Security authentication method and device, electronic equipment and storage medium
By comparing the IMEI in the SIM card and performing security authentication, including real-person authentication and risk assessment, the problem of passive and lagging telecom fraud prevention methods is solved, and proactive security protection for the SIM card usage environment is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA MOBILE INTERNET CO LTD
- Filing Date
- 2024-11-11
- Publication Date
- 2026-04-28
AI Technical Summary
Existing methods for preventing telecommunications fraud are passive and delayed, failing to prevent victims from being defrauded in the first instance, resulting in irrecoverable financial losses.
By obtaining the IMEI of the terminal device where the SIM card is located and comparing it with the stored IMEI, if they do not match, a security authentication process is performed, including real-person authentication, risk assessment, and corresponding security policies, such as micro-shutdown and dual authentication, to ensure the security of the SIM card usage environment.
By proactively and promptly curbing fraud at its source, the efficiency of security is improved, the problem of passive and delayed prevention methods is solved, and the security of the SIM card usage environment is ensured.
Smart Images

Figure CN119584122B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of security authentication technology, specifically relating to a security authentication method, device, electronic device, and storage medium. Background Technology
[0002] With the development of the internet and smartphones, telecommunications fraud has become increasingly rampant. Current methods for preventing fraud include: mobile operators and third-party service providers can use number identification technology to identify and mark incoming calls in real time; suspicious numbers can be flagged as potential fraudulent numbers, alerting users; analyzing user communication behavior and patterns can detect abnormal communication behaviors, such as sending large amounts of text messages or frequently calling unknown numbers; once abnormal behavior is detected, users can be alerted or appropriate protective measures can be taken; and anti-fraud platforms and reporting mechanisms can be established, allowing users to easily report suspicious numbers and fraudulent activities. These reports can help operators and law enforcement agencies better understand the fraud situation and take appropriate measures.
[0003] In other words, relevant technologies for preventing telecom fraud require users (victims) to have a strong sense of initiative and rely on them to identify the risk of fraud. This method of prevention is very passive and has a certain lag, and it cannot directly stop victims from being defrauded in the first instance. There will be a window of opportunity during which victims may transfer money, resulting in irrecoverable personal financial losses.
[0004] In other words, the relevant technologies for preventing telecommunications fraud are characterized by passive and delayed prevention methods. Summary of the Invention
[0005] This application provides a security authentication method, device, electronic device, and storage medium, which can solve the problems of passive and delayed prevention methods in related anti-telecom fraud technologies.
[0006] In a first aspect, embodiments of this application provide a security authentication method applied to a Subscriber Identity Module (SIM) card. The method includes: obtaining a first International Mobile Equipment Identity (IMEI) of a first terminal device where the SIM card is located; determining whether the first IMEI is the same as a second IMEI stored in the SIM card; the second IMEI is the IMEI corresponding to a second terminal device; the second terminal device includes: the terminal device to which the SIM card is initially bound and / or the terminal device where the SIM card is located when it passes security authentication; if they are different, then performing security authentication processing on the SIM card through the first terminal device.
[0007] Secondly, embodiments of this application provide a security authentication device applied to a SIM card. The device includes: an acquisition module for acquiring a first IMEI of a first terminal device where the SIM card is located; a judgment module for judging whether the first IMEI is the same as a second IMEI stored in the SIM card; the second IMEI is the IMEI corresponding to a second terminal device; the second terminal device includes: the terminal device to which the SIM card is initially bound and / or the terminal device where the SIM card is located when it passes security authentication; and a security authentication module for performing security authentication processing on the SIM card through the first terminal device if they are different.
[0008] Thirdly, embodiments of this application provide a security authentication device, which includes: a processor; and a memory arranged to store computer-executable instructions configured to be executed by the processor, the executable instructions including instructions for performing the security authentication method as described in the first aspect.
[0009] Fourthly, embodiments of this application provide a storage medium for storing computer-executable instructions that cause a computer to perform the security authentication method as described in the first aspect.
[0010] Fifthly, embodiments of this application provide a chip, the chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor being used to run programs or instructions to implement the security authentication method as described in the first aspect.
[0011] In a sixth aspect, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the security authentication method as described in the first aspect.
[0012] In this embodiment, the first IMEI of the first terminal device where the SIM card is located is obtained; it is determined whether the first IMEI is the same as the second IMEI stored in the SIM card; the second IMEI is the IMEI corresponding to the second terminal device; the second terminal device includes: the terminal device where the SIM card is initially bound and / or the terminal device where the SIM card is located when it passes security authentication; if they are different, the SIM card is processed for security authentication through the first terminal device. Compared with related anti-telecom fraud technologies that require users (victims) to have strong subjective initiative and rely on users (victims) to identify fraud risks, this solution starts from the source of telecom fraud (fraudsters). When the card application determines that the first IMEI is different from the second IMEI stored in the SIM card, the card application actively performs security authentication on the SIM card through the terminal device, thereby ensuring the security of the SIM card usage environment. This proactively and promptly stops fraudulent behavior from the source. Furthermore, by determining whether to perform security authentication through the card application's determination of whether the first IMEI is the same as the second IMEI stored in the SIM card, the efficiency of security protection is ensured, solving the problem of passive and delayed prevention methods in related anti-telecom fraud technologies. Attached Figure Description
[0013] Figure 1 This is a flowchart illustrating a security authentication method provided in an embodiment of this application;
[0014] Figure 2 This is a schematic diagram of a process for initially binding a SIM card to a terminal device according to an embodiment of this application;
[0015] Figure 3 This is a schematic diagram illustrating an offline authentication prompt displayed to a user, as provided in an embodiment of this application.
