Cloud terminal service registration method and device, computer equipment and storage medium
By sending a registration request for the target network application function key and boot transaction identifier to the message server from the cloud terminal, and using the GBA authentication result to obtain a random number and authentication token, the 5G message service registration problem caused by the lack of a SIM card in the cloud terminal is solved, and rapid authentication is achieved.
Patent Information
- Application Number
- CN202510881953.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-09-19
Smart Images

Figure CN120676356A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of cloud terminal technology, and in particular to a cloud terminal service registration method, apparatus, computer equipment, and storage medium. Background Art
[0002] With the rapid development of mobile devices and cloud technology, cloud terminals have been widely adopted and have long been well-received. Take cloud phones, for example. These are virtual phones running on cloud servers, leveraging cloud computing virtualization technology. Currently, calls and text messages on cloud phones are still handled locally, with the cloud primarily hosting games and video applications. 5G messaging, the fifth-generation mobile communication technology, is an upgrade to short message services, offering users a variety of message formats, including images, videos, voice, and cards combining media content and text. It also supports interoperability with SMS and allows for intermixing of short messages and 5G messages on the same interface. If 5G messaging is built into physical terminals, terminal manufacturers would need to adapt the SDK individually, which would be a significant effort and require a high development threshold. Therefore, placing 5G messaging services on cloud phones is more conducive to the promotion of 5G messaging services.
[0003] Since cloud terminals do not have the SIM (Subscriber Identity Module) cards of physical terminals, if 5G messaging services are configured on cloud terminals, the problem of authentication and authorization will arise when registering for the 5G messaging services on the cloud terminals. Summary of the Invention
[0004] Based on this, it is necessary to provide a cloud terminal service registration method, device, computer equipment and storage medium for realizing rapid authentication and authorization of cloud terminals in response to the above technical problems.
[0005] In a first aspect, the present application provides a cloud terminal service registration method, which is applied to a cloud terminal, and the method includes:
[0006] Sending a registration request to a message server; wherein the registration request carries at least a target network application function key and / or a target bootstrap transaction identifier; the target network application function key and / or the target bootstrap transaction identifier are obtained by the cloud terminal by sending a GBA authentication result acquisition request to the local physical terminal; the registration request is used to instruct the message server to authenticate the cloud terminal based on the target network application function key and / or the target bootstrap transaction identifier, and to feed back a registration response message to the cloud terminal based on the authentication result;
[0007] Receive the registration response message sent by the message server.
[0008] In one embodiment, sending a registration request to a message server includes:
[0009] Obtaining the current usage duration and validity duration of the first network application function key; wherein the current usage duration refers to the duration between the time when the target network application function key is received and the current time;
[0010] When the current usage duration does not exceed the valid duration, a registration request is sent to the message server; wherein, the target network application function key is the first network application function key, and / or the target boot transaction identifier is the first boot transaction identifier; the first network application function key and / or the first boot transaction identifier are obtained by the cloud terminal by sending a first GBA authentication result acquisition request to the local physical terminal.
[0011] In one embodiment, sending a registration request to a message server includes:
[0012] When the current usage duration exceeds the valid duration, a second GBA authentication result acquisition request is sent to the local physical terminal; wherein the second GBA authentication result acquisition request is used to instruct the local physical terminal to send a GBA bootstrapping request carrying the user identifier to the BSF network element; the GBA bootstrapping request is used to instruct the BSF network element to obtain the authentication vector corresponding to the user identifier through the HSS network element, generate a second bootstrapping transaction identifier based on the authentication vector, the authentication vector including a random number and an authentication token, and feedback the random number, authentication token, and second bootstrapping transaction identifier to the local physical terminal;
[0013] Receiving a second boot transaction identifier and a second network application function key sent by the local physical terminal; wherein the second network application function key is determined by the local physical terminal based on a SIM card key in the SIM card, a random number, and an authentication token;
[0014] Generate a registration request; wherein the target network application function key is the second network application function key, and / or the target boot transaction identifier is the second boot transaction identifier.
[0015] In one of the embodiments, the registration request is specifically used to instruct the message server to send the target network application function key and / or the target boot transaction identifier to the BSF network element, so that the BSF network element authenticates the cloud terminal based on the target network application function key and / or the target boot transaction identifier, and feeds back the authentication result to the message server.
