Identity identification card activation method and device and readable medium

By establishing a non-terrestrial communication network connection between the terminal and the server, verifying and activate the identity card, the traditional activation operation inconvenience and security risks are solved, and higher security and convenience are achieved.

CN120018105APending Publication Date: 2025-05-16ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311522998.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-14
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

Traditional activation operations such as card binding, identity authentication, and network authorization have inconveniences and security risks, especially when non-terrestrial communication networks are required, the prior art is difficult to effectively solve these problems.

Method used

By establishing a non-terrestrial communication network connection between the terminal and the server, interactively verify the legality of the activation operation, and activate the identity card under legal circumstances. This method uses non-terrestrial communication networks such as satellite communication to avoid the inconvenience of scanning QR codes on site and the risk of leakage caused by QR code transmission.

Benefits of technology

It realizes SIM card activation on terminals that do not have the usual network service capabilities, reduces the risks caused by early network authorization, and improves the security and convenience of the activation process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120018105A_ABST
    Figure CN120018105A_ABST
Patent Text Reader

Abstract

The invention provides an identity identification card activation method and device and a readable medium, and belongs to the technical field of communication. The identity identification card activation method is applied to the terminal provided with the identity identification card, the terminal establishes communication connection with a server through a non-ground communication network, and the method comprises the following steps: verifying the validity of activation operation through interaction with the server; and under the condition that the activation operation is legal, activating the identity identification card through interaction with the server. The method is used for improving the security and convenience of activation of the identification card.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communication technology, and in particular to an identity card activation method, device and readable medium. Background Art

[0002] At present, mobile phone models include industry-specific models customized by users, including power, coal and other industry-specific models. Considering the user's security needs, when a new industry-customized mobile phone is issued to a user, the user needs to perform a series of activation operations such as machine card binding, identity authentication and network authorization when using it for the first time to ensure that the industry-customized mobile phone has higher security.

[0003] There are two ways to activate traditional card binding, identity authentication, and network authorization:

[0004] Method 1: QR code scanning

[0005] Before scanning the QR code, the subscriber identification module (SIM) card service of the mobile phone is in a fully restricted state, and users cannot make calls, surf the Internet, or send and receive text messages. The desktop program (Launcher) restricts users from entering the desktop, and users can only open the camera. After scanning the QR code, the Launcher program cancels the entry restriction, and obtains the relevant configuration information of the private network from the QR code and writes it into the mobile phone, so that the mobile phone can access the private network. At this time, the mobile phone activates the call, Internet and text message functions. This method requires users to scan the QR code on site, which is extremely inconvenient. There is a risk of leakage and cracking of the QR code when it is circulated, which poses a security risk. In addition, since the work system and the life system need to correspond to the QR code one by one, the QR code scanned by customer group A is different from the QR code scanned by customer group B, which can easily cause users to scan the wrong QR code, which in turn leads to problems such as the mobile phone not being able to be used normally.

[0006] Method 2: Activate via wireless cellular network data

[0007] This method requires the mobile phone to access the network first, establish a wireless data connection, and establish a data exchange channel with the server to activate the mobile phone. The obvious problem with this method is that it is unsafe, because the mobile phone must first register the network and activate the data connection. The mobile phone already has the ability to access the private network, which is basically equivalent to authorizing all business capabilities for the mobile phone. This requires secondary control on the mobile phone side. This method has many control loopholes and is rarely used in practice. If it is replaced with access through WiFi hotspots, it will be even more incomplete. The reason is that there are many WiFi hotspots in the outside world, and the security of the WiFi hotspots connected to the mobile phone cannot be controlled. The security of WiFi hotspots can only be further confirmed after access. Industry user mobile phones usually require the WiFi function to be disabled. The basic requirement for industry customized mobile phones is that they are not allowed to connect to the Internet of Things, and can only be connected through a private network, and the private network can only be accessed through a cellular network. Summary of the invention

[0008] The embodiments of the present disclosure provide an identity card activation method, device, and readable medium.

[0009] A first aspect of an embodiment of the present disclosure provides an identity card activation method, which is applied to a terminal on which the identity card is installed, wherein the terminal establishes a communication connection with a server via a non-terrestrial communication network, and the method includes:

[0010] Verify the legitimacy of the activation operation by interacting with the server;

[0011] When the activation operation is legal, the identity card is activated by interacting with the server.

[0012] A second aspect of the disclosed embodiment provides an identity card activation method, which is applied to a server, wherein the server establishes a communication connection with a terminal in which the identity card is installed via a non-terrestrial communication network;

[0013] Verifying the legitimacy of the activation operation by interacting with the terminal;

[0014] When the activation operation is legal, the identity card is activated by interacting with the terminal.

[0015] A third aspect of the disclosed embodiment provides an identity card activation device, comprising:

[0016] at least one processor;

[0017] A memory having at least one program stored thereon, wherein when the at least one program is executed by the at least one processor, the at least one processor implements the method according to the first aspect or the second aspect;

[0018] At least one I / O interface is connected between the processor and the memory and is configured to implement information interaction between the processor and the memory.

[0019] A fourth aspect of the embodiments of the present disclosure provides a computer-readable medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the method according to the first aspect or the second aspect.

