Authentication method and device, computer device, storage medium and program product

By receiving authentication subscription information from the network side, the terminal can accurately determine and adopt the appropriate authentication method, thus solving the problem of authentication failure and improving the success rate and efficiency of authentication.

CN117098121BActive Publication Date: 2025-11-07CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310949592.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-31
Publication Date
2025-11-07
Estimated Expiration
2043-07-31

AI Technical Summary

Technical Problem

Applications on the terminal cannot accurately know the authentication method configured on the network side, resulting in authentication failure and inefficiency.

Method used

The terminal receives the authentication subscription information sent by the network side, determines the authentication method corresponding to the target user card, and uses that method for authentication.

Benefits of technology

It improves the success rate and efficiency of authentication, avoids failures caused by calling invalid authentication methods, and ensures the reliability of the authentication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117098121B_ABST
    Figure CN117098121B_ABST
Patent Text Reader

Abstract

The application relates to an authentication method and device, a computer device, a storage medium and a program product. The method is applied to a terminal side and comprises the following steps: receiving authentication subscription information sent by a network side; the authentication subscription information is stored in the network side and corresponds to a target user card carried by the terminal; based on the authentication subscription information, a target authentication mode corresponding to a to-be-authenticated application on the terminal is determined; and the to-be-authenticated application is authenticated by using the target authentication mode, so that an authentication result is obtained. That is, when the terminal application performs authentication, the terminal can obtain authentication subscription information corresponding to the target user card carried by the terminal from the network side, so that the terminal can determine the actual authentication mode corresponding to the target user card; then, the corresponding authentication service can be accurately called, accurate authentication of the to-be-authenticated application is realized, the success rate of authentication is improved, and the authentication efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, and in particular to an authentication method and device, a computer device, a storage medium and a program product. BACKGROUND

[0002] With the development of communication technology, the requirements for communication security and communication efficiency are increasingly high. When an application on a terminal performs network communication with a server, the application usually needs to be authenticated first. After authentication, a secure communication connection between the application and the server can be established based on the key obtained through authentication.

[0003] In a traditional method, for a user card carried on a terminal, the network side configures authentication for the user card, thereby determining the authentication method corresponding to the user card on the network side. Subsequently, the terminal carrying the user card can authenticate the application thereon based on the authentication method.

[0004] However, in the traditional technology, the user card or the terminal carrying the user card does not know which authentication method is configured on the network side. Therefore, when the terminal authenticates the application thereon, authentication failure may occur, resulting in low authentication efficiency. SUMMARY

[0005] Therefore, it is necessary to provide an authentication method, device, computer device, computer readable storage medium and computer program product capable of improving authentication efficiency to solve the above technical problems.

[0006] In a first aspect, the present application provides an authentication method. The method is applied to a terminal and includes the following steps.

[0007] Receiving authentication subscription information sent by the network side; the authentication subscription information is stored on the network side and corresponds to a target user card carried by the terminal;

[0008] Based on the authentication subscription information, determining a target authentication method corresponding to a to-be-authenticated application on the terminal;

[0009] Using the target authentication method to authenticate the to-be-authenticated application, and obtaining an authentication result.

[0010] In one embodiment, receiving the authentication subscription information sent by the network side includes the following steps.

[0011] Receiving an encrypted data short message sent by a short message service gateway of the network side; the encrypted data short message carries the authentication subscription information of the target user card carried by the terminal;

[0012] The encrypted data message is parsed to obtain authentication subscription information of a target user card carried by the terminal.

[0013] In one of the embodiments, the authentication subscription information includes at least one authentication mode corresponding to the target user card and a support attribute of each authentication mode; the support attribute is used to represent whether the target user card supports the authentication mode; based on the authentication subscription information, the target authentication mode corresponding to the application to be authenticated on the terminal is determined, including:

[0014] According to the support attribute of each authentication mode, a candidate authentication mode is determined from the at least one authentication mode; the candidate authentication mode includes an authentication mode supported by the target user card;

[0015] According to the use information of the candidate authentication mode, the target authentication mode corresponding to the application to be authenticated on the terminal is determined from the candidate authentication mode.

[0016] In one of the embodiments, the use information includes an authentication success rate; if the candidate authentication mode includes multiple, according to the use information of the candidate authentication mode, the target authentication mode corresponding to the application to be authenticated on the terminal is determined from the candidate authentication mode, including:

[0017] Obtaining an authentication success rate corresponding to each candidate authentication mode;

[0018] According to the authentication success rate corresponding to each candidate authentication mode, the candidate authentication mode with the highest authentication success rate is determined as the target authentication mode corresponding to the application to be authenticated on the terminal.

[0019] In one of the embodiments, the method further includes:

[0020] According to the authentication result, the authentication success rate corresponding to the target authentication mode is updated.

[0021] In one of the embodiments, the authentication subscription information includes at least one authentication mode corresponding to the target user card and a support attribute of each authentication mode; the support attribute is used to represent whether the target user card supports the authentication mode; based on the authentication subscription information, the target authentication mode corresponding to the application to be authenticated on the terminal is determined, including:

[0022] Obtaining a preset authentication mode corresponding to the application to be authenticated;

[0023] Judging whether the preset authentication mode is included in the authentication subscription information;

[0024] If the preset authentication mode is included in the authentication subscription information, it is determined whether the target user card supports the preset authentication mode according to a support attribute of the preset authentication mode.

[0025] If the target user card supports the preset authentication mode, the preset authentication mode is determined as the target authentication mode corresponding to the application to be authenticated on the terminal.

[0026] In a second aspect, the application provides an authentication method. The method is applied to a network side and includes:

[0027] Obtaining authentication subscription information corresponding to a target user card;

[0028] Sending the authentication subscription information corresponding to the target user card to a terminal corresponding to the target user card; the authentication subscription information is used to instruct the terminal to determine a target authentication mode corresponding to an application to be authenticated on the terminal based on the authentication subscription information, and to authenticate the application to be authenticated by using the target authentication mode to obtain an authentication result.

[0029] In one of the embodiments, the obtaining of the authentication subscription information corresponding to the target user card includes:

[0030] Sending an authentication configuration request to a signaling processing network element of the network side through a customer relationship management network element of the network side; the authentication configuration request carries subscription information of the target user card;

[0031] Performing authentication configuration on the target user card based on the subscription information of the target user card through the signaling processing network element, and sending a configuration result to the customer relationship management network element;

[0032] Generating the authentication subscription information corresponding to the target user card based on the configuration result through the customer relationship management network element.

[0033] In one of the embodiments, the sending of the authentication subscription information corresponding to the target user card to the terminal corresponding to the target user card includes:

[0034] Sending a data encryption request to a trusted service management network element through the customer relationship management network element; the data encryption request carries the authentication subscription information corresponding to the target user card;

[0035] Encrypting the authentication subscription information corresponding to the target user card through the trusted service management network element to obtain encrypted data short messages corresponding to the target user card, and sending the encrypted data short messages corresponding to the target user card to the customer relationship management network element;

[0036] Sending the encrypted data short messages corresponding to the target user card to a short message service gateway of the network side through the customer relationship management network element;

[0037] The encrypted data short message corresponding to the target user card is sent to the terminal corresponding to the target user card in the form of a data short message through a short message service gateway.

[0038] In one embodiment, the authentication subscription information includes at least one authentication mode corresponding to the target user card and a support attribute of each authentication mode; the support attribute is used to indicate whether the target user card supports the authentication mode.

[0039] The support attribute is used to instruct the terminal to determine a candidate authentication mode from the at least one authentication mode according to the support attribute of each authentication mode; the candidate authentication mode includes an authentication mode supported by the target user card; and a target authentication mode corresponding to the application to be authenticated on the terminal is determined from the candidate authentication mode according to the use information of the candidate authentication mode.