[0016] In a second aspect, the present application provides another cloud terminal service registration method, which is configured on a local physical terminal, and includes:
[0017] Receiving a first GBA authentication result acquisition request sent by the cloud terminal;
[0018] Feedback the GBA authentication result to the cloud terminal; wherein the GBA authentication result is used to instruct the cloud terminal to obtain the target network application function key and / or target boot transaction identifier, generate a registration request based on the target network application function key and / or target boot transaction identifier, and send the registration request to the message server; the registration request is used to instruct the message server to authenticate the cloud terminal, and based on the authentication result, feedback a registration response message to the cloud terminal.
[0019] In one embodiment, the GBA authentication result carries a first network application function key; the GBA authentication result is used to instruct the cloud terminal to obtain the current usage time and validity time of the first network application function key; and when the current usage time does not exceed the validity time, a registration request is generated based on the target network application function key and / or the target boot transaction identifier; wherein the current usage time refers to the time between the time when the target network application function key is received and the current time; the target network application function key is the first network application function key, and / or the target boot transaction identifier is the first boot transaction identifier.
[0020] In one embodiment, the method further comprises:
[0021] Receiving a second GBA authentication result acquisition request sent by the cloud terminal; wherein the second GBA authentication result acquisition request is sent by the cloud terminal when the current usage duration exceeds the valid duration;
[0022] Sending a GBA bootstrapping request carrying a user identifier to the BSF network element; wherein the GBA bootstrapping request is used to instruct the BSF network element to obtain an authentication vector corresponding to the user identifier through the HSS network element and generate a second bootstrapping transaction identifier based on the authentication vector; the authentication vector includes a random number and an authentication token;
[0023] Receive the random number, authentication token and second boot transaction identifier fed back by the BSF network element;
[0024] Determine a second network application function key based on a SIM card key in the SIM card, a random number, and an authentication token;
[0025] Feedback the second bootstrapping transaction identifier and / or the second network application function key to the cloud terminal, so that the cloud terminal uses the second bootstrapping transaction identifier as the target bootstrapping transaction identifier and / or the second network application function key as the target network application function key, and generates a registration request based on the target network application function key and / or the target bootstrapping transaction identifier.
[0026] In a third aspect, the present application provides a cloud terminal service registration method, which is configured on a local physical terminal, and the device includes:
[0027] A first sending module is configured to send a registration request to a message server; the registration request carries at least a target network application function key and / or a target bootstrapping transaction identifier; the target network application function key and / or the target bootstrapping transaction identifier are obtained by the cloud terminal by sending a GBA authentication result acquisition request to the local physical terminal; the registration request is configured to instruct the message server to authenticate the cloud terminal based on the target network application function key and / or the target bootstrapping transaction identifier, and to feed back a registration response message to the cloud terminal based on the authentication result;
[0028] The second sending module is used to receive the registration response message sent by the message server.
[0029] In a fourth aspect, the present application provides another cloud terminal service registration method, which is configured on a local physical terminal and includes:
[0030] A first receiving module is configured to receive a first GBA authentication result acquisition request sent by a cloud terminal;
[0031] The third sending module is used to feed back the GBA authentication result to the cloud terminal; wherein the GBA authentication result is used to instruct the cloud terminal to obtain the target network application function key and / or the target boot transaction identifier, generate a registration request based on the target network application function key and / or the target boot transaction identifier, and send the registration request to the message server; the registration request is used to instruct the message server to authenticate the cloud terminal and, based on the authentication result, feed back a registration response message to the cloud terminal.
[0032] In a fifth aspect, the present application further provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0033] Sending a registration request to a message server; wherein the registration request carries at least a target network application function key and / or a target bootstrap transaction identifier; the target network application function key and / or the target bootstrap transaction identifier are obtained by the cloud terminal by sending a GBA authentication result acquisition request to the local physical terminal; the registration request is used to instruct the message server to authenticate the cloud terminal based on the target network application function key and / or the target bootstrap transaction identifier, and to feed back a registration response message to the cloud terminal based on the authentication result;
[0034] Receive the registration response message sent by the message server.