[0020] The embodiments of the present disclosure have the following advantages:

[0021] The terminal and the server establish a communication connection through a non-terrestrial communication network. The terminal and the server interact to verify the legality of the SIM card activation operation. If the legality is confirmed, the terminal activates the SIM card through interaction with the server. Therefore, even if the terminal does not have the usual network service capabilities, it only needs to be able to perform non-terrestrial communications to activate the SIM card, avoiding the risks caused by giving the terminal certain network service capabilities before activating the SIM card; and, using a non-terrestrial communication network to activate the SIM card also avoids the inconvenience caused by scanning the QR code on site, and there is no risk of leakage caused by the transmission of the QR code, making the operation more convenient. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 A schematic diagram of a communication system architecture provided in an embodiment of the present disclosure;

[0023] Figure 2 A schematic diagram of an exemplary structure of a terminal provided in an embodiment of the present disclosure;

[0024] Figure 3 A schematic diagram of the structure of an input and output device provided in an embodiment of the present disclosure;

[0025] Figure 4 A schematic diagram of the structure of a communication module management module provided in an embodiment of the present disclosure;

[0026] Figure 5 A schematic diagram of a flow chart of an identity card activation method applied to a terminal provided in an embodiment of the present disclosure;

[0027] Figure 6 A schematic diagram of a flow chart of an identity card activation method applied to a server provided in an embodiment of the present disclosure;

[0028] Figure 7 A schematic diagram of a process of a terminal interacting with a server to perform machine-card binding provided in an embodiment of the present disclosure;

[0029] Figure 8 A schematic diagram of the structure of an identity card activation device provided in an embodiment of the present disclosure;

[0030] Fig. 9 The present invention is a schematic diagram of the structure of another identity card activation device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0031] The specific implementation of the present disclosure is described in detail below in conjunction with the accompanying drawings. It should be understood that the specific implementation described herein is only used to illustrate and explain the present disclosure, and is not used to limit the present disclosure.

[0032] As used in this disclosure, the term "and / or" includes any and all combinations of one or more of the associated listed items.

[0033] The terms used in the present disclosure are only used to describe specific embodiments and are not intended to limit the present disclosure.As used in the present disclosure, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.

[0034] When the terms “comprising” and / or “made of…” are used in the present disclosure, it specifies the existence of the stated features, integers, steps, operations, elements and / or components, but does not exclude the existence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.

[0035] Unless otherwise defined, all terms (including technical and scientific terms) used in this disclosure have the same meaning as those commonly understood by those of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and this disclosure, and will not be interpreted as having an idealized or overly formal meaning unless explicitly defined in this disclosure.

[0036] Satellite communication technology is a technology that uses artificial satellites as relay stations to forward radio waves for communication between two or more earth base stations. Since the 1990s, the rapid development of satellite communication has promoted the advancement of antenna technology. Satellite communication has many advantages, such as wide coverage, large communication capacity, good transmission quality, convenient and rapid networking, and easy global seamless connection. It is considered to be an indispensable means to establish global personal communication.

[0037] With the popularity of smart phones, mobile phones have become an indispensable device in people's lives. However, in some special circumstances, such as remote areas or emergencies, mobile phone signals may be interrupted, causing the trouble of being unable to contact the outside world. In order to solve this problem, the mobile phone satellite communication function came into being. This function allows users to send messages and location information via satellite when there is no mobile network signal, ensuring that they can always stay in touch with the outside world.

[0038] The satellite communication function of mobile phones can be realized through two working mechanisms: the Radio Determination Satellite Service (RDSS) of the Beidou Satellite Navigation System and the Radio Navigation Satellite System (RNSS). The working principle of RNSS is similar to that of the Global Positioning System (GPS), which can achieve accurate and fast positioning and is widely used in map navigation applications. RDSS is a unique function of the Beidou system, providing fast positioning, location reporting, short message communication and high-precision timing services. The "short message communication" in the satellite communication function of mobile phones allows users to communicate simply and send location information without a mobile network, which has certain practical value.

[0039] Industrial user phones are generally dual-system phones, including work system and life system, and the two systems can be switched at will during operation. The work system has a very high security level, prohibits connecting to the external network, uses a dedicated SIM card, and the SIM card and the phone are bound to each other. Replacing the SIM card will lock the phone. The SIM card contains encrypted certificate information, which needs to be decrypted, read, and verified when accessing the network. Industrial user phones also have single-system phones, and the single system and the work system have the same security requirements.

[0040] In traditional activation operations such as machine-card binding, identity authentication, and network authorization, there are problems of inconvenient and unsafe operation. In order to solve these problems, a method for activating a terminal SIM card using a non-terrestrial communication network such as satellite communication is provided in the embodiments of the present disclosure, so as to improve the security and convenience of the SIM card activation process. The method can be used for SIM card activation in various scenarios, such as SIM card activation for industry customized users, or SIM card activation for users with high security requirements.

[0041] The present disclosure provides a communication system architecture. Figure 1 The figure shows a schematic diagram of the communication system architecture, which includes a terminal 10, a non-terrestrial communication link 11 and a server 12. The terminal 10 and the server 12 establish a communication connection through the non-terrestrial communication link 11. The terminal 10 and the server 12 here need to have a non-terrestrial communication function. Among them, the non-terrestrial communication link includes a satellite, and the corresponding non-terrestrial communication function refers to a satellite communication function. The server 12 is used to manage terminals with non-terrestrial communication functions. The non-terrestrial communication link includes a satellite, Figure 1 Take satellite as an example.

[0042] The terminal 10 includes various electronic devices such as mobile phones, computers, wearable devices, etc. The terminal 10 and the server 12 form a client / server architecture.

[0043] The server 12 is used to implement short message and / or data interaction with a terminal having non-terrestrial communication capabilities, and at the same time connect to the authentication server and / or gateway of the industry user's intranet to provide a bridge for information exchange between the terminal and the authentication server of the intranet.

[0044] The communication system architecture also includes a 3A authentication gateway 13 that establishes a communication connection with the server. The 3A authentication gateway 13 is used to execute a specific operation of activating the identity card of the terminal according to information provided by the server.

