Processing Method, Terminal, System, and Storage Medium for Authenticating Capabilities
By introducing capability acquisition modules into the terminal, dynamic acquisition and storage authentication capabilities are solved, the complex requirements of terminal and user cards are improved, and the terminal coverage and availability of authentication applications are improved.
Patent Information
- Application Number
- CN202211174410.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-26
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-09-26
AI Technical Summary
The prior art is difficult to effectively solve the complex requirements of terminals and user cards, which makes it difficult to develop authentication applications or services on a large scale, and it is difficult to improve terminal coverage.
By introducing a capability acquisition module into the terminal, the authentication capability parameters sent by the capability detection platform are received, the corresponding authentication module is called, and the availability of authentication capability is determined based on the actual and expected call results, and the available authentication capability information is stored.
It realizes dynamic collection and storage of terminal authentication capabilities, masters the terminal's authentication capabilities support, facilitates application promotion, and improves terminal coverage and application availability.
Smart Images

Figure CN117768874B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of communication security technologies, and particularly to a processing method, a terminal, a system, and a storage medium for authentication capabilities. Background Art
[0002] Currently, when performing application authentication or identity authentication involving a terminal and a user card, there are strict requirements for the terminal software and hardware environment and the user card, such as:
[0003] (1) The type of the card, such as a Java card / NFC (Near Field Communication) card, a GBA (Generic Bootstrapping Architecture) card, or whether a specified card application is pre-installed, etc.;
[0004] (2) Whether the terminal environment meets the corresponding OS (Operating System) version, whether a specified APP (Application) is installed, or a specified SDK (Software Development Kit) is integrated;
[0005] (3) Whether the terminal-card channel is effective, especially the terminal-card channel of non-mobile terminals (such as in-vehicle terminals, etc.).
[0006] In the related art, if these complex requirements are to be met, it is usually necessary to replace the terminal / user card and pre-install the application. Even so, it is difficult to control the user terminal market, and it is impossible to ensure that all terminals and cards meet the requirements. In the case where the terminal coverage rate is difficult to increase, it is difficult to scale the authentication application or service. Summary of the Invention
[0007] One technical problem solved by the present disclosure is to provide a processing method for authentication capabilities to detect and obtain the authentication capabilities of a terminal, understand the authentication capability support situation of the terminal, and facilitate improving the terminal coverage rate of the authentication application and the usability of the application during application promotion.
[0008] According to one aspect of the present disclosure, there is provided a processing method for authenticating capabilities, which is applied to a terminal and includes: a capability acquisition module of the terminal receives a capability detection requirement message from a capability detection platform, and the capability detection requirement message carries the authentication capability parameters. Among them, the capability detection platform receives the authentication capability parameters from an authentication application background. The authentication capability parameters include a call instruction corresponding to the authentication application, an expected call result, and an authentication application identifier, and associates the call instruction, the expected call result, and the authentication application identifier, and stores them in a detection instruction library; the capability acquisition module calls a corresponding authentication module according to the authentication capability parameters; and the capability acquisition module receives the returned actual call result, determines whether the corresponding authentication capability is available according to the actual call result and the expected call result, and stores the available authentication capability information.
[0009] In some embodiments, determining whether the corresponding authentication capability is available according to the actual call result and the expected call result includes: determining that the corresponding authentication capability is available when the actual call result is the same as the expected call result; and determining that the corresponding authentication capability is unavailable when the actual call result is different from the expected call result.
[0010] In some embodiments, the available authentication capability information includes: an authentication application identifier, and information indicating that the authentication capability corresponding to the authentication application identifier is marked as available.
[0011] In some embodiments, the processing method further includes: the application client of the terminal obtains the authentication capability information supported by the terminal; the application client sends a first application request message to the network application function entity, and the first application request message carries service request data and the authentication capability information supported by the terminal; wherein, the network application function entity determines the authentication method to be adopted according to the service policy corresponding to the application client and the authentication capability information supported by the terminal, and returns an authentication and authorization requirement message to the application client, and the authentication and authorization requirement message carries the authentication method and / or the authorization parameter corresponding to the authentication method; the application client executes the authentication and authorization process corresponding to the authentication method through the authentication platform according to the authentication and authorization requirement message; after executing the authentication and authorization process, the application client sends a second application request message to the network application function entity, and the second application request message carries information indicating successful authorization; wherein, the network application function entity obtains corresponding authorization data from the authentication platform according to the information indicating successful authorization, generates an application key according to the authorization data, and sends the service request data and the application key to the application server; and the application client generates an application key consistent with the application key generated by the network application function entity according to the authorization data, and communicates with the application server through the application key.
[0012] In some embodiments, the application client of the terminal obtaining the authentication capability information supported by the terminal includes: the application client sending a capability query request message to the capability collection module of the terminal; and the capability collection module, after receiving the capability query request message, reading the authentication capability information supported by the terminal stored locally, and returning the authentication capability information to the application client.
[0013] According to another aspect of the present disclosure, a processing method for authentication capabilities is provided, including: the capability detection platform receives authentication capability parameters from the authentication application background, and the authentication capability parameters include a call instruction corresponding to the authentication application, an expected call result, and an authentication application identifier; the capability detection platform associates the call instruction, the expected call result with the authentication application identifier, and stores them in the detection instruction library; the capability detection platform sends a capability detection requirement message to the capability collection module of the terminal, and the capability detection requirement message carries the authentication capability parameters; the capability collection module calls the corresponding authentication module according to the authentication capability parameters; and the capability collection module receives the returned actual call result, determines whether the corresponding authentication capability is available according to the actual call result and the expected call result, and stores the available authentication capability information.
[0014] In some embodiments, the ability collection module determines whether the corresponding authentication ability is available according to the actual call result and the expected call result, including: when the actual call result is the same as the expected call result, the ability collection module determines that the corresponding authentication ability is available; and when the actual call result is different from the expected call result, the ability collection module determines that the corresponding authentication ability is unavailable.
[0015] In some embodiments, the available authentication ability information includes: an authentication application identifier, and information indicating that the authentication ability corresponding to the authentication application identifier is marked as available.
