Supplementary service execution method and device, storage medium and terminal

By setting the modulation side authentication type when GBA authentication fails and performing secondary calculation verification, the problem of terminal failure when XCAP is executed for supplementary services is solved, and the service success rate and user experience are improved.

CN120018131APending Publication Date: 2025-05-16TCL COMM TECH (CHENGDU) LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510142323.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-08
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

After the popularization of 5G networks, when using XCAP to perform supplementary services, the terminal fails to calculate and verify the authentication parameters on the universal integrated circuit card (UICC) during the GBA authentication process, resulting in the GBA authentication unsuccessful, which makes the terminal unable to successfully perform supplementary services, seriously affecting the user experience.

Method used

When GBA authentication fails, the terminal sets the boot authentication type to the modulation-side authentication type, and performs secondary calculation verification through the modem to improve the authentication success rate.

Benefits of technology

Through secondary calculation verification, the success rate of terminals using XCAP to perform supplementary services is improved and the user experience is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120018131A_ABST
    Figure CN120018131A_ABST
Patent Text Reader

Abstract

The invention discloses a supplementary service execution method and device, a storage medium and a terminal, and relates to the technical field of communication, and the method comprises the steps: after an integrated user identification card is inserted and a multimedia subsystem is registered, a guide authentication request is sent to a guide server when a guide authentication condition is satisfied; receiving an authentication message returned by the guide server, wherein the authentication message carries an authentication parameter; performing calculation verification based on the authentication parameter in the universal integrated circuit card, and sending indication information to the modem when the verification fails, so as to trigger the modem to set a guide authentication type as a modulation side authentication type; and triggering to execute the supplementary service again, so that the terminal adopts the modem to perform secondary calculation verification according to the modulation side authentication type. According to the application, the success rate of passing the authentication of the boot server can be improved, the success rate of executing supplementary services by the terminal by using an extensible markup language configuration access protocol (XCAP) is improved, and the user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a method, device, storage medium and terminal for executing a supplementary service. Background Art

[0002] With the popularization of 5G networks, more and more operators will withdraw from 3G networks. It is no longer applicable for supplementary services (SS) to go through the 3G core network. Therefore, many operators have changed their needs from using 3G protocols to using Extensible Markup Language Configuration Access Protocol (XCAP) to perform supplementary services (for example, call forwarding, call restriction, etc.). Terminals using IP Multimedia Subsystem (IMS) use XCAP to perform supplementary services, which requires XCAP authentication. However, XCAP authentication mainly uses Generic Bootstrapping Architecture (GBA) authentication, and GBA authentication mainly uses the AKA authentication mechanism process.

[0003] For a terminal using an integrated user identity card (ISIM card), after the user inserts the ISIM card and registers the IMS system, GBA authentication is required when executing a supplementary service (for example, when executing a supplementary service for the first time). During GBA authentication, the bootstrapping server (i.e., BSF (Bootstrapping server function) server) of the XCAP server side will send an authentication message (i.e., 401Unauthrized message), and the terminal (UE) will calculate and verify the authentication parameters (such as the authentication token (AUTN)) in the authentication message on the universal integrated circuit card (UICC), and continue to execute the supplementary service after the verification is successful. However, in the process of verifying the authentication token, it often happens that the GBA authentication fails because the verification based on the authentication parameter calculation on the universal integrated circuit card (UICC), causing the terminal to fail to go through XCAP, and at the same time, the terminal cannot fall back (CSFB) to the 3G network, causing the entire supplementary service of the terminal to be unusable, which seriously affects the user experience. Summary of the invention

[0004] The embodiment of the present application provides a solution that can effectively improve the success rate of a terminal executing supplementary services using the Extensible Markup Language Configuration Access Protocol (XCAP) and improve user experience.

[0005] The embodiments of the present application provide the following technical solutions:

[0006] According to one embodiment of the present application, a method for executing a supplementary service includes: after inserting an integrated user identification card and registering a multimedia subsystem, triggering the use of an extensible markup language configuration access protocol to execute a supplementary service, and sending a boot authentication request to a boot server when the boot authentication condition is met; receiving an authentication message returned by the boot server based on the boot authentication request, wherein the authentication message carries authentication parameters; performing calculation verification based on the authentication parameters in a universal integrated circuit card, and when the verification fails, sending an indication message to a modem to trigger the modem to set the boot authentication type to a modulation side authentication type; triggering the use of an extensible markup language configuration access protocol to execute the supplementary service again, so that the terminal uses the modem to perform a secondary calculation verification on the boot server based on the modulation side authentication type.

[0007] In some embodiments of the present application, the triggering of reusing the Extensible Markup Language Configuration Access Protocol to execute supplementary services so that the terminal uses the modem to perform a secondary calculation verification on the boot server according to the modulation side authentication type, including: triggering the reusing of the Extensible Markup Language Configuration Access Protocol to execute supplementary services, and sending a new boot authentication request to the boot server when the execution meets the boot authentication condition; receiving a new authentication message returned by the boot server according to the new boot authentication request, the new authentication message carrying new authentication parameters; and using the modem to perform a calculation verification on the new authentication parameters.