[0040] In a third aspect, the present application also provides an authentication device. The device is applied to the terminal side and includes:

[0041] The receiving module is configured to receive authentication subscription information sent by the network side; the authentication subscription information is stored on the network side and corresponds to the target user card carried by the terminal;

[0042] The determining module is configured to determine a target authentication mode corresponding to the application to be authenticated on the terminal based on the authentication subscription information;

[0043] The authentication module is configured to authenticate the application to be authenticated by using the target authentication mode to obtain an authentication result.

[0044] In a fourth aspect, the present application also provides an authentication device. The device is applied to the network side and includes:

[0045] The obtaining module is configured to obtain authentication subscription information corresponding to the target user card;

[0046] The sending module is configured to send the authentication subscription information corresponding to the target user card to the terminal corresponding to the target user card; the authentication subscription information is used to instruct the terminal to determine a target authentication mode corresponding to the application to be authenticated on the terminal based on the authentication subscription information, and to authenticate the application to be authenticated by using the target authentication mode to obtain an authentication result.

[0047] In a fifth aspect, the present application also provides a computer device. The computer device includes a memory and a processor; the memory stores a computer program; and the processor implements the steps of the authentication method in the first aspect and / or the second aspect when executing the computer program.

[0048] In a sixth aspect, the present application also provides a computer readable storage medium. The computer readable storage medium has a computer program stored thereon, and the computer program, when executed by a processor, implements the steps of the authentication method in the first aspect and / or the second aspect.

[0049] In a seventh aspect, the present application also provides a computer program product. The computer program product includes a computer program, and the computer program, when executed by a processor, implements the steps of the authentication method in the first aspect and / or the second aspect.

[0050] The authentication method, device, computer device, storage medium and computer program product described above, the terminal side receives the authentication subscription information sent by the network side; the authentication subscription information is stored in the network side and corresponds to the target user card carried by the terminal; then, based on the authentication subscription information, the target authentication mode corresponding to the application to be authenticated on the terminal is determined; and the target authentication mode is used to authenticate the application to be authenticated, and an authentication result is obtained. That is, in the embodiments of the present application, when the terminal application performs authentication, the terminal can first obtain the authentication subscription information corresponding to the target user card carried by the terminal from the network side, so that the terminal can determine the actual authentication mode corresponding to the target user card; then, the terminal can determine the target authentication mode corresponding to the application to be authenticated based on the authentication mode corresponding to the target user card; and the application to be authenticated is authenticated based on the target authentication mode. Since the terminal has determined the authentication mode configured by the network side for the target user card, the terminal can accurately call the corresponding authentication service, thereby achieving accurate authentication of the application to be authenticated. Not only can the problem of authentication failure caused by calling invalid authentication service by the terminal be avoided, but also the problem of authentication failure caused by inconsistency between the terminal and the network side can be avoided. Therefore, by using the method, the success rate and reliability of authentication can be greatly improved, and the efficiency of authentication can be improved. BRIEF DESCRIPTION OF DRAWINGS

[0051] Figure 1 An application environment diagram of the authentication method in an embodiment;

[0052] Figure 2 A flowchart of the authentication method on the terminal side in an embodiment;

[0053] Figure 3 A flowchart of the authentication method on the terminal side in another embodiment;

[0054] Figure 4 A flowchart of the authentication method on the terminal side in another embodiment;

[0055] Figure 5 Flowchart of the authentication method on the terminal side in another embodiment;

[0056] Figure 6 Flowchart of the authentication method on the network side in an embodiment;

[0057] Figure 7 Flowchart of the authentication method in an embodiment;

[0058] Figure 8 Flowchart of the adaptive workflow of the application layer bootstrapping authentication in an embodiment;

[0059] Figure 9 Flowchart of the workflow of the application layer bootstrapping authentication and availability feedback in an embodiment;

[0060] Figure 10 Block diagram of the authentication device on the terminal side in an embodiment;

[0061] Figure 11 Block diagram of the authentication device on the network side in an embodiment;

[0062] Figure 12 Internal structure diagram of the terminal device in an embodiment;

[0063] Figure 13 Internal structure diagram of the network device in an embodiment. DETAILED DESCRIPTION

[0064] In order to make the objects, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and should not be used to limit the present application.

[0065] The authentication method provided by the embodiments of the present application can be applied to the field of wireless communication and terminals. Network operators usually provide network-based native authentication and authorization services for applications on terminals, such as Generic Bootstrapping Architecture (GBA) services, Authentication and Key Management for Application (AKMA) services, and the like. In one case, if the two application layer authentication and authorization methods of GBA and AKMA are mixedly deployed, the applications on the terminal can adaptively use the effective authentication and authorization method, so as to improve the success rate of bootstrapping authentication and authorization, and further improve the authentication and authorization efficiency.

[0066] However, in another case, if only GBA or AKMA is deployed, there is only relevant bootstrapping authentication subscription information in the network side signaling processing network elements such as the home subscriber server (HSS) and the unified data management (UDM); that is, the authentication subscription information corresponding to different user cards is stored in the HSS / UDM.

[0067] This will cause the following problems:

[0068] (1) The user card or the terminal carrying the user card cannot know what application layer authentication is subscribed on the network side, so that the application on the terminal cannot implement accurate authentication service calling;

[0069] (2) The application on the terminal may fail to request the related service due to calling an invalid bootstrapping authentication mode;

[0070] (3) When the terminal side environment changes (such as replacing the terminal / user card), the subscription information on the network side is inconsistent with the terminal side capability support, resulting in failure of the related service request.

[0071] That is, the user card or the terminal carrying the user card does not know which authentication mode is configured on the network side, so that when the terminal authenticates the application thereon, authentication failure may occur, resulting in low authentication efficiency.

[0072] Based on this, the embodiments of the present application propose an authentication method to solve the problem that the user card and the terminal cannot know what application layer bootstrapping authentication is actually subscribed when GBA or AKMA is deployed, or the network side application layer bootstrapping authentication subscription information is inconsistent with the terminal side capability support when the terminal side environment changes, resulting in that the terminal application cannot accurately call the available authentication service or the application layer session establishment fails; in the case that the network side completes the authentication configuration of the user card, the authentication subscription information of the user card is sent to the corresponding user card, so that the terminal application can obtain the corresponding authentication subscription information from the user card when performing authentication, and completes the authentication of the application based on the authentication mode matched with the user card, thereby accurately authenticating the application and avoiding the problem of authentication failure caused by using an invalid authentication mode; the success rate of authentication can be improved, and the authentication efficiency can be improved.

[0073] The authentication method provided by the embodiments of the present application can be applied to, for example Figure 1The application environment shown. Among them, the terminal 102 communicates with the server 106 through the network 104. The terminal 102 is loaded with different applications, and each application communicates with the same or different server 106. The secure communication between the application on the terminal 102 and the corresponding server 106 can be realized through the network 104; when the application establishes a secure communication connection with the network 104, it needs to be authenticated first, and after the authentication is passed, the secure communication connection between the application and the network side is established based on the key obtained by the authentication, and then the network side establishes a secure communication connection between the corresponding server, so as to realize the secure communication connection between the application and the corresponding server 106.

[0074] In addition, the data storage system can store the data that the server 106 needs to process. The data storage system can be integrated on the server 106, or placed on the cloud or other network servers.

[0075] The terminal 102 can be, but is not limited to, various personal computers, notebook computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things device can be a smart speaker, a smart television, a smart air conditioner, a smart vehicle device, etc. The portable wearable device can be a smart watch, a smart bracelet, a head-mounted device, etc. The network 104 can include network elements and gateways with different functions to realize data transmission and management between the terminal and the server. The server 106 can be realized by an independent server or a server cluster composed of multiple servers.

[0076] In one embodiment, as Figure 2 shown, an authentication method is provided, which is applied to the terminal in Figure 1 The method includes the following steps:

[0077] Step 202, receiving the authentication subscription information sent by the network side.