[0016] In some embodiments, the processing method further includes: the application client of the terminal obtains the authentication ability information supported by the terminal; the application client sends a first application request message to the network application function entity, and the first application request message carries service request data and the authentication ability information supported by the terminal; the network application function entity determines the authentication method to be adopted according to the service policy corresponding to the application client and the authentication ability information supported by the terminal, and returns an authentication authorization requirement message to the application client, and the authentication authorization requirement message carries the authentication method and / or the authorization parameter corresponding to the authentication method; the application client executes the authentication and authorization process corresponding to the authentication method through the authentication platform according to the authentication authorization requirement message; after executing the authentication and authorization process, the application client sends a second application request message to the network application function entity, and the second application request message carries information indicating successful authorization; the network application function entity obtains the corresponding authorization data from the authentication platform according to the information indicating successful authorization, generates an application key according to the authorization data, and sends the service request data and the application key to the application server; and the application client generates an application key consistent with the application key generated by the network application function entity according to the authorization data, and communicates with the application server through the application key.
[0017] In some embodiments, the application client of the terminal obtains the authentication ability information supported by the terminal, including: the application client sends an ability query request message to the ability collection module of the terminal; and after receiving the ability query request message, the ability collection module reads the authentication ability information supported by the terminal stored locally, and returns the authentication ability information to the application client.
[0018] According to another aspect of the present disclosure, a terminal is provided, including: a capability acquisition module, wherein the capability acquisition module includes: a receiving unit, configured to receive a capability detection requirement message from a capability detection platform, the capability detection requirement message carrying the authentication capability parameter, wherein the capability detection platform receives the authentication capability parameter from an authentication application background, the authentication capability parameter includes a call instruction corresponding to the authentication application, an expected call result, and an authentication application identifier, and associates the call instruction, the expected call result with the authentication application identifier, and stores them in a detection instruction library; a calling unit, configured to call a corresponding authentication module according to the authentication capability parameter; and a determining unit, configured to receive the returned actual call result, determine whether the corresponding authentication capability is available according to the actual call result and the expected call result, and store the available authentication capability information.
[0019] According to another aspect of the present disclosure, a terminal is provided, including: a memory; and a processor coupled to the memory, the processor being configured to execute the method as described above based on instructions stored in the memory.
[0020] According to another aspect of the present disclosure, a system for secure communication is provided, including: the terminal as described above.
[0021] In some embodiments, the system further includes: a capability detection platform, configured to receive an authentication capability parameter from an authentication application background, the authentication capability parameter includes a call instruction corresponding to the authentication application, an expected call result, and an authentication application identifier, associate the call instruction, the expected call result with the authentication application identifier, and store them in a detection instruction library, and send a capability detection requirement message to the capability acquisition module of the terminal, the capability detection requirement message carrying the authentication capability parameter.
[0022] In some embodiments, the system further includes: a network application function entity, configured to determine an authentication method to be adopted according to a service policy corresponding to an application client of the terminal and the authentication capability information supported by the terminal, and return an authentication and authorization requirement message to the application client, the authentication and authorization requirement message carrying the authentication method and / or an authorization parameter corresponding to the authentication method, obtain corresponding authorization data from the authentication platform according to the authorization passed information returned by the application client, generate an application key according to the authorization data, and send the service request data and the application key to an application server.
[0023] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method as described above is implemented.
[0024] In the above method, the capability acquisition module of the terminal receives a capability detection requirement message from the capability detection platform. The capability detection requirement message carries authentication capability parameters. Among them, the capability detection platform receives the authentication capability parameters from the authentication application background. The authentication capability parameters include a call instruction corresponding to the authentication application, an expected call result, and an authentication application identifier, and associates the call instruction, the expected call result with the authentication application identifier, and stores them in the detection instruction library. The capability acquisition module calls the corresponding authentication module according to the authentication capability parameters. And the capability acquisition module receives the returned actual call result, determines whether the corresponding authentication capability is available according to the actual call result and the expected call result, and stores the available authentication capability information. This method can realize the acquisition and storage of the authentication capabilities of the terminal, and fully master the support situation of the authentication capabilities of the terminal, which is convenient for the subsequent use of the authentication capabilities, so as to improve the terminal coverage rate and application availability of the authentication application during application promotion.
[0025] Other features and advantages of the present disclosure will become clear from the following detailed description of exemplary embodiments of the present disclosure with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] The drawings forming a part of the specification depict embodiments of the present disclosure and, together with the description, are used to explain the principles of the present disclosure.
[0027] Referring to the accompanying drawings, the present disclosure can be more clearly understood from the following detailed description, wherein:
[0028] Figure 1 is a flowchart showing a processing method for authentication capabilities according to some embodiments of the present disclosure;
[0029] Figure 2 is a flowchart showing a processing method for authentication capabilities according to other embodiments of the present disclosure;
[0030] Figure 3 is a flowchart showing a processing method for authentication capabilities according to other embodiments of the present disclosure;
[0031] Figure 4 is a flowchart showing a processing method for authentication capabilities according to other embodiments of the present disclosure;
[0032] Figure 5 is a flowchart showing a processing method for authentication capabilities according to other embodiments of the present disclosure;
[0033] Figure 6 is a schematic block diagram showing a terminal according to some embodiments of the present disclosure;
[0034] Figure 7is a block diagram schematically showing the structure of a terminal according to other embodiments of the present disclosure;
[0035] Figure 8 is a block diagram schematically showing the structure of a terminal according to other embodiments of the present disclosure;
[0036] Figure 9 is a block diagram schematically showing the structure of a system according to some embodiments of the present disclosure. Detailed implementation manners
[0037] Various exemplary embodiments of the present disclosure will now be described in detail with reference to the accompanying drawings. It should be noted that: unless otherwise specifically stated, the relative arrangements of components and steps, numerical expressions and values set forth in these embodiments do not limit the scope of the present disclosure.
[0038] Meanwhile, it should be understood that, for the sake of description, the dimensions of the various parts shown in the drawings are not drawn in actual proportional relationship.
[0039] The following description of at least one exemplary embodiment is merely illustrative in nature and in no way serves as a limitation on the present disclosure, its application or use.
[0040] Technologies, methods and devices known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, the technologies, methods and devices should be regarded as part of the specification.
[0041] In all the examples shown and discussed here, any specific value should be construed as merely exemplary and not as a limitation. Therefore, other examples of the exemplary embodiments may have different values.