[0008] In some embodiments of the present application, after the trigger re-uses the extensible markup language to configure the access protocol to perform supplementary services, so that the terminal uses the modem to perform a secondary calculation verification on the boot server according to the modulation side authentication type, the method also includes: if the verification is successful, sending a terminal authentication request to the boot server; receiving a verification notification message sent by the boot server according to the terminal authentication request; and interacting with the network application server according to the verification notification message to perform supplementary services.

[0009] In some embodiments of the present application, the execution of supplementary services by interacting with the network application server according to the verification notification message includes: if the verification notification message indicates that the boot server has passed the verification of the terminal, sending a service execution request to the network application server; and receiving the service execution result data returned by the network application server according to the service execution request.

[0010] In some embodiments of the present application, the triggering uses the Extensible Markup Language Configuration Access Protocol to execute a supplementary service, and sends a bootstrap authentication request to a bootstrap server when the execution satisfies a bootstrap authentication condition, including: in response to a service triggering operation of a user, sending a supplementary service execution message to a modem, so that the modem establishes a packet data network connection corresponding to the Extensible Markup Language Configuration Access Protocol with a mobile network, and obtains a domain name server assigned by the mobile network; querying the domain name server for an address of a network application server through the modem; sending a supplementary service request to the network application server according to the address of the network application server; receiving a bootstrap authentication indication message issued by the network application server in response to the supplementary service request; in response to the bootstrap authentication indication message, querying the domain name server for the address of the bootstrap server; and sending a bootstrap authentication request to the bootstrap server according to the address of the bootstrap server.

[0011] In some embodiments of the present application, querying the domain name server for the address of the network application server through the modem includes: obtaining relevant parameters corresponding to the extensible markup language configuration access protocol from the integrated user identification card through the modem; generating a domain name corresponding to the network application server according to the relevant parameters corresponding to the extensible markup language configuration access protocol; and querying the domain name server according to the domain name corresponding to the network application server to obtain the address of the network application server.

[0012] In some embodiments of the present application, querying the domain name server for the address of the boot server includes: generating a domain name corresponding to the boot server according to relevant parameters corresponding to the extensible markup language configuration access protocol; and querying the domain name server according to the domain name corresponding to the boot server to obtain the address of the boot server.

[0013] According to one embodiment of the present application, a supplementary service execution device includes: a sending module, which is used to: after an integrated user identification card is inserted and a multimedia subsystem is registered, trigger the use of an extensible markup language configuration access protocol to execute the supplementary service, and send a boot authentication request to a boot server when the boot authentication condition is met; a receiving module, which is used to: receive an authentication message returned by the boot server according to the boot authentication request, wherein the authentication message carries authentication parameters; a verification module, which is used to: perform calculation verification based on the authentication parameters in a universal integrated circuit card, and when the verification fails, send an indication message to a modem to trigger the modem to set the boot authentication type to a modulation side authentication type; a triggering module, which is used to: trigger the use of an extensible markup language configuration access protocol to execute the supplementary service again, so that the terminal uses the modem to perform a secondary calculation verification on the boot server according to the modulation side authentication type.

[0014] According to another embodiment of the present application, a storage medium stores a computer program thereon, and when the computer program is executed by a processor of a terminal, the terminal executes the method described in the embodiment of the present application.

[0015] According to another embodiment of the present application, a terminal may include: a memory storing a computer program; and a processor reading the computer program stored in the memory to execute the method described in the embodiment of the present application.

[0016] According to another embodiment of the present application, a computer program product or a computer program includes a computer instruction stored in a computer-readable storage medium. A processor of a terminal reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the terminal executes the method provided in various optional implementations described in the embodiments of the present application.

[0017] In an embodiment of the present application, after the integrated user identification card is inserted and the multimedia subsystem is registered, the use of the extensible markup language configuration access protocol to execute supplementary services is triggered, and a boot authentication request is sent to the boot server when the boot authentication condition is met; an authentication message returned by the boot server according to the boot authentication request is received, and the authentication message carries authentication parameters; a calculation check is performed based on the authentication parameters in the universal integrated circuit card, and when the check fails, an indication message is sent to the modem to trigger the modem to set the boot authentication type to the modulation side authentication type; and the use of the extensible markup language configuration access protocol to execute supplementary services again is triggered, so that the terminal uses the modem to perform a secondary calculation check on the boot server according to the modulation side authentication type.

