request message contains the digital signature of the application client to be authenticated;
[0033] The application client is authenticated based on its digital signature.
[0034] Fifthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, performs the following steps:
[0035] A first request message is sent to the SIM card of the user identification module; wherein the first request message contains a digital signature of the application client to be authenticated, and the digital signature is used by the SIM card to perform security authentication of the application client.
[0036] Alternatively, when the computer program is executed by the processor, it performs the following steps:
[0037] Receive a first request message sent by a terminal device; wherein the first request message contains the digital signature of the application client to be authenticated;
[0038] The application client is authenticated based on its digital signature.
[0039] Sixthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, performs the following steps:
[0040] A first request message is sent to the SIM card of the user identification module; wherein the first request message contains a digital signature of the application client to be authenticated, and the digital signature is used by the SIM card to perform security authentication of the application client.
[0041] Alternatively, when the computer program is executed by the processor, it performs the following steps:
[0042] Receive a first request message sent by a terminal device; wherein the first request message contains the digital signature of the application client to be authenticated;
[0043] The application client is authenticated based on its digital signature.
[0044] The aforementioned security authentication method, device, computer equipment, and storage medium, when an application client requests to obtain SIM card information, verify the digital signature of the application client to identify whether the application client is a legitimate application. If the application client is a legitimate application, the SIM card information is returned to the application client; if the application client is an illegitimate application, the request to obtain SIM card information is rejected, thereby preventing the leakage of SIM card information and reducing the security risks of terminal devices. Attached Figure Description
[0045] Figure 1 This is a diagram illustrating the application environment of a security authentication method in one embodiment;
[0046] Figure 2 This is a flowchart illustrating a security authentication method in one embodiment;
[0047] Figure 3This is a flowchart illustrating a security authentication method in another embodiment;
[0048] Figure 4 This is a flowchart illustrating a security authentication method in another embodiment;
[0049] Figure 5 This is a block diagram of a security authentication system in one embodiment;
[0050] Figure 6 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0051] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0052] As mentioned in the background section, GBA is a lightweight security infrastructure defined by 3GPP based on mobile communication networks. It can provide unified security authentication services for application layer services of application clients. It uses the AKA authentication mechanism to establish a secure channel key between the application client and the application server, and then uses the secure channel key to establish a secure channel between the application client and the application server for identity authentication and secure communication.
[0053] 3GPP TS 33.220 specifies the technical standard for GBA function in mobile terminals. When the application client and the application server negotiate to adopt the GBA authentication method, the application client can directly obtain the identification information of the SIM card from the SIM card and send the GBA authentication request to the BSF network element. The BSF network element forwards the GBA authentication request to the HSS network element or UDM network element. The HSS network element or UDM network element performs authentication based on the GUSS (GBA User Security Parameter Set) in the iFC user subscription parameters, generates an authentication vector, and continues the subsequent authentication process.
[0054] The problem with the aforementioned standard technical solution is that when the application client and server negotiate the use of GBA authentication, the application client obtains SIM card information from the SIM card and then sends a GBA authentication request message to the operator's BSF network element. During this process, the application client only needs to pass Android's signature authentication to obtain SIM card information. If the application client is malicious, there is a risk of SIM card information leakage. Simultaneously, some unauthorized application clients may use this method to attack the operator's BSF network element, posing a security risk to the operator's network.
[0055] Based on this, this application provides a secure authentication method, apparatus, computer device, and storage medium. The SIM card is pre-loaded with the operator's public key and BSF network element domain name information via OTA (Over-The-Air) updates. Before a user downloads and installs an application client using GBA authentication, the operator digitally signs the application client using its certificate private key. When the application client sends a request message to the SIM card to obtain the user's IMPI identifier, it carries the application client's digital signature. After receiving the application client's request message to obtain SIM card information, the SIM card verifies the digital signature carried in the message using the operator's public key. If the verification is successful, the IMPI identifier and BSF network element access information are returned to the application client. This enhances the security of the IMPI identifier information and BSF network element information in the SIM card.
