Method and device for determining user identity, processing equipment and storage medium
By passing user identity information and digital signature information between the registration server and the terminal, the convenience and reliability of caller identity identification in the prior art are solved, and efficient authentication without downloading APP and database updates are achieved.
Patent Information
- Application Number
- CN202410104258.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-23
- Publication Date
- 2025-07-25
AI Technical Summary
In the prior art, the caller identity identification method requires the user to download the APP, the data update is not timely and the identification is unreliable, and efficient and reliable identity authentication cannot be achieved in the call request and identity identification process.
The first terminal sends a request to the registration server containing the user identity information and the user identity digital signature information, and receives and sends information for the call, including the user identity information and the digital signature information, to the second terminal, so that the second terminal can perform identity authentication.
No additional applications need to be downloaded and database updates require efficient, fast and reliable calling terminal identity recognition.
Smart Images

Figure CN120378524A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to, and is not limited to, the field of information processing, and in particular, to a method, apparatus, processing device, and storage medium for determining a user identity. Background Art
[0002] In a call scenario, the called terminal displays the information of the calling party when ringing, but the displayed information may not be reliable. In the related art, the problem of identifying the calling party's identity can be solved by technical means. Exemplarily, the identity of the calling party is identified through a mobile application (APP) for incoming call number recognition. The operators of such APPs establish a user identity database of phone numbers by actively annotating or collecting from users. When a mobile phone receives an incoming call, the APP queries the database based on the calling number to obtain the corresponding calling party identity information, and prompts the calling party identity on the incoming call interface, such as a suspected fraud call, a courier or food delivery call, etc. However, this method has the problems of inconvenient use, untimely data update, and unreliable recognition. Summary of the Invention
[0003] In view of this, the present invention discloses a method, apparatus, processing device, and storage medium for determining a user identity.
[0004] According to a first aspect of an embodiment of the present disclosure, there is provided a method for determining a user identity, which is executed by a first terminal, and the method includes:
[0005] Sending a first message to a registration server, the first message being used to request a second message, the second message including: user identity information and user identity digital signature information of the first terminal;
[0006] Receiving the second message sent by the registration server;
[0007] Sending a third message to a second terminal, the third message being used to call the second terminal, the third message including the second message, and the third message being used for the second terminal to determine the user identity of the first terminal.
[0008] In some embodiments, the second message includes the user identity information, the user identity digital signature information, and a registration server signature certificate.
[0009] In some embodiments, the first message is sent through a network registration request message, and / or, the second message is received through a network registration response message, and / or, the third message is sent through a calling request message.
[0010] According to a second aspect of an embodiment of the present disclosure, there is provided a method for determining a user identity, which is executed by a registration server, and the method includes:
[0011] Receive a first piece of information sent by a first terminal, where the first piece of information is used to request a second piece of information, and the second piece of information includes: user identity information of the first terminal and user identity digital signature information;
[0012] Obtain the second piece of information;
[0013] Send the second piece of information to the first terminal.
[0014] In some embodiments, the second piece of information includes the user identity information, the user identity digital signature information, and a registration server signature certificate.
[0015] In some embodiments, the method further includes:
[0016] Establish an association relationship between the user identity information and a Session Initiation Protocol (SIP) identity identifier (ID) of a session initiation service.
[0017] In some embodiments, the first piece of information is received through a network registration request message, and / or the second piece of information is sent through a network registration response message.
[0018] In some embodiments, the method further includes:
[0019] Query the user identity information;
[0020] In response to querying the user identity information, generate digital signature information for the user identity information by using a signature secret key.
[0021] In some embodiments, the querying the user identity information includes:
[0022] After completing the network registration authentication of the first terminal, query the user identity information.
[0023] In some embodiments, the method further includes:
[0024] Generate a document to be signed based on predetermined information; the predetermined information includes at least one of the following: user identity information, user identity information format, Session Initiation Protocol (SIP) Uniform Resource Identifier (URI) of the user, current timestamp, random string, and validity period of the current signature;
[0025] The generating the digital signature information for the user identity information by using the signature secret key includes:
[0026] Generate the digital signature information by using the signature secret key and the document to be signed.
[0027] In some embodiments, the method further includes:
[0028] Send the signature key to the certification authority CA;
[0029] Receive the registration server signature certificate sent by the CA, where the registration server signature certificate is generated based on the signature key.
[0030] According to a third aspect of the embodiments of the present disclosure, a method for determining a user identity is provided. The method is executed by a second terminal, and the method includes:
[0031] Receive third information sent by a first terminal, where the third information is used to call the second terminal and for the second terminal to determine the user identity of the first terminal. The third information includes: the user identity information of the first terminal and user identity digital signature information;
[0032] Perform a determination operation based on the third information to obtain a determination result; where the determination operation includes at least one of the following: registration server signature certificate verification, user identity information verification, user identity digital signature information verification;
[0033] Determine the user identity of the first terminal based on the determination result.
[0034] In some embodiments, the second information includes the user identity information, the user identity digital signature information, and a registration server signature certificate.
[0035] In some embodiments, the third information is received through a calling request message.
[0036] In some embodiments, the performing a determination operation based on the third information to obtain a determination result includes:
[0037] Determine that the third information includes the user identity information, the user identity digital signature information, and the registration server signature certificate, and perform a determination operation based on the third information to obtain the determination result.
[0038] In some embodiments, the performing a determination operation based on the third information to obtain a determination result includes:
[0039] Verify the registration server signature certificate based on a preset CA certificate;
[0040] Determine that the verification of the registration server signature certificate is successful, and perform the user identity information verification;
[0041] Determine that the verification of the user identity information is successful, perform the user identity digital signature information verification, and obtain the determination result.