[0045] In an exemplary embodiment, Figure 2 The diagram shown is a schematic diagram of an example terminal structure, which mainly includes a main control module, input and output devices, a SIM / flash memory (TF) card reading device, a communication module management module, a wireless parameter configuration module, a satellite communication data transmission module and a satellite communication module.

[0046] like Figure 3 As shown, the input and output devices are used to receive information input by the user, including data input such as characters, numbers, symbols, camera image pickup, sound pickup, eyeprint scanning, NFC scanning, infrared scanning, Bluetooth reading, WiFi scanning, etc. This type of input capability facilitates users to have a variety of choices when entering identity information, including facial recognition, voiceprint recognition, ID card NFC induction reading, chip induction scanning, etc. Therefore, the input and output devices include but are not limited to keyboards, Bluetooth, cameras, screens, NFC, and infrared.

[0047] like Figure 4 As shown, the communication module management module includes at least one of a communication framework, a local radio interface layer (RIL Native) and a modem. The communication module management module has the ability to manage the communication modules.

[0048] SIM / Flash Memory (TF) card reader, used to read certificates from SIM cards or TF cards. Encrypted certificate information set by some units is stored on SIM cards or TF cards. Certificate reading and verification is required to confirm that it is a legal SIM card issued by the unit, or to confirm that the user can access the corresponding content according to chip authorization.

[0049] The satellite communication data transmission module has the ability to re-encapsulate and encrypt data, and needs to negotiate information communication with the server to establish a communication rule for device activation or remote control.

[0050] The satellite communication module has the ability to send control information.

[0051] The wireless parameter configuration module has the wireless parameter configuration capability.

[0052] Based on the system architecture, an embodiment of the present disclosure provides an identity card activation method, which is applied to a terminal on which the identity card is installed, and the terminal establishes a communication connection with a server via a non-terrestrial communication network.

[0053] The premise for the terminal to establish a communication connection with the server through the non-terrestrial communication network is that the terminal can search for an effective non-terrestrial communication network signal and meet non-terrestrial communication conditions. For example, the terminal searches for satellite signals and meets satellite communication conditions.

[0054] Figure 5 The figure shows a flow chart of the method for activating the identity card applied to the terminal, which mainly includes the following steps:

[0055] Step 501: The terminal verifies the legitimacy of the activation operation by interacting with the server.

[0056] In some embodiments, the terminal verifies the legitimacy of the activation operation by interacting with the server, including: the terminal sends an activation operation verification request to the server, the activation operation verification request includes the identification information of the terminal, the identification information of the identity card and the current physical location information of the terminal; the terminal receives an activation operation verification response returned by the server, the activation operation verification response is returned by the server after verifying the legitimacy of the activation operation verification request.

[0057] Among them, the server verifies whether the terminal is legal based on the terminal's identification information, verifies whether the identity card is legal based on the identity information of the identity card, and verifies whether the current location area of ​​the terminal is legal based on the terminal's current physical location information. If the terminal is legal, the identity card is legal, and the terminal's current physical location information is legal, the server returns a verified activation operation verification response to the terminal.

[0058] In some embodiments, the activation operation verification response includes a token, and the token is used to indicate the validity duration of the legal verification result; the method also includes: when the token expires, the terminal re-executes the step of verifying the legality of the activation operation by interacting with the server.

[0059] In an exemplary embodiment, the terminal sends an activation operation verification request to the server through a satellite communication network within the maximum activation waiting time, and the request includes at least one of the identification information such as the International Mobile Subscriber Identification Number (IMSI) and the Integrated Circuit Card Identity (ICCID) of the SIM card, at least one of the identification information such as the International Mobile Equipment Identity (IMEI) of the terminal, and the longitude and latitude information of the current location of the terminal. After the server verifies that the SIM card is legal, the terminal is legal, and the longitude and latitude information of the current location of the terminal is legal, it returns an activation operation verification response to the terminal, which carries a token. During the validity period of the token, the terminal does not need to initiate an activation operation verification request to the server again.

[0060] Tokens can be used to avoid the situation where multiple activation operation verification requests are initiated due to signal loss in non-ground communication networks or transmission delays exceeding expectations, thereby reducing unnecessary verification processes. In addition, the server side can also improve security by customizing and changing tokens.

[0061] Step 502: If the activation operation is legal, the terminal activates the identity card by interacting with the server.

[0062] In some embodiments, before the terminal activates the identity card through interaction with the server, the method also includes: the terminal shakes hands with the server through the non-terrestrial communication network to obtain a session identifier; the session identifier is used to carry in the process of interacting with the server to activate the identity card to indicate that the interactive activation process is a further process of this handshake.

[0063] In an exemplary embodiment, the specific process of the terminal shaking hands with the server through the non-terrestrial communication network includes: the terminal sends a handshake signal to the server through the non-terrestrial communication network, for example, the handshake signal includes connection request information; the terminal receives a response signal from the server indicating that the connection request is accepted, and the response signal includes a session identifier (transaction id) generated for this session. For example, the terminal sends a handshake signal to the server through a satellite short message or satellite data. Alternatively, the terminal receives a handshake signal sent by the server through the non-terrestrial communication network, for example, the handshake signal includes connection request information, and replies to the server with a response signal indicating that the connection request is accepted, and the response signal includes a session identifier generated for this session.

[0064] When the terminal receives the session identifier returned by the server or the terminal returns the session identifier to the server, it means that the handshake is successful and the server has paid attention to further information interaction with the terminal. The session identifier is carried in the further information interaction process to distinguish other information, such as carrying the session identifier in messages such as mdm_request and mdm_response.

[0065] In some embodiments, the terminal obtains information carrying the session identifier but does not display it to ensure information security.

[0066] In some embodiments, when the activation operation is legal, the terminal activates the identity card by interacting with the server, including:

[0067] If the activation operation is legal, the terminal completes at least one service required to activate the identity card through interaction with the server and obtains network configuration parameters of the identity card;

[0068] The terminal configures the terminal according to the network configuration parameters to activate the identity card.