[0056] The security authentication method provided in this application embodiment can be applied to, for example... Figure 1 The application environment shown. For example... Figure 1 As shown, the application environment includes: terminal 10, BSF network element 11, NAF network element 12, and HSS (home subscriber server) network element 13.
[0057] In this configuration, BSF network element 11 is located in the home network of terminal 10 and is used to provide bootstrapping services for terminal 10. It obtains the terminal's authentication vector from HSS network element 13 to complete the authentication of terminal 10 and establish a shared key with terminal 10. It should be noted that BSF network element 11 communicates with terminal 10 via the Ub interface and with HSS network element 13 via the Zh interface, and the authentication of terminal 10 by BSF network element 11 is based on the AKA protocol.
[0058] In the GBA, NAF element 12 is equivalent to an AS (application server). After receiving a service request from a terminal, it obtains the shared key negotiated between terminal 10 and BSF element 11 from BSF element 11 and authenticates terminal 10. After authentication, NAF element 12 can share a session key with terminal 10 and establish a secure channel based on this key, enabling encrypted data transmission between them. It should be noted that NAF element 12 communicates with terminal 10 via the Ua interface and with BSF element 11 via the Zn interface.
[0059] HSS network element 13 is used to store the subscription information of terminal 10 and generate security information of terminal 10, etc.
[0060] Terminal 10 supports the AKA protocol and Hypertext Transfer Protocol (HTTP) to achieve authentication with BSF network elements and NAF network elements. Terminal 10 can be an IoT terminal, or a mobile phone, cellular phone, cordless phone, Session Initiation Protocol (SIP) phone, smartphone, etc. However, it is important to note that Terminal 10 supports a SIM card, enabling data communication based on the Long Term Evolution (LTE) network. The SIM card stores a root key shared with the core network, the operator's public key, operator's private key, SIM card identification information, information about BSF network element 11, etc. The SIM card serves as the root of trust between Terminal 10 and the network, and this root key can be used to generate a shared key for Terminal 10.
[0061] Terminal 10 can also be various electronic devices, including but not limited to smartphones, tablets, laptops, desktop computers, smart speakers, smartwatches, wearable devices, augmented reality devices, virtual reality devices, etc. Optionally, the clients of the applications installed on different terminal devices can be the same, or clients of the same type of application based on different operating systems. Depending on the terminal platform, the specific form of the application client can also differ; for example, the application client can be a mobile client, a PC client, etc.
[0062] It should be noted that in the above architecture, the GBA process includes a bootstrap authentication process and a security association process. The bootstrap authentication process is used to realize the authentication between BSF network element 11 and terminal 10 and the negotiation of the shared key through the AKA protocol. The security association process is used to realize the authentication between NAF network element 12 and terminal 10 and the negotiation of the session key.
[0063] The BSF network element, acting as the anchor point in the entire GBA architecture, obtains authentication vectors from the HSS or UDM network elements to verify the terminal and uses the AKA mechanism to generate a shared key with the HSS or UDM network elements. The NAF network element guides the application client through GBA authentication and obtains the shared key from the BSF network element, generating a secure communication session key between the application client and the NAF application server. The HSS network element generates the AKA authentication vector and authenticates the terminal and USIM. The terminal is used to install the application client, and the USIM is used to generate the shared key and the application's external key.
[0064] The embodiments of this application will now be described in detail with reference to the accompanying drawings and examples.
[0065] In one embodiment, such as Figure 2 As shown, a security authentication method is provided, which can be applied to... Figure 1 The UE, or the application client installed on the UE that is to be authenticated, or the execution entity such as the processor of the UE, includes the following steps:
[0066] S202, send the first request message to the SIM card of the user identification module.
[0067] The first request message contains the digital signature of the application client to be authenticated. The digital signature is used by the SIM card to perform security authentication of the application client. The first request message is used to request the identification information of the SIM card or the device identifier of the terminal device.