[0042] It should be noted that: like reference numerals and letters denote like items in the following drawings, and thus, once an item is defined in one drawing, it does not need to be further discussed in subsequent drawings.
[0043] Figure 1 is a flowchart showing a processing method for authenticating capabilities according to some embodiments of the present disclosure. This method is applied to a terminal. As Figure 1 shown, this method includes steps S102 to S106.
[0044] In step S102, the capability acquisition module of the terminal receives a capability detection requirement message from the capability detection platform, and the capability detection requirement message carries authentication capability parameters.
[0045] Here, the capability detection platform receives authentication capability parameters from the background of the authentication application. The authentication capability parameters include a call instruction corresponding to the authentication application, an expected call result, and an authentication application identifier. The call instruction, the expected call result, and the authentication application identifier are associated and stored in the detection instruction library. Moreover, the capability detection platform sends a capability detection requirement message to the capability collection module of the terminal.
[0046] In step S104, the capability collection module calls the corresponding authentication module according to the authentication capability parameters.
[0047] In step S106, the capability collection module receives the returned actual call result, determines whether the corresponding authentication capability is available according to the actual call result and the expected call result, and stores the available authentication capability information.
[0048] For example, the available authentication capability information includes: the authentication application identifier, and information indicating that the authentication capability corresponding to the authentication application identifier is marked as available. For example, the available authentication capability information can be stored in the form of a data table, such as shown in Table 1.
[0049] Table 1 Authentication Capability Information Table
[0050] Authentication Application Identifier 1 Available Authentication Application Identifier 2 Available Authentication Application Identifier 3 Available …… ……
[0051] In some embodiments, determining whether the corresponding authentication capability is available according to the actual call result and the expected call result includes: when the actual call result is the same as the expected call result, determining that the corresponding authentication capability is available (i.e., the terminal supports the corresponding authentication capability); and when the actual call result is different from the expected call result, determining that the corresponding authentication capability is unavailable (i.e., the terminal does not support the corresponding authentication capability).
[0052] So far, a method for secure communication according to some other embodiments of the present disclosure is provided. The method includes: the capability collection module of the terminal receives a capability detection requirement message from the capability detection platform. The capability detection requirement message carries authentication capability parameters. Here, the capability detection platform receives the authentication capability parameters from the background of the authentication application. The authentication capability parameters include a call instruction corresponding to the authentication application, an expected call result, and an authentication application identifier. The call instruction, the expected call result, and the authentication application identifier are associated and stored in the detection instruction library; the capability collection module calls the corresponding authentication module according to the authentication capability parameters; and the capability collection module receives the returned actual call result, determines whether the corresponding authentication capability is available according to the actual call result and the expected call result, and stores the available authentication capability information. This method can achieve the collection and storage of the authentication capabilities of the terminal, and fully master the support situation of the authentication capabilities of the terminal, which is convenient for the subsequent use of the authentication capabilities, thereby improving the terminal coverage rate and application availability of the authentication application during application promotion.
[0053] The above method can achieve dynamic capability collection, so as to adapt to the requirements of various terminal environments. For different terminal environments or capability requirements, corresponding multiple call instructions can be configured to fully master the support situation of the authentication capabilities of the terminal.
[0054] Figure 2 is a flowchart showing a processing method for authentication capabilities according to some other embodiments of the present disclosure. This method is applied to a terminal. As Figure 2 shown, this method includes steps S202 to S210.
[0055] In step S202, the application client of the terminal acquires the authentication capability information supported by the terminal.
[0056] In some embodiments, step S202 includes: the application client sending a capability query request message to the capability collection module of the terminal; and after receiving the capability query request message, the capability collection module reads the authentication capability information supported by the terminal stored locally and returns the authentication capability information to the application client.
[0057] In step S204, the application client sends a first application request message to the network application function entity, and the first application request message carries service request data and the authentication capability information supported by the terminal.
[0058] The network application function entity determines the authentication method to be adopted according to the service policy corresponding to the application client and the authentication capability information supported by the terminal, and returns an authentication and authorization requirement message to the application client. The authentication and authorization requirement message carries the authentication method and / or the authorization parameters corresponding to the authentication method.
[0059] For example, the network application function entity may pre-store the service policy corresponding to the application client. For example, the service policy may include the authentication security level of the application client, etc. For example, if the terminal supports authentication capabilities such as mobile phone number authentication and SIM card shield digital certificate authentication. According to the service policy corresponding to the application client, the application client can use an authentication method with a general security level such as mobile phone number authentication when logging in; the application client adopts an authentication method with a high security level such as SIM card shield digital certificate authentication during important transactions. Therefore, the network application function entity can determine the authentication method to be adopted according to the service policy corresponding to the application client and the authentication capability information supported by the terminal.
[0060] The authorization parameter is a parameter related to the execution of the authorization process. For example, the authorization parameter includes a random number, etc. Of course, the scope of the present disclosure is not limited thereto. The authorization parameter may also include other parameters for authorization.
[0061] In step S206, the application client performs an authentication and authorization process corresponding to the authentication method through the authentication platform according to the authentication and authorization requirement message.
[0062] Here, the application client obtains the authentication method and / or authorization parameters from the authentication and authorization requirement message. For example, the application client can perform operations on the random number, so as to perform an authentication and authorization process corresponding to the authentication method through the authentication platform. It should be noted that the above authorization process adopts the authorization process known to those skilled in the art and will not be elaborated here.
[0063] In step S208, after performing the authentication and authorization process, the application client sends a second application request message to the network application function entity, and the second application request message carries the information indicating successful authentication.
[0064] The network application function entity obtains the corresponding authorization data from the authentication platform according to the information indicating successful authentication, generates an application key according to the authorization data, and sends the service request data and the application key to the application server (Application Server, abbreviated as AS).
[0065] The above information indicating successful authentication includes the identification information corresponding to the above authorization process. Therefore, the network application function entity can obtain the corresponding authorization data from the authentication platform according to the information indicating successful authentication. The authorization data is the data generated after the authorization process is completed, and includes, for example, a key or other parameters. The network application function entity derives an application key according to the authorization data, which enables the application server to communicate with the application client according to the application key without knowing the authorization data, thereby improving the confidentiality.
[0066] It should be noted that the network application function entity can adopt a known key generation method to derive an application key according to the authorization data.
[0067] In step S210, the application client generates an application key consistent with the application key generated by the network application function entity according to the authorization data, and communicates with the application server through the application key.