[0069] In some embodiments, the terminal completes at least one service required to activate the identity card by interacting with the server, including: for any task in the at least one service, the terminal obtains a time control parameter corresponding to activating the service by interacting with the server, determines a time limit for executing the service according to the time control parameter, and interacts with the server within the time specified by the time limit to complete the service.

[0070] In some embodiments, the terminal obtains the time control parameter corresponding to the activation of the service through interaction with the server, determines the time limit for executing the service according to the time control parameter, and completes the service by interacting with the server within the time limit, including: sending the type identifier of the service to the server; receiving the time control parameter corresponding to the service returned by the server; determining the latest first time to initiate the service according to the time control parameter, sending a request to execute the service to the server before the first time; determining the latest second time to terminate the service according to the time control parameter, and waiting to receive the response returned by the server to execute the service before the second time. The service interacting with the server is thus completed.

[0071] In some embodiments, the time control parameters include: the time required for the service to be completed, the maximum response time of the server, and the maximum delay time of the non-terrestrial communication network transmission.

[0072] The terminal determines the first moment of initiating the service at the latest according to the time control parameter, including: on the basis of the moment of obtaining the time control parameter, superimposing the time required for the completion of the service to obtain a first sum value, subtracting the maximum response time of the server and subtracting 2 times the maximum delay time of the non-terrestrial communication network transmission from the first sum value, to obtain the first moment of initiating the service at the latest;

[0073] The terminal determines the second time at which the service is to be terminated at the latest according to the time control parameters, including: based on the time of sending the request to execute the service, superimposing the maximum response time of the server to obtain a second sum value, and adding the second sum value to twice the maximum delay time of the non-terrestrial communication network transmission to obtain the second time at which the service is to be terminated at the latest.

[0074] It should be noted that, when the terminal and the server agree on the service type or only need to interact with the server to complete one type of service, it is not necessary to send the service type identifier to the server, and the service interaction can be completed directly according to the time control parameter returned by the server. Specifically, the time limit for executing the service is determined according to the time control parameter, and the service is completed by interacting with the server within the time limit, including: on the basis of the moment of obtaining the time control parameter, superimposing the time required for completing the service to obtain a first sum value, subtracting the maximum response time of the server and subtracting 2 times the maximum delay time of the non-terrestrial communication network transmission from the first sum value to obtain the first moment of initiating the service at the latest; on the basis of the moment of sending the request to execute the service, superimposing the maximum response time of the server to obtain a second sum value, adding the second sum value to 2 times the maximum delay time of the non-terrestrial communication network transmission to obtain the second moment of terminating the service at the latest; interacting with the server within the time limit of the first moment and the second moment to complete the service.

[0075] It should be noted that increasing time control is an important feature of non-terrestrial communication networks such as satellites. Taking satellites as an example, because the orbital altitude of synchronous satellites is usually above 36,000 kilometers, the signal transmission back and forth between the earth and the satellite will produce a certain transmission delay. During the satellite transmission process, the movement of the terminal may cause signal loss, disconnection, and reconnection. The server needs to reserve resources in a certain time window to ensure that the terminal establishing the session can obtain communication services. At the same time, the use of satellite resources follows the principle of economy, so effective time control is required.

[0076] The terminal initiates the service before the first moment in order to reserve a reasonable time for the server to reply to the information. The reasonable time reserved includes the internal response time of the server (i.e. the maximum response time of the server), the time taken for the round-trip transmission of satellite information (i.e. the maximum delay time of the non-ground communication network transmission * 2) and the time required to complete the service.

[0077] The terminal waits for the satellite information reply, and needs to end the waiting after the second moment times out, which is considered as a failure in the activation of the service. After the failure, the service is reactivated after re-obtaining the token. If the token cannot be re-obtained, the handshake negotiation and token re-obtaining are required.

[0078] In some embodiments, the at least one service includes at least one of the following:

[0079] User identity information authentication service;

[0080] Encryption certificate authentication business;

[0081] A service for binding the terminal, the identity card and the user's identity information.

[0082] In an exemplary embodiment, the user identity information authenticated in the user identity information authentication service includes but is not limited to at least one of the following: the user's work number, ID number, fingerprint, voiceprint, eyeprint, facial scan image, etc.

[0083] In an exemplary embodiment, in the encryption certificate authentication service, the encryption certificate may be read from an encryption card of a SIM card, a TF card or other media.

[0084] In some embodiments, the terminal obtains network configuration information in a response to executing a service, and the network configuration information includes the target network Public Land Mobile Network (PLMN) information, the access point name (APN) of the private network connection or the switching data network name (DNN) information, etc. The terminal uses the network configuration information to configure the wireless module, thereby obtaining the wireless network server and activating the wireless network data connection.

[0085] In some embodiments, during communication through a non-terrestrial communication network, the terminal obtains control instructions sent by the server, and controls the terminal functions according to the control instructions, for example, disabling device functions, enabling device functions, or remotely configuring parameters.

[0086] The disclosed embodiment also provides another method for activating an identity card, which is applied to a server, wherein the server establishes a communication connection with a terminal on which the identity card is installed via a non-terrestrial communication network.

[0087] Figure 6 The figure shows a flow chart of the identity card activation method applied to the server, which mainly includes the following steps:

[0088] Step 601: The server verifies the legitimacy of the activation operation by interacting with the terminal.