[0016] Figure 4 This is a schematic diagram illustrating a carrier authentication prompt displayed to a user, as provided in an embodiment of this application.
[0017] Figure 5 This is a schematic diagram of a first interface displayed to a user according to an embodiment of this application;
[0018] Figure 6 This is a flowchart illustrating another security authentication method provided in an embodiment of this application;
[0019] Figure 7 This is a schematic diagram of the structure of a security authentication device provided in an embodiment of this application;
[0020] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0021] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0022] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0023] The security authentication method, apparatus, electronic device, and storage medium provided in this application will be described in detail below with reference to the accompanying drawings and through specific embodiments and application scenarios.
[0024] Figure 1 This illustration shows a security authentication method provided by an embodiment of the present invention. This method can be executed by a card application of a SIM card in an electronic device, which may include a server and / or a terminal device, wherein the terminal device may be, for example, an in-vehicle terminal or a mobile phone terminal. In other words, the method can be executed by software or hardware installed in the SIM card application of the electronic device, and the method includes the following steps:
[0025] S102: Obtain the first IMEI of the first terminal device where the SIM card is located.
[0026] Considering that telecom fraudsters frequently switch terminal devices and SIM cards to evade detection, which involves inserting and removing SIM cards, this solution was specifically designed to address the problem of telecom fraud at its source (the fraudsters).
[0027] Optionally, the SIM card application can periodically obtain the IMEI of the terminal device where the SIM card is currently located (i.e., the first IMEI of the first terminal device), or it can obtain and record the IMEI of the terminal device where the SIM card is currently located (i.e., the first IMEI of the first terminal device) when a change in the card slot is detected. Alternatively, it can obtain the International Mobile Equipment Identity and Software Version Number (IMEISV) of the first terminal device where the SIM card is located. The IMEISV can be used in S102 and subsequent steps, and will not be elaborated further.
[0028] Specifically, the SIM card can be either a Super SIM card or a regular SIM card.
[0029] S104: Determine whether the first IMEI is the same as the second IMEI stored in the SIM card; the second IMEI is the IMEI corresponding to the second terminal device.
[0030] The second terminal device includes: the terminal device to which the SIM card is initially bound and / or the terminal device where the SIM card is located when it passes security authentication.
[0031] Specifically, the security verification process of the terminal device where the SIM card passes security authentication is performed is the security verification process corresponding to S106 below.
[0032] In practical applications, the terminal device initially bound to the SIM card can be the same terminal device used when the SIM card was initially activated. Specifically, it can be as follows: Figure 2As shown, the Trusted Service Manager (TSM) server 210 can respond to the service activation command corresponding to this card application and silently send the card application to the user's SIM card 220 via the Bearer Independent Protocol (BIP) to complete the installation of the card application. Through the interaction between the TSM server and the card application, the personalization and activation of the card application 230 are completed. The user can activate this service through an application (APP) or other carriers such as web pages and 5G messaging. Taking an app as an example, when a user clicks the service subscription button on the app's H5 page, the H5 page responds to the user's subscription instruction by transmitting the subscription information and the user-set password to the TSM trusted service server. Next, the TSM server silently downloads the card application to the SIM card via the BIP protocol and personalizes the card application using the BIP protocol. During personalization, the card application is granted full access permissions and Application Data Management (ADM) permissions. Once the card application is fully personalized, its functionality is activated by default. Subsequently, the card application creates a new linear record file. Then, when the card application reads the terminal device 230 (providing location information) using the SIM card's SIM Application Toolkit (STK), it obtains the terminal device's IMEI and records this IMEI in the linear record file. The linear record file can be located in a dedicated file (DF) under the SIM card's root directory (MasterFile, MF). For example, the linear record file may include the following content:
[0033]
[0034] The card application determines whether the IMEI has changed, that is, whether the first IMEI corresponding to the current terminal device (the first terminal device) is the same as the second IMEI stored in the SIM card.
[0035] S106: If they are different, the SIM card will be security authenticated by the first terminal device.
[0036] If the first IMEI is different from the second IMEI stored in the SIM card, the first terminal device performs security authentication on the SIM card, thereby ensuring real-time monitoring of changes in the SIM card's usage environment.
[0037] The security authentication method provided in this invention obtains the first IMEI of the first terminal device where the SIM card is located; determines whether the first IMEI is the same as the second IMEI stored in the SIM card; the second IMEI is the IMEI corresponding to the second terminal device; the second terminal device includes: the terminal device where the SIM card is initially bound and / or the terminal device where the SIM card is located when it passes security authentication; if they are different, the SIM card is processed for security authentication through the first terminal device. Compared with related anti-telecom fraud technologies that require users (victims) to have strong subjective initiative and rely on users (victims) to identify fraud risks, this solution starts from the source of telecom fraud (fraudsters). When the card application determines that the first IMEI is different from the second IMEI stored in the SIM card, the card application actively performs security authentication on the SIM card through the terminal device, thereby ensuring the security of the SIM card usage environment and proactively and promptly stopping fraudulent behavior from the source. Furthermore, by determining whether to perform security authentication through the card application's determination of whether the first IMEI is the same as the second IMEI stored in the SIM card, the efficiency of security protection is ensured, solving the problem of passive and delayed prevention methods in related anti-telecom fraud technologies.
[0038] In one implementation, the aforementioned security authentication process for the SIM card via the first terminal device (i.e., S106) can be specifically executed as follows: steps A1 to A3:
[0039] Step A1: The first terminal device displays a first interface instructing the user to perform real-person authentication, and if the user's real-person authentication is successful, the pre-collected risk data is obtained.