[0068] Optionally, during the process of the SIM card performing security authentication on the application client based on the digital signature, the SIM card uses the locally stored operator public key to decrypt the digital signature. If the digital signature is successfully decrypted, the application client is determined to have passed the security authentication; if the digital signature is not successfully decrypted, the application client is determined to have failed the security authentication, that is, the application client has a security risk, and the application client steals the SIM card information, thereby causing the SIM card information to be leaked.
[0069] In this embodiment, when an application client requests SIM card information, the SIM card verifies the digital signature of the application client to identify whether the application client is a legitimate application. If the application client is a legitimate application, the SIM card information is returned to the application client; if the application client is an illegitimate application, the application client's request to obtain SIM card information is rejected, thereby preventing the leakage of SIM card information and reducing the security risks of the terminal device.
[0070] In one embodiment, the method further includes: receiving a first response message sent by a SIM card; the first response message is sent when the SIM card determines that the application client has passed security authentication. Optionally, after the SIM card determines that the application client has passed security authentication, the SIM card may send a first response message to the terminal device to notify the terminal device that the application client has passed security authentication.
[0071] In one embodiment, the first response message includes the identification information of the SIM card and the information of the Bootstrap Service Function (BSF) network element. The method further includes: sending a General Authentication Mechanism (GBA) authentication request to the BSF network element based on the identification information of the SIM card and the information of the BSF network element; wherein the GBA authentication request is used to instruct the BSF network element to initiate the GBA authentication process. Optionally, after determining that the application client has passed security authentication, the SIM card can send a first response message to the application client. The first response message carries the identification information of the SIM card and the information of the Bootstrap Service Function (BSF) network element, so that the application client can send a General Authentication Mechanism (GBA) authentication request to the BSF network element based on the identification information of the SIM card and the information of the BSF network element. In this embodiment, the SIM card only returns the identification information of the SIM card and the information of the Bootstrap Service Function (BSF) network element to the application client when the application client is determined to be a secure application, avoiding the risk of SIM card information being stolen by unauthorized applications and enhancing the security of the IMPI identification information and the BSF network element in the SIM card.
[0072] Optionally, the identification information of the SIM card can be information used to initiate the GBA authentication process, such as IMPI (IP Multimedia Private Identity).
[0073] Optionally, the application client can send a GBA authentication request carrying the identification information of the SIM card to the BSF network element based on the information of the BSF network element.
[0074] In one embodiment, sending a first request message to a user identification module (SIM card) includes: sending a second request message to a network application function (NAF) element; wherein the second request message is used to instruct the NAF element to determine the authentication method; if a second response message is received from the NAF element, the first request message is sent to the SIM card according to the GBA authentication method carried in the second response message.
[0075] In one embodiment, such as Figure 3 As shown, a security authentication method is provided. Taking the application of this method to a SIM card as an example, the method includes the following steps:
[0076] S302, Receive the first request message sent by the terminal device.
[0077] The first request message contains the digital signature of the application client to be authenticated. This message requests the identification information of the SIM card or the device identifier of the terminal device. The identification information can be an IMPI (Integrated Mobile Subscriber Identity), and the device identifier can be a unique identifier for the terminal, such as the International Mobile Subscriber Identity (IMSI). The SIM card can have the operator's public key and relevant information about BSF network elements written to it via OTA (Over-the-Air Technology) or pre-installed methods.
[0078] S304 performs security authentication on the application client based on the application client's digital signature.
[0079] Optionally, during the process of the SIM card performing security authentication on the application client based on the digital signature, the SIM card uses the locally stored operator public key to decrypt the digital signature. If the digital signature is successfully decrypted, the application client is determined to have passed security authentication; if the digital signature is not successfully decrypted, the application client is determined to have failed security authentication, meaning that the application client has a security risk. In this case, the application client may steal SIM card information, leading to SIM card information leakage.
[0080] In this embodiment, when the application client obtains SIM card information, the SIM card verifies the digital signature of the application client to identify whether the application client is a legitimate application. If the application client is a legitimate application, the SIM card information is returned to the application client; if the application client is an illegitimate application, the application client's request to obtain SIM card information is rejected, thereby avoiding the leakage of SIM card information and reducing the risk of SIM card information leakage.