[0018] In this way, when the first verification result of the calculation verification in the universal integrated circuit card (UICC) is a verification failure, the terminal in the embodiment of the present application will not consider that the GBA authentication is unsuccessful and end the execution of the supplementary service. In the embodiment of the present application, another calculation verification method will be further adopted, and the modem will be used again to perform calculation verification, thereby improving the success rate of the boot server authentication and certification, improving the success rate of the terminal using the Extensible Markup Language Configuration Access Protocol (XCAP) to execute supplementary services, and improving the user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.

[0020] Figure 1 A flow chart of a method for executing a supplementary service according to an embodiment of the present application is shown.

[0021] Figure 2 A flow chart of a method for executing a supplementary service according to another embodiment of the present application is shown.

[0022] Figure 3 A flow chart of a method for executing a supplementary service according to another embodiment of the present application is shown.

[0023] Figure 4 A block diagram of a supplementary service execution device according to an embodiment of the present application is shown.

[0024] Figure 5 A block diagram of a terminal according to an embodiment of the present application is shown. DETAILED DESCRIPTION

[0025] The present disclosure is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the embodiments provided herein are only used to explain the present disclosure and are not intended to limit the present disclosure. In addition, the embodiments provided below are partial embodiments for implementing the present disclosure, rather than providing all embodiments for implementing the present disclosure. In the absence of conflict, the technical solutions recorded in the embodiments of the present disclosure can be implemented in any combination.

[0026] It should be noted that, in the embodiments of the present disclosure, the terms "include", "comprises" or any other variants thereof are intended to cover non-exclusive inclusion, so that a method or apparatus including a series of elements includes not only the elements explicitly recorded, but also includes other elements not explicitly listed, or also includes elements inherent to the implementation of the method or apparatus. In the absence of further restrictions, an element defined by the sentence "includes a ..." does not exclude the presence of other related elements in the method or apparatus including the element (such as a step in the method or a unit in the apparatus, for example, a unit may be a part of a circuit, a part of a processor, a part of a program or software, etc.).

[0027] For example, the supplementary service execution method provided by the embodiment of the present disclosure includes a series of steps, but the supplementary service execution method provided by the embodiment of the present disclosure is not limited to the recorded steps. Similarly, the supplementary service execution device provided by the embodiment of the present disclosure includes a series of units, but the device provided by the embodiment of the present disclosure is not limited to including the units explicitly recorded, and may also include units required to obtain relevant information or perform processing based on the information.

[0028] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which the present disclosure belongs. The terms used herein are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.

[0029] It is understandable that in the specific implementation of this application, relevant data is involved. When the embodiments in this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of relevant data need to comply with relevant laws, regulations and standards of relevant countries and regions.

[0030] Figure 1 The flowchart of the supplementary service execution method according to an embodiment of the present application is schematically shown. The execution subject of the supplementary service execution method can be a terminal with supplementary service execution capability, such as a mobile phone, a smart watch, a door lock, and a monitor, etc. Among them, the supplementary service execution system of the supplementary service execution method may include at least a terminal (UE), a network application server (NAF (Network Application Function) server), and a boot server (BSF (Bootstrapping server function) server).

[0031] Specifically, Figure 1 As shown, the supplementary service execution method may include steps S110 to S140.

[0032] Step S110, after the integrated user identification card is inserted and the multimedia subsystem is registered, triggering the use of the extensible markup language to configure the access protocol to execute the supplementary service, and sending a bootstrap authentication request to the bootstrap server when the bootstrap authentication condition is met;

[0033] Step S120, receiving an authentication message returned by the boot server according to the boot authentication request, wherein the authentication message carries an authentication parameter;

[0034] Step S130, performing calculation verification based on the authentication parameter in the universal integrated circuit card, and when the verification fails, sending indication information to the modem to trigger the modem to set the boot authentication type to the modulation side authentication type;

[0035] Step S140, triggering the use of the extensible markup language configuration access protocol to perform supplementary services again, so that the terminal uses the modem to perform a secondary calculation verification on the bootstrap server according to the modulation side authentication type.

[0036] After the terminal is inserted with an integrated user identity card (i.e., an ISIM card), it will register with the multimedia subsystem, which is the IMS system (e.g., Voice Over LTE (VOLTE) or Voice Over WIFI (VOWIFI)). After registering with the multimedia subsystem, the user can trigger the execution of a supplementary service (SS) on the terminal, such as triggering the execution of a supplementary service for the first time.

[0037] When the integrated user identity card (i.e., ISIM card) is inserted, when the supplementary service is triggered, the Extensible Markup Language Configuration Access Protocol will be used by default to execute the supplementary service. At this time, the terminal will first interact with the network application server (NAF server) to request execution. When the boot authentication condition is met, the terminal sends a boot authentication request to the boot server (BSF server). Among them, the Extensible Markup Language Configuration Access Protocol is the XML Configuration Access Protocol (XCAP: XMLConfiguration Access Protocol).