[0042] In some embodiments, the method further includes:
[0043] Determine that the identity of the first terminal is trustworthy and display the user identity information;
[0044] Determine that the identity of the first terminal is untrustworthy and do not display the user identity information.
[0045] According to the fourth aspect of the embodiments of the present disclosure, there is provided a device for determining a user identity, the device including a transceiver module configured to:
[0046] Send a first message to a registration server, the first message being used to request a second message, the second message including: the user identity information and user identity digital signature information of the first terminal;
[0047] Receive the second message sent by the registration server;
[0048] Send a third message to a second terminal, the third message being used to call the second terminal, the third message including the second message, and the third message being used for the second terminal to determine the user identity of the first terminal.
[0049] According to the fifth aspect of the embodiments of the present disclosure, there is provided a device for determining a user identity, the device including:
[0050] A transceiver module configured to receive a first message sent by a first terminal, the first message being used to request a second message, the second message including: the user identity information and user identity digital signature information of the first terminal;
[0051] An acquisition module configured to acquire the second message;
[0052] The transceiver module is configured to send the second message to the first terminal.
[0053] According to the sixth aspect of the embodiments of the present disclosure, there is provided a device for determining a user identity, the device including:
[0054] A transceiver module configured to receive a third message sent by a first terminal, the third message being used to call a second terminal and for the second terminal to determine the user identity of the first terminal, the third message including: the user identity information and user identity digital signature information of the first terminal;
[0055] A determination module configured to perform a determination operation based on the third message to obtain a determination result; wherein, the determination operation includes at least one of the following: registration server signature certificate verification, user identity information verification, user identity digital signature information verification;
[0056] A determination module configured to determine the user identity of the first terminal based on the determination result.
[0057] According to a seventh aspect of the embodiments of the present disclosure, a processing device is provided, and the processing device includes:
[0058] A memory for storing an executable program;
[0059] A processor, when executing the executable program stored in the memory, implements the method according to any one of the embodiments of the present disclosure.
[0060] According to an eighth aspect of the embodiments of the present disclosure, a computer storage medium is provided, and the computer storage medium stores an executable program, and when the executable program is executed by a processor, the method according to any one of the embodiments of the present disclosure is implemented.
[0061] According to a ninth aspect of the embodiments of the present disclosure, a computer program product is provided, including a computer program or an instruction, and when the computer program or the instruction is executed by a processor, the method according to any one of the embodiments of the present disclosure is implemented.
[0062] In the embodiments of the present disclosure, a first piece of information is sent to a registration server, and the first piece of information is used to request a second piece of information, and the second piece of information includes: user identity information and user identity digital signature information of the first terminal; the second piece of information sent by the registration server is received. In this way, the first terminal can obtain the user identity information and user identity digital signature information of the first terminal from the registration server in a request manner, and the obtained information can be used for subsequent identification of the user identity of the first terminal. A third piece of information is sent to a second terminal, and the third piece of information is used to call the second terminal, and the third piece of information includes the second piece of information, and the third piece of information is used for the second terminal to determine the user identity of the first terminal. In this way, the second piece of information can be sent to the second terminal during the process of the first terminal calling the second terminal, so that the second terminal can identify the user identity of the first terminal based on the second piece of information. Compared with the method of identifying the user identity of the first terminal by using an additional application, there is no need to download and install an application, no need to update the database, and no need to rely on unreliable data. In this way, the identification of the first terminal will be more efficient, fast and reliable. Description of the Drawings
[0063] Figure 1 It is a schematic flowchart of a method for determining a user identity shown according to a first embodiment;
[0064] Figure 2 It is a schematic flowchart of a method for determining a user identity shown according to a second embodiment;
[0065] Figure 3 It is a schematic flowchart of a method for determining a user identity shown according to a third embodiment;
[0066] Figure 4 It is a schematic flow diagram of a method for determining user identity shown in the fourth embodiment;
[0067] Figure 5 It is a schematic flow diagram of a network registration process shown in the fifth embodiment;
[0068] Figure 6 It is a schematic flow diagram of an outgoing call process shown in the sixth embodiment;
[0069] Figure 7 It is a schematic flow diagram of a method for determining user identity shown in the seventh embodiment;
[0070] Figure 8 It is a schematic diagram of the generation of user identity digital signature information shown in the eighth embodiment;
[0071] Figure 9 It is a schematic flow diagram of a method for verifying user identity information shown in the ninth embodiment;
[0072] Figure 10 It is a schematic diagram of signature verification shown in the tenth embodiment;
[0073] Figure 11 It is a schematic diagram of a device for determining user identity shown in the eleventh embodiment.
[0074] Figure 12 It is a schematic diagram of a device for determining user identity shown in the twelfth embodiment.
[0075] Figure 13 It is a schematic diagram of a device for determining user identity shown in the thirteenth embodiment. Detailed implementation manners
[0076] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations to the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present invention.
[0077] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments. However, it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict.
[0078] In the following description, the terms "first", "second", and "third" are only used to distinguish similar objects and do not represent a specific order for the objects. It can be understood that, when permitted, "first", "second", and "third" can be interchanged in a specific order or sequence so that the embodiments of the present invention described herein can be implemented in an order other than that illustrated or described herein.
[0079] In the following description, the terms "greater than" and "less than" are involved. It should be noted that in the present disclosure, "greater than" can be used to indicate "greater than" or "equal to"; "less than" can be used to indicate "less than" or "equal to".
[0080] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs. The terms used herein are only for the purpose of describing the embodiments of the present invention and are not intended to limit the present invention.