[0040] Specifically, the pre-collected risk data is data related to the risks associated with the SIM card's usage environment. This includes, for example, IMEI interaction counts, risk marker data for SIM cards in the TSM server's database, detection information from the IMEI database, location information, call and SMS behavior, etc., ensuring the dataset covers different types of risk factors.
[0041] In practical applications, this first interface can be displayed to the user in the form of a pop-up window.
[0042] Step A2: Based on the pre-collected risk data, conduct a risk assessment of the SIM card's usage environment to obtain the target risk level of the SIM card.
[0043] The card application includes a pre-trained decision tree model.
[0044] Specifically, the card application can encode the pre-collected risk data to standardize it, obtaining standard risk data. Then, the card application inputs the standard risk data into a pre-trained decision tree model, which outputs the target risk level of the SIM card corresponding to the pre-collected risk data. Determining the pre-trained decision tree model includes: acquiring sample data containing different types of risk factors; selecting an appropriate tree depth for training the decision tree by using pre-pruning (e.g., max_depth) or post-pruning (e.g., min_samples_leaf) to avoid overfitting; constructing the decision tree using the Apache Commons Math library, and using cross-validation to evaluate the model's generalization ability, confusion matrix to evaluate the model's classification accuracy, and ROC curves to verify and evaluate the model's ability to distinguish different risk levels; assigning risk scores according to the decision tree path, and dividing the risk scores into four levels, thus obtaining the pre-trained decision tree model.
[0045] Step A3: Execute the corresponding security authentication strategy based on the target risk level.
[0046] Different security authentication policies are set for different risk levels. The security authentication policy corresponding to the risk level of the SIM card is executed.
[0047] In this embodiment, a dual authentication method of real-person authentication and security authentication strategy is set up to improve the security of security authentication. Different security authentication strategies are adopted according to the risk level of the SIM card, making security authentication more humane.
[0048] Because the relevant security authentication methods mainly rely on operators prompting SIM card users to undergo secondary identity verification via SMS, and this is not mandatory, the user operation process is not only cumbersome, but also the control of abnormal SIM cards is delayed and uncertain due to the macro-level control of abnormal SIM cards by the operator. Furthermore, the SIM card may still retain caller ID and network functions for a certain period of time, giving fraudsters an opportunity to exploit the system. Considering this situation, one implementation method also includes a micro-suspension of the SIM card through the following step B1:
[0049] Step B1: Perform a minor shutdown on the SIM card.
[0050] The micro-suspension process involves deactivating the file containing the International Mobile Subscriber Identification Number (IMSI) stored in the SIM card.
[0051] Specifically, after S104, the following can be executed: if they are different, the card application performs security authentication on the SIM card through the first terminal device, and the card application performs micro-suspension processing on the SIM card.
[0052] It should be noted that micro-suspension processing is not the same as shutdown in related technologies, but rather disconnects the SIM card's network and communication functions, which can be restored later.
[0053] Before acquiring the pre-collected risk data (i.e., step A1), the SIM card can also be restored via step B2 as follows:
[0054] Step B2: Perform recovery processing on the SIM card.
[0055] The recovery function involves activating the file storing the IMSI on the SIM card.
[0056] Specifically, if the user's real-person authentication is successful, the card application can first perform a recovery function on the SIM card, and then obtain the pre-collected risk data.
[0057] The card application can perform the aforementioned deactivation and activation operations through its own Application Programming Interface (API). Alternatively, the card application can also rewrite the network capability parameters in the SIM card to interrupt the SIM card's network signal (performing a micro-shutdown) and perform recovery operations.
[0058] This embodiment breaks through the traditional method of operators suspending service at the macro level. By deactivating and activating the file storing the IMSI in the SIM card, it achieves accurate and timely micro-suspension and network restoration technology, thereby protecting the security of the SIM card faster and more flexibly.
[0059] In one implementation, the corresponding security authentication policy is executed according to the target risk level (i.e., step A3), which can be specifically executed as follows: steps A3.1 to A3.3:
[0060] Step A3.1: If the target risk level is the second risk level, perform card application authentication.
[0061] In practical applications, if the target risk level is Level 1, no action is taken. If the target risk level is Level 1, it indicates that there is no abnormal behavior or only occasional abnormal behavior, which may be part of the user's normal use. Therefore, it is determined that the SIM card has no fraud risk and can continue to be used normally without further authentication.
[0062] Among them, card application authentication is the verification performed through a card application.
[0063] Step A3.2: If the target risk level is the third risk level, perform card application authentication and operator authentication.
[0064] Among them, operator authentication is verification conducted through the operator's platform.
[0065] If the target risk level is the third risk level, then two-factor authentication will be triggered, which is a dual authentication method of card application authentication + operator authentication.
[0066] Step A3.3: If the target risk level is level four, perform a minor shutdown on the SIM card; and display an offline authentication prompt to the user.
[0067] Among them, the offline authentication prompt 310 is used to instruct users to go to a physical service center for security authentication. Specifically, for example... Figure 3 As shown.
[0068] In this embodiment, a security authentication strategy is designed from multiple dimensions using multiple technologies, making security authentication more user-friendly and improving its accuracy.
[0069] In one implementation, the card application authentication described above (i.e., step A3.1 or step A3.2) can be specifically executed as follows: steps A3.1.1 to A3.1.2:
[0070] Step A3.1.1: The first terminal device displays a second interface to the user, instructing the user to enter the identity information bound to the SIM card, in order to perform card application authentication.