[0038] The bootstrapping authentication request is a request sent by the terminal to the bootstrapping server through HTTP for a universal bootstrapping authentication request. Universal bootstrapping authentication is GAB (Generic Bootstrapping Architecture) authentication. After receiving the bootstrapping authentication request, the bootstrapping server calculates an authentication vector (AV, Authentication Vector), which includes authentication parameters such as a random number (RAND) and an authentication token (AUTN). Then, the bootstrapping server sends an authentication message (i.e., 401Unauthrized message) to the terminal, and the authentication message carries the authentication parameters.

[0039] After receiving the authentication message, the terminal will default to the boot authentication type of "card-side authentication type (i.e., running the AKA protocol in the UICC card for calculation verification)", that is, the terminal will perform calculation verification based on the authentication parameters in the universal integrated circuit card (UICC) (i.e., perform the first calculation verification on the boot server) to obtain the first verification result. At this time, according to the prior art, when the first verification result is a verification failure, the terminal considers that the GBA authentication is unsuccessful and will end the execution of the supplementary service, resulting in the terminal supplementary service being unusable. Among them, the first verification result is obtained by performing calculation verification based on the authentication parameters in the universal integrated circuit card (UICC), which can be specifically: using the random number (RAND) in the authentication parameters and the predetermined parameters in the integrated circuit card to calculate, and obtain a calculated authentication token, and then comparing the calculated authentication token with the authentication token (AUTN) in the authentication parameters. If the two are consistent, the first verification result is a verification pass, otherwise the first verification result is a verification failure.

[0040] In an embodiment of the present application, when the first verification result is a verification failure, an indication message is sent to the modem, and the indication message is used to trigger the modem to set the boot authentication type to "modulation side authentication type (i.e., running the AKA protocol in the modem for calculation and verification)", for example, setting the boot authentication type to GBA_ME.

[0041] After setting the bootstrap authentication type to the modulation side authentication type, the terminal is triggered to re-use the extensible markup language to configure the access protocol to perform supplementary services. At this time, the terminal will interact with the network application server (NAF server) again to perform related services. When the bootstrap authentication conditions are met, the terminal sends a new bootstrap authentication request to the bootstrap server (BSF server).

[0042] After receiving the new boot authentication request, the boot server recalculates the authentication vector (AV, Authentication Vector). The calculated new authentication vector includes new authentication parameters. The new authentication parameters may specifically include a newly calculated random number (RAND) and an authentication token (AUTN). Then, the boot server sends a new authentication message (i.e., 401Unauthrized message) to the terminal, and the new authentication message carries new authentication parameters.

[0043] Then, since the boot authentication type has been set to the modulation side authentication type, the terminal will re-use the modem to perform calculation verification based on the new authentication parameters (that is, perform a second calculation verification on the boot server) to obtain a second verification result, and continue to execute the supplementary service when the second verification result is a passed verification.

[0044] In this manner in the embodiment of the present application, when the first verification result of the calculation verification in the universal integrated circuit card (UICC) is a verification failure, the terminal in the embodiment of the present application will not consider that the GBA authentication is unsuccessful and end the execution of the supplementary service. In the embodiment of the present application, another calculation verification method will be further adopted, and the modem will be re-adopted for calculation verification to improve the success rate of the boot server authentication and certification, improve the success rate of the terminal using the Extensible Markup Language Configuration Access Protocol (XCAP) to execute the supplementary service, and improve the user experience.

[0045] Described below Figure 1 When performing supplementary services under the embodiment, further optional specific embodiments are provided under each step performed.

[0046] In one embodiment, the triggering of using the Extensible Markup Language Configuration Access Protocol to execute a supplementary service, and sending a bootstrap authentication request to a bootstrap server when the execution meets the bootstrap authentication condition, may include: in response to a user's service triggering operation, sending a supplementary service execution message to a modem, so that the modem establishes a packet data network connection corresponding to the Extensible Markup Language Configuration Access Protocol with a mobile network, and obtains a domain name server assigned by the mobile network; querying the domain name server for an address of a network application server through the modem; sending a supplementary service request to the network application server according to the address of the network application server; receiving a bootstrap authentication indication message issued by the network application server in response to the supplementary service request; querying the domain name server for the address of the bootstrap server according to the bootstrap authentication indication message; and sending a bootstrap authentication request to the bootstrap server according to the address of the bootstrap server.

[0047] The user's service triggering operation is an operation used to trigger the execution of a supplementary service. For example, the service triggering operation may be "the user enters the call setting interface through a dialing application (such as a Dialer APP) and clicks on the supplementary service menu in the setting interface"; or, the service triggering operation may be "the user enters the supplementary service code on the dial pad through a dialing application (such as a Dialer APP).