[0081] To better understand the embodiments of the present disclosure, the application scenarios of the technical solutions of the present disclosure will be described first:
[0082] In some embodiments, the Session Initiation Protocol (SIP), i.e., the RFC3261 protocol, is one of the key communication protocols in technical fields such as the core network of the IP Multimedia Subsystem (IMS) and Voice over Internet Protocol (VoIP), and is used to initiate a communication session. The embodiments of the present disclosure can be applied to a call scenario based on SIP.
[0083] In some embodiments, a session establishment request (INVITE) of the SIP protocol contains several header fields. The calling party is declared through the FROM (call initiator) header field, and the called party is declared through the TO (call recipient) header field. When the called party receives the INVITE request, i.e., when ringing, two pieces of information of the calling party can be obtained through the FROM header field: the display name of the calling user and the SIP identity document (ID) of the calling user. Corresponding to the actual call scenario, the calling phone number will be displayed on the called terminal when ringing.
[0084] In some embodiments, if the called party only sees one phone number of the calling party when receiving an incoming call, it is not possible to accurately determine the true social identity of the other party. For example, it is not clear whether the other party is really a so-called bank clerk. Therefore, it is still easy for fraudsters to succeed. On the other hand, the frequent occurrence of telecommunications fraud cases has also made some people particularly distrust incoming calls in a certain pattern. There have been incidents where calls from street office staff were regarded as fraud calls and hung up. Therefore, if the true and reliable identity information of the calling party can be displayed in the incoming call information, it will effectively combat telecommunications fraud and protect normal call activities at the same time.
[0085] In some embodiments, in the SIP protocol, the From header field is defined as the display name of the calling user plus the SIP ID of the calling user. These two pieces of information do not contain the identity information that can help the called user identify the calling party. On the other hand, although the Call-Info header field in the protocol can be used to additionally describe the identity information of the calling party, the protocol clearly requires that the UA (User Agent) can only display the information in this header field to the user when it can verify that the Call-Info information is credible. As for how to verify the credibility of the Call-Info information, the protocol itself does not make any provisions.
[0086] For the above reasons, the SIP protocol is not complete in the transmission and verification of user identity information. Therefore, other technical means have emerged in the market to solve the problem of identifying the calling party's identity, mainly mobile applications (APPs) for incoming call number identification. The operators of such APPs have established a user identity database for phone numbers through active annotation or collection from users. When there is an incoming call on the mobile phone, the APP queries the database according to the calling number to obtain the corresponding calling party identity information and prompts the calling party identity on the incoming call interface, such as suspected fraud calls, express delivery and takeaway calls, etc.
[0087] Such mobile APPs for incoming call number identification have several disadvantages. First, users need to download and install the APP, and the convenience of use is not high. Second, in order to query the calling party identity data instantly when there is an incoming call, it is usually necessary to download the calling party identity database to the local terminal of the user, which brings the problem of untimely data update. Third, and most importantly, the call request and identity recognition are two separate processes. The call request is part of the SIP session, and the incoming call identity recognition is an additional process. The credibility of the calling party identity information prompted by such APPs is based on the trust of the called user in such APPs, rather than established through technical means.
[0088] As Figure 1 shown, in the embodiments of the present disclosure, a method for determining user identity is provided. The method is executed by a first terminal and includes:
[0089] Step S101: Send a first message to a registration server. The first message is used to request a second message, and the second message includes: user identity information of the first terminal and user identity digital signature information.
[0090] Step S102: Receive the second message sent by the registration server.
[0091] Step S103: Send a third message to a second terminal. The third message is used to call the second terminal, and the third message includes the second message. The third message is used for the second terminal to determine the user identity of the first terminal.
[0092] In the embodiments of the present disclosure, the method for determining user identity can be applied to scenarios based on SIP calls, but is not limited thereto.
[0093] In some embodiments, the first terminal may be a mobile phone. Exemplarily, the first terminal may be a mobile phone acting as a calling terminal. The second terminal may be a mobile phone. Exemplarily, the second terminal may be a mobile phone acting as a called terminal.
[0094] In some embodiments, send a first message to a registration server. The first message is used to request a second message, and the second message includes: user identity information of the first terminal, user identity digital signature information, and a registration server signature certificate. Receive the second message sent by the registration server. Send a third message to a second terminal. The third message is used to call the second terminal, and the third message includes the second message. The third message is used for the second terminal to determine the user identity of the first terminal.
[0095] In some embodiments, the third message is used for the second terminal to authenticate the user identity of the first terminal.
[0096] In some embodiments, the third message directly indicates the user identity of the first terminal.
[0097] In some embodiments, the third message is used for the second terminal to determine whether the user identity of the first terminal is trustworthy.
[0098] In some embodiments, the first message is sent through a network registration request message.
[0099] In some embodiments, the second message is received through a network registration response message.
[0100] In some embodiments, the third message is sent through a calling request message.
[0101] In some embodiments, a network registration request message (REGISTER request) is sent to a registration server. The network registration request message includes first information for requesting second information, and the second information includes user identity information and user identity digital signature information of the first terminal. A network registration response message sent by the registration server is received. The network registration response message includes the second information. A calling request message (INVITE request) is sent to a second terminal. The calling request message includes third information for calling the second terminal. The third information includes the second information and is used for the second terminal to determine the user identity of the first terminal.
[0102] In some embodiments, the network registration response message may include at least one of the following header fields:
[0103] User-Info header field;
[0104] User-Info-Signature header field;
[0105] Server-Cert header field.
[0106] In some embodiments, the main function of the User-Info header field is to return the user identity information authenticated by the identity authentication center. The content included in the user identity information can be diverse, and the information format can include various common data formats such as vCard format, JSON format, and XML format.