[0078] The authentication subscription information is stored on the network side and corresponds to the target user card loaded on the terminal. The network side stores configuration information corresponding to different user cards, which includes but is not limited to the authentication subscription information corresponding to the user card.

[0079] In one implementation, when the authentication subscription information of the user card is added or modified on the network side, the network side can send the authentication subscription information of the user card to the user card or to the terminal carrying the user card.

[0080] In another implementation, the terminal can also send an authentication subscription information request to the network side, the authentication subscription information request carrying an identifier of the target user card mounted on the terminal. Upon receiving the authentication subscription information request, the network side sends the authentication subscription information corresponding to the target user card to the target user card or to the terminal mounting the target user card.

[0081] Illustratively, in the case where the network side sends the authentication subscription information of the target user card to the target user card, the terminal can read the authentication subscription information from the target user card.

[0082] Step 204: Based on the authentication subscription information, determine the target authentication mode corresponding to the application to be authenticated on the terminal.

[0083] Illustratively, the authentication subscription information can include at least one authentication mode supported by the target user card. In the case where the authentication subscription information includes one authentication mode supported by the target user card, the terminal can determine the authentication mode as the target authentication mode corresponding to the application to be authenticated on the terminal. In the case where the authentication subscription information includes multiple authentication modes supported by the target user card, the terminal can employ different screening strategies to determine one authentication mode from the multiple authentication modes as the target authentication mode corresponding to the application to be authenticated on the terminal.

[0084] Illustratively, the screening strategy can include a random screening strategy, i.e., the terminal can randomly determine one authentication mode from the multiple authentication modes as the target authentication mode corresponding to the application to be authenticated on the terminal.

[0085] Illustratively, the screening strategy can also include a conditional screening strategy configured based on different screening conditions, including but not limited to the number of uses, the number of successes, the authentication rate, the default authentication mode of the application, etc. Based on the different conditional screening strategies, one authentication mode matching the corresponding screening condition can be determined from the multiple authentication modes as the target authentication mode corresponding to the application to be authenticated on the terminal.

[0086] It should be noted that, in addition to the above-described determination methods, other determination methods can also be employed to determine the target authentication mode corresponding to the application to be authenticated on the terminal from the multiple authentication modes, which are not limited herein.

[0087] Step 206: Perform authentication on the application to be authenticated using the target authentication mode, and obtain an authentication result.

[0088] Exemplarily, in a case that the target authentication and authorization manner is the GBA authentication and authorization manner, the terminal can invoke the GBA authentication and authorization service based on the GBA authentication and authorization manner to perform authentication and authorization on the to-be-authenticated application and obtain an authentication and authorization result. In a case that the target authentication and authorization manner is the AKMA authentication and authorization manner, the terminal can invoke the AKMA authentication and authorization service based on the AKMA authentication and authorization manner to perform authentication and authorization on the to-be-authenticated application and obtain an authentication and authorization result.

[0089] It should be noted that the authentication and authorization processes of the GBA authentication and authorization service and the AKMA authentication and authorization service can refer to the technical introduction of the GBA authentication and authorization and the AKMA authentication and authorization in the related art, and the authentication and authorization processes thereof are not described in detail in this embodiment.

[0090] Further, after obtaining the authentication and authorization result, the terminal can establish a secure communication connection with the network side based on the key obtained from the network side after authentication and authorization. Alternatively, after obtaining the authentication and authorization result, the terminal can also send the authentication and authorization result to the target user card, so that the target user card can record and feed back the use of the target authentication and authorization manner.

[0091] In the above authentication and authorization method, the terminal side receives the authentication and authorization subscription information sent by the network side, wherein the authentication and authorization subscription information is stored in the network side and corresponds to the target user card carried by the terminal. Then, based on the authentication and authorization subscription information, the target authentication and authorization manner corresponding to the to-be-authenticated application on the terminal is determined. Further, the to-be-authenticated application is authenticated and authorized by using the target authentication and authorization manner, and an authentication and authorization result is obtained. That is, in this embodiment, when the terminal application performs authentication and authorization, the terminal can first obtain the authentication and authorization subscription information corresponding to the target user card carried by the terminal from the network side, so that the terminal can determine the actual authentication and authorization manner corresponding to the target user card. Then, the terminal can determine the target authentication and authorization manner corresponding to the to-be-authenticated application based on the authentication and authorization manner corresponding to the target user card. The to-be-authenticated application is authenticated and authorized based on the target authentication and authorization manner. Since the terminal has determined the authentication and authorization manner configured by the network side for the target user card, the terminal can accurately invoke the corresponding authentication and authorization service, thereby achieving accurate authentication and authorization of the to-be-authenticated application. This can not only avoid the problem of authentication failure caused by the terminal invoking invalid authentication and authorization service, but also avoid the problem of authentication failure caused by the inconsistency between the terminal and the network side. Therefore, by using this method, the success rate and reliability of authentication and authorization can be greatly improved, and the efficiency of authentication and authorization can be improved.

[0092] Figure 3Figure 1 is a flowchart illustrating a method for authenticating a terminal in an embodiment. The embodiment relates to a method for authenticating a terminal. The method comprises the following steps. Figure 3 As shown in Figure 1, the step 102 comprises the following steps.

[0093] The step 202 comprises the following steps.

[0094] The encrypted data message carries the authentication subscription information of the target user card.

[0095] For example, after the network side completes the authentication configuration of the target user card, the authentication subscription information of the target user card can be sent to the short message service gateway, so as to instruct the short message service gateway to send the authentication subscription information of the target user card to the target user card in the form of a data message, or to the terminal carrying the target user card.

[0096] For example, the encrypted data message carrying the authentication subscription information of the target user card sent by the short message service gateway can be set to be invisible to the user, and only needs to be stored in the target user card or the terminal, so that the terminal can obtain the authentication subscription information of the target user card from the encrypted data message, and then perform authentication on the to-be-authenticated application on the terminal based on the authentication subscription information of the target user card.

[0097] The step 304 comprises the following steps.

[0098] For example, when the terminal needs to authenticate the to-be-authenticated application, the terminal can parse the encrypted data message to obtain the authentication subscription information of the target user card. Of course, the terminal can also parse the encrypted data message sent by the short message service gateway of the network side to obtain the authentication subscription information of the target user card from the encrypted data message. Then, the terminal can store the authentication subscription information of the target user card locally, for example, in the target user card or in a preset storage space of the terminal. The embodiment does not make a specific limitation on this.

[0099] In this embodiment, the terminal receives the encrypted data message sent by the network side short message service gateway, and the encrypted data message carries the authentication subscription information of the target user card carried by the terminal. Then, the authentication subscription information of the target user card carried by the terminal is obtained by analyzing the encrypted data message. That is, in this embodiment, after completing the authentication configuration of the target user card, the network side sends the authentication subscription information of the target user card to the target user card in the form of a data message, or to the terminal carrying the target user card; so that the terminal can clearly know the actual authentication mode configured by the network side for the target user card, so that the terminal can accurately call the authentication service, realize the authentication of the application, improve the success rate of authentication, and further improve the authentication efficiency. In addition, in this embodiment, the authentication subscription information of the target user card is sent to the target user card in the form of a data message, or to the terminal carrying the target user card, which can realize information sharing of the configuration information of the network side and the target user card or the terminal, and can improve the security and reliability of data transmission in the case that the terminal does not establish a secure communication connection with the network side.

[0100] In one embodiment, the authentication subscription information described above can include at least one authentication mode corresponding to the target user card and the support attribute of each authentication mode; wherein the support attribute of the authentication mode can be used to represent whether the target user card supports the authentication mode. For example: the authentication subscription information can include the GBA authentication mode, and the support attribute is support, the AKMA authentication mode, and the support attribute is not supported; or the authentication subscription information can include the GBA authentication mode, and the support attribute is not supported, the AKMA authentication mode, and the support attribute is supported; or the authentication subscription information can include the GBA authentication mode, and the support attribute is support, the AKMA authentication mode, and the support attribute is support.