[0068] For example, the application client can adopt the same key generation method as the network application function entity to derive an application key according to the authorization data, and the application key is consistent with the application key derived by the network application function entity. In this way, the application client can achieve secure communication with the application server through the application key.
[0069] So far, a method for secure communication according to some embodiments of the present disclosure has been provided. The method includes: an application client of a terminal obtains authentication capability information supported by the terminal; the application client sends a first application request message to a network application function entity, and the first application request message carries service request data and the authentication capability information supported by the terminal; wherein, the network application function entity determines an authentication method to be adopted according to the service policy corresponding to the application client and the authentication capability information supported by the terminal, and returns an authentication and authorization requirement message to the application client, and the authentication and authorization requirement message carries the authentication method and / or the authorization parameter corresponding to the authentication method; the application client executes an authentication and authorization process corresponding to the authentication method through an authentication platform according to the authentication and authorization requirement message; after the application client executes the authentication and authorization process, the application client sends a second application request message to the network application function entity, and the second application request message carries information indicating successful authorization; wherein, the network application function entity obtains corresponding authorization data from the authentication platform according to the information indicating successful authorization, generates an application key according to the authorization data, and sends the service request data and the application key to an application server; and the application client generates an application key consistent with the application key generated by the network application function entity according to the authorization data, and communicates with the application server through the application key. In this method, when the terminal sends the first application request, it carries the authentication capabilities it supports, and the server (network application function entity) can determine the authentication method to be adopted according to the authentication capability support of the terminal and the application demand policy, and return the corresponding authorization requirements to the terminal. In this way, the authentication method can be adapted based on the understanding of the terminal's authentication capability support, and the terminal coverage rate of the authentication application and the usability of the application can be improved during the application promotion.
[0070] Figure 3 is a flowchart showing a processing method for authentication capabilities according to other embodiments of the present disclosure. As Figure 3 shown, the method includes steps S302 to S310.
[0071] In step S302, the capability detection platform receives authentication capability parameters from the authentication application background, and the authentication capability parameters include a call instruction corresponding to the authentication application, an expected call result, and an authentication application identifier.
[0072] In step S304, the capability detection platform associates the call instruction, the expected call result with the authentication application identifier, and stores them in the detection instruction library.
[0073] In step S306, the capability detection platform sends a capability detection requirement message to the capability collection module of the terminal, and the capability detection requirement message carries the authentication capability parameters.
[0074] For example, the capability detection platform periodically (or when the capability collection module of the terminal is awakened) sends a capability detection requirement to the capability collection module in the terminal, carrying the latest call instruction set for each authentication application.
[0075] In step S308, the capability collection module calls the corresponding authentication module according to the authentication capability parameters.
[0076] In step S310, the capability collection module receives the returned actual call result, determines whether the corresponding authentication capability is available according to the actual call result and the expected call result, and stores the available authentication capability information.
[0077] In some embodiments, the capability collection module determining whether the corresponding authentication capability is available according to the actual call result and the expected call result includes: the capability collection module determining that the corresponding authentication capability is available when the actual call result is the same as the expected call result; and the capability collection module determining that the corresponding authentication capability is unavailable when the actual call result is different from the expected call result.
[0078] In some embodiments, the available authentication capability information includes: the authentication application identifier, and information indicating that the authentication capability corresponding to the authentication application identifier is marked as available.
[0079] So far, a method for secure communication according to some other embodiments of the present disclosure is provided. This method can realize the collection and storage of the authentication capabilities of the terminal, and fully master the support situation of the authentication capabilities of the terminal, which is convenient for the subsequent use of authentication capabilities. In this method, dynamic capability collection can adapt to various terminal environment requirements, and corresponding multiple standard call instructions can be configured for different terminal environments or capability requirements to fully master the support situation of the authentication capabilities of the terminal, so as to improve the terminal coverage rate of authentication applications and the usability of applications when the applications are promoted.
[0080] Figure 4 is a flowchart showing a processing method for authentication capabilities according to some other embodiments of the present disclosure. As Figure 4 shown, this method includes steps S402 to S414.
[0081] In step S402, the application client of the terminal obtains the authentication capability information supported by the terminal.
[0082] In some embodiments, step S402 includes: the application client sending a capability query request message to the capability collection module of the terminal; and after receiving the capability query request message, the capability collection module reads the authentication capability information supported by the terminal stored locally and returns the authentication capability information to the application client.
[0083] In step S404, the application client sends a first application request message to the network application function entity. The first application request message carries service request data and authentication capability information supported by the terminal.
[0084] In step S406, the network application function entity determines the authentication method to be adopted according to the service policy corresponding to the application client and the authentication capability information supported by the terminal, and returns an authentication and authorization requirement message to the application client. The authentication and authorization requirement message carries the authentication method and / or the authorization parameters corresponding to the authentication method.
[0085] In step S408, the application client performs an authentication and authorization process corresponding to the authentication method through the authentication platform according to the authentication and authorization requirement message.
[0086] In step S410, after performing the authentication and authorization process, the application client sends a second application request message to the network application function entity. The second application request message carries information indicating successful authorization.
[0087] In step S412, the network application function entity obtains corresponding authorization data from the authentication platform according to the information indicating successful authorization, generates an application key based on the authorization data, and sends the service request data and the application key to the application server.
[0088] In step S414, the application client generates an application key that is consistent with the application key generated by the network application function entity based on the authorization data, and communicates with the application server through the application key.
[0089] So far, a method for secure communication according to some other embodiments of the present disclosure is provided. In this method, when the terminal issues a first application request, it carries the authentication capabilities it supports, and the server can return corresponding authorization requirements to the terminal according to the terminal's authentication capability support situation and application demand strategy. In this way, the adaptability of the authentication method is realized on the basis of mastering the terminal's authentication capability support situation, and the terminal coverage rate of the authentication application and the usability of the application can be improved when the application is promoted.
[0090] In the method of the embodiments of the present disclosure, a suitable terminal authentication scheme can be provided for various terminal types through a unified interface, expanding the applicable range of the authentication application for terminals, providing high-quality service usage guarantee for users, and ensuring the consistency of the user service experience. In addition to terminals such as mobile phones and computers, it can also be extended and applied to more types of general terminals such as in-vehicle terminals, or IoT (Internet of Things) terminals. The capabilities of such terminals often vary greatly, and it is impossible to conduct one-to-one debugging when performing authentication and authorization on the terminals. Through the method of the present disclosure, the adaptation work of the terminals can be accelerated, and cumbersome problems such as user card or terminal replacement caused by the limitation of a single authentication method can be avoided.