[0089] In some embodiments, the server verifies the legitimacy of the activation operation by interacting with the terminal, including:

[0090] receiving an activation operation verification request sent by the terminal, wherein the activation operation verification request includes identification information of the terminal, identification information of the identity card, and current physical location information of the terminal;

[0091] Verifying the legitimacy of the terminal according to the identification information of the terminal;

[0092] Verifying the legitimacy of the identity card according to the identification information of the identity card;

[0093] Determining whether the terminal is currently located in an authorized location area according to the current physical location information of the terminal;

[0094] In the case that the terminal is legal, the identity card is legal, and the terminal is currently located in an authorized location area, the terminal is determined to be a valid authorized device, and an activation operation verification response is returned to the terminal.

[0095] In an exemplary embodiment, the server sends the identification information of the terminal, the identification information of the identity card, and the current physical location information of the terminal to a 3A authentication gateway, and the legitimacy is verified by the 3A authentication gateway.

[0096] In some embodiments, the activation operation verification response includes a token, and the token is used to indicate the effective duration of the legality of the verification result; the method also includes: in the event that the token expires, the server re-executes the step of verifying the legality of the activation operation by interacting with the terminal.

[0097] Tokens can be used to avoid the situation where multiple activation operation verification requests are initiated due to signal loss in non-ground communication networks or transmission delays exceeding expectations, thereby reducing unnecessary verification processes. In addition, the server side can also improve security by customizing and changing tokens.

[0098] Step 602: If the activation operation is legal, the server activates the identity card by interacting with the terminal.

[0099] In some embodiments, before the server activates the identity card through interaction with the terminal, it also includes: the server shakes hands with the terminal through a non-terrestrial communication network to obtain a session identifier, and the session identifier is used to carry in the process of interacting with the terminal to activate the identity card to indicate that the interactive activation process is a further process of this handshake.

[0100] In an exemplary embodiment, the specific process of the server shaking hands with the server through the non-terrestrial communication network includes: the server sends a handshake signal through the non-terrestrial communication network, for example, the handshake signal includes connection request information, and receives a response signal from the terminal indicating that the connection request is accepted, and the response signal includes a session identifier generated for this session, for example, the server sends a handshake signal to the terminal through a satellite short message or satellite data. Alternatively, the server receives a handshake signal sent by the terminal through the non-terrestrial communication network, for example, the handshake signal includes connection request information, and replies to the terminal with a response signal indicating that the connection request is accepted, and the response signal includes a session identifier generated for this session.

[0101] In some embodiments, when the activation operation is legal, the server activates the identity card by interacting with the terminal, including:

[0102] In the case where the activation operation is legal, at least one service required for activating the identity card is completed through interaction with the terminal, and the network configuration parameters of the identity card are sent to the terminal.

[0103] In some embodiments, the server completes at least one service required to activate the identity card through interaction with the terminal, including:

[0104] For any task in the at least one service, the time control parameters corresponding to the activation of the service are returned to the terminal, and the time limit for executing the service is determined according to the time control parameters, and the service is completed by interacting with the terminal within the time limit.

[0105] In some embodiments, the time control parameters include: the time required for the service to be completed, the maximum response time of the server, and the maximum delay time of the non-terrestrial communication network transmission.

[0106] In some embodiments, the server returns a time control parameter corresponding to activating the service to the terminal, determines a time limit for executing the service according to the time control parameter, and interacts with the terminal to complete the service within the time limit, including:

[0107] Determine an effective response time window according to the time required for completion of the service, wherein the starting point of the effective response time window is the moment when the time control parameter is sent to the terminal, and the end point of the effective response time window is the cumulative moment of the starting point, the time required for completion of the service and the maximum delay time of the non-terrestrial communication network transmission;

[0108] When a moment obtained by superimposing the maximum delay time of the non-terrestrial communication network transmission at the current moment falls within the effective response time window, interacting with the terminal to complete the service;

[0109] When the time obtained by adding the maximum delay duration of the non-terrestrial communication network transmission to the current time exceeds the effective response time window, the interaction of the service with the terminal is stopped.

[0110] Among them, the maximum delay duration of non-terrestrial communication network transmission superimposed on the starting point of the effective response time window is to align the terminal side's calculation of the starting point of the service time window (ie the first moment).

[0111] It should be noted that increasing time control is an important feature of non-terrestrial communication networks such as satellites. Taking satellites as an example, because the orbital altitude of synchronous satellites is usually above 36,000 kilometers, the signal transmission back and forth between the earth and the satellite will produce a certain transmission delay. During the satellite transmission process, the movement of the terminal may cause signal loss, disconnection, and reconnection. The server needs to reserve resources in a certain time window to ensure that the terminal establishing the session can obtain communication services. At the same time, the use of satellite resources follows the principle of economy, so effective time control is required.

[0112] In some embodiments, the at least one service includes at least one of the following:

[0113] User identity information authentication service;

[0114] Encryption certificate authentication business;

[0115] A service for binding the terminal, the identity card and the user's identity information.

[0116] In an exemplary embodiment, the user identity information authenticated in the user identity information authentication service includes but is not limited to at least one of the following: the user's work number, ID number, fingerprint, voiceprint, eyeprint, facial scan image, etc.

[0117] In an exemplary embodiment, in the encryption certificate authentication service, the encryption certificate can be read from an encryption card of a SIM card, a TF card or other media. The server sends the encryption certificate to the 3A authentication gateway to verify the legitimacy of the encryption certificate.

[0118] In some embodiments, the network configuration information includes target network PLMN information, access point APN of private network connection or switching DNN information, etc. The terminal uses the network configuration information to configure the wireless module to obtain the wireless network server and activate the wireless network data connection.

[0119] In some embodiments, the activation process of the service that binds the terminal, the identity card and the user identity information includes: the server updates the user identity authentication server, establishes a binding relationship between the terminal, the identity card and the user identity information, turns on the network server of the SIM card through the operator network, activates the identity authentication server gateway and obtains the intranet IP address assigned to the user; and returns the network configuration information to the terminal through the non-terrestrial communication network.