[0071] Specifically, the identity information bound to the SIM card can be a preset number of digits, for example, the last 6 digits of the current SIM card identity information.
[0072] In practical applications, this second interface can be displayed to the user in the form of a pop-up window.
[0073] Step A3.1.2: Upon receiving the target identity information input by the user, compare the identity information bound to the SIM card with the target identity information to determine whether the card application authentication is successful.
[0074] Specifically, if the comparison matches, the card application authentication is successful; if the comparison does not match, the card application authentication fails.
[0075] In one implementation, before displaying the second interface (i.e., step A3.1.1) to the user via the first terminal device, instructing the user to input the identity information bound to the SIM card, step A3.1.3 can also be performed to generate the target data packet:
[0076] Step A3.1.3: Generate the target data packet based on the first IMEI, the mobile phone number in the SIM card, the identity information bound to the SIM card, and the timestamp.
[0077] Specifically, the card application packages the first IMEI of the current terminal device (the first terminal device), the mobile phone number of the current SIM card, the identity information bound to the SIM card, and a timestamp (the checksum is not involved in the calculation) into a structured data packet. Furthermore, this data packet can be encrypted using the 3DES-CBC algorithm. To further ensure the security of this data packet during transmission, a pre-installed private key in the card application can be used to digitally sign the data packet using the HMAC SHA-256 algorithm. Finally, the target data packet is generated.
[0078] Accordingly, before comparing the identity information bound to the SIM card with the target identity information (i.e., step A3.1.2), step A3.1.4 can also be performed to obtain the identity information bound to the SIM card:
[0079] Based on the target data packet, the identity information bound to the SIM card is obtained.
[0080] Specifically, the card application verifies and decrypts the target data packet to obtain the identity information bound to the SIM card.
[0081] In one implementation, operator authentication (i.e., step A3.2) can be specifically performed as follows: steps A3.2.1 to A3.2.2:
[0082] Step A3.2.1: If the card application authentication is successful, send the target data packet to the operator platform so that the operator platform can send the specified information to the mobile phone number corresponding to the SIM card stored on the operator platform based on the target data packet; and display the operator authentication prompt to the user.
[0083] The operator authentication prompt includes a prompt instructing the user to send specified information to the operator for operator authentication; the target data packet is generated based on the first IMEI, the mobile phone number in the SIM card, the identity information bound to the SIM card, and the timestamp.
[0084] For example, the operator platform can encrypt the received target data packet using the SM4 algorithm, then convert it to ASCII encoding and take the first 8 bytes as the specified content.
[0085] Step A3.2.2: Determine whether the first message sent by the operator platform has been received to determine whether the operator authentication was successful.
[0086] The first message is sent by the operator platform after receiving the target information sent by the user and determining that the target information is the same as the specified information.
[0087] Specifically, if the first message from the operator's platform is received, the operator authentication is considered successful; if the first message from the operator's platform is not received, the operator authentication is considered to have failed.
[0088] In one implementation, the second interface also includes a first-time prompt, which instructs the user to perform card application authentication within a first preset time period. Step C1 can also be performed:
[0089] Step C1: Register a timer in the first terminal device and set the timer so that when a first preset time determined based on a first preset duration is reached, the timer sends a second message to the card application indicating that the first preset time has been reached.
[0090] Specifically, the card application uses the SIM card's STK capability to register a Time Management timer on the first terminal device. The first preset time is the sum of the current time (the time of setting) and the first preset duration.
[0091] For example, the first preset duration can be 12 hours. The first prompt is used to instruct the user to authenticate the card application within 12 hours.
[0092] Correspondingly, steps C2 to C3 can also be performed:
[0093] Step C2 involves performing a minor shutdown on the SIM card if the card application authentication fails and a second message is received; and displaying a re-authentication prompt and the first interface to the user so that the user can perform real-person authentication.
[0094] The second time prompt is used to indicate that the user needs to perform operator authentication within a second preset time period.
[0095] Step C3: If the card application authentication is successful, send a request to the first terminal device to indicate the cancellation of the timer.
[0096] In this embodiment, a timer is introduced to precisely control the first preset duration corresponding to card application authentication (the error can be controlled within 10 seconds), thereby precisely controlling the card application to perform micro-suspension processing on the SIM card and requiring the user to re-authenticate.
[0097] In one implementation, such as Figure 4 As shown, the aforementioned operator authentication prompt 410 also includes a second time prompt, which indicates that the user needs to perform operator authentication within a second preset time period. Step D1 can also be performed as follows:
[0098] Step D1: Register a timer in the first terminal device and set the timer so that when a second preset time is reached based on a second preset duration, the timer sends a third message to the card application indicating that the second preset time has been reached.
[0099] In practical applications, the second preset duration can be the same as or different from the first preset duration. For example, the second preset duration can be 3 hours. The initial prompt is used to instruct the user to authenticate the card application within 3 hours.
[0100] Correspondingly, steps D2 to D3 can also be performed:
[0101] Step D2: If the operator authentication fails and a third message is received, perform a minor suspension of the SIM card; and display a re-authentication prompt and a first interface to the user so that the user can perform real-person authentication.
[0102] The re-authentication prompt indicates that the user has failed the operator's authentication and needs to re-authenticate.
[0103] Step D3: If the operator authentication is successful, send a request to the first terminal device to indicate the cancellation of the timer.
[0104] In this embodiment, a timer is introduced to precisely control the second preset duration corresponding to operator authentication (the error can be controlled within 10 seconds), thereby precisely controlling the card application to perform micro-suspension processing on the SIM card and requiring the user to re-authenticate.