[0101] For example, on the basis of the above-mentioned embodiments, as shown in Figure 4 The step 204 of determining the target authentication mode corresponding to the application to be authenticated on the terminal based on the authentication subscription information can include:

[0102] Step 402: According to the support attribute of each authentication mode, determine the candidate authentication mode from at least one authentication mode.

[0103] The candidate authentication mode includes one or more authentication modes supported by the target user card.

[0104] Exemplarily, the terminal can filter out, from the at least one authentication manner, an authentication manner whose support attribute represents that the target user card supports the authentication manner, as a candidate authentication manner, according to the support attributes of the authentication manners; for example, the authentication manner with the support attribute of "support" can be filtered out as the candidate authentication manner.

[0105] At step 404, a target authentication manner corresponding to the application to be authenticated on the terminal is determined from the candidate authentication manners according to usage information of the candidate authentication manners.

[0106] The usage information of the authentication manner can include, but is not limited to, the number of uses, the number of authentication successes, the number of authentication failures, the authentication success rate, the authentication success rate in a certain period of time, the frequency of use in a certain period of time, and the like.

[0107] Exemplarily, in the case where the candidate authentication manners include multiple authentication manners, the terminal can determine a target authentication manner corresponding to the application to be authenticated on the terminal from the multiple candidate authentication manners according to the usage information of the candidate authentication manners; here, in determining the target authentication manner from the multiple candidate authentication manners based on the usage information of the authentication manners, the determination can be based on one usage information, or can be based on a comprehensive screening judgment of multiple usage information, and the like; the embodiments of the present application do not make specific limitations thereto.

[0108] Exemplarily, in the case where the usage information includes the authentication success rate, the terminal can obtain the authentication success rate corresponding to each candidate authentication manner, and determine a candidate authentication manner with the highest authentication success rate as the target authentication manner corresponding to the application to be authenticated on the terminal according to the authentication success rate corresponding to each candidate authentication manner.

[0109] Exemplarily, in the case where the usage information includes the frequency of use, the terminal can also obtain the frequency of use corresponding to each candidate authentication manner, and determine a candidate authentication manner with the highest frequency of use as the target authentication manner corresponding to the application to be authenticated on the terminal according to the frequency of use corresponding to each candidate authentication manner.

[0110] Exemplarily, in the case where the usage information includes the authentication success rate and the frequency of use, the terminal can also obtain the authentication success rate and the frequency of use corresponding to each candidate authentication manner, and determine a candidate authentication manner with an authentication success rate greater than a preset authentication success rate threshold and a frequency of use greater than a preset frequency threshold as the target authentication manner corresponding to the application to be authenticated on the terminal according to the authentication success rate and the frequency of use corresponding to each candidate authentication manner.

[0111] That is, the terminal can set a filtering condition based on different use information, so as to obtain a condition filtering strategy, so as to filter out a candidate authentication mode meeting the condition as the target authentication mode corresponding to the to-be-authenticated application on the terminal based on the condition filtering strategy.

[0112] Further, after obtaining an authentication result by authenticating the to-be-authenticated application based on the target authentication mode, the terminal can update the use information corresponding to the target authentication mode according to the authentication result; for example, in the case of successful authentication, the use frequency, the number of successful authentications, the authentication success rate, and the like of the target authentication mode can be updated.

[0113] In addition, it should be noted that, in the case that the authentication subscription information of the target user card and the use information of each authentication mode are stored in the target user card, the terminal can also instruct the target user card to determine the target authentication mode corresponding to the to-be-authenticated application on the terminal based on the authentication subscription information; that is, the target authentication mode is determined by the target user card, and the target authentication mode is fed back to the terminal, so that the terminal authenticates the to-be-authenticated application based on the target authentication mode.

[0114] For example, if the to-be-authenticated application has a default authentication mode, that is, the to-be-authenticated application has its own supported authentication mode, based on the above embodiment, as shown in the following table, the step 204 of determining the target authentication mode corresponding to the to-be-authenticated application on the terminal based on the authentication subscription information can further include: Figure 5

[0115] Step 502, obtaining a preset authentication mode corresponding to the to-be-authenticated application.

[0116] Step 504, determining whether the preset authentication mode is included in the authentication subscription information.

[0117] Step 506, if the preset authentication mode is included in the authentication subscription information, determining whether the target user card supports the preset authentication mode according to the support attribute of the preset authentication mode.

[0118] Step 508, if the target user card supports the preset authentication mode, determining the preset authentication mode as the target authentication mode corresponding to the to-be-authenticated application on the terminal.

[0119] ​That is, in the embodiment, the target authentication mode used by the terminal to authenticate the application to be authenticated can be determined according to the authentication mode supported by the target user card and the authentication mode supported by the application to be authenticated. If the preset authentication mode supported by the application to be authenticated is also the authentication mode supported by the target user card, that is, the preset authentication mode supported by the application to be authenticated and the authentication mode supported by the target user card have the same authentication mode, then the authentication is successful to a great extent when the preset authentication mode is used to authenticate the application to be authenticated.

[0120] On the contrary, if the preset authentication mode supported by the application to be authenticated and the authentication mode supported by the target user card do not have the same authentication mode, then the authentication is likely to fail whether the preset authentication mode supported by the application to be authenticated or the authentication mode supported by the target user card is used.

[0121] Therefore, when the target authentication mode corresponding to the application to be authenticated on the terminal is determined by using the method in the embodiment, it can be determined in advance whether the application to be authenticated and the target user card have the same authentication mode. If they have the same authentication mode, the same authentication mode is used, which can greatly improve the success rate of authentication. If the application to be authenticated and the target user card do not have the same authentication mode, the authentication mode supported by the application to be authenticated or the target user card can be adjusted based on a preset solution strategy, so that the application to be authenticated and the target user card support the same authentication mode, thereby successfully authenticating the application to be authenticated. The authentication failure caused by the terminal using an invalid authentication mode to authenticate the application to be authenticated is avoided, the terminal performs invalid authentication operations, the number of authentications of the terminal is reduced, and the authentication efficiency is improved.

[0122] In addition, it should be noted that the processes described in steps 502 to 508 are only one implementation of determining the authentication and authorization mode of the application to be authenticated and the target user card. Of course, the process can also include: obtaining the preset authentication and authorization mode corresponding to the application to be authenticated, and determining the candidate authentication and authorization mode supported by the target user card from at least one authentication and authorization mode according to the support attributes of each authentication and authorization mode; then, judging whether the candidate authentication and authorization mode includes the preset authentication and authorization mode corresponding to the application to be authenticated, if yes, it means that the application to be authenticated and the target user card have the same authentication and authorization mode, then the terminal can authenticate the application to be authenticated based on the same authentication and authorization mode; if the candidate authentication and authorization mode does not include the preset authentication and authorization mode corresponding to the application to be authenticated, it means that the application to be authenticated and the target user card do not have the same authentication and authorization mode, at this time, a preset solution strategy can be used to adjust the authentication and authorization mode supported by the application to be authenticated or the target user card, so that the application to be authenticated and the target user card have the same authentication and authorization mode, and finally the authentication and authorization of the application to be authenticated is realized.

[0123] In one embodiment, as shown in Figure 6 , an authentication and authorization method is provided. Taking the network side in Figure 1 as an example, the method includes the following steps:

[0124] Step 602: Obtain the authentication and authorization subscription information corresponding to the target user card.

[0125] For example, the network side can receive the authentication and authorization subscription information sent by the target user card, or receive the authentication and authorization subscription information of the target user card sent by the operator server corresponding to the target user card, etc.