[0091] Figure 5 is a flow chart showing a processing method for authentication capability according to other embodiments of the present disclosure. Figure 5 As shown, the method includes steps S501 to S521. In the method, steps S501 to S507 belong to the authentication capability acquisition process, and steps S508 to S521 belong to the authentication capability use process.
[0092] In step S501, when a new authentication capability needs to be accessed, the authentication application background performs application access through the authentication capability access module provided by the capability detection platform, carrying authentication capability parameters such as the call instruction content corresponding to the authentication application, the expected call result content and the authentication application identifier.
[0093] In step S502, the capability detection platform associates the above-mentioned calling instruction content, expected calling result content and authentication application identifier, and stores them in the detection instruction library.
[0094] In step S503, the capability detection platform periodically (or when the capability acquisition module in the terminal is awakened) sends a capability detection request to the capability acquisition module in the terminal, carrying the latest call instruction set of each authentication application (ie, the authentication capability parameters described above).
[0095] In step S504, after receiving the call instruction set, the capability acquisition module in the terminal executes each call instruction in sequence and attempts to call the corresponding authentication module.
[0096] In step S505, the capability collection module in the terminal receives the returned call result.
[0097] In step S506, the capability collection module determines the availability of the authentication capability according to the returned call result. For example, if the returned call result is consistent with the expected call result content, it means that the authentication capability exists and is available.
[0098] In step S507, the capability collection module stores available authentication capability related data, that is, stores available authentication capability information.
[0099] The above steps S501 to S507 describe the authentication capability acquisition process.
[0100] In step S508, the user initiates a service authentication request through the application client.
[0101] In step S509, the application client obtains local authentication capabilities from the local capability collection module of the terminal.
[0102] In step S510, the local capability collection module of the terminal reads the locally stored available authentication capability data (ie, authentication capability information supported by the terminal).
[0103] In step S511, the capability acquisition module returns the local authentication capability set to the application client.
[0104] In step S512, the application client sends a first application request message (which can also be referred to as an initial application request) to the network application function entity. This first application request message carries service request-related data, authentication capability information supported by the terminal side, etc.
[0105] In step S513, the network application function entity determines the authentication method to be adopted based on the service policy of the application and the terminal local authentication capability information.
[0106] In step S514, the network application function entity returns an authentication and authorization requirement to the application client, carrying the required authentication method or authorization parameters (if any), etc. Of course, if there are no authorization parameters, the authentication and authorization requirement may not carry authorization parameters either.
[0107] In step S515, the application client completes the authentication and authorization in the corresponding manner according to the returned authorization requirement.
[0108] In step S516, the application client sends an application request (a second application request message) to the network application function entity again, carrying the relevant data obtained after authentication completion (for example, authentication passed information).
[0109] In step S517, the network application function entity obtains the authorization data corresponding to this authentication and authorization from the corresponding authentication platform to complete the authentication of the terminal.
[0110] In step S518, the network application function entity generates an application key based on the authorization data and forwards the service request of the application and the application key to the application server.
[0111] In step S519, the network application function entity returns a response to the application client.
[0112] In step S520, the application client also derives the corresponding application key based on the authentication and authorization data of this time.
[0113] In step S521, the application client and the application server have the same application key and can perform secure communication based on the application key.
[0114] The above steps S508 to S521 describe the process of using the authentication capability.
[0115] So far, a method for secure communication according to some other embodiments of the present disclosure has been provided. In view of the problem that existing authentication methods mostly involve terminals and user cards, and have strict requirements for the type of card, terminal environment, card-terminal channel, etc., and it is often necessary to replace the terminal or user card or pre-install the application in the application deployment process, making it difficult to ensure a high terminal coverage rate and thus difficult for the application to develop on a large scale, the above method is provided. In the above method, a terminal capability acquisition module is introduced, and the standard call instruction set of the accessed authentication application is pushed to the terminal capability acquisition module. After the terminal executes the instruction set, it analyzes the corresponding return result to determine whether the terminal locally has the corresponding authentication capability and stores the corresponding authentication capability identifier; when the terminal sends an initial application request, it carries the authentication capabilities it supports, and the server can return corresponding authentication requirements to the terminal according to the authentication capability support situation of the terminal and the application demand strategy. Based on mastering the authentication capability support situation of the terminal, the authentication method is made adaptive, and the terminal coverage rate and application availability are improved during application promotion.
[0116] When users use terminals / generalized terminals with different capabilities or user cards with different capabilities for secure authentication, they can obtain the local authentication capabilities of the terminals and user cards in advance through capability acquisition. When performing authentication, they can select the corresponding authentication method according to the business requirements and the type of capabilities the terminal has, so that different authentication application services are no longer limited by the terminal's capability deployment situation during the deployment and promotion process, and the high availability of the business application and the high coverage rate of the terminal are achieved.
[0117] In the above method, standard instructions of each authentication application (such as APDU (Application Protocol Data Unit) instructions / AT (Attention) commands / software call instructions, etc.) are periodically pushed to the terminal. After the terminal sequentially executes these standard instructions, it analyzes the return result. If the normal return result is satisfied, it can be considered that the corresponding authentication capability is satisfied. After the acquisition of the authentication capability is completed, the initial application request of the terminal will carry the authentication capabilities it supports, and the server can return corresponding authentication requirements according to the authentication capability support situation of the terminal and the application demand, so that the deployment and promotion of different authentication application services are no longer limited by the terminal's capability deployment situation, and the application coverage rate and availability are improved.
[0118] Therefore, in the above method, the periodic dynamic capability collection can adapt to the requirements of various terminal environments. For different terminal environments or capability requirements, multiple corresponding standard call instructions can be configured to fully understand the authentication capability support situation of the terminal. Moreover, the above method can implement an authentication method with adaptive support, improve the terminal coverage rate of the authentication application, and the server returns corresponding authentication requirements to the terminal according to the authentication capability support situation reported by the terminal and the application demand strategy. Even if a certain terminal authentication capability is not supported, it will basically not affect the authentication of the application to the terminal and the usability of the application on the terminal.