[0081] In one embodiment, security authentication of the application client is performed based on the application client's digital signature, including: verifying the digital signature within the application client using a management key to obtain the application client's security authentication result. Optionally, the management key is an operator's public key or other public key used for decryption.
[0082] In one embodiment, the method further includes sending a first response message to a terminal device if it is determined that the application client has passed security authentication. Optionally, after the SIM card determines that the application client has passed security authentication, the SIM card may send a first response message to the terminal device to notify the terminal device that the application client has passed security authentication.
[0083] In one embodiment, the first response message includes the SIM card's identification information and the BSF network element information. The first response message is used by the terminal device to send a GBA authentication request to the BSF network element based on the SIM card's identification information and the BSF network element information. The GBA authentication request instructs the BSF network element to initiate the GBA authentication process. Optionally, after determining that the application client has passed security authentication, the SIM card can send a first response message to the application client. The first response message carries the SIM card's identification information and the BSF network element information, so that the application client can send a General Authentication Mechanism (GBA) authentication request to the BSF network element based on the SIM card's identification information and the BSF network element information. In this embodiment, the SIM card only returns the SIM card's identification information and the BSF network element information to the application client when the application client is determined to be a secure application, avoiding the risk of SIM card information being stolen by unauthorized applications. The SIM card's identification information can be information used to initiate the GBA authentication process, such as IMPI.
[0084] In one embodiment, before receiving the first request message sent by the terminal device, the method further includes: signing the application client subscribed to the GBA authentication service based on the operator's private key. Optionally, the operator's private key can be used to sign the code information or registration information of the application client subscribed to the GBA authentication service, wherein the code information is the executable code of the application client, and the registration information is the information of the application client's developer or company. After signing the application client subscribed to the GBA authentication service, the application developer can upload the application client to the app store for user devices to download using the digital signature. After downloading the application client, the user device sends a second request message to the application server.
[0085] For example, this embodiment provides an optional implementation process based on the above embodiments, see [link to example]. Figure 4 The diagram illustrates another security authentication method, which specifically includes the following steps:
[0086] S402, the application client sends a second request message to the NAF network element.
[0087] The second request message is used to instruct the NAF network element to determine the authentication method.
[0088] S404, the NAF network element sends a second response message to the application client.
[0089] The second response message carries the GBA authentication method.
[0090] S406, the application client sends the first request message to the SIM card.
[0091] The first request message contains the digital signature of the application client to be authenticated, which is used by the SIM card to perform security authentication of the application client.
[0092] Optionally, the application client may send a first request message to the SIM card based on the GBA authentication method carried in the second response message.
[0093] S408: The SIM card performs security authentication on the application client based on the digital signature.
[0094] Optionally, the SIM card uses a management key to verify the digital signature within the application client, thereby obtaining the security authentication result of the application client.
[0095] S410: Once the SIM card determines that the application client has passed security authentication, it sends a first response message to the application client.
[0096] The first response message includes the SIM card's identification information and information about the BSF network element for the guidance service function.
[0097] S412: The application client sends a GBA authentication request to the BSF network element based on the SIM card's identification information and the BSF network element's information, in order to initiate the GBA authentication process.
[0098] Optionally, the application client can send a GBA authentication request carrying the identification information of the SIM card to the BSF network element based on the information of the BSF network element.
[0099] The specific processes of S402-S412 described above can be found in the description of the above method embodiments. Their implementation principles and technical effects are similar, and will not be repeated here.
[0100] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0101] Based on the same inventive concept, this application also provides a security authentication system for implementing the security authentication method described above. The solution provided by this system is similar to the implementation scheme described in the above method; therefore, the specific limitations in one or more security authentication system embodiments provided below can be found in the limitations of the security authentication method described above, and will not be repeated here.