[0105] In one implementation, such as Figure 5 As shown, the first interface 510 includes a unified resource locator (URL) 520 provided by the TSM server, which is used by users for real-person authentication.
[0106] If the user's real-person authentication is successful, the pre-collected risk data is obtained (i.e., step A1), which can be specifically executed as follows: Step A1.1:
[0107] Step A1.1: Receive a message from the TSM server indicating successful real-person authentication of the user, and obtain pre-collected risk data by interacting with the TSM server.
[0108] Specifically, it can parse IMEI or IMEISV and interact with the TSM server to obtain pre-collected risk data.
[0109] If the target risk level is level two, after card application authentication (i.e., step A3.1), the following step E1 can also be performed:
[0110] Step E1: If the card application authentication is successful, a fourth message is reported to the TSM server so that the TSM server can clear the risk mark for the SIM card from the TSM server's database.
[0111] The fourth message is the message indicating successful authentication of the character card application.
[0112] If the target risk level is level three, after card application authentication and operator authentication (i.e., step A3.2), the following step E2 can also be performed:
[0113] Step E2: If the card application authentication and the operator authentication are successful, a fifth message is reported to the TSM server so that the TSM server can clear the risk mark for the SIM card in the TSM server's database; wherein, the fifth message is a message indicating that the card application authentication and the operator authentication are successful.
[0114] In this embodiment, the TSM server provides a URL for user authentication, which saves significant costs compared to the H5 pop-up method provided by the terminal device's APP. By setting risk markers for the SIM card in the TSM server's database and interacting with the TSM server through the card application, pre-collected risk data, including the risk markers for the SIM card, can be obtained, enabling a more accurate assessment of the SIM card's risk level. Furthermore, in conjunction with the aforementioned embodiments, the first terminal device displays the first interface described above to the user for authentication. That is, this application integrates the SIM card application, the terminal device, and the TSM server to continuously exchange data and information. By combining the security authentication strategies developed using multiple technologies in the aforementioned embodiments, a complete security authentication system can be created, providing accurate, efficient, and flexible security for the user's SIM card usage environment, thereby preventing fraud at its source.
[0115] Figure 6 This is a flowchart illustrating a security authentication method provided in an embodiment of this application. Figure 6 As shown, the method includes:
[0116] Step 602: The card application is activated, and the card application obtains the second IMEI of the second terminal device it is located on.
[0117] Of course, it is also possible to obtain the second IMEI ID of the second terminal device.
[0118] Step 604: If the card slot changes, obtain the first IMEI of the first terminal device where the SIM card is located.
[0119] Similarly, the first IMEI ID of the first terminal device can also be obtained.
[0120] Step 606: Determine whether the first IMEI and the second IMEI are the same.
[0121] Similarly, it is also possible to determine whether the first IMEISV and the second IMEISV are the same.
[0122] If so, proceed with step 632 below.
[0123] Step 608: If so, a pop-up window including the URL provided by the TSM server is displayed to the user through the first terminal device, asking the user to perform real-person authentication; and the card application calls its preset API to perform an inactivation operation on the file storing the IMSI in the SIM card, so as to realize the micro-suspension processing of the SIM card.
[0124] Step 610: Determine whether the real-person authentication was successful.
[0125] If not, no action will be taken, and the SIM card will remain in a slightly disabled state.
[0126] Step 612: If the user's real-person authentication is successful, the card application calls its preset API to activate the file storing the IMSI in the SIM card, so as to realize the SIM card recovery function.
[0127] Step 614: By interacting with the TSM server, pre-collected risk data is obtained, and based on the pre-collected risk data, a risk assessment is conducted on the SIM card's usage environment to obtain the target risk level of the SIM card.
[0128] Step 616: Determine whether the target risk level of the SIM card is the first risk level.
[0129] If so, proceed with step 632 below.
[0130] Step 618: If not, determine whether the target risk level of the SIM card is the second risk level.
[0131] Step 620: If the target risk level is the second risk level, the card application registers a timer in the first terminal device. The timer is associated with the micro-suspension process, and the card application is authenticated through the card application, the first terminal device, and the TSM server.
[0132] Step 622: Determine whether card application authentication is successful within the first preset time period.
[0133] If not, proceed to step 608; if yes, proceed to step 632.
[0134] Step 624: If the target risk level is not the second risk level, then determine whether the target risk level of the SIM card is the third risk level.
[0135] Step 626: If not, determine the target risk level of the SIM card as the fourth risk level and perform a micro-shutdown on the SIM card.
[0136] Step 628: If yes, the card application registers a timer in the first terminal device. The timer is associated with the micro-suspension process. Card application authentication and operator authentication are performed through the card application, the first terminal device, and the TSM server.
[0137] Step 630: Determine whether both card application authentication and operator authentication are successful within the second preset time period.
[0138] If not, proceed to step 608; if yes, proceed to step 632.
[0139] Step 632: The card application performs a recovery function on the SIM card / the SIM card function is now working normally.
[0140] In this embodiment, the first IMEI of the first terminal device where the SIM card is located is obtained; it is determined whether the first IMEI is the same as the second IMEI stored in the SIM card; the second IMEI is the IMEI corresponding to the second terminal device; the second terminal device includes: the terminal device where the SIM card is initially bound and / or the terminal device where the SIM card is located when it passes security authentication; if they are different, the SIM card is processed for security authentication through the first terminal device. Compared with related anti-telecom fraud technologies that require users (victims) to have strong subjective initiative and rely on users (victims) to identify fraud risks, this solution starts from the source of telecom fraud (fraudsters). When the card application determines that the first IMEI is different from the second IMEI stored in the SIM card, the card application actively performs security authentication on the SIM card through the terminal device, thereby ensuring the security of the SIM card usage environment. This proactively and promptly stops fraudulent behavior from the source. Furthermore, by determining whether to perform security authentication through the card application's determination of whether the first IMEI is the same as the second IMEI stored in the SIM card, the efficiency of security protection is ensured, solving the problem of passive and delayed prevention methods in related anti-telecom fraud technologies.