[0107] Exemplarily:
[0108] User-Info: content-type=application / json; content=<{name:”He Maowei”,organization:”China Merchants Bank”,organization-type:”bank”}>.
[0109] In some embodiments, the User-Info-Signature header field is used to return the digital signature information of the user identity in User-Info. To enhance the security of the signature, this header field also includes auxiliary fields such as subject, timestamp, nonce, etc. Among them, the subject field is the Session Initiation Protocol (SIP) identity document of the calling user, the timestamp is the timestamp for generating the digital signature of the user identity, the nonce is a group of random strings, the expire is the expiration time of this signature, and the signature field is the digital signature information of the user identity.
[0110] Exemplarily:
[0111] User-Info-Signature: nonce="81L9FL14", timestamp="2023-07-27 21:32:00", subject="13091903552@domain.com", expire="2023-07-28 9:32:00", sign-type="SM2", signature="f549485e3ff18ae86388d851eef45ac4".
[0112] In some embodiments, the Server-Cert header field is used to return the signature certificate of the registration server. When the registration server signs based on the sub-certificate of the certificate chain, it returns its own signature certificate through this header field.
[0113] Exemplarily:
[0114] Server-Cert: cert="MIILkzCCCnugAw……", cert="MIIFRjCCAy6gAw……".
[0115] In some embodiments, after receiving the network registration response message, the first terminal will locally save the information of the above three header fields. It can be understood that it saves the user identity information, the digital signature information of the user identity, and the signature certificate of the registration server.
[0116] In an embodiment of the present disclosure, a first message is sent to a registration server, the first message being used to request a second message, the second message including: user identity information of the first terminal and user identity digital signature information; and the second message sent by the registration server is received. In this way, the first terminal can obtain the user identity information and user identity digital signature information of the first terminal from the registration server by means of a request, and the obtained information can be used for subsequent identification of the user identity of the first terminal. A third message is sent to a second terminal, the third message being used to call the second terminal, the third message including the second message, and the third message being used for the second terminal to determine the user identity of the first terminal. In this way, the second message can be sent to the second terminal during the process of the first terminal calling the second terminal, so that the second terminal can identify the user identity of the first terminal based on the second message. Compared with the method of using an additional application to identify the user identity of the first terminal, there is no need to download and install an application, no need to update the database, and no need to rely on unreliable data. In this way, the identification of the first terminal will be more efficient, fast, and reliable.
[0117] As Figure 2 shown, in an embodiment of the present disclosure, a method for determining a user identity is provided, the method being executed by a registration server, and the method includes:
[0118] Step S201: Receive a first message sent by a first terminal, the first message being used to request a second message, the second message including: user identity information of the first terminal and user identity digital signature information.
[0119] Step S202: Obtain the second message.
[0120] Step S203: Send the second message to the first terminal.
[0121] In an embodiment of the present disclosure, the method for determining a user identity can be applied to a scenario based on a SIP call, but is not limited thereto.
[0122] In some embodiments, the first terminal may be a mobile phone. Exemplarily, the first terminal may be a mobile phone acting as a calling terminal. The second terminal may be a mobile phone. Exemplarily, the second terminal may be a mobile phone acting as a called terminal.
[0123] In some embodiments, receive a first message sent by a first terminal, the first message being used to request a second message, the second message including: user identity information of the first terminal, user identity digital signature information, and a registration server signature certificate. Obtain the second message. Send the second message to the first terminal.
[0124] In some embodiments, a network registration request message sent by a first terminal is received. The network registration request message includes first information for requesting second information, where the second information includes: user identity information and user identity digital signature information of the first terminal. The second information is obtained. A network registration response message is sent to the first terminal, and the network registration response message contains the second information.
[0125] In some embodiments, a first terminal (calling user) completes real-name identity information authentication at its home location, and the SIP ID of the calling user and the corresponding identity information are saved in a registration server or an associated server.
[0126] In some embodiments, user identity authentication can be implemented by an operator or a party entrusted by the operator, and the user completes identity authentication by providing valid identity proof materials.
[0127] In some embodiments, to ensure the timeliness of authentication information, each identity authentication is only valid for a certain period, and re-authentication is required after the validity period expires.
[0128] In some embodiments, by combining data such as user call behavior and resident city, and using capabilities similar to user profiling, users whose identities may change can be automatically identified, and their identity authentication information can be invalidated in advance.
[0129] In some embodiments, the first terminal establishes an association relationship between the user identity information and the session initiation service SIP identity identifier ID.
[0130] In some embodiments, first information sent by a first terminal is received. The first information is used to request second information, where the second information includes: user identity information and user identity digital signature information of the first terminal. The user identity information is queried. In response to querying the user identity information, digital signature information is generated for the user identity information using a signature secret key. The second information is obtained. The second information is sent to the first terminal.
[0131] In some embodiments, first information sent by a first terminal is received. The first information is used to request second information, where the second information includes: user identity information and user identity digital signature information of the first terminal. After completing the network registration authentication of the first terminal, the authenticated user identity information is queried. In response to querying the user identity information, digital signature information is generated for the user identity information using a signature secret key. The second information is obtained. The second information is sent to the first terminal.
[0132] In some embodiments, a first message sent by a first terminal is received. The first message is used to request a second message, and the second message includes: user identity information of the first terminal and user identity digital signature information. The user identity information is queried. In response to querying the user identity information, a document to be signed is generated based on predetermined information; the predetermined information includes at least one of the following: user identity information, user identity information format, the user's Session Initiation Protocol (SIP) Uniform Resource Identifier (URI), current timestamp, random string, and the validity period of the current signature. The digital signature information is generated by using the signature secret key and the document to be signed. The second message is obtained. The second message is sent to the first terminal.