[0102] In one embodiment, such as Figure 5 As shown, a security authentication system is provided, including:
[0103] Terminal device 510 is used to send a first request message to the user identification module SIM card; wherein the first request message contains the digital signature of the application client to be authenticated;
[0104] SIM card 520 is used to perform security authentication on application clients based on their digital signatures.
[0105] In the aforementioned system, when an application client obtains SIM card information, the SIM card verifies the digital signature of the application client to identify whether the application client is a legitimate application. If the application client is a legitimate application, the system returns the SIM card information to the application client; if the application client is an illegitimate application, the system rejects the application client's request to obtain SIM card information, thereby preventing the leakage of SIM card information and reducing the security risks of terminal devices.
[0106] In one embodiment, the terminal device 510 is further configured to receive a first response message sent by the SIM card; the first response message is sent when the SIM card determines that the application client has passed security authentication.
[0107] In one embodiment, the first response message includes the identification information of the SIM card and the information of the Guided Service Function (BSF) network element. The terminal device is further configured to send a General Authentication Mechanism (GBA) authentication request to the BSF network element based on the identification information of the SIM card and the information of the BSF network element. The GBA authentication request is used to instruct the BSF network element to initiate the GBA authentication process.
[0108] In one embodiment, the terminal device 510 is further configured to send a second request message to the Network Application Function (NAF) network element; wherein the second request message is used to instruct the NAF network element to determine the authentication method.
[0109] In one embodiment, the terminal device 510 is further configured to send a first request message to the user identification module SIM card if it receives a second response message sent by the NAF network element; wherein the second response message is used to instruct the terminal device to use GBA authentication.
[0110] In one embodiment, the SIM card 520 is also used to verify the digital signature in the application client using a management key to obtain the security authentication result of the application client.
[0111] In one embodiment, the SIM card 520 is also configured to send a first response message to the terminal device when it is determined that the application client has passed security authentication.
[0112] In one embodiment, the SIM card 520 is also used to sign the application client that has signed up for the GBA authentication service based on the operator's private key.
[0113] Each module in the aforementioned security authentication system can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0114] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 6 As shown in the figure, the computer device includes a processor, memory, network interface, and transceiver (not shown) connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores operator public keys, operator private keys, BSF network element information, and SIM card identification information, among other data. The network interface communicates with external terminals via a network connection. The transceiver, under the control of the processor, performs operations to receive or send data. The computer program, when executed by the processor, implements a secure authentication method.
[0115] Those skilled in the art will understand that Figure 6 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0116] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor performs the following steps when executing processing logic in the computer program:
[0117] A first request message is sent to the SIM card of the user identification module; wherein the first request message contains the digital signature of the application client to be authenticated, and the digital signature is used by the SIM card to perform security authentication of the application client.
[0118] Alternatively, the processor may perform the following steps when executing processing logic in a computer program:
[0119] Receive a first request message sent by a terminal device; wherein the first request message contains the digital signature of the application client to be authenticated;
[0120] The application client is authenticated based on its digital signature.
[0121] In one embodiment, when the processor executes processing logic in a computer program, it also performs the following steps:
[0122] Receive the first response message sent by the SIM card; the first response message is sent after the SIM card determines that the application client has passed security authentication.
[0123] In one embodiment, the first response message includes the identification information of the SIM card and the information of the Bootstrap Service Function (BSF) network element. When the processor executes the processing logic in the computer program, it also implements the following steps: sending a General Authentication Mechanism (GBA) authentication request to the BSF network element based on the identification information of the SIM card and the information of the BSF network element; wherein, the GBA authentication request is used to instruct the BSF network element to initiate the GBA authentication process.
[0124] In one embodiment, when the processor executes the processing logic in the computer program that sends a first request message to the SIM card, it further implements the following steps: sending a second request message to the Network Application Function (NAF) element; wherein the second request message is used to instruct the NAF element to determine the authentication method; if a second response message is received from the NAF element, the first request message is sent to the SIM card according to the GBA authentication method carried in the second response message.
[0125] In one embodiment, when the processor executes the processing logic in the computer program to perform security authentication on the application client based on the application client's digital signature, it also implements the following steps: using a management key to verify the digital signature in the application client and obtain the security authentication result of the application client.