[0141] Corresponding to the security authentication method provided in the above embodiments, based on the same technical concept, the present invention also provides a security authentication device. Figure 7 This is a schematic diagram of a security authentication device according to an embodiment of the present invention, which is used to perform... Figures 1 to 6 The described security authentication method, such as Figure 7As shown, the security authentication device includes: an acquisition module 710, a judgment module 720, and a security authentication module 730.
[0142] The acquisition module 710 is used to acquire the first IMEI of the first terminal device where the SIM card is located;
[0143] The judgment module 720 is used to determine whether the first IMEI is the same as the second IMEI stored in the SIM card; the second IMEI is the IMEI corresponding to the second terminal device; the second terminal device includes: the terminal device to which the SIM card is initially bound and / or the terminal device where the SIM card is located when it passes security authentication.
[0144] The security authentication module 730 is used to perform security authentication processing on the SIM card through the first terminal device if the SIM card is different.
[0145] In one implementation, the security authentication module 730 includes:
[0146] The real-person authentication unit 7301 is used to display a first interface to the user through the first terminal device, instructing the user to perform real-person authentication, and to obtain pre-collected risk data when the user's real-person authentication is successful.
[0147] Risk level assessment unit 7302 is used to assess the risk of the SIM card’s usage environment based on pre-collected risk data and obtain the target risk level of the SIM card.
[0148] The security policy execution unit 7303 is used to execute the corresponding security authentication policy according to the target risk level.
[0149] In one implementation, the security authentication device further includes a micro-stop module 740. The micro-stop module 740 is used for:
[0150] Perform a minor shutdown on the SIM card;
[0151] The security authentication device also includes a recovery function module 750, used for:
[0152] Perform recovery processing on the SIM card;
[0153] The micro-shutdown process involves deactivating the file storing the IMSI on the SIM card; the recovery process involves activating the file storing the IMSI on the SIM card.
[0154] In one implementation, the security policy enforcement unit 7303 includes:
[0155] Card application authentication subunit 73031 is used to perform card application authentication if the target risk level is the second risk level.
[0156] The operator authentication subunit 73032 is used to perform card application authentication and operator authentication if the target risk level is the third risk level.
[0157] The micro-suspension subunit 73033 is used to perform micro-suspension processing on the SIM card if the target risk level is the fourth risk level; and to display an offline authentication prompt to the user; wherein the offline authentication prompt is used to instruct the user to go to an offline business hall for security authentication.
[0158] In one implementation, the card application authentication subunit 73031 or the operator authentication subunit 73032 is specifically used for:
[0159] The first terminal device displays a second interface to the user, instructing the user to enter the identity information bound to the SIM card, in order to perform card application authentication;
[0160] Upon receiving the target identity information input by the user, the identity information bound to the SIM card is compared with the target identity information to determine whether the card application authentication is successful.
[0161] In one implementation, the card application authentication subunit 73031 or the operator authentication subunit 73032 is further used for:
[0162] Generate the target data packet based on the first IMEI, the mobile phone number in the SIM card, the identity information bound to the SIM card, and the timestamp;
[0163] Based on the target data packet, the identity information bound to the SIM card is obtained.
[0164] In one implementation, the operator authentication subunit 73032 is also used for:
[0165] Upon successful card application authentication, a target data packet is sent to the operator platform, enabling the operator platform to send specified information to the mobile phone number corresponding to the SIM card stored on the operator platform based on the target data packet; and an operator authentication prompt is displayed to the user; wherein, the operator authentication prompt includes a prompt instructing the user to send specified information to the operator for operator authentication; the target data packet is generated based on the first IMEI, the mobile phone number in the SIM card, the identity information bound to the SIM card, and the timestamp;
[0166] Determine whether the first message sent by the operator platform has been received to determine whether the operator authentication was successful; the first message is sent by the operator platform after receiving the target information sent by the user and determining that the target information is the same as the specified information.
[0167] In one implementation, the second interface also includes a first-time prompt, which is used to instruct the user to perform card application authentication within a first preset time.
[0168] The security authentication device also includes a first registration module 760. The first registration module 760 is used for:
[0169] A timer is registered in the first terminal device and configured so that when a first preset time is reached based on a first preset duration, the timer sends a second message to the card application indicating that the first preset time has been reached.
[0170] If the card application authentication fails and a second message is received, the SIM card is temporarily suspended; and a re-authentication prompt and a first interface are displayed to the user so that the user can perform real-person authentication; wherein, the re-authentication prompt is used to indicate that the user has failed the card application authentication and needs to perform real-person authentication again.
[0171] If the card application authentication is successful, a request to instruct the first terminal device to cancel the timer is sent.
[0172] In one implementation, the above-mentioned operator authentication prompt also includes a second time prompt, which is used to indicate that the user needs to perform operator authentication within a second preset time period;
[0173] The security authentication device also includes a second registration module 770. The second registration module 770 is used for:
[0174] A timer is registered in the first terminal device and configured so that when a second preset time is reached based on a second preset duration, the timer sends a third message to the card application indicating that the second preset time has been reached.