[0048] In response to the user's service triggering operation, the terminal sends a supplementary service execution message to the modem, which triggers the modem to establish a packet data network connection corresponding to the Extensible Markup Language Configuration Access Protocol (XCAP) with the mobile network, and can obtain the domain name server (DNS server) assigned by the mobile network. Specifically, after the supplementary service execution message reaches the modem, the SSDS (Service Selection and Domain Selection) module in the modem will select the domain, and the selected domain is XCAP; then, the modem will establish a PDN (Packet Data Network) according to the APN (Access Point Name) of the XCAP type sent to the modem by the AP (Access Point) to establish a dedicated bearer of the XCAP type, and the mobile network assigns a domain name server to the terminal.

[0049] The modem can query the domain name server for the address of the network application server (NAF server), and then the terminal can send a supplementary service request to the network application server according to the address of the network application server. After receiving the supplementary service request, the network application server sends a guided authentication indication message (for example, a 401 Unauthorized message) to the terminal to inform the terminal that authentication is required.

[0050] After the terminal receives the boot authentication indication message sent by the network application server, it queries the domain name server for the address of the boot server. After querying the address of the boot server, it is considered that the boot authentication condition is met, and a boot authentication request can be sent to the boot server according to the address of the boot server to request general boot authentication.

[0051] Furthermore, after the terminal inserts the integrated subscriber identity card (ie, ISIM card) and registers the multimedia subsystem, when triggering the execution of the supplementary service, it successfully requests the bootstrap server to perform universal bootstrap authentication through XCAP triggering.

[0052] Furthermore, in one embodiment, querying the domain name server for the address of the network application server via the modem may include: obtaining relevant parameters corresponding to the extensible markup language configuration access protocol from the integrated user identification card via the modem; generating a domain name corresponding to the network application server according to the relevant parameters corresponding to the extensible markup language configuration access protocol; and querying the domain name server according to the domain name corresponding to the network application server to obtain the address of the network application server.

[0053] The modem can obtain relevant parameters corresponding to the Extensible Markup Language Configuration Access Protocol (XCAP) from the integrated user identification card, for example, matching relevant parameters corresponding to the XCAP configured for MCC (Mobile Country Code) and MNC (Mobile Network Code) from the integrated user identification card.

[0054] According to the relevant parameters corresponding to the access protocol configured in the extensible markup language, the domain name corresponding to the network application server (for example, xcap.ims.mncxxx.mccxxx.pub.3gppnetwork.org) can be generated. According to the domain name corresponding to the network application server, a DNS query can be performed to the domain name server to successfully obtain the address of the network application server. Therefore, after the terminal inserts the integrated user identity card (i.e., ISIM card) and registers the multimedia subsystem, when the execution of the supplementary service is triggered, the address of the network application server is successfully obtained through XCAP.

[0055] Further, in one embodiment, querying the domain name server for the address of the boot server may include: generating a domain name corresponding to the boot server according to relevant parameters corresponding to the extensible markup language configuration access protocol; and querying the domain name server according to the domain name corresponding to the boot server to obtain the address of the boot server.

[0056] According to the relevant parameters corresponding to the access protocol configured in the extensible markup language, the domain name corresponding to the bootstrap server (for example, bsf.ims.mncxxx.mccxxx.pub.3gppnetwork.org) can be generated. According to the domain name corresponding to the bootstrap server, a DNS query can be performed to the domain name server to successfully obtain the address of the bootstrap server. Therefore, after the terminal inserts the integrated user identity card (i.e., ISIM card) and registers the multimedia subsystem, when the execution of the supplementary service is triggered, the address of the bootstrap server is successfully obtained through XCAP.

[0057] In one embodiment, see Figure 2Step S140, the triggering of reusing the extensible markup language to configure the access protocol to perform the supplementary service so that the terminal uses the modem to perform a secondary calculation check on the boot server according to the modulation side authentication type, may specifically include:

[0058] Step S210, triggering the use of the extensible markup language configuration access protocol to execute the supplementary service again, and sending a new bootstrap authentication request to the bootstrap server when the bootstrap authentication condition is met;

[0059] Step S220, receiving a new authentication message returned by the boot server according to the new boot authentication request, wherein the new authentication message carries new authentication parameters;

[0060] Step S230: Using the modem to calculate and verify the new authentication parameters.

[0061] The terminal triggers the use of the extensible markup language configuration access protocol to execute the supplementary service again, and sends a new bootstrap authentication request to the bootstrap server when the bootstrap authentication condition (for example, obtaining the address of the bootstrap server) is met.

[0062] After receiving the new boot authentication request, the boot server recalculates the authentication vector (AV, Authentication Vector). The calculated new authentication vector includes new authentication parameters. The new authentication parameters may specifically include a newly calculated random number (RAND) and an authentication token (AUTN). Then, the boot server sends a new authentication message (i.e., 401Unauthrized message) to the terminal, and the new authentication message carries new authentication parameters.

[0063] Then, since the boot authentication type has been set to the modulation side authentication type, the terminal will re-use the modem to perform calculation verification based on the new authentication parameters (that is, perform a second calculation verification on the boot server) to obtain a second verification result, and continue to execute the supplementary service when the second verification result is a passed verification.