[0133] In some embodiments, a first message sent by a first terminal is received. The first message is used to request a second message, and the second message includes: user identity information of the first terminal and user identity digital signature information. The user identity information is queried. In response to querying the user identity information, a digital signature information is generated for the user identity information by using a signature secret key. The second message is obtained. The second message is sent to the first terminal. The signature secret key is sent to a Certification Authority (CA). The registration server signature certificate sent by the CA is received, and the registration server signature certificate is generated based on the signature secret key.
[0134] In some embodiments, to enhance the credibility of the registration server signature process, the signature public key of the registration server needs to be submitted to the CA center for issuing a public key certificate.
[0135] As Figure 3 shown, in an embodiment of the present disclosure, a method for determining a user identity is provided. The method is executed by a second terminal, and the method includes:
[0136] Step S301: Receive a third message sent by a first terminal. The third message is used to call the second terminal and is used for the second terminal to determine the user identity of the first terminal. The third message includes: user identity information of the first terminal and user identity digital signature information.
[0137] Step S302: Perform a determination operation based on the third message to obtain a determination result; wherein, the determination operation includes at least one of the following: registration server signature certificate verification, user identity information verification, user identity digital signature information verification.
[0138] Step S303: Determine the user identity of the first terminal based on the determination result.
[0139] In the embodiments of the present disclosure, the method for determining the user identity can be applied to scenarios based on SIP calls, but is not limited thereto.
[0140] In some embodiments, the first terminal may be a mobile phone. Exemplarily, the first terminal may be a mobile phone acting as the calling terminal. The second terminal may be a mobile phone. Exemplarily, the second terminal may be a mobile phone acting as the called terminal.
[0141] In some embodiments, receive third information sent by the first terminal, where the third information is used to call the second terminal and for the second terminal to determine the user identity of the first terminal. The third information includes: the user identity information of the first terminal, the user identity digital signature information, and the registration server signature certificate. Perform a determination operation based on the third information to obtain a determination result; where the determination operation includes verification of the registration server signature certificate, verification of the user identity information, and verification of the user identity digital signature information. Determine the user identity of the first terminal based on the determination result. Here, it may be determined whether the user identity of the first terminal is credible based on the determination result.
[0142] In some embodiments, receive a calling request message sent by the first terminal, where the calling request message includes third information, and the third information is used to call the second terminal and for the second terminal to determine the user identity of the first terminal. The third information includes: the user identity information of the first terminal, the user identity digital signature information, and the registration server signature certificate. Perform a determination operation based on the third information to obtain a determination result; where the determination operation includes verification of the registration server signature certificate, verification of the user identity information, and verification of the user identity digital signature information. Determine the user identity of the first terminal based on the determination result. It should be noted that the determination operation may be an authentication operation, and the determination result may be an authentication result.
[0143] In some embodiments, receive third information sent by the first terminal, where the third information is used to call the second terminal and for the second terminal to determine the user identity of the first terminal. The third information includes: the user identity information of the first terminal, the user identity digital signature information, and the registration server signature certificate. Determine that the third information includes the user identity information, the user identity digital signature information, and the registration server signature certificate, perform a determination operation based on the third information to obtain the determination result; where the determination operation includes verification of the registration server signature certificate, verification of the user identity information, and verification of the user identity digital signature information. Determine the user identity of the first terminal based on the determination result.
[0144] In some embodiments, third information sent by a first terminal is received. The third information is used to call a second terminal and for the second terminal to determine the user identity of the first terminal. The third information includes: the user identity information of the first terminal, user identity digital signature information, and a registration server signature certificate. The registration server signature certificate is verified based on a preset CA certificate. If it is determined that the verification of the registration server signature certificate is successful, the user identity information verification is performed. If it is determined that the verification of the user identity information is successful, the user identity digital signature information verification is performed to obtain the determination result. The user identity of the first terminal is determined based on the determination result.
[0145] In some embodiments, third information sent by a first terminal is received. The third information is used to call a second terminal and for the second terminal to determine the user identity of the first terminal. The third information includes: the user identity information of the first terminal and user identity digital signature information. A determination operation is performed based on the third information to obtain a determination result. Wherein, the determination operation includes at least one of the following: registration server signature certificate verification; user identity information verification; user identity digital signature information verification. The user identity of the first terminal is determined based on the determination result. If it is determined that the identity of the first terminal is trustworthy, the user identity information is displayed. If it is determined that the identity of the first terminal is untrustworthy, the user identity information is not displayed.
[0146] To better understand the embodiments of the present disclosure, the present disclosure is further described below through 3 exemplary embodiments:
[0147] Example 1:
[0148] In the embodiments of the present disclosure, based on the existing SIP protocol, the SIP user identity information and the identity information verification (determination or authentication) mechanism are extended and added, so that a clear and trustworthy caller identity prompt can be realized in the session initiation stage, thereby effectively reducing the risk of telecommunications fraud.
[0149] Please refer to Figure 4 , and a method for determining a user identity is provided. The method includes:
[0150] Step S401, user identity information authentication.
[0151] In some embodiments, the registration server associates the user identity information with the SIP ID.
[0152] In some embodiments, the calling user (corresponding to the first terminal, or can also be referred to as the calling client user agent (UAC, User Agent Client)) completes real-name identity information authentication at the place of residence, and the SIP ID of the calling user and the corresponding user identity information are stored in the registration server or an associated server.
[0153] Step S402: The calling UAC completes registration.
[0154] In some embodiments, the calling UAC obtains user identity information, a user identity digital signature, and a registration server certificate.