[0126] In one embodiment, when the processor executes the processing logic in the computer program, it also performs the following steps: if it determines that the application client has passed security authentication, it sends a first response message to the terminal device.
[0127] In one embodiment, when the processor executes the processing logic in the computer program before receiving the first request message sent by the terminal device, it further implements the following steps: signing the application client that has signed up for the GBA authentication service based on the operator's private key.
[0128] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, wherein the processing logic in the computer program, when executed by a processor, performs the following steps:
[0129] A first request message is sent to the SIM card of the user identification module; wherein the first request message contains the digital signature of the application client to be authenticated, and the digital signature is used by the SIM card to perform security authentication of the application client.
[0130] Alternatively, the processing logic in a computer program, when executed by the processor, performs the following steps:
[0131] Receive a first request message sent by a terminal device; wherein the first request message contains the digital signature of the application client to be authenticated;
[0132] The application client is authenticated based on its digital signature.
[0133] In one embodiment, when the processing logic in the computer program is executed by the processor, it further implements the following steps: receiving a first response message sent by the SIM card; the first response message is sent when the SIM card determines that the application client has passed security authentication.
[0134] In one embodiment, the first response message includes the identification information of the SIM card and the information of the Bootstrap Service Function (BSF) network element. When the processing logic in the computer program is executed by the processor, the following steps are also implemented: based on the identification information of the SIM card and the information of the BSF network element, a General Authentication Mechanism (GBA) authentication request is sent to the BSF network element; wherein, the GBA authentication request is used to instruct the BSF network element to initiate the GBA authentication process.
[0135] In one embodiment, when the processing logic in the computer program that sends a first request message to the SIM card is executed by the processor, the following steps are also implemented: sending a second request message to the Network Application Function (NAF) element; wherein the second request message is used to instruct the NAF element to determine the authentication method; if a second response message is received from the NAF element, the first request message is sent to the SIM card according to the GBA authentication method carried in the second response message.
[0136] In one embodiment, when the processing logic in the computer program that performs security authentication on the application client based on the application client's digital signature is executed by the processor, the following steps are also implemented: using a management key to verify the digital signature in the application client to obtain the security authentication result of the application client.
[0137] In one embodiment, when the processing logic in the computer program is executed by the processor, the following steps are also performed: if it is determined that the application client has passed security authentication, a first response message is sent to the terminal device.
[0138] In one embodiment, when the processing logic in the computer program before receiving the first request message sent by the terminal device is executed by the processor, the following steps are also implemented: signing the application client that has signed up for the GBA authentication service based on the operator's private key.
[0139] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:
[0140] A first request message is sent to the SIM card of the user identification module; wherein the first request message contains the digital signature of the application client to be authenticated, and the digital signature is used by the SIM card to perform security authentication of the application client.
[0141] Alternatively, the processing logic in a computer program, when executed by the processor, performs the following steps:
[0142] Receive a first request message sent by a terminal device; wherein the first request message contains the digital signature of the application client to be authenticated;
[0143] The application client is authenticated based on its digital signature.
[0144] In one embodiment, when the processing logic in the computer program is executed by the processor, it further implements the following steps: receiving a first response message sent by the SIM card; the first response message is sent when the SIM card determines that the application client has passed security authentication.
[0145] In one embodiment, the first response message includes the identification information of the SIM card and the information of the Bootstrap Service Function (BSF) network element. When the processing logic in the computer program is executed by the processor, the following steps are also implemented: based on the identification information of the SIM card and the information of the BSF network element, a General Authentication Mechanism (GBA) authentication request is sent to the BSF network element; wherein, the GBA authentication request is used to instruct the BSF network element to initiate the GBA authentication process.
[0146] In one embodiment, when the processing logic in the computer program that sends a first request message to the SIM card is executed by the processor, the following steps are also implemented: sending a second request message to the Network Application Function (NAF) element; wherein the second request message is used to instruct the NAF element to determine the authentication method; if a second response message is received from the NAF element, the first request message is sent to the SIM card according to the GBA authentication method carried in the second response message.