[0126] For example, the network side can also receive the authentication and authorization configuration request corresponding to the target user card sent by the target user card or the operator server, configure the authentication and authorization mode of the target user card based on the authentication and authorization configuration request; and after the configuration is completed, generate the authentication and authorization subscription information corresponding to the target user card.

[0127] Step 604: Send the authentication and authorization subscription information corresponding to the target user card to the terminal corresponding to the target user card.

[0128] Exemplarily, the network side can send the authentication and subscription information corresponding to the target user card to the target user card or the terminal carrying the target user card based on the network connection between the terminal or the target user card and the network side. Alternatively, the network side can also send an encrypted data short message carrying the authentication and subscription information corresponding to the target user card to the target user card or the terminal carrying the target user card through the short message service gateway of the network side, so that the terminal or the target user card can obtain the authentication and subscription information corresponding to the target user card by analyzing the encrypted data short message when receiving the encrypted data short message.

[0129] The authentication and subscription information can be used to instruct the terminal to determine the target authentication and subscription mode corresponding to the to-be-authenticated application on the terminal based on the authentication and subscription information, and to authenticate the to-be-authenticated application by using the target authentication and subscription mode to obtain an authentication and subscription result. Exemplarily, if the authentication and subscription information corresponding to the target user card is stored in the target user card, the terminal can obtain the authentication and subscription information corresponding to the target user card from the target user card, and then determine the target authentication and subscription mode corresponding to the to-be-authenticated application on the terminal based on the authentication and subscription information, and authenticate the to-be-authenticated application by using the target authentication and subscription mode to obtain an authentication and subscription result. Alternatively, the terminal can also instruct the target user card to determine the target authentication and subscription mode corresponding to the to-be-authenticated application on the terminal based on the authentication and subscription information, and feed back the target authentication and subscription mode to the terminal; so that the terminal can authenticate the to-be-authenticated application by using the target authentication and subscription mode to obtain an authentication and subscription result.

[0130] The specific implementation process can also be described with reference to the related content in the above-mentioned embodiments, which will not be repeated here. Figure 2

[0131] ​In the embodiment, the network side acquires the authentication and authorization subscription information corresponding to the target user card, and sends the authentication and authorization subscription information corresponding to the target user card to the terminal corresponding to the target user card. The authentication and authorization subscription information is used to instruct the terminal to determine the target authentication and authorization mode corresponding to the to-be-authenticated application on the terminal based on the authentication and authorization subscription information, and to authenticate the to-be-authenticated application by using the target authentication and authorization mode to obtain an authentication and authorization result. That is, in the embodiment, the network side can not only configure the authentication and authorization of the target user card, but also send the authentication and authorization subscription information of the target user card to the terminal corresponding to the target user card, so that the terminal carrying the target user card can determine the actual authentication and authorization mode corresponding to the target user card. Then, the terminal can determine the target authentication and authorization mode corresponding to the to-be-authenticated application based on the authentication and authorization mode corresponding to the target user card, and authenticate the to-be-authenticated application based on the target authentication and authorization mode. Since the terminal has determined the authentication and authorization mode configured by the network side for the target user card, the terminal can accurately invoke the corresponding authentication and authorization service, thereby achieving accurate authentication and authorization of the to-be-authenticated application. The method can not only avoid the problem of authentication failure caused by the terminal invoking invalid authentication and authorization service, but also avoid the problem of authentication failure caused by the inconsistency between the terminal and the network side. Therefore, the method can greatly improve the success rate and reliability of authentication and authorization, and improve the efficiency of authentication and authorization.

[0132] In one embodiment, the step of acquiring the authentication and authorization subscription information corresponding to the target user card in step 602 can include: sending an authentication and authorization configuration request to a signaling processing network element of the network side by a customer relationship management network element (CRM) of the network side. The authentication and authorization configuration request can carry the subscription information of the target user card. The signaling processing network element can include a home subscriber server (HSS), a unified data management (UDM), etc. Then, the HSS / UDM of the signaling processing network element performs authentication and authorization configuration on the target user card based on the subscription information of the target user card, and sends a configuration result to the CRM of the customer relationship management network element. Further, the CRM of the customer relationship management network element generates the authentication and authorization subscription information corresponding to the target user card based on the configuration result.

[0133] Exemplarily, the authentication subscription information can include at least one authentication mode corresponding to the target user card and a support attribute of each authentication mode; the support attribute can be used to represent whether the target user card supports the authentication mode; the support attribute is used to instruct the terminal to determine a candidate authentication mode from the at least one authentication mode according to the support attribute of each authentication mode; the candidate authentication mode includes an authentication mode supported by the target user card; and a target authentication mode corresponding to the terminal-side to-be-authenticated application is determined from the candidate authentication mode according to usage information of the candidate authentication mode.

[0134] In one embodiment, the step of sending the authentication subscription information corresponding to the target user card to the terminal corresponding to the target user card in step 604 can include: sending a data encryption request to a trusted service management network element (TSM) through a customer relationship management network element (CRM); the data encryption request carries the authentication subscription information corresponding to the target user card; then, the authentication subscription information corresponding to the target user card is encrypted by the TSM to obtain encrypted data short message corresponding to the target user card, and the encrypted data short message corresponding to the target user card is sent to the CRM; the encrypted data short message corresponding to the target user card is sent to a short message service center (SMSC) on the network side by the CRM; and the encrypted data short message corresponding to the target user card is sent to the terminal corresponding to the target user card in the form of a data short message by the SMSC; so that the terminal can obtain the authentication subscription information of the target user card after decrypting and parsing the encrypted data short message.

[0135] In one embodiment, a complete embodiment of an authentication method is provided. In this embodiment, after setting or updating GBA USS (GBA User Security Setting) or AKMA indication information in the HSS / UDM network element, a data short message of related configuration information can be sent to the user card, the application on the terminal can obtain the network-side subscription configuration information from the user card through the machine-card interface, and then initiate the corresponding application layer authentication; in addition, after the authentication process is completed, the actual capability support information can be further fed back to the user card according to the authentication result; the terminal side can adapt to multiple guided authentication services, effectively improve the success rate and availability of the application layer guided authentication, and further improve the authentication efficiency.

[0136] Reference Figure 7 As shown in the figure, the authentication configuration and the workflow of the authentication are shown, including the following steps:

[0137] Step 1, configure the GUSS or AKMA service indication to the HSS / UDM network element through the CRM network element, and send the data short message of the related configuration information to the user card after the HSS / UDM network element completes the configuration;

[0138] Step 2, encrypt the data short message through the TSM network element and send it to the user card (Universal Integrated Circuit Card, UICC);

[0139] Step 3, the user card UICC saves the subscribed bootstrapping authentication service information;

[0140] Step 4, when the user terminal (User Equipment, UE) wants to request GBA authentication service or AKMA authentication service, read the authentication subscription information from the user card UICC through the card interface, and if a certain authentication service is subscribed, initiate an authentication request for the authentication service;

[0141] If the GBA authentication service is subscribed, initiate an authentication request to the network application function (Network Application Function, NAF) network element; if the AKMA authentication service is subscribed, initiate an authentication request to the application function (Application Function, AF) network element.

[0142] Step 5, the user terminal further feeds back the actual capability support information to the user card according to the authentication result, so as to improve the availability of the application authentication service.