[0119] Figure 6 is a schematic block diagram of a terminal according to some embodiments of the present disclosure.
[0120] As Figure 6 shown, the terminal includes a capability collection module 620. The capability collection module 620 includes: a receiving unit 621, a calling unit 622, and a determining unit 623.
[0121] The receiving unit 621 is configured to receive a capability detection requirement message from a capability detection platform. The capability detection requirement message carries authentication capability parameters. The capability detection platform receives the authentication capability parameters from the authentication application background. The authentication capability parameters include call instructions corresponding to the authentication application, expected call results, and an authentication application identifier, and associates the call instructions, expected call results, and the authentication application identifier, and stores them in a detection instruction library.
[0122] The calling unit 622 is configured to call a corresponding authentication module according to the authentication capability parameters.
[0123] The determining unit 623 is configured to receive the returned actual call result, determine whether the corresponding authentication capability is available according to the actual call result and the expected call result, and store the available authentication capability information.
[0124] So far, a terminal according to some embodiments of the present disclosure has been provided. This can achieve the collection and storage of the authentication capabilities of the terminal, and fully understand the authentication capability support situation of the terminal, facilitating the subsequent use of the authentication capabilities, thereby improving the terminal coverage rate of the authentication application and the usability of the application during application promotion.
[0125] In some embodiments, the determining unit 623 can be configured to determine that the corresponding authentication capability is available when the actual call result is the same as the expected call result, and determine that the corresponding authentication capability is unavailable when the actual call result is different from the expected call result.
[0126] In some embodiments, the capability acquisition module may be integrated on the terminal OS side or in the application in the form of an SDK, or exist as a separate APP, responsible for sending standard call instructions for each authentication capability and analyzing the returned results to determine the effectiveness of the authentication capability.
[0127] In some embodiments, the available authentication capability information includes: the authentication application identifier, and information indicating that the authentication capability corresponding to the authentication application identifier is marked as available.
[0128] In some embodiments, as Figure 6 shown, the terminal further includes an application client 610. The application client 610 includes: an acquisition unit 611, a first sending unit 612, an authentication unit 613, a second sending unit 614, and a communication unit 615.
[0129] The acquisition unit 611 is used to acquire the authentication capability information supported by the terminal.
[0130] The first sending unit 612 is used to send a first application request message to the network application function entity. The first application request message carries service request data and the authentication capability information supported by the terminal. The network application function entity determines the authentication method to be adopted according to the service policy corresponding to the application client and the authentication capability information supported by the terminal, and returns an authentication and authorization requirement message to the application client. The authentication and authorization requirement message carries the authentication method and / or the authorization parameters corresponding to the authentication method.
[0131] The authentication unit 613 is used to execute the authentication and authorization process corresponding to the authentication method through the authentication platform according to the authentication and authorization requirement message.
[0132] The second sending unit 614 is used to send a second application request message to the network application function entity after executing the authentication and authorization process. The second application request message carries information indicating successful authorization. The network application function entity obtains the corresponding authorization data from the authentication platform according to the information indicating successful authorization, generates an application key according to the authorization data, and sends the service request data and the application key to the application server.
[0133] The communication unit 615 is used to generate an application key consistent with the application key generated by the network application function entity according to the authorization data, and communicate with the application server through the application key.
[0134] Thus far, a terminal according to some other embodiments of the present disclosure has been provided. The terminal can achieve the adaptability of the authentication method, and can improve the terminal coverage rate of the authentication application and the availability of the application during application promotion.
[0135] In some embodiments, as Figure 6As shown, the application client 610 may further include a third sending unit 616. The third sending unit 616 is configured to send a capability query request message to the capability acquisition module 620 of the terminal.
[0136] In some embodiments, the capability acquisition module 620 may further include a reading unit ( Figure 6 not shown in the figure), which is configured to read the authentication capability information supported by the terminal stored locally after receiving the capability query request message, and return the authentication capability information to the application client 610.
[0137] Figure 7 FIG. is a schematic block diagram of a terminal according to some other embodiments of the present disclosure. The terminal includes a memory 710 and a processor 720. Among them:
[0138] The memory 710 may be a magnetic disk, a flash memory, or any other non-volatile storage medium. The memory is used to store Figure 1 and / or Figure 2 the instructions corresponding to the corresponding embodiments.
[0139] The processor 720 is coupled to the memory 710 and may be implemented as one or more integrated circuits, such as a microprocessor or a microcontroller. The processor 720 is configured to execute the instructions stored in the memory, and can implement the acquisition and storage of the authentication capability of the terminal, and fully master the support situation of the authentication capability of the terminal, which is convenient for the subsequent use of the authentication capability, so as to improve the terminal coverage rate of the authentication application and the usability of the application when the application is promoted.
[0140] In one embodiment, as Figure 8 shown, the terminal 800 includes a memory 810 and a processor 820. The processor 820 is coupled to the memory 810 through the BUS bus 830. The terminal 800 may also be connected to an external storage device 850 through a storage interface 840 to call external data, and may also be connected to a network or another computer system (not shown) through a network interface 860. Details are not described here.
[0141] In this embodiment, by storing data instructions in the memory and then processing the above instructions by the processor, the acquisition and storage of the authentication capability of the terminal can be realized, and the support situation of the authentication capability of the terminal can be fully mastered, which is convenient for the subsequent use of the authentication capability, so as to improve the terminal coverage rate of the authentication application and the usability of the application when the application is promoted.
[0142] Figure 9 FIG. is a schematic block diagram of a system according to some embodiments of the present disclosure.
[0143] As Figure 9As shown, the system includes a terminal 910. For example, the terminal 910 can be a terminal such as Figure 6 , Figure 7 or Figure 8 shown. As Figure 9 shown, the terminal 910 includes an application client 912 and a capability collection module 914.
[0144] In some embodiments, as Figure 9 shown, the system further includes a capability detection platform 930. The capability detection platform 930 is used to receive authentication capability parameters from the authentication application background. The authentication capability parameters include a call instruction corresponding to the authentication application, an expected call result, and an authentication application identifier. The call instruction, the expected call result, and the authentication application identifier are associated and stored in a detection instruction library, and a capability detection requirement message is sent to the capability collection module of the terminal. The capability detection requirement message carries the authentication capability parameters. That is, the capability detection platform manages the authentication application information and its standard call instruction set, and (for example, periodically) pushes the standard call instruction set to the terminal capability collection module for terminal authentication capability detection.