[0120] In some embodiments, the method further includes: the server interacts with the terminal through the non-terrestrial communication network to control the terminal. For example, the server controls the terminal to disable device functions, enable device functions, or remotely configure parameters through the satellite communication network.

[0121] In an exemplary embodiment, the server remotely controls the terminal. When the terminal is not in the wireless network coverage area, the server monitors the end point using satellite communication, and implements control and use of key points during the satellite communication time, by remotely disabling various device functions of the terminal, or by remotely enabling various device functions, or by remotely configuring parameters, etc. For example, the server remotely controls IoT devices in remote areas through satellite communication.

[0122] In an exemplary embodiment, the process of the terminal interacting with the server to perform machine-card binding is as follows: Figure 7 As shown, it mainly includes the following steps:

[0123] Step 701, the terminal searches for satellite signals and matches the antenna angle;

[0124] Step 702, the terminal negotiates a service transmission mode with the server;

[0125] Step 703: The terminal and the server communicate through service signaling to confirm that the terminal, the SIM card and the current location of the terminal are legitimate, and obtain a Token;

[0126] Step 704, the terminal interacts with the server to authenticate the user identity through activation instructions. If the interaction fails, step 705 is executed. If the interaction succeeds, step 707 is executed.

[0127] Step 705, determine whether the Token is invalid, if so, return to step 703 and re-execute, otherwise, execute step 706;

[0128] Step 706: If there is no network response or the network feedback fails, the process returns to step 702.

[0129] Step 707, the terminal performs encryption certificate authentication with the server, and returns to step 705 if the authentication fails, and executes step 708 if the authentication succeeds;

[0130] Step 708: The machine and card are bound successfully.

[0131] Among them, through the steps of negotiation and business signaling communication, it is equivalent to building a virtual session channel in Client / Server mode between the terminal and the server. The purpose of establishing the virtual session channel is to allow the server to reserve resources for a certain signaling communication. When multiple sets of signaling processes are concurrent, different signaling processes can be clearly distinguished.

[0132] In the disclosed embodiment, a communication connection is established between the terminal and the server through a non-terrestrial communication network, and the terminal and the server interact to verify the legality of the SIM card activation operation. When the legality is confirmed, the terminal activates the SIM card through interaction with the server. Therefore, even if the terminal does not have the usual network service capabilities, it only needs to be able to perform non-terrestrial communications to activate the SIM card, avoiding the risk caused by giving the terminal certain network service capabilities before activating the SIM card; and, using a non-terrestrial communication network to activate the SIM card also avoids the inconvenience caused by scanning the QR code on site, and there is no risk of leakage caused by the transmission of the QR code, and the operation is more convenient.

[0133] In addition, it can make full use of the advantages of location information carried by non-ground communications such as satellites to determine the area to which the terminal's current physical location information belongs, and then activate the SIM card if the area belongs to the activation area. In this way, an activation area limitation strategy can be adopted to ensure security. For example, SIM cards are only allowed to be activated in the area where the unit is located. There are restrictions on people entering and leaving the area where the unit is located, which ensures the security of activating the SIM card.

[0134] The step division of the above various methods is only for clear description. When implemented, they can be combined into one step or some steps can be split and decomposed into multiple steps. As long as they include the same logical relationship, they are all within the protection scope of this disclosure. Adding insignificant modifications to the algorithm or process or introducing insignificant designs without changing the core design of the algorithm and process are all within the protection scope of this disclosure.

[0135] An embodiment of the present disclosure provides an identity card activation device, which is applied to a terminal. The terminal establishes a communication connection with a server via a non-terrestrial communication network. The specific implementation of the terminal can refer to the relevant description of the method embodiment, which will not be repeated here. Figure 8The structure diagram of the identity card activation device applied to the terminal is shown, which mainly includes:

[0136] Verification module 801, used to verify the legitimacy of the activation operation by interacting with the server;

[0137] The activation module 802 is used to activate the identity card by interacting with the server if the activation operation is legal.

[0138] In some embodiments, the verification module 801 is used to:

[0139] Sending an activation operation verification request to the server, wherein the activation operation verification request includes identification information of the terminal, identification information of the identity card, and current physical location information of the terminal;

[0140] An activation operation verification response returned by the server is received, where the activation operation verification response is returned by the server after performing a validity verification according to the activation operation verification request.

[0141] In some embodiments, the activation operation verification response includes a token, and the token is used to indicate the effective duration of the verification result being legal;

[0142] The verification module 801 is also used for:

[0143] In the event that the token is invalid, the step of verifying the legitimacy of the activation operation by interacting with the server is re-executed.

[0144] In some embodiments, the activation module 802 is used to:

[0145] If the activation operation is legal, completing at least one service required for activating the identity card through interaction with the server and obtaining network configuration parameters of the identity card;

[0146] The terminal is configured according to the network configuration parameters to activate the identity card.

[0147] In some embodiments, the activation module 802 is used to:

[0148] For any task in at least one of the services, a time control parameter corresponding to activating the service is obtained by interacting with the server, a time limit for executing the service is determined based on the time control parameter, and the service is completed by interacting with the server within the time limit.

[0149] In some embodiments, the activation module 802 is used to:

[0150] Sending a type identifier of the service to the server;

[0151] Receiving a time control parameter corresponding to the service returned by the server;

[0152] Determine a first time at which the service is initiated at the latest according to the time control parameter, and send a request to the server to execute the service before the first time;

[0153] A second time at which the service is to be terminated at the latest is determined according to the time control parameter, and before the second time, a response for executing the service returned by the server is waited for.