[0155] In some embodiments, the calling terminal initiates a REGISTER request (the first piece of information). After the registration server completes the registration authentication, it queries the user identity information corresponding to the user, generates a digital signature for the user identity information using its own signature key, and returns the user identity information, the user identity digital signature information, and the registration server signature certificate in the header field of a 200OK response (indicating that the other party's phone has been answered) (the second piece of information). The calling terminal locally stores the returned user identity information, the user identity digital signature information, and the registration server signature certificate.
[0156] Step S403: The calling UAC sends an INVITE request.
[0157] In some embodiments, the INVITE request carries user identity information, user identity digital signature information, and a registration server certificate.
[0158] In some embodiments, the calling terminal initiates an INVITE request (the third piece of information), and carries the user identity information, the user identity digital signature, and the registration server signature certificate through the header field.
[0159] Step S404: The called UAS receives the INVITE request.
[0160] In some embodiments, the calling user identity information is verified.
[0161] In some embodiments, the called terminal (the second terminal, or also referred to as the called server user agent (UAS, User Agent Server)) receives the INVITE request, resolves the calling user identity information and the corresponding user identity digital signature through the header field, and verifies the user identity digital signature through the registration server signature certificate.
[0162] Step S405: After successful signature verification (checking, verifying, or authenticating), while ringing, the called terminal prompts the calling identity information to the user.
[0163] Step S406: When the signature verification is unsuccessful or the INVITE request does not contain the header field extended by the present disclosure, the called terminal only rings and does not prompt the calling identity information.
[0164] Step S407: Execute the subsequent call process.
[0165] In some embodiments, user identity authentication can be implemented by the operator or the operator's trustee, and the user completes identity authentication by providing valid identity proof materials. To ensure the timeliness of authentication information, each identity authentication is only valid for a certain period, and re - authentication is required after the expiration date. At the same time, by combining data such as the user's call behavior and the city of residence, and using similar capabilities such as user portraits, users whose identities may change can be automatically identified, and their identity authentication information can be invalidated in advance.
[0166] Example 2
[0167] In some embodiments, please refer to Figure 5 , a method for determining whether a user identity is feasible is provided, and the method includes:
[0168] Step S501: The calling terminal (the first terminal) sends a network registration request (REGISTER request) to the registration server;
[0169] Step S502: Return 401 Unauthorized (this may not be executed).
[0170] Step S503: The calling terminal sends a REGISTER request (carrying an identity authentication header field) to the registration server.
[0171] Step S504: Query the user identity information and sign the user identity information.
[0172] Step S505: Return 200 OK (carrying header fields such as identity information).
[0173] In some embodiments, after the registration server receives the REGISTER request from the calling terminal and the user registration authentication is successful, it needs to query whether the user has authenticated user identity information. If valid user identity information is queried, the registration server uses its own signature secret key to generate a digital signature for the user identity information. When signing, in addition to the user identity information, the current timestamp and the nonce random number can also be added for digital signature.
[0174] Step S505: Return 200 OK (carrying header fields such as identity information). 200 OK corresponds to the network registration response message, and the header fields of the network registration response message can refer to the description of the relevant part of the network registration response message in the foregoing part.
[0175] Example 3
[0176] In some embodiments, please refer to Figure 6 , a method for determining whether a user identity is feasible is provided, and the method includes:
[0177] Step S601: The calling terminal (the first terminal) sends an INVITE request to the called terminal (the second terminal).
[0178] Step S602: Verify the user identity information and the user identity digital signature information.
[0179] Step S603: Prompt the user identity information.
[0180] Step S604: Return 100 Trying.
[0181] Step S605: Return 200 OK.
[0182] In some embodiments, in step S601, when the calling terminal issues an INVITE request, three header field information, namely User-Info, User-Info-Signature, and Server-Cert, received from the registration server upon successful registration, are added on the basis of the standard SIP protocol.
[0183] In some embodiments, after receiving the INVITE request, the called terminal checks whether the three header field information, namely User-Info, User-Info-Signature, and Server-Cert, exist simultaneously. If they exist simultaneously, the user identity digital signature information is verified. After successful verification, the calling user identity information is prompted while ringing; otherwise, only ringing occurs.
[0184] In some embodiments, please refer to Figure 7 , and a method for determining whether the user identity is feasible is provided. The method includes:
[0185] Step S701: Check whether the three header fields, namely User-Info, User-info-Signature, and Server-Cert, exist.
[0186] Step S702: Verify the user identity signature information.
[0187] Step S703: Ring and prompt the calling user identity according to the content of the User-info header field.
[0188] Step S704: Only ring.
[0189] Step S705: Execute the subsequent call process.
[0190] Example 4
[0191] In some embodiments, please refer to Figure 8 , and the logic of the user identity information signature is as Figure 8As shown in the figure, when signing, the user's identity information (the content value in the User-Info header field), the identity information format (the content-type value in the User-Info header field), the user's SIP URI (the subject value in the User-Info-Signature header field), the current timestamp (the timestamp value in the User-Info-Signature header field), the random string (the nonce value in the User-Info-Signature header field), and the validity period of this signature (the expire value in the User-Info-Signature header field) are concatenated into the document to be signed, and the signature string is generated using the signature private key of the registration server. The algorithm for the registration server to generate the signature needs to be set in the sign-type field in the User-Info-Signature header field.
[0192] In some embodiments, to enhance the credibility of the registration server's signature process, the signature public key of the registration server needs to be submitted to the CA center for signing the public key certificate, and the signature public key certificate is added to the SIP message through the Server-Cert header field. The root certificate of the CA is preset in the called terminal to verify the public key certificate of the registration server. This root certificate is globally unique, and for the case of multiple registration servers, the sub-certificates of each registration server are different.