[0145] The capability collection module 914 is used to call the corresponding authentication module according to the authentication capability parameters, receive the returned actual call result, determine whether the corresponding authentication capability is available according to the actual call result and the expected call result, and store the available authentication capability information.
[0146] In some embodiments, as Figure 9 shown, the terminal 910 may further include an authentication capability memory 916. The authentication capability memory 916 is used to store the available authentication capability information. That is, the capability collection module 914 stores the available authentication capability information in the authentication capability memory 916.
[0147] It should be noted that, in some embodiments, the authentication capability memory 916 can be inside the capability collection module 914 and be a part of the capability collection module 914; in other embodiments, the authentication capability memory 916 can also be outside the capability collection module 914 and not be a part of the capability collection module 914.
[0148] In some embodiments, as Figure 9 shown, the terminal 910 may further include authentication modules 1 to N, where N is a positive integer. Each authentication module is used to perform authentication and authorization operations with the corresponding authentication platform.
[0149] In some embodiments, as Figure 9 shown, the system may further include an authentication capability access module 950. The authentication capability access module 950 is used to receive the authentication capabilities from the authentication application background ( Figure 9 not shown in the figure).
[0150] In some embodiments, such as Figure 9 shown, the system may further include a detection instruction library 960. The detection instruction library 960 is used to store call instruction content, expected call result content, and authentication application identifiers.
[0151] It should be noted that, in some embodiments, the authentication capability access module 950 and the detection instruction library 960 may be disposed inside the capability detection platform 930 and be part of the capability detection platform 930; in other embodiments, the authentication capability access module 950 and the detection instruction library 960 may also be disposed outside the capability detection platform 930 and not be part of the capability detection platform 930.
[0152] In some embodiments, the application client 912 is used to: obtain authentication capability information supported by the terminal; send a first application request message to the network application function entity, where the first application request message carries service request data and the authentication capability information supported by the terminal; perform an authentication and authorization process corresponding to the authentication method through an authentication platform (for example, at least one of authentication platforms 1 to N) according to the authentication and authorization requirement message; after performing the authentication and authorization process, send a second application request message to the network application function entity 920, where the second application request message carries information indicating successful authorization; and generate an application key consistent with the application key generated by the network application function entity 920 according to the authorization data, and communicate with the application server 940 through the application key.
[0153] In some embodiments, such as Figure 9 shown, the system further includes a network application function entity 920. The network application function entity 920 is used to determine the authentication method to be adopted according to the service policy corresponding to the application client 912 of the terminal 910 and the authentication capability information supported by the terminal 910, and return an authentication and authorization requirement message to the application client. The authentication and authorization requirement message carries the authentication method and / or the authorization parameter corresponding to the authentication method. According to the information indicating successful authorization returned by the application client, obtain the corresponding authorization data from the authentication platform, generate an application key according to the authorization data, and send the service request data and the application key to the application server. That is to say, after the network application function entity receives the application request from the terminal and guides the terminal to complete the authorization, it forwards the application request to the application server.
[0154] In some embodiments, the application client 912 is used to send a capability query request message to the capability collection module 914 of the terminal. The capability collection module 914 is used to, after receiving the capability query request message, read the authentication capability information supported by the terminal stored locally and return the authentication capability information to the application client.
[0155] In some embodiments, such as Figure 9As shown, the system may further include authentication platforms 1 to N, where N is a positive integer. The authentication platforms correspond one-to-one with the authentication modules. Each authentication platform is used to perform authentication and authorization operations with the corresponding authentication module.
[0156] In some embodiments, as Figure 9 shown, the system may further include an application server 940. The application server 940 is used to provide application services by communicating with the application client 912.
[0157] In another embodiment, the present disclosure also provides a computer-readable storage medium (e.g., a non-transitory computer-readable storage medium) having computer program instructions stored thereon, and when the instructions are executed by a processor, the steps of the method in at least one of the corresponding embodiments of Figures 1 to 5 are implemented. Those skilled in the art should understand that the embodiments of the present disclosure may be provided as a method, an apparatus, or a computer program product. Therefore, the present disclosure may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present disclosure may take the form of a computer program product implemented on one or more computer-usable non-transitory storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0158] The present disclosure is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present disclosure. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure One one flow or multiple flows and / or blocks Figure One one block or multiple blocks.
[0159] These computer program instructions can also be stored in a computer-readable memory capable of guiding the computer or other programmable data processing devices to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure One one flow or multiple flows and / or blocks Figure One one block or multiple blocks.
[0160] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable apparatus provide steps for realizing the functions specified in one process or a plurality of processes and / or blocks Figure One one process or a plurality of processes and / or blocks Figure One or steps for realizing the functions specified in one block or a plurality of blocks.
[0161] So far, the present disclosure has been described in detail. To avoid obscuring the concept of the present disclosure, some details well known in the art are not described. Those skilled in the art can fully understand how to implement the technical solutions disclosed herein based on the above description.
[0162] Although some specific embodiments of the present disclosure have been described in detail by way of examples, those skilled in the art should understand that the above examples are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Those skilled in the art should understand that the above embodiments can be modified without departing from the scope and spirit of the present disclosure. The scope of the present disclosure is defined by the appended claims.
Claims
1. A processing method for authenticating capabilities, which is applied to a terminal, including: A capability acquisition module of the terminal receives a capability detection requirement message from a capability detection platform. The capability detection requirement message carries authentication capability parameters. Among them, the capability detection platform receives the authentication capability parameters from an authentication application background. The authentication capability parameters include a call instruction corresponding to the authentication application, an expected call result, and an authentication application identifier, and associates the call instruction, the expected call result with the authentication application identifier, and stores them in a detection instruction library; The capability acquisition module calls a corresponding authentication module according to the authentication capability parameters; and The capability acquisition module receives the returned actual call result, determines whether the corresponding authentication capability is available according to the actual call result and the expected call result, and stores the available authentication capability information.