[0154] In some embodiments, the time control parameters include: the time required for the service to be completed, the maximum response time of the server, and the maximum delay time of the non-terrestrial communication network transmission;

[0155] The activation module 802 is used to:

[0156] On the basis of the moment of obtaining the time control parameter, the time required for the completion of the service is superimposed to obtain a first sum value, and the maximum response time of the server and twice the maximum delay time of the non-terrestrial communication network transmission are subtracted from the first sum value to obtain the first moment of initiating the service at the latest;

[0157] The determining, according to the time control parameter, the second time at which the service is to be terminated at the latest comprises:

[0158] Based on the time of sending the request to execute the service, the maximum response time of the server is superimposed to obtain a second sum value, and the second sum value is added with twice the maximum delay time of the non-terrestrial communication network transmission to obtain the second time when the service is terminated at the latest.

[0159] In some embodiments, the at least one service includes at least one of the following:

[0160] User identity information authentication service;

[0161] Encryption certificate authentication business;

[0162] A service for binding the terminal, the identity card and the user's identity information.

[0163] The disclosed embodiment also provides an identity card activation device, which is applied to a server. The server establishes a communication connection with a terminal on which the identity card is installed via a non-terrestrial communication network. The specific implementation of the server can be found in the relevant description of the method embodiment, which will not be repeated here. Figure 8 The figure shows the structure diagram of the identity card activation device applied to the server, which mainly includes:

[0164] Verification module 801, verifying the legitimacy of the activation operation by interacting with the terminal;

[0165] The activation module 802 activates the identity card by interacting with the terminal if the activation operation is legal.

[0166] In some embodiments, the verification module 801 is used to:

[0167] receiving an activation operation verification request sent by the terminal, wherein the activation operation verification request includes identification information of the terminal, identification information of the identity card, and current physical location information of the terminal;

[0168] Verifying the legitimacy of the terminal according to the identification information of the terminal;

[0169] Verifying the legitimacy of the identity card according to the identification information of the identity card;

[0170] Determining whether the terminal is currently located in an authorized location area according to the current physical location information of the terminal;

[0171] In the case that the terminal is legal, the identity card is legal, and the terminal is currently located in an authorized location area, the terminal is determined to be a valid authorized device, and an activation operation verification response is returned to the terminal.

[0172] In some embodiments, the activation module 802 is used to:

[0173] In the case where the activation operation is legal, at least one service required for activating the identity card is completed through interaction with the terminal, and the network configuration parameters of the identity card are sent to the terminal.

[0174] In some embodiments, the activation module 802 is used to:

[0175] For any task in the at least one service, the time control parameters corresponding to the activation of the service are returned to the terminal, and the time limit for executing the service is determined according to the time control parameters, and the service is completed by interacting with the terminal within the time limit.

[0176] In some embodiments, a management and control module is further included, which is used to interact with the terminal through the non-terrestrial communication network to manage the terminal.

[0177] The functions or modules included in the device provided in the embodiments of the present disclosure can be used to execute the method described in the method embodiments. The specific implementation and technical effects thereof can be referred to the description of the method embodiments above, and will not be described again here for the sake of brevity.

[0178] It should be noted that all modules involved in this embodiment are logic modules. In practical applications, a logic unit may be a physical unit, or a part of a physical unit, or may be implemented as a combination of multiple physical units. In addition, in order to highlight the innovative part of the present disclosure, this embodiment does not introduce units that are not closely related to solving the technical problems proposed by the present disclosure, but this does not mean that there are no other units in this embodiment.

[0179] Reference Fig. 9 The present disclosure provides an identity card activation device, which includes:

[0180] at least one processor 901;

[0181] A memory 902 storing at least one program, which, when executed by the at least one processor, enables the at least one processor to implement the above method;

[0182] At least one I / O interface 903 is connected between the processor and the memory and is configured to implement information exchange between the processor and the memory.

[0183] Among them, the processor 901 is a device with data processing capabilities, including but not limited to a central processing unit (CPU); the memory 902 is a device with data storage capabilities, including but not limited to random access memory (RAM, more specifically SDRAM, DDR, etc.), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory (FLASH); the I / O interface (read-write interface) 903 is connected between the processor 901 and the memory 902, and can realize information interaction between the processor 901 and the memory 902, including but not limited to a data bus (Bus), etc.

[0184] In some embodiments, the processor 901 , the memory 902 , and the I / O interface 903 are connected to each other through a bus, and further connected to other components of the computing device.

[0185] This embodiment further provides a computer-readable medium on which a computer program is stored. When the program is executed by a processor, the method provided in this embodiment is implemented. To avoid repeated description, the specific steps of the method are not repeated here.

[0186] It will be appreciated by those skilled in the art that all or some of the steps, systems, and functional modules / units in the methods applied for above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In hardware implementations, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium). As known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those skilled in the art that communication media typically contain computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

[0187] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.

[0188] Those skilled in the art will understand that although some embodiments described herein include certain features included in other embodiments but not other features, the combination of features from different embodiments is meant to be within the scope of the present embodiment and to form different embodiments.

[0189] It is to be understood that the above embodiments are merely exemplary embodiments used to illustrate the principles of the present disclosure, but the present disclosure is not limited thereto. For those of ordinary skill in the art, various modifications and improvements can be made without departing from the spirit and substance of the present disclosure, and these modifications and improvements are also considered to be within the scope of protection of the present disclosure.

Claims

1. A method for activating an identity card, applied to a terminal on which the identity card is installed, wherein the terminal establishes a communication connection with a server via a non-terrestrial communication network, and the method comprises: Verify the legitimacy of the activation operation by interacting with the server; When the activation operation is legal, the identity card is activated by interacting with the server.