[0064] The modem performs calculation verification based on the new authentication parameters to obtain the second verification result, which can be specifically: the modem uses the newly calculated random number (RAND) and the predetermined parameters on the modem side to perform calculation to obtain the calculated authentication token, and then compares the calculated authentication token with the authentication token (AUTN) in the new authentication parameters. If the two are consistent, the second verification result is verification passed, otherwise the second verification result is verification failed. Thus, the modem successfully completes the secondary calculation verification of the boot server.

[0065] In one embodiment, see Figure 3After the triggering of reusing the extensible markup language to configure the access protocol to perform the supplementary service so that the terminal uses the modem to perform a secondary calculation verification on the boot server according to the modulation side authentication type, the method further includes:

[0066] Step S310: If the verification is successful, a terminal authentication request is sent to the boot server;

[0067] Step S320, receiving a verification notification message sent by the guidance server according to the terminal authentication request;

[0068] Step S330: interact with the network application server to execute supplementary services according to the verification notification message.

[0069] When the second verification result is successful verification, the terminal further sends a terminal authentication request to the boot server to request the boot server to authenticate the terminal. The boot server can further send a verification notification message to the terminal to inform the terminal whether the authentication is successful.

[0070] After the terminal receives the verification notification message sent by the boot server according to the terminal authentication request, it can further determine whether to interact with the network application server to perform supplementary services according to whether the boot server has authenticated the terminal indicated in the verification notification message. Therefore, after the terminal inserts the integrated user identity card (i.e., ISIM card) and registers the multimedia subsystem, when the execution of supplementary services is triggered, the mutual authentication between the terminal and the boot server is successfully completed through XCAP.

[0071] In one embodiment, the execution of supplementary services by interacting with the network application server according to the verification notification message may specifically include: if the verification notification message indicates that the boot server has passed the terminal verification, a service execution request is sent to the network application server; and service execution result data returned by the network application server according to the service execution request.

[0072] The terminal can determine whether the verification notification message indicates that the bootstrap server has successfully authenticated the terminal. For example, the verification notification message is a 200OK message. If the verification notification message carries Ks (Session Key) and B-TID (Bootstrap Transaction ID), the terminal can determine that the verification notification message indicates that the bootstrap server has successfully authenticated the terminal.

[0073] When the terminal determines that the verification notification message indicates that the boot server has passed the terminal verification, it can send a service execution request to the network application server. After the mutual authentication between the terminal and the boot server is passed, the network application server can perform corresponding processing according to the service execution request (for example, initialize the XML file storing the data of the supplementary service) to obtain the service execution result data (for example, all the supplementary services supported by the current ISIM card and the current status of the supplementary service on the network side (enable, disable)). The network application server can feed back the service execution result data to the terminal through a feedback message (for example, a 200OK message), so that the terminal successfully executes the supplementary service through XCAP.

[0074] In order to better implement the supplementary service execution method provided in the embodiment of the present application, the embodiment of the present application also provides a supplementary service execution device based on the above supplementary service execution method. The meanings of the terms are the same as those in the above supplementary service execution method, and the specific implementation details can refer to the description in the method embodiment. Figure 4 A block diagram of a supplementary service execution device according to an embodiment of the present application is shown.

[0075] like Figure 4 As shown, the supplementary service execution device 400 may include: a sending module 410 may be used to: after the integrated user identification card is inserted and the multimedia subsystem is registered, trigger the use of the extensible markup language configuration access protocol to execute the supplementary service, and send a boot authentication request to the boot server when the boot authentication condition is met; a receiving module 420 may be used to: receive an authentication message returned by the boot server according to the boot authentication request, and the authentication message carries authentication parameters; a verification module 430 may be used to: perform calculation verification based on the authentication parameters in a universal integrated circuit card, and when the verification fails, send an indication message to the modem to trigger the modem to set the boot authentication type to the modulation side authentication type; a triggering module 440 may be used to: trigger the use of the extensible markup language configuration access protocol to execute the supplementary service again, so that the terminal uses the modem to perform a secondary calculation verification on the boot server according to the modulation side authentication type.

[0076] In some embodiments of the present application, the trigger module 440 can be used to: trigger the use of the extensible markup language configuration access protocol to execute supplementary services again, and send a new boot authentication request to the boot server when the boot authentication condition is met; receive a new authentication message returned by the boot server based on the new boot authentication request, and the new authentication message carries new authentication parameters; and use the modem to calculate and verify the new authentication parameters.

[0077] In some embodiments of the present application, after the trigger re-uses the extensible markup language to configure the access protocol to execute the supplementary service, so that the terminal uses the modem to perform a secondary calculation verification on the boot server according to the modulation side authentication type, the device also includes an execution module, which is used to: if the verification is successful, send a terminal authentication request to the boot server; receive a verification notification message sent by the boot server according to the terminal authentication request; and interact with the network application server according to the verification notification message to execute the supplementary service.