2. The processing method according to claim 1, wherein, Determining whether the corresponding authentication capability is available according to the actual call result and the expected call result includes: Determining that the corresponding authentication capability is available when the actual call result is the same as the expected call result; and Determining that the corresponding authentication capability is unavailable when the actual call result is different from the expected call result.
3. The processing method according to claim 1, wherein, The available authentication capability information includes: an authentication application identifier, and information indicating that the authentication capability corresponding to the authentication application identifier is marked as available.
4. The processing method according to claim 1, further including: An application client of the terminal obtains the authentication capability information supported by the terminal; The application client sends a first application request message to a network application function entity. The first application request message carries service request data and the authentication capability information supported by the terminal. Among them, the network application function entity determines the authentication method to be adopted according to the service policy corresponding to the application client and the authentication capability information supported by the terminal, and returns an authentication and authorization requirement message to the application client. The authentication and authorization requirement message carries the authentication method and / or the authorization parameters corresponding to the authentication method; The application client executes an authentication and authorization process corresponding to the authentication method through an authentication platform according to the authentication and authorization requirement message; After executing the authentication and authorization process, the application client sends a second application request message to the network application function entity. The second application request message carries information indicating successful authorization. Among them, the network application function entity obtains corresponding authorization data from the authentication platform according to the information indicating successful authorization, generates an application key according to the authorization data, and sends the service request data and the application key to an application server; and The application client generates an application key consistent with the application key generated by the network application function entity according to the authorization data, and communicates with the application server through the application key.
5. The method according to claim 4, wherein, The application client of the terminal obtaining the authentication capability information supported by the terminal includes: The application client sends a capability query request message to the capability collection module of the terminal; and After receiving the capability query request message, the capability collection module reads the authentication capability information supported by the terminal stored locally, and returns the authentication capability information to the application client.
6. A processing method for authentication capabilities, including: The capability detection platform receives authentication capability parameters from the authentication application background, where the authentication capability parameters include a call instruction corresponding to the authentication application, an expected call result, and an authentication application identifier; The capability detection platform associates the call instruction, the expected call result, and the authentication application identifier, and stores them in the detection instruction library; The capability detection platform sends a capability detection requirement message to the capability collection module of the terminal, and the capability detection requirement message carries the authentication capability parameters; The capability collection module calls the corresponding authentication module according to the authentication capability parameters; and The capability collection module receives the returned actual call result, determines whether the corresponding authentication capability is available according to the actual call result and the expected call result, and stores the available authentication capability information.
7. The processing method according to claim 6, wherein, The capability collection module determines whether the corresponding authentication capability is available according to the actual call result and the expected call result, including: The capability collection module determines that the corresponding authentication capability is available when the actual call result is the same as the expected call result; and The capability collection module determines that the corresponding authentication capability is unavailable when the actual call result is different from the expected call result.
8. The processing method according to claim 6, wherein, The available authentication capability information includes: the authentication application identifier, and information indicating that the authentication capability corresponding to the authentication application identifier is marked as available.
9. The processing method according to claim 6, further including: The application client of the terminal obtains the authentication capability information supported by the terminal; The application client sends a first application request message to the network application function entity, and the first application request message carries service request data and the authentication capability information supported by the terminal; The network application function entity determines the authentication method to be adopted according to the service policy corresponding to the application client and the authentication capability information supported by the terminal, and returns an authentication and authorization requirement message to the application client, and the authentication and authorization requirement message carries the authentication method and / or the authorization parameter corresponding to the authentication method; The application client performs an authentication and authorization process corresponding to the authentication method through the authentication platform according to the authentication and authorization requirement message; After performing the authentication and authorization process, the application client sends a second application request message to the network application function entity, and the second application request message carries information indicating successful authorization; The network application function entity obtains the corresponding authorization data from the authentication platform according to the information indicating successful authorization, generates an application key according to the authorization data, and sends the service request data and the application key to the application server; and The application client generates an application key that is consistent with the application key generated by the network application function entity according to the authentication data, and communicates with the application server through the application key.
10. The method according to claim 9, wherein, the application client of the terminal obtaining the authentication capability information supported by the terminal includes: the application client sending a capability query request message to the capability collection module of the terminal; and after receiving the capability query request message, the capability collection module reads the authentication capability information supported by the terminal stored locally, and returns the authentication capability information to the application client.
11. A terminal, comprising: a capability collection module, wherein the capability collection module includes: a receiving unit, configured to receive a capability detection requirement message from a capability detection platform, the capability detection requirement message carrying authentication capability parameters, wherein the capability detection platform receives the authentication capability parameters from an authentication application background, the authentication capability parameters include a call instruction corresponding to the authentication application, an expected call result, and an authentication application identifier, and associates the call instruction, the expected call result, and the authentication application identifier, and stores them in a detection instruction library; a calling unit, configured to call a corresponding authentication module according to the authentication capability parameters; and a determining unit, configured to receive the returned actual call result, determine whether the corresponding authentication capability is available according to the actual call result and the expected call result, and store the available authentication capability information.
12. A terminal, comprising: a memory; and a processor coupled to the memory, the processor being configured to execute the method according to any one of claims 1 to 5 based on instructions stored in the memory.
13. A system for authentication capabilities, comprising: the terminal according to claim 11 or 12.
14. The system according to claim 13, further comprising: a capability detection platform, configured to receive authentication capability parameters from an authentication application background, the authentication capability parameters include a call instruction corresponding to the authentication application, an expected call result, and an authentication application identifier, associate the call instruction, the expected call result, and the authentication application identifier, and store them in a detection instruction library, and send a capability detection requirement message carrying the authentication capability parameters to the capability collection module of the terminal.
15. The system according to claim 13 or 14, further comprising: a network application function entity, configured to determine an authentication method to be adopted according to a service policy corresponding to the application client of the terminal and the authentication capability information supported by the terminal, and return an authentication authorization requirement message to the application client, the authentication authorization requirement message carrying the authentication method and / or authentication parameters corresponding to the authentication method, obtain corresponding authentication data from the authentication platform according to the authentication passed information returned by the application client, generate an application key according to the authentication data, and send the service request data and the application key to the application server.
16. A computer-readable storage medium having computer program instructions stored thereon, which, when executed by a processor, implement the method according to any one of claims 1 to 10.
Citation Information
Patent Citations
System and method for detecting usability of certification process for broadband access user
CN101753370A
Authentication algorithm selecting method, device and system
CN104754577A