[0175] If the operator authentication fails and a third message is received, the SIM card will be temporarily suspended; and a re-authentication prompt and a first interface will be displayed to the user to enable the user to perform real-person authentication; wherein, the re-authentication prompt is used to indicate that the user has failed the operator authentication and needs to perform real-person authentication again.
[0176] If the operator authentication is successful, a request to cancel the timer is sent to the first terminal device.
[0177] In one implementation, the first interface includes a URL provided by the TSM server, which is used by the user for real-person authentication. The real-person authentication unit 7301 is specifically used for:
[0178] Upon receiving a message from the TSM server indicating successful real-person authentication for the user, the user obtains pre-collected risk data through interaction with the TSM server.
[0179] The security policy execution unit 7303 further includes a first mark-clearing subunit 73034. The first mark-clearing subunit 73034 is used for:
[0180] If the card application authentication is successful, a fourth message is reported to the TSM server so that the TSM server can clear the risk mark for the SIM card from the TSM server's database; the fourth message is a message indicating that the card application authentication is successful.
[0181] The security policy execution unit 7303 further includes a second mark-clearing subunit 73035. The second mark-clearing subunit 73035 is used for:
[0182] If both card application authentication and operator authentication are successful, a fifth message is reported to the TSM server so that the TSM server can clear the risk marker for the SIM card from its database; the fifth message is a message indicating that both card application authentication and operator authentication are successful.
[0183] In this embodiment, the first IMEI of the first terminal device where the SIM card is located is obtained; it is determined whether the first IMEI is the same as the second IMEI stored in the SIM card; the second IMEI is the IMEI corresponding to the second terminal device; the second terminal device includes: the terminal device where the SIM card is initially bound and / or the terminal device where the SIM card is located when it passes security authentication; if they are different, the SIM card is processed for security authentication through the first terminal device. Compared with related anti-telecom fraud technologies that require users (victims) to have strong subjective initiative and rely on users (victims) to identify fraud risks, this solution starts from the source of telecom fraud (fraudsters). When the card application determines that the first IMEI is different from the second IMEI stored in the SIM card, the card application actively performs security authentication on the SIM card through the terminal device, thereby ensuring the security of the SIM card usage environment. This proactively and promptly stops fraudulent behavior from the source. Furthermore, by determining whether to perform security authentication through the card application's determination of whether the first IMEI is the same as the second IMEI stored in the SIM card, the efficiency of security protection is ensured, solving the problem of passive and delayed prevention methods in related anti-telecom fraud technologies.
[0184] Those skilled in the art will understand that the above-described security authentication device can be used to implement the security authentication method described above, and the detailed description therein should be similar to the method description in the preceding text. To avoid repetition, it will not be repeated here.
[0185] Based on the same technical concept, this application also provides a security authentication device for performing the above-described security authentication method. Figure 8This is a schematic diagram of the structure of an electronic device to implement various embodiments of this application. The electronic device can vary significantly due to differences in configuration or performance, and may include a processor 810, a communications interface 820, a memory 830, and a communication bus 840. The processor 810, communications interface 820, and memory 830 communicate with each other via the communication bus 840. The processor 810 can call a computer program stored in the memory 830 and executable on the processor 810 to perform the following steps:
[0186] Obtain the first IMEI of the first terminal device where the SIM card is located;
[0187] Determine whether the first IMEI is the same as the second IMEI stored in the SIM card; the second IMEI is the IMEI corresponding to the second terminal device; the second terminal device includes: the terminal device initially bound to the SIM card and / or the terminal device where the SIM card is located when it passes security authentication;
[0188] If they are different, the SIM card will be used for security authentication through the first terminal device.
[0189] In this embodiment, the first IMEI of the first terminal device where the SIM card is located is obtained; it is determined whether the first IMEI is the same as the second IMEI stored in the SIM card; the second IMEI is the IMEI corresponding to the second terminal device; the second terminal device includes: the terminal device where the SIM card is initially bound and / or the terminal device where the SIM card is located when it passes security authentication; if they are different, the SIM card is processed for security authentication through the first terminal device. Compared with related anti-telecom fraud technologies that require users (victims) to have strong subjective initiative and rely on users (victims) to identify fraud risks, this solution starts from the source of telecom fraud (fraudsters). When the card application determines that the first IMEI is different from the second IMEI stored in the SIM card, the card application actively performs security authentication on the SIM card through the terminal device, thereby ensuring the security of the SIM card usage environment. This proactively and promptly stops fraudulent behavior from the source. Furthermore, by determining whether to perform security authentication through the card application's determination of whether the first IMEI is the same as the second IMEI stored in the SIM card, the efficiency of security protection is ensured, solving the problem of passive and delayed prevention methods in related anti-telecom fraud technologies.
[0190] The specific execution steps can be found in the various steps of the above security authentication method embodiments, and can achieve the same technical effect. To avoid repetition, they will not be described again here.
[0191] It should be noted that the security authentication device in this application embodiment includes: a server, a terminal, or other devices besides a terminal.
[0192] The above electronic device structure does not constitute a limitation on the electronic device. An electronic device may include more or fewer components than illustrated, or combine certain components, or arrange them differently. For example, an input unit may include a Graphics Processing Unit (GPU) and a microphone, and a display unit may use a liquid crystal display (LCD), organic light-emitting diode (OLED), or other similar display panels. User input units include at least one of a touch panel and other input devices. A touch panel is also called a touchscreen. Other input devices may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, and joysticks, which will not be elaborated further here.