[0143] Among them, referring to Figure 8 As shown in the figure, the adaptive workflow of the application layer bootstrapping authentication can include the following steps:

[0144] Step 1, send the user card corresponding new or updated bootstrapping authentication subscription information to the HSS network element and / or UDM network element through the CRM network element;

[0145] Step 2, after the HSS / UDM network element completes the configuration of the user card subscription information, encapsulate the subscription update data short message through the CRM network element; the data short message can carry authentication subscription information, wherein the authentication subscription information can include at least one authentication method corresponding to the user card and the support attribute of each authentication method;

[0146] Step 3, call the data short message encryption interface of the TSM network element through the CRM network element to generate an encrypted data short message; that is, an encrypted subscription update data short message;

[0147] Step 4, sending the encrypted subscription update data short message to the SMSC gateway through the CRM network element, and sending the encrypted subscription update data short message to the user card through the SMSC gateway;

[0148] Step 5, after receiving the encrypted subscription update data short message, the user card performs decryption processing to obtain the authentication subscription information of the user card, and saves it in the related storage file in the card.

[0149] Next, referring to FIG. 8, for the workflow of the application layer bootstrap authentication and availability feedback, the following steps can be included: Figure 9

[0150] Step 1, the terminal application queries the user card for application layer bootstrap authentication subscription data through the card interface;

[0151] Step 2, the user card returns the available bootstrap authentication subscription type to the terminal application; that is, the user card can feed back the authentication mode supported by the user card to the terminal application;

[0152] Step 3, if the GBA subscription is available, perform the GBA authentication process; including the following steps:

[0153] Step a1, the terminal application initiates an initial service request to the NAF network element, which can carry an authentication type identifier (i.e., GBA authentication identifier) and a host address; the host address can be the server address that the application wants to connect to;

[0154] Step a2, the NAF network element responds to the initial service request by feeding back an unauthorized result to the terminal and instructing the terminal to perform bootstrap authentication; the terminal completes the GBA bootstrap authentication and derives the corresponding application key;

[0155] Step a3, the terminal initiates a service request carrying B-TID (the identifier information corresponding to this bootstrap authentication transaction) to the NAF network element again, and the NAF network element requests the application key corresponding to the B-TID from the service function network element (Bootstrapping Server Function, BSF);

[0156] Step a4, the end user terminal and the NAF network element both hold the same application key, and establish an application session based on the application key to perform secure communication;

[0157] Step 4, if the AKMA service subscription is available, perform the AKMA authentication process; including the following steps:

[0158] ​Step b1, the user terminal obtains a key K from an authentication server function (AUSF) in the main authentication AUSF and derives an intermediate key K AKMA and a key identifier A-KID, and initiates an application session establishment request to the AF network element, carrying the key identifier A-KID;

[0159] Step b2, the AF network element carries the key identifier A-KID and the AF network element identifier AF_ID, and requests an application key K AF from an anchor function network element (AAnF);

[0160] Step b3, the user terminal also derives an application key K AKMA from the intermediate key K AF according to the same rule;

[0161] Step b4, the end user terminal and the AF network element both hold the same application key K AF , and establish an application session based on the application key K AF for secure communication;

[0162] Step 5, the terminal application feeds back the availability of the bootstrapping authentication service to the user card through the card interface according to the authentication result;

[0163] Step 6, the user card updates the number of successes or failures of the corresponding authentication method, which can be used as a consideration factor for subsequent authentication service strategy.

[0164] The authentication method proposed in the embodiments of the application can make the user terminal know which bootstrapping authentication service the user card mounted thereon subscribes on the network side, so that the terminal can select to initiate which bootstrapping authentication request according to the obtained subscription information in the case of mixed deployment or separate deployment of GBA and AKMA application layer authentication methods. In addition, the result of the bootstrapping authentication is fed back to the user card in real time, so that the user terminal can further feed back the actual capability support information to the user card according to the authentication result, which can further improve the availability of the application authentication service and provide data support for subsequent bootstrapping authentication service strategy. The accuracy and efficiency of the authentication are improved.

[0165] In one embodiment, a complete embodiment of an authentication method is also provided. It includes the following steps:

[0166] Step 1, send the newly added or updated bootstrapping authentication subscription information of the user card to the HSS network element and / or the UDM network element through the CRM network element;

[0167] Step 2, after the HSS / UDM network element completes the subscription information configuration of the user card, encapsulate the subscription update data short message through the CRM network element; The data short message can carry authentication subscription information, wherein the authentication subscription information can include at least one authentication method corresponding to the user card and the support attribute of each authentication method;

[0168] Step 3, call the data short message encryption interface of the TSM network element through the CRM network element to generate an encrypted data short message; That is, the encrypted subscription update data short message;

[0169] Step 4, send the encrypted subscription update data short message to the SMSC gateway through the CRM network element, and send the encrypted subscription update data short message to the user card through the SMSC gateway;

[0170] Step 5, after receiving the encrypted subscription update data short message, the user card decrypts it, obtains the authentication subscription information of the user card, and saves it in the card file.

[0171] Step 6, the terminal application queries the application layer boot authentication subscription data from the user card through the card interface;

[0172] Step 7, the user card returns the available boot authentication subscription type to the terminal application;

[0173] Step 8, if the GBA subscription is available, execute the GBA authentication process; Including the following steps:

[0174] Step a1, the terminal application initiates an initial service request to the NAF network element; The initial service request can carry an authentication type identifier (i.e. GBA authentication identifier) and a host address; Here, the host address can be the server address that the application wants to connect to;

[0175] Step a2, the NAF network element responds to the initial service request and feeds back an unauthorized result to the terminal, and instructs the terminal to perform boot authentication; The terminal completes the GBA boot authentication and derives the corresponding application key;

[0176] Step a3, the terminal initiates a service request carrying B-TID (the identifier information corresponding to this boot authentication transaction) to the NAF network element again, and the NAF network element requests the application key corresponding to B-TID from the BSF network element;

[0177] Step a4, the end user terminal and the NAF network element both hold the same application key, and establish an application session based on the application key for secure communication;

[0178] Step 9, if the AKMA service subscription is available, execute the AKMA authentication process; Including the following steps:

[0179] Step b1, the user terminal obtains the key K from the main authentication AUSF network element AUSF and derives the intermediate key K AKMA and the key identifier A-KID, and initiates an application session establishment request to the AF network element carrying the key identifier A-KID;

[0180] Step b2, the AF network element carries the key identifier A-KID and the AF network element identifier AF_ID to request the application key K AF from the AAnF network element;

[0181] Step b3, the user terminal also derives the application key K AKMA from the intermediate key K AF according to the same rule;

[0182] Step b4, the end user terminal and the AF network element both hold the same application key K AF , and establish an application session based on the application key K AF for secure communication;

[0183] Step 10, the terminal application feeds back the availability of the bootstrapping authentication service to the user card through the card interface according to the authentication result.

[0184] Step 11, the user card updates the success or failure number of the corresponding authentication mode, which can be used as a consideration factor for subsequent authentication service policy.

[0185] In this embodiment, the network side bootstrapping authentication service subscription information can be sent to the user card through data short message, and the user terminal can know from the user card which bootstrapping authentication service is subscribed. In the case of mixed deployment or separate deployment of GBA and AKMA two application layer authentication modes, the user terminal can select to initiate which bootstrapping authentication request according to the obtained subscription information. In addition, the result of bootstrapping authentication is fed back in real time, i.e. the user terminal further feeds back the actual capability support information to the user card according to the authentication result, which can further improve the availability of the application authentication service, and also provide data support for the subsequent bootstrapping authentication service policy.

[0186] It should be understood that although the steps in the flowcharts involved in the embodiments described above are shown in sequence according to the arrows, the steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, the execution of the steps is not strictly limited in sequence, and the steps can be executed in other orders. Moreover, at least some of the steps in the flowcharts involved in the embodiments described above can include multiple steps or multiple stages, which are not necessarily executed at the same time but can be executed at different times, and the execution of the steps or stages is not necessarily sequential but can be performed alternately or alternately with at least part of other steps or steps or stages in other steps.

[0187] Based on the same inventive concept, the embodiments of the present application also provide an authentication and authorization device for implementing the authentication and authorization method described above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme described in the above method, so the specific limitations in one or more authentication and authorization device embodiments provided below can refer to the limitations of the authentication and authorization method described above, which will not be repeated here.