[0193] In some embodiments, please refer to Figure 9 , a method for determining the user's identity is provided. When the called terminal receives an INVITE request, it will verify whether the user information is trustworthy. The calling identity verification process includes:
[0194] Step S901: Verify the server signature certificate carried in the Server-Cert header field through the CA certificate preset in the called terminal.
[0195] Step S902: Compare whether the subject field value in the User-Info-Signature header field in the INVITE message is the same as the calling SIP URI in the From header field. If they are not the same, the identity information verification fails. Next, if the user information signature is verified in step S903, the user identity information verification passes and the identity information is trustworthy.
[0196] Step S903: Verify the user identity digital signature information. Specifically, as Figure 10 shown, corresponding to the signature generation method in the previous text, the signature public key used for signature verification is taken from the Server-Cert header field, and the signature value is taken from the signature field value in the User-Info-Signature header field.
[0197] Step S904: The user identity information verification is successful.
[0198] Step S905: The user identity information verification fails.
[0199] As Figure 11 shown, an embodiment of the present disclosure provides a device for determining a user identity. The device includes a transceiver module 111, which is configured to:
[0200] Send a first message to a registration server, where the first message is used to request a second message, and the second message includes: the user identity information and the user identity digital signature information of the first terminal;
[0201] Receive the second message sent by the registration server;
[0202] Send a third message to a second terminal, where the third message is used to call the second terminal, and the third message includes the second message, and the third message is used for the second terminal to determine the user identity of the first terminal.
[0203] As Figure 12 shown, an embodiment of the present disclosure provides a device for determining a user identity. The device includes:
[0204] A transceiver module 121, which is configured to receive a first message sent by a first terminal, where the first message is used to request a second message, and the second message includes: the user identity information and the user identity digital signature information of the first terminal;
[0205] An acquisition module 122, which is configured to acquire the second message;
[0206] The transceiver module 121 is configured to send the second message to the first terminal.
[0207] As Figure 13 shown, an embodiment of the present disclosure provides a device for determining a user identity. The device includes:
[0208] A transceiver module 131, which is configured to receive a third message sent by a first terminal, where the third message is used to call the second terminal and for the second terminal to determine the user identity of the first terminal, and the third message includes: the user identity information and the user identity digital signature information of the first terminal;
[0209] An authentication module 132, which is configured to perform a determination operation based on the third message to obtain a determination result; where the determination operation includes at least one of the following: registration server signature certificate verification, user identity information verification, and user identity digital signature information verification;
[0210] A determination module 133, configured to determine whether the user identity of the first terminal is trustworthy based on the determination result.
[0211] An embodiment of the present disclosure provides a processing device, which includes:
[0212] A memory for storing an executable program;
[0213] A processor, when executing the executable program stored in the memory, implements the method according to any one of the embodiments of the present disclosure.
[0214] It can be understood that the memory can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM, Read Only Memory), a programmable read-only memory (PROM, Programmable Read-Only Memory), an erasable programmable read-only memory (EPROM, Erasable Programmable Read-Only Memory), an electrically erasable programmable read-only memory (EEPROM, Electrically Erasable Programmable Read-Only Memory), a ferromagnetic random access memory (FRAM, ferromagnetic random access memory), a flash memory (Flash Memory), a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM, Compact Disc Read-Only Memory); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM, Random Access Memory), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as a static random access memory (SRAM, Static Random Access Memory), a synchronous static random access memory (SSRAM, Synchronous Static Random Access Memory), a dynamic random access memory (DRAM, Dynamic Random Access Memory), a synchronous dynamic random access memory (SDRAM, Synchronous Dynamic Random Access Memory), a double data rate synchronous dynamic random access memory (DDR SDRAM, Double Data Rate Synchronous Dynamic Random Access Memory), an enhanced synchronous dynamic random access memory (ESDRAM, Enhanced Synchronous Dynamic Random Access Memory), a sync link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), a direct rambus random access memory (DRRAM, Direct Rambus Random Access Memory).The memories described in the embodiments of the present application are intended to include, but are not limited to, these and any other suitable types of memories.
[0215] Among them, the method for determining the topological structure disclosed in the present invention can be applied to or implemented by the processor. The processor can be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the method for determining the topological structure can be completed by the integrated logic circuit of the hardware in the processor or the instructions in the form of software. The above-mentioned processor can be a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor can implement or execute each method, step, and logic block diagram disclosed in the present invention. The general-purpose processor can be a microprocessor or any conventional processor, etc. Combining the steps of the method disclosed in the present invention, it can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by the combination of the hardware and software modules in the decoding processor. The software module can be located in the storage medium, and this storage medium is located in the memory. The processor reads the information in the memory and combines its hardware to complete the steps of the method for determining the topological structure provided in the embodiments of the present application.
[0216] The present invention also provides a computer storage medium. The computer storage medium stores an executable program, and when the executable program is executed by a processor, it implements the method for determining the topological structure as described in any one of the embodiments of the present disclosure. Specifically, it can be a computer-readable storage medium, for example, including a memory storing a computer program. The above-mentioned computer program can be executed by the processor of the processing device to complete the steps of the method described in the embodiments of the present application. The computer-readable storage medium can be a ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc.
[0217] The embodiments of the present disclosure provide a computer program product, which includes: a computer program or executable instructions, and the computer program or executable instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer program or executable instructions from the computer-readable storage medium, and the processor executes the computer program or executable instructions, so that the computer device executes any one of the methods for determining the user identity described above in the embodiments of the present disclosure.