[0193] Memory can be used to store software programs and various data. Memory can primarily include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area can store the operating system, application programs or instructions required for at least one function (such as sound playback, image playback, etc.). Furthermore, memory can include volatile memory or non-volatile memory, or both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (Synchlink DRAM, SLDRAM), and direct memory bus RAM (DRRAM).
[0194] The processor may include one or more processing units; optionally, the processor integrates an application processor and a modem processor, wherein the application processor mainly handles operations related to the operating system, user interface, and applications, while the modem processor mainly handles wireless communication signals, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into the processor.
[0195] This application also provides a storage medium storing computer-executable instructions. When these computer-executable instructions are executed by a processor, they implement the various processes of the above-described security authentication method embodiments and achieve the same technical effects. To avoid repetition, they will not be described again here.
[0196] The processor is the processor in the electronic device described in the above embodiments. The storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0197] This application also provides a chip, which includes a processor and a communication interface. The communication interface and the processor are coupled. The processor is used to run programs or instructions to implement the various processes of the above-described security authentication method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0198] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0199] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the various processes of the above-described security authentication method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0200] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include multitasking and parallel processing according to the functions involved, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0201] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods of the various embodiments of this application.
[0202] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
Claims
1. A security authentication method, characterized in that, The method, applied to a card application for a user identification SIM card, includes: Obtain the International Mobile Equipment Identity (IMEI) of the first terminal device where the SIM card is located; Determine whether the first IMEI is the same as the second IMEI stored in the SIM card; the second IMEI is the IMEI corresponding to the second terminal device; the second terminal device includes: the terminal device initially bound to the SIM card and / or the terminal device where the SIM card is located when it passes security authentication; If they are different, the first terminal device will display a first interface to the user instructing the user to perform real-person authentication. Upon receiving a message from the TSM server indicating that the user's real-person authentication has been successful, the user will interact with the TSM server to obtain pre-collected risk data. Based on the pre-collected risk data, a risk assessment is performed on the usage environment of the SIM card to obtain the target risk level of the SIM card; If the target risk level is the second risk level, card application authentication is performed, and if the card application authentication is successful, a fourth message is reported to the TSM server so that the TSM server can clear the risk mark for the SIM card from the database of the TSM server; wherein, the fourth message is a message indicating that the card application authentication is successful; If the target risk level is the third risk level, perform card application authentication and operator authentication. If the target risk level is level four, a micro-suspension process is performed on the SIM card; and an offline authentication prompt is displayed to the user; wherein, the micro-suspension process is to deactivate the file storing the International Mobile Subscriber Identity (IMSI) on the SIM card; and the offline authentication prompt is used to instruct the user to go to an offline service center for security authentication.
2. The method according to claim 1, characterized in that, Prior to obtaining the pre-collected risk data, the following is also included: Perform recovery processing on the SIM card; The recovery function involves activating the file storing the IMSI in the SIM card.
3. The method according to claim 1, characterized in that, The card application authentication includes: The first terminal device displays a second interface to the user, instructing the user to input the identity information bound to the SIM card, in order to perform card application authentication; Upon receiving the target identity information input by the user, the identity information bound to the SIM card is compared with the target identity information to determine whether the card application authentication is successful.
4. The method according to claim 1, characterized in that, The first interface includes a URL for the Unified Resource Locator (URL) provided by the TSM server, which is used by users for real-person authentication. If the target risk level is the third risk level, after performing card application authentication and operator authentication, the method further includes: If the card application authentication and the operator authentication are both successful, a fifth message is reported to the TSM server so that the TSM server can clear the risk marker for the SIM card from its database; wherein, the fifth message is a message indicating that the card application authentication and the operator authentication are both successful.
5. A security authentication device, characterized in that, Card application for SIM cards, the device comprising: The acquisition module is used to acquire the first International Mobile Equipment Identity (IMEI) of the first terminal device where the SIM card is located; The determination module is used to determine whether the first IMEI is the same as the second IMEI stored in the SIM card; the second IMEI is the IMEI corresponding to the second terminal device; the second terminal device includes: the terminal device to which the SIM card is initially bound and / or the terminal device where the SIM card is located when it passes security authentication; The security authentication module is used to display a first interface to the user through the first terminal device if the two are different, instructing the user to perform real-person authentication. When the TSM server returns a message indicating that the user's real-person authentication is successful, the module interacts with the TSM server to obtain pre-collected risk data. Based on the pre-collected risk data, a risk assessment is performed on the usage environment of the SIM card to obtain the target risk level of the SIM card; If the target risk level is the second risk level, card application authentication is performed, and if the card application authentication is successful, a fourth message is reported to the TSM server so that the TSM server can clear the risk mark for the SIM card from the database of the TSM server; wherein, the fourth message is a message indicating that the card application authentication is successful; If the target risk level is the third risk level, perform card application authentication and operator authentication. If the target risk level is level four, perform a micro-shutdown on the SIM card; and display an offline authentication prompt to the user; wherein, the micro-shutdown is to deactivate the file storing the IMSI on the SIM card; and the offline authentication prompt is used to instruct the user to go to an offline service center for security authentication.
6. A security authentication device, characterized in that, The security authentication device includes: Processor; and A memory configured to store computer-executable instructions configured to be executed by the processor, the executable instructions including instructions for performing the security authentication method as described in any one of claims 1-4.
7. A storage medium, characterized in that, The storage medium is used to store computer-executable instructions that cause a computer to perform the security authentication method as described in any one of claims 1-4.
8. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the security authentication method as described in any one of claims 1-4.
Citation Information
Patent Citations
Mobile phone card anti-theft method and device and readable storage medium
CN110312257A
Method for switching login accounts of electronic equipment
CN118656820A