[0078] In some embodiments of the present application, the execution module is used to: if the verification notification message indicates that the boot server has passed the terminal verification, send a service execution request to the network application server; and receive service execution result data returned by the network application server according to the service execution request.

[0079] In some embodiments of the present application, the sending module 410 can be used to: in response to a service trigger operation of a user, send a supplementary service execution message to a modem, so that the modem establishes a packet data network connection corresponding to the extensible markup language configuration access protocol with a mobile network, and obtains a domain name server assigned by the mobile network; query the domain name server for an address of a network application server through the modem; send a supplementary service request to the network application server according to the address of the network application server; receive a boot authentication indication message issued by the network application server in response to the supplementary service request; in response to the boot authentication indication message, query the domain name server for the address of the boot server; and send a boot authentication request to the boot server according to the address of the boot server.

[0080] In some embodiments of the present application, the sending module 410 can be used to: obtain relevant parameters corresponding to the extensible markup language configuration access protocol from the integrated user identification card through the modem; generate a domain name corresponding to the network application server according to the relevant parameters corresponding to the extensible markup language configuration access protocol; query the domain name server according to the domain name corresponding to the network application server to obtain the address of the network application server.

[0081] In some embodiments of the present application, the sending module 410 can be used to: generate a domain name corresponding to the boot server according to relevant parameters corresponding to the extensible markup language configuration access protocol; query the domain name server according to the domain name corresponding to the boot server to obtain the address of the boot server.

[0082] It should be noted that, although several modules or units of the equipment for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of two or more modules or units described above can be embodied in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into being embodied by multiple modules or units.

[0083] In addition, the present application embodiment also provides a terminal, such as Figure 5 As shown, Figure 5 A block diagram of a terminal according to an embodiment of the present application is shown, specifically:

[0084] The terminal may include one or more processing core processors 501, one or more computer-readable storage media memories 502, a power supply 503, an input unit 504 and other components. Those skilled in the art will appreciate that Figure 5 The terminal structure shown in the figure does not constitute a limitation on the terminal, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0085] The processor 501 is the control center of the terminal. It uses various interfaces and lines to connect various parts of the entire computer device. By running or executing software programs and / or modules stored in the memory 502 and calling data stored in the memory 502, it executes various functions of the computer device and processes data, thereby monitoring the terminal as a whole. Optionally, the processor 501 may include one or more processing cores; preferably, the processor 501 may integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system, user pages and application programs, etc., and the modem processor mainly processes wireless communications. It is understandable that the above-mentioned modem processor may not be integrated into the processor 501.

[0086] The memory 502 can be used to store software programs and modules. The processor 501 executes various functional applications and data processing by running the software programs and modules stored in the memory 502. The memory 502 may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc.; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 502 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage devices. Accordingly, the memory 502 may also include a memory controller to provide the processor 501 with access to the memory 502.

[0087] The terminal also includes a power supply 503 for supplying power to each component. Preferably, the power supply 503 can be logically connected to the processor 501 through a power management system, so as to manage charging, discharging, and power consumption through the power management system. The power supply 503 can also include any components such as one or more DC or AC power supplies, recharging systems, power failure detection circuits, power converters or inverters, and power status indicators.

[0088] The terminal may further include an input unit 504, which may be used to receive input digital or character information and generate keyboard, mouse, joystick, optical or trackball signal inputs related to user settings and function control.

[0089] Although not shown, the terminal may also include a display unit, etc., which will not be described in detail herein. Specifically in this embodiment, the processor 501 in the terminal will load the executable files corresponding to the processes of one or more computer programs into the memory 502 according to the following instructions, and the processor 501 will run the computer programs stored in the memory 502, thereby realizing various functions in the aforementioned embodiments of the present application.

[0090] Those skilled in the art will appreciate that all or part of the steps in the various methods of the above embodiments may be completed by a computer program, or by controlling related hardware through a computer program. The computer program may be stored in a computer-readable storage medium and loaded and executed by a processor.

[0091] To this end, an embodiment of the present application further provides a storage medium, in which a computer program is stored. The computer program can be loaded by a processor to execute the steps in any method provided in the embodiment of the present application.

[0092] The storage medium may be a computer-readable storage medium, and the storage medium may include: a read-only memory (ROM), a random access memory (RAM), a disk or an optical disk, etc.

[0093] Since the computer program stored in the storage medium can execute the steps in any method provided in the embodiments of the present application, the beneficial effects that can be achieved by the method provided in the embodiments of the present application can be achieved. Please refer to the previous embodiments for details and will not be repeated here.

[0094] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the embodiments disclosed herein. The present application is intended to cover any variations, uses or adaptations of the present application, which follow the general principles of the present application and include common knowledge or customary technical means in the art that are not disclosed in the present application.