[0188] In one embodiment, as shown in Figure 10 An authentication and authorization device is provided, applied to a terminal, comprising: a receiving module 1002, a determining module 1004, and an authentication and authorization module 1006, wherein:

[0189] The receiving module 1002 is configured to receive authentication and authorization subscription information sent by the network side; the authentication and authorization subscription information is stored on the network side and corresponds to a target user card carried by the terminal.

[0190] The determining module 1004 is configured to determine a target authentication and authorization mode corresponding to an application to be authenticated on the terminal based on the authentication and authorization subscription information.

[0191] The authentication and authorization module 1006 is configured to authenticate the application to be authenticated using the target authentication and authorization mode to obtain an authentication and authorization result.

[0192] In one embodiment, the receiving module 1002 comprises:

[0193] The receiving unit is configured to receive an encrypted data short message sent by a short message service gateway of the network side; the encrypted data short message carries authentication and authorization subscription information of a target user card carried by the terminal.

[0194] The parsing unit is configured to parse the encrypted data short message to obtain the authentication and authorization subscription information of the target user card carried by the terminal.

[0195] In one of the embodiments, the authentication subscription information includes at least one authentication mode corresponding to the target user card and support attributes of the authentication modes; the support attributes are used to represent whether the target user card supports the authentication mode; the determining module 1004 includes:

[0196] The first determining unit is configured to determine a candidate authentication mode from the at least one authentication mode according to the support attributes of the authentication modes; the candidate authentication mode includes an authentication mode supported by the target user card;

[0197] The second determining unit is configured to determine a target authentication mode corresponding to the application to be authenticated on the terminal from the candidate authentication mode according to the usage information of the candidate authentication mode.

[0198] In one of the embodiments, the usage information includes an authentication success rate; if the candidate authentication mode includes multiple authentication modes, the second determining unit includes:

[0199] The obtaining subunit is configured to obtain the authentication success rate corresponding to each candidate authentication mode;

[0200] The determining subunit is configured to determine, according to the authentication success rates corresponding to the candidate authentication modes, the candidate authentication mode with the highest authentication success rate as the target authentication mode corresponding to the application to be authenticated on the terminal.

[0201] In one of the embodiments, the apparatus further includes:

[0202] The updating module is configured to update the authentication success rate corresponding to the target authentication mode according to the authentication result.

[0203] In one of the embodiments, the authentication subscription information includes at least one authentication mode corresponding to the target user card and support attributes of the authentication modes; the support attributes are used to represent whether the target user card supports the authentication mode; the determining module 1004 includes:

[0204] The obtaining unit is configured to obtain a preset authentication mode corresponding to the application to be authenticated;

[0205] The judging unit is configured to judge whether the authentication subscription information includes the preset authentication mode;

[0206] The third determining unit is configured to, in the case where the authentication subscription information includes the preset authentication mode, determine whether the target user card supports the preset authentication mode according to the support attribute of the preset authentication mode;

[0207] The fourth determining unit is configured to determine the preset authentication mode as the target authentication mode corresponding to the application to be authenticated on the terminal in a case where the target user card supports the preset authentication mode.

[0208] In one embodiment, as shown in Figure 11 An authentication device is provided, applied to a network side, and includes an obtaining module 1102 and a sending module 1104.

[0209] The obtaining module 1102 is configured to obtain authentication subscription information corresponding to a target user card.

[0210] The sending module 1104 is configured to send the authentication subscription information corresponding to the target user card to a terminal corresponding to the target user card; the authentication subscription information is used to instruct the terminal to determine a target authentication mode corresponding to an application to be authenticated on the terminal based on the authentication subscription information, and to perform authentication on the application to be authenticated by using the target authentication mode to obtain an authentication result.

[0211] In one embodiment, the obtaining module 1102 includes:

[0212] The first sending unit is configured to send an authentication configuration request to a signaling processing network element on the network side through a customer relationship management network element on the network side; the authentication configuration request carries subscription information of the target user card.

[0213] The authentication configuration unit is configured to perform authentication configuration on the target user card based on the subscription information of the target user card through the signaling processing network element, and to send a configuration result to the customer relationship management network element.

[0214] The generating unit is configured to generate authentication subscription information corresponding to the target user card based on the configuration result through the customer relationship management network element.

[0215] In one embodiment, the sending module 1104 includes:

[0216] The second sending unit is configured to send a data encryption request to a trusted service management network element through the customer relationship management network element; the data encryption request carries the authentication subscription information corresponding to the target user card.

[0217] The encryption unit is configured to perform encryption processing on the authentication subscription information corresponding to the target user card through the trusted service management network element to obtain encrypted data short messages corresponding to the target user card, and to send the encrypted data short messages corresponding to the target user card to the customer relationship management network element.

[0218] The third sending unit is configured to send the encrypted data short messages corresponding to the target user card to a short message service gateway on the network side through the customer relationship management network element.

[0219] The fourth sending unit is used to send the encrypted data SMS corresponding to the target user card to the terminal corresponding to the target user card in the form of a data SMS through the short message service gateway.

[0220] In one embodiment, the authentication subscription information includes at least one authentication method corresponding to the target user card and support attributes for each authentication method; the support attributes are used to characterize whether the target user card supports the authentication method; the support attributes are used to instruct the terminal to determine a candidate authentication method from the at least one authentication method based on the support attributes of each authentication method; the candidate authentication methods include authentication methods supported by the target user card; and the target authentication method corresponding to the application to be authenticated on the terminal is determined from the candidate authentication methods based on the usage information of the candidate authentication methods.

[0221] Each module in the aforementioned authentication device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.

[0222] In one embodiment, a computer device is provided, which may be a terminal device on the terminal side, and its internal structure diagram may be as follows: Figure 12 As shown, the computer device includes a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a terminal-side authentication method. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad mounted on the computer device casing, or an external keyboard, touchpad, or mouse.

[0223] In one embodiment, a computer device is also provided, which may be a network device on the network side, and its internal structure diagram may be as follows: Figure 13As shown, the computer device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores configuration data related to different user cards, including but not limited to authentication and subscription data. The network interface communicates with external terminals via a network connection. When executed by the processor, the computer program implements an authentication method.

[0224] Those skilled in the art will understand that Figure 12 and 13 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0225] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the authentication method in any of the embodiments corresponding to the terminal side described above.

[0226] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the authentication method in any of the above-described network-side embodiments.

[0227] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, which, when executed by a processor, implements the steps of the authentication method in any of the embodiments corresponding to the terminal side or the network side described above.

[0228] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the authentication method in any of the embodiments corresponding to the terminal side or network side described above.

[0229] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0230] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when the computer program is executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (Read-Only Memory, ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive memory (ReRAM), magnetoresistive random access memory (Magnetoresistive Random Access Memory, MRAM), ferroelectric memory (Ferroelectric Random Access Memory, FRAM), phase change memory (Phase Change Memory, PCM), graphene memory, etc. Volatile memory can include random access memory (Random Access Memory, RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (Static Random Access Memory, SRAM) or dynamic random access memory (Dynamic Random Access Memory, DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., without being limited thereto.

[0231] Any combination of the technical features of the above embodiments can be made. In order to make the description simple, all possible combinations of the technical features in the above embodiments are not described, however, as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the present application.