[0218] As described above, it is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A method for determining a user's identity, characterized in that, The method is executed by a first terminal, and the method includes: Sending first information to a registration server, where the first information is used to request second information, and the second information includes: user identity information and user identity digital signature information of the first terminal; Receiving the second information sent by the registration server; Sending third information to a second terminal, where the third information is used to call the second terminal, and the third information includes the second information, and the third information is used for the second terminal to determine the user identity of the first terminal.
2. The method according to claim 1, wherein The second information includes the user identity information, the user identity digital signature information, and a registration server signature certificate.
3. The method according to claim 1, wherein The first information is sent through a network registration request message, and / or, the second information is received through a network registration response message, and / or, the third information is sent through a calling request message.
4. A method for determining a user identity, characterized in that, The method is executed by a registration server, and the method includes: Receiving first information sent by a first terminal, where the first information is used to request second information, and the second information includes: user identity information and user identity digital signature information of the first terminal; Obtaining the second information; Sending the second information to the first terminal.
5. The method according to claim 4, characterized in that, The second information includes the user identity information, the user identity digital signature information, and a registration server signature certificate.
6. The method according to claim 4, wherein The method further includes: Establishing an association relationship between the user identity information and a Session Initiation Protocol (SIP) identity identifier (ID) of a session initiation service.
7. The method according to claim 4, characterized in that, The first information is received through a network registration request message, and / or, the second information is sent through a network registration response message.
8. The method according to claim 5, wherein The method further includes: Querying the user identity information; In response to querying the user identity information, generating digital signature information for the user identity information by using a signature secret key.
9. The method according to claim 8, wherein The querying of the user identity information includes: After completing the network registration authentication of the first terminal, querying the user identity information.
10. The method according to claim 8, characterized in that The method further includes: Generating a document to be signed based on predetermined information; the predetermined information includes at least one of the following: user identity information, user identity information format, the Session Initiation Protocol (SIP) Uniform Resource Identifier (URI) of the user, current timestamp, random string, and validity period of the current signature; The generating of the digital signature information for the user identity information by using the signature secret key includes: Generating the digital signature information by using the signature secret key and the document to be signed.
11. The method according to claim 8, characterized in that, The method further includes: Sending the signature secret key to a Certification Authority (CA); Receiving the registration server signature certificate sent by the CA, where the registration server signature certificate is generated based on the signature secret key.
12. A method for determining a user identity, characterized in that, The method is executed by a second terminal, and the method includes: Receiving third information sent by a first terminal, where the third information is used to call the second terminal and is used for the second terminal to determine the user identity of the first terminal, and the third information includes: user identity information and user identity digital signature information of the first terminal; Perform a determination operation based on the third information to obtain a determination result; wherein, the determination operation includes at least one of the following: registration server signature certificate verification; user identity information verification; user identity digital signature information verification; Determine the user identity of the first terminal based on the determination result.
13. The method according to claim 12, characterized in that The second information includes the user identity information, the user identity digital signature information, and the registration server signature certificate.
14. The method according to claim 12, wherein The third information is received through a calling request message.
15. The method according to claim 12, wherein The performing a determination operation based on the third information to obtain a determination result includes: Determine that the third information includes the user identity information, the user identity digital signature information, and the registration server signature certificate, and perform a determination operation based on the third information to obtain the determination result.
16. The method according to claim 12, wherein The performing a determination operation based on the third information to obtain a determination result includes: Verify the registration server signature certificate based on a pre-set CA certificate; Determine that the verification of the registration server signature certificate is successful, and perform the user identity information verification; Determine that the verification of the user identity information is successful, and perform the user identity digital signature information verification to obtain the determination result.
17. The method according to claim 12, wherein The method further includes: Determine that the identity of the first terminal is trustworthy, and display the user identity information; Determine that the identity of the first terminal is untrustworthy, and do not display the user identity information.
18. A device for determining a user's identity, characterized in that, The apparatus includes a transceiver module, which is configured to: Send a first information to a registration server, where the first information is used to request second information, and the second information includes: the user identity information and the user identity digital signature information of the first terminal; Receive the second information sent by the registration server; Send a third information to a second terminal, where the third information is used to call the second terminal, the third information includes the second information, and the third information is used for the second terminal to determine the user identity of the first terminal.
19. A device for determining a user's identity, characterized in that, The apparatus includes: A transceiver module, which is configured to receive a first information sent by a first terminal, where the first information is used to request second information, and the second information includes: the user identity information and the user identity digital signature information of the first terminal; An obtaining module, which is configured to obtain the second information; The transceiver module, which is configured to send the second information to the first terminal.
20. A device for determining a user's identity, characterized in that, The apparatus includes: A transceiver module, which is configured to receive a third information sent by a first terminal, where the third information is used to call the second terminal and is used for the second terminal to determine the user identity of the first terminal, and the third information includes: the user identity information and the user identity digital signature information of the first terminal; A determination module, which is configured to perform a determination operation based on the third information to obtain a determination result; wherein, the confirmation operation includes at least one of the following: registration server signature certificate verification, user identity information verification, user identity digital signature information verification; A determination module, which is configured to determine the user identity of the first terminal based on the determination result.
21. A processing device, characterized in that, The processing device includes: A memory, which is used to store an executable program; A processor, when executing the executable program stored in the memory, implements the method according to any one of claims 1 to 3, 4 to 11, and / or 12 to 17.
22. A computer storage medium, characterized in that, The computer storage medium stores an executable program, which, when executed by a processor, implements the method according to any one of claims 1 to 3, 4 to 11, and / or 12 to 17.
23. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instruction is executed by a processor, the method according to any one of claims 1 to 3, 4 to 11, and / or 12 to 17 is implemented.