2. The method according to claim 1, wherein: The verification of the legitimacy of the activation operation by interacting with the server includes: Sending an activation operation verification request to the server, wherein the activation operation verification request includes identification information of the terminal, identification information of the identity card, and current physical location information of the terminal; An activation operation verification response is received from the server, where the activation operation verification response is returned by the server after the server verifies the legitimacy of the activation operation verification request.

3. The method according to claim 2, wherein: The activation operation verification response includes a token, and the token is used to indicate the effective duration of the legal verification result; The method further comprises: In the event that the token is invalid, the step of verifying the legitimacy of the activation operation by interacting with the server is re-executed.

4. The method according to claim 1, wherein: When the activation operation is legal, activating the identity card by interacting with the server includes: If the activation operation is legal, completing at least one service required for activating the identity card through interaction with the server and obtaining network configuration parameters of the identity card; The terminal is configured according to the network configuration parameters to activate the identity card.

5. The method according to claim 4, wherein: The completing at least one service required for activating the identity card through interaction with the server includes: For any task in at least one of the services, a time control parameter corresponding to activating the service is obtained by interacting with the server, a time limit for executing the service is determined based on the time control parameter, and the service is completed by interacting with the server within the time limit.

6. The method according to claim 5, wherein: The step of obtaining a time control parameter corresponding to activating the service through interaction with the server, determining a time limit for executing the service according to the time control parameter, and completing the service by interacting with the server within the time limit, includes: Sending a type identifier of the service to the server; Receiving a time control parameter corresponding to the service returned by the server; Determine a first time at which the service is initiated at the latest according to the time control parameter, and send a request to the server to execute the service before the first time; A second time at which the service is to be terminated at the latest is determined according to the time control parameter, and before the second time, a response for executing the service returned by the server is waited for.

7. The method according to claim 5 or 6, wherein: The time control parameters include: the time required for the service to be completed, the maximum response time of the server, and the maximum delay time of the non-terrestrial communication network transmission; Determining the time limit for executing the service according to the time control parameter, and interacting with the server to complete the service within the time limit, includes: On the basis of the moment of obtaining the time control parameter, the time required for the completion of the service is superimposed to obtain a first sum value, and the maximum response time of the server and twice the maximum delay time of the non-terrestrial communication network transmission are subtracted from the first sum value to obtain the first moment of initiating the service at the latest; On the basis of the time of sending the request for executing the service, superimposing the maximum response time of the server to obtain a second sum value, and adding twice the maximum delay time of the non-terrestrial communication network transmission to the second sum value to obtain the second time of terminating the service at the latest; The service is completed by interacting with the server within the time defined by the first moment and the second moment.

8. The method according to claim 4, wherein: The at least one service includes at least one of the following: User identity information authentication service; Encryption certificate authentication business; A service for binding the terminal, the identity card and the user's identity information.

9. An identity card activation method, applied to a server, wherein the server establishes a communication connection with a terminal on which the identity card is installed via a non-terrestrial communication network; Verifying the legitimacy of the activation operation by interacting with the terminal; When the activation operation is legal, the identity card is activated by interacting with the terminal.

10. The method according to claim 9, wherein: The verifying the legitimacy of the activation operation by interacting with the terminal includes: receiving an activation operation verification request sent by the terminal, wherein the activation operation verification request includes identification information of the terminal, identification information of the identity card, and current physical location information of the terminal; Verifying the legitimacy of the terminal according to the identification information of the terminal; Verifying the legitimacy of the identity card according to the identification information of the identity card; Determining whether the terminal is currently located in an authorized location area according to the current physical location information of the terminal; In the case that the terminal is legal, the identity card is legal, and the terminal is currently located in an authorized location area, the terminal is determined to be a valid authorized device, and an activation operation verification response is returned to the terminal.

11. The method according to claim 9, wherein: When the activation operation is legal, activating the identity card by interacting with the terminal includes: In the case where the activation operation is legal, at least one service required for activating the identity card is completed through interaction with the terminal, and the network configuration parameters of the identity card are sent to the terminal.

12. The method according to claim 11, wherein: The completing at least one service required for activating the identity card through interaction with the terminal includes: For any task in the at least one service, the time control parameters corresponding to the activation of the service are returned to the terminal, and the time limit for executing the service is determined according to the time control parameters, and the service is completed by interacting with the terminal within the time limit.

13. The method according to claim 12, wherein: The time control parameters include: the time required for the service to be completed, the maximum response time of the server, and the maximum delay time of the non-terrestrial communication network transmission.

14. The method according to claim 13, wherein: The step of returning the time control parameter corresponding to the activation of the service to the terminal, determining the time limit for executing the service according to the time control parameter, and interacting with the terminal to complete the service within the time limit includes: Determine an effective response time window according to the time required for completion of the service, wherein the starting point of the effective response time window is the moment when the time control parameter is sent to the terminal, and the end point of the effective response time window is the cumulative moment of the starting point, the time required for completion of the service and the maximum delay time of the non-terrestrial communication network transmission; When a moment obtained by superimposing the maximum delay time of the non-terrestrial communication network transmission at the current moment falls within the effective response time window, interacting with the terminal to complete the service; When the time obtained by adding the maximum delay duration of the non-terrestrial communication network transmission to the current time exceeds the effective response time window, the interaction of the service with the terminal is stopped.

15. An identity card activation device, comprising: at least one processor; A memory having at least one program stored thereon, wherein when the at least one program is executed by the at least one processor, the at least one processor implements the method according to any one of claims 1 to 8 or the method according to any one of claims 9 to 14; At least one I / O interface is connected between the processor and the memory and is configured to implement information interaction between the processor and the memory.

16. A computer readable medium having a computer program stored thereon, wherein when the program is executed by a processor, the method according to any one of claims 1 to 8 or the method according to any one of claims 9 to 14 is implemented.