[0232] The above embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent of the present application. It should be pointed out that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A method of authenticating an authentication, characterized by, Applied to a terminal, the method comprises: Receiving authentication and subscription information sent by a network side; the authentication and subscription information is stored in the network side and corresponds to a target user card carried by the terminal; Based on the authentication and subscription information, determining a target authentication and subscription mode corresponding to an application to be authenticated on the terminal; Using the target authentication and subscription mode to authenticate the application to be authenticated, and obtaining an authentication result; The authentication and subscription information includes at least one authentication and subscription mode corresponding to the target user card and a support attribute of each authentication and subscription mode; the support attribute is used to represent whether the target user card supports the authentication and subscription mode; based on the authentication and subscription information, determining a target authentication and subscription mode corresponding to an application to be authenticated on the terminal comprises: According to the support attribute of each authentication and subscription mode, determining a candidate authentication and subscription mode from the at least one authentication and subscription mode; the candidate authentication and subscription mode includes an authentication and subscription mode supported by the target user card; according to the use information of the candidate authentication and subscription mode, determining a target authentication and subscription mode corresponding to an application to be authenticated on the terminal from the candidate authentication and subscription mode; Or, Obtaining a preset authentication and subscription mode corresponding to the application to be authenticated; judging whether the authentication and subscription information includes the preset authentication and subscription mode; if the authentication and subscription information includes the preset authentication and subscription mode, determining whether the target user card supports the preset authentication and subscription mode according to the support attribute of the preset authentication and subscription mode; if the target user card supports the preset authentication and subscription mode, determining the preset authentication and subscription mode as a target authentication and subscription mode corresponding to an application to be authenticated on the terminal.

2. The method of claim 1, wherein, The receiving authentication and subscription information sent by the network side comprises: Receiving an encrypted data short message sent by a short message service gateway of the network side; the encrypted data short message carries authentication and subscription information of a target user card carried by the terminal; Analyzing the encrypted data short message to obtain the authentication and subscription information of the target user card carried by the terminal.

3. The method of claim 1, wherein, The use information includes an authentication success rate; if the candidate authentication and subscription mode includes multiple, according to the use information of the candidate authentication and subscription mode, determining a target authentication and subscription mode corresponding to an application to be authenticated on the terminal from the candidate authentication and subscription mode comprises: Obtaining an authentication success rate corresponding to each candidate authentication and subscription mode; According to the authentication success rate corresponding to each candidate authentication and subscription mode, determining a candidate authentication and subscription mode with the highest authentication success rate as a target authentication and subscription mode corresponding to an application to be authenticated on the terminal.

4. The method of claim 3, wherein, The method further comprises: According to the authentication result, updating an authentication success rate corresponding to the target authentication and subscription mode.

5. An authentication method, characterized by, Applied to a network side, the method comprises: Obtaining authentication and subscription information corresponding to a target user card; sending the authentication and authorization subscription information corresponding to the target user card to the terminal corresponding to the target user card; the authentication and authorization subscription information is used to instruct the terminal to determine a target authentication and authorization mode corresponding to a to-be-authenticated application on the terminal based on the authentication and authorization subscription information, and to authenticate the to-be-authenticated application by using the target authentication and authorization mode to obtain an authentication and authorization result; the authentication and authorization subscription information includes at least one authentication and authorization mode corresponding to the target user card and support attributes of each authentication and authorization mode; the support attributes are used to represent whether the target user card supports the authentication and authorization mode; the support attributes are used to instruct the terminal to determine a candidate authentication and authorization mode from the at least one authentication and authorization mode according to the support attributes of each authentication and authorization mode; the candidate authentication and authorization mode includes an authentication and authorization mode supported by the target user card; and a target authentication and authorization mode corresponding to the to-be-authenticated application on the terminal is determined from the candidate authentication and authorization mode according to usage information of the candidate authentication and authorization mode.

6. The method of claim 5, wherein, the authentication and authorization subscription information corresponding to the target user card is obtained by: sending, by the customer relationship management network element on the network side, an authentication and authorization configuration request to a signaling processing network element on the network side; the authentication and authorization configuration request carries the subscription information of the target user card; performing, by the signaling processing network element, authentication and authorization configuration on the target user card based on the subscription information of the target user card, and sending a configuration result to the customer relationship management network element; generating, by the customer relationship management network element, the authentication and authorization subscription information corresponding to the target user card based on the configuration result.

7. The method of claim 6, wherein, the authentication and authorization subscription information corresponding to the target user card is sent to the terminal corresponding to the target user card by: sending, by the customer relationship management network element, a data encryption request to a trusted service management network element on the network side; the data encryption request carries the authentication and authorization subscription information corresponding to the target user card; performing, by the trusted service management network element, encryption processing on the authentication and authorization subscription information corresponding to the target user card to obtain encrypted data short messages corresponding to the target user card, and sending the encrypted data short messages corresponding to the target user card to the customer relationship management network element; sending, by the customer relationship management network element, the encrypted data short messages corresponding to the target user card to a short message service gateway on the network side; sending, by the short message service gateway, the encrypted data short messages corresponding to the target user card to the terminal corresponding to the target user card in the form of data short messages.

8. An authentication apparatus characterized by comprising: applied to a terminal, the apparatus comprises: a receiving module configured to receive authentication and authorization subscription information sent by a network side; the authentication and authorization subscription information is stored on the network side and corresponds to a target user card carried by the terminal; a determining module configured to determine a target authentication and authorization mode corresponding to a to-be-authenticated application on the terminal based on the authentication and authorization subscription information; The authentication and certification module is configured to perform authentication and certification on the application to be authenticated by using the target authentication and certification mode, and obtain an authentication and certification result. The authentication and certification subscription information includes at least one authentication and certification mode corresponding to the target user card and support attributes of each authentication and certification mode; the support attributes are used to represent whether the target user card supports the authentication and certification mode; and the target authentication and certification mode corresponding to the application to be authenticated on the terminal is determined based on the authentication and certification subscription information, including: The support attributes are used to determine a candidate authentication and certification mode from the at least one authentication and certification mode according to the support attributes of each authentication and certification mode; the candidate authentication and certification mode includes an authentication and certification mode supported by the target user card; and the target authentication and certification mode corresponding to the application to be authenticated on the terminal is determined from the candidate authentication and certification mode according to usage information of the candidate authentication and certification mode. Alternatively, A preset authentication and certification mode corresponding to the application to be authenticated is obtained; it is determined whether the preset authentication and certification mode is included in the authentication and certification subscription information; if the preset authentication and certification mode is included in the authentication and certification subscription information, it is determined whether the target user card supports the preset authentication and certification mode according to a support attribute of the preset authentication and certification mode; and if the target user card supports the preset authentication and certification mode, the preset authentication and certification mode is determined as the target authentication and certification mode corresponding to the application to be authenticated on the terminal.

9. An authentication apparatus characterized by comprising: The device applied to a network side includes: An acquisition module configured to acquire authentication and certification subscription information corresponding to a target user card; A sending module configured to send the authentication and certification subscription information corresponding to the target user card to a terminal corresponding to the target user card; the authentication and certification subscription information is used to instruct the terminal to determine a target authentication and certification mode corresponding to an application to be authenticated on the terminal based on the authentication and certification subscription information, and perform authentication and certification on the application to be authenticated by using the target authentication and certification mode, and obtain an authentication and certification result; The authentication and certification subscription information includes at least one authentication and certification mode corresponding to the target user card and support attributes of each authentication and certification mode; the support attributes are used to represent whether the target user card supports the authentication and certification mode; The support attributes are used to instruct the terminal to determine a candidate authentication and certification mode from the at least one authentication and certification mode according to the support attributes of each authentication and certification mode; the candidate authentication and certification mode includes an authentication and certification mode supported by the target user card; and the target authentication and certification mode corresponding to the application to be authenticated on the terminal is determined from the candidate authentication and certification mode according to usage information of the candidate authentication and certification mode. 10.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-9. The processor executes the computer program to implement the steps of the method in any one of claims 1 to 7.

11. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method in any one of claims 1 to 7.

12. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Acquisition method of authentication policy, authentication method, authentication device, communication device, base station and terminal

    CN101166363A

  • Extended universal boot architecture authentication method and device and storage medium

    CN114363890A