[0147] In one embodiment, when the processing logic in the computer program that performs security authentication on the application client based on the application client's digital signature is executed by the processor, the following steps are also implemented: using a management key to verify the digital signature in the application client to obtain the security authentication result of the application client.
[0148] In one embodiment, when the processing logic in the computer program is executed by the processor, the following steps are also performed: if it is determined that the application client has passed security authentication, a first response message is sent to the terminal device.
[0149] In one embodiment, when the processing logic in the computer program before receiving the first request message sent by the terminal device is executed by the processor, the following steps are also implemented: signing the application client that has signed up for the GBA authentication service based on the operator's private key.
[0150] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0151] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0152] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0153] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A security authentication method characterized by, The method includes: Send a second request message to the Network Application Function (NAF) network element; wherein the second request message is used to instruct the NAF network element to determine the authentication method; If a second response message is received from the NAF network element, a first request message is sent to the SIM card according to the GBA authentication method carried in the second response message; wherein, the first request message contains a digital signature of the application client to be authenticated, the digital signature is generated by signing the code information or catalog information of the application client based on the operator's private key; the digital signature is used for the SIM card to perform security authentication of the application client.
2. The method of claim 1, wherein, The method further includes: Receive a first response message sent by the SIM card; the first response message is sent when the SIM card determines that the application client has passed security authentication.
3. The method of claim 2, wherein, The first response message includes the identification information of the SIM card and the information of the Bootstrap Service (BSF) network element. The method further includes: Based on the identification information of the SIM card and the information of the BSF network element, a General Authentication Mechanism (GBA) authentication request is sent to the BSF network element; wherein, the GBA authentication request is used to instruct the BSF network element to initiate the GBA authentication process.
4. A security authentication method characterized by, Applied to a SIM card, the method includes: The terminal device receives a first request message; wherein the first request message is sent to the SIM card by the terminal device according to the GBA authentication method carried in the second response message sent by the NAF network element, and the first request message contains a digital signature of the application client to be authenticated, and the digital signature is generated by signing the code information or catalog information of the application client according to the operator's private key. The application client is authenticated based on its digital signature.
5. The method of claim 4, wherein, The step of performing security authentication on the application client based on the application client's digital signature includes: The digital signature within the application client is verified using the management key to obtain the security authentication result of the application client.
6. The method of claim 5, wherein, The management key is the operator's public key.
7. The method of claim 4, wherein, The method further includes: If the application client passes security authentication, a first response message is sent to the terminal device.
8. The method according to claim 7, characterized in that, The first response message includes the identification information of the SIM card and the information of the BSF network element; the first response message is used for the terminal device to send a GBA authentication request to the BSF network element based on the identification information of the SIM card and the information of the BSF network element; The GBA authentication request is used to instruct the BSF network element to initiate the GBA authentication process.
9. The method of claim 5, wherein, Before receiving the first request message sent by the terminal device, the method further includes: The application client that has signed up for the GBA authentication service is signed based on the operator's private key.
10. A secure authentication system characterized by, The system includes: A terminal device is configured to send a second request message to a Network Application Function (NAF) element; wherein the second request message is used to instruct the NAF element to determine an authentication method; if a second response message is received from the NAF element, a first request message is sent to the SIM card according to the GBA authentication method carried in the second response message; wherein the first request message contains a digital signature of the application client to be authenticated; the digital signature is generated by signing the code information or catalog information of the application client based on the operator's private key; The SIM card is used to perform security authentication on the application client based on the application client's digital signature. 11.A computer device, comprising a memory, a transceiver and a processor, wherein the memory stores a computer program, and the computer device is characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 3, or when the processor executes the computer program, it implements the steps of the method according to any one of claims 4 to 9, wherein the transceiver is configured to perform the operation of receiving data or sending data under the control of the processor.
12. A computer readable storage medium having stored thereon a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 9.
13. A computer program product comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 9.