[0095] It should be understood that the present application is not limited to the embodiments that have been described above and shown in the accompanying drawings, but various modifications and changes may be made without departing from the scope thereof.

Claims

1. A method for executing a supplementary service, characterized in that: Applied to a terminal, the method comprises: After the integrated user identification card is inserted and the multimedia subsystem is registered, the supplementary service is triggered by using the extensible markup language to configure the access protocol, and a bootstrap authentication request is sent to the bootstrap server when the bootstrap authentication condition is met; receiving an authentication message returned by the boot server according to the boot authentication request, wherein the authentication message carries an authentication parameter; Performing calculation verification based on the authentication parameter in the universal integrated circuit card, and sending indication information to the modem when the verification fails, so as to trigger the modem to set the boot authentication type to the modulation side authentication type; The extensible markup language configuration access protocol is triggered to execute the supplementary service again, so that the terminal uses the modem to perform a secondary calculation verification on the boot server according to the modulation side authentication type.

2. The method according to claim 1, characterized in that The triggering of reusing the extensible markup language to configure the access protocol to perform the supplementary service so that the terminal uses the modem to perform a secondary calculation verification on the boot server according to the modulation side authentication type, comprises: triggering the use of the extensible markup language configuration access protocol to execute the supplementary service again, and sending a new bootstrap authentication request to the bootstrap server when the bootstrap authentication condition is met; Receiving a new authentication message returned by the boot server according to the new boot authentication request, wherein the new authentication message carries new authentication parameters; The new authentication parameters are calculated and verified using the modem.

3. The method according to claim 1 or 2, characterized in that: After the triggering of reusing the extensible markup language to configure the access protocol to perform the supplementary service so that the terminal uses the modem to perform a secondary calculation check on the boot server according to the modulation side authentication type, the method further includes: If the verification is successful, sending a terminal authentication request to the boot server; Receiving a verification notification message sent by the guidance server according to the terminal authentication request; The supplementary service is executed by interacting with the network application server according to the verification notification message.

4. The method according to claim 3, characterized in that: The performing of the supplementary service by interacting with the network application server according to the verification notification message includes: If the verification notification message indicates that the boot server has successfully verified the terminal, a service execution request is sent to the network application server; Receive the service execution result data returned by the network application server according to the service execution request.

5. The method according to claim 1, characterized in that The triggering of using extensible markup language to configure access protocol to execute supplementary services, and sending a bootstrap authentication request to a bootstrap server when the bootstrap authentication condition is met, includes: In response to a service triggering operation of a user, sending a supplementary service execution message to a modem, so that the modem establishes a packet data network connection corresponding to the extensible markup language configuration access protocol with a mobile network, and obtains a domain name server assigned by the mobile network; querying the domain name server for an address of a network application server via the modem; Sending a supplementary service request to the network application server according to the address of the network application server; receiving a boot authentication indication message sent by the network application server in response to the supplementary service request; In response to the boot authentication indication message, querying the domain name server for an address of the boot server; A boot authentication request is sent to the boot server according to the address of the boot server.

6. The method according to claim 5, characterized in that The querying the domain name server for the address of the network application server through the modem includes: Obtaining relevant parameters corresponding to the Extensible Markup Language Configuration Access Protocol from the integrated user identification card through the modem; Generate a domain name corresponding to the network application server according to relevant parameters corresponding to the extensible markup language configuration access protocol; The domain name server is queried according to the domain name corresponding to the network application server to obtain the address of the network application server.

7. The method according to claim 6, characterized in that The querying the domain name server for the address of the boot server includes: Generate a domain name corresponding to the boot server according to relevant parameters corresponding to the extensible markup language configuration access protocol; The domain name server is queried according to the domain name corresponding to the boot server to obtain the address of the boot server.

8. A supplementary service execution device, characterized in that: include: The sending module is used to: after the integrated user identification card is inserted and the multimedia subsystem is registered, trigger the use of the extensible markup language to configure the access protocol to perform the supplementary service, and send a boot authentication request to the boot server when the boot authentication condition is met; A receiving module, configured to: receive an authentication message returned by the boot server according to the boot authentication request, wherein the authentication message carries an authentication parameter; A verification module is used to: perform calculation verification based on the authentication parameters in the universal integrated circuit card, and when the verification fails, send indication information to the modem to trigger the modem to set the boot authentication type to the modulation side authentication type; The trigger module is used to trigger the use of the extensible markup language to configure the access protocol to perform supplementary services again, so that the terminal uses the modem to perform secondary calculation verification on the boot server according to the modulation side authentication type.

9. A storage medium, characterized in that: A computer program is stored thereon, and when the computer program is executed by a processor of a terminal, the terminal is caused to execute the method according to any one of claims 1 to 7.

10. A terminal, characterized in that: include: a memory storing a computer program; A processor reads a computer program stored in a memory to execute the method according to any one of claims 1 to 7.