[0035] In a sixth aspect, the present application further provides another computer device, the computer device comprising a memory and a processor, the memory storing a computer program, and the processor implementing the following steps when executing the computer program:
[0036] Receiving a first GBA authentication result acquisition request sent by the cloud terminal;
[0037] Feedback the GBA authentication result to the cloud terminal; wherein the GBA authentication result is used to instruct the cloud terminal to obtain the target network application function key and / or target boot transaction identifier, generate a registration request based on the target network application function key and / or target boot transaction identifier, and send the registration request to the message server; the registration request is used to instruct the message server to authenticate the cloud terminal, and based on the authentication result, feedback a registration response message to the cloud terminal.
[0038] In a seventh aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the following steps:
[0039] Sending a registration request to a message server; wherein the registration request carries at least a target network application function key and / or a target bootstrap transaction identifier; the target network application function key and / or the target bootstrap transaction identifier are obtained by the cloud terminal by sending a GBA authentication result acquisition request to the local physical terminal; the registration request is used to instruct the message server to authenticate the cloud terminal based on the target network application function key and / or the target bootstrap transaction identifier, and to feed back a registration response message to the cloud terminal based on the authentication result;
[0040] Receive the registration response message sent by the message server.
[0041] In an eighth aspect, the present application further provides another computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0042] Receiving a first GBA authentication result acquisition request sent by the cloud terminal;
[0043] Feedback the GBA authentication result to the cloud terminal; wherein the GBA authentication result is used to instruct the cloud terminal to obtain the target network application function key and / or target boot transaction identifier, generate a registration request based on the target network application function key and / or target boot transaction identifier, and send the registration request to the message server; the registration request is used to instruct the message server to authenticate the cloud terminal, and based on the authentication result, feedback a registration response message to the cloud terminal.
[0044] In a ninth aspect, the present application further provides a computer program product, the computer program product comprising a computer program, which, when executed by a processor, implements the following steps:
[0045] Sending a registration request to a message server; wherein the registration request carries at least a target network application function key and / or a target bootstrap transaction identifier; the target network application function key and / or the target bootstrap transaction identifier are obtained by the cloud terminal by sending a GBA authentication result acquisition request to the local physical terminal; the registration request is used to instruct the message server to authenticate the cloud terminal based on the target network application function key and / or the target bootstrap transaction identifier, and to feed back a registration response message to the cloud terminal based on the authentication result;
[0046] Receive the registration response message sent by the message server.
[0047] In a tenth aspect, the present application further provides another computer program product, the computer program product comprising a computer program, which, when executed by a processor, implements the following steps:
[0048] Receiving a first GBA authentication result acquisition request sent by the cloud terminal;
[0049] Feedback the GBA authentication result to the cloud terminal; wherein the GBA authentication result is used to instruct the cloud terminal to obtain the target network application function key and / or target boot transaction identifier, generate a registration request based on the target network application function key and / or target boot transaction identifier, and send the registration request to the message server; the registration request is used to instruct the message server to authenticate the cloud terminal, and based on the authentication result, feedback a registration response message to the cloud terminal.
[0050] The above-mentioned cloud terminal service registration method, device, computer equipment and storage medium send a registration request to the message server; wherein, the registration request carries at least the first network application function key and / or the first boot transaction identifier; the first network application function key and / or the first boot transaction identifier are obtained by the cloud terminal by sending a first general boot architecture GBA authentication result acquisition request to the local physical terminal; the registration request is used to instruct the message server to authenticate the cloud terminal based on the first network application function key and / or the first boot transaction identifier, and based on the authentication result, feedback a registration response message to the cloud terminal. Receive the registration response message sent by the message server. Based on this application, the message server can realize authentication and authorization of the cloud terminal, thereby solving the problem of 5G message service registration faced when configuring the 5G message service in the cloud terminal, and providing a good technical foundation for the application of 5G message service in the cloud terminal. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 This is an application environment diagram of a cloud terminal service registration method provided in this embodiment;
[0052] Figure 2 A flowchart of the first cloud terminal service registration method provided in this embodiment;
[0053] Figure 3 A schematic diagram of a process for sending a registration request to a message server provided in an embodiment;
[0054] Figure 4 A schematic diagram of the process of generating a registration request provided in this embodiment;
[0055] Figure 5 A flowchart of the second cloud terminal service registration method provided in this embodiment;
[0056] Figure 6 Signaling interaction diagram of the cloud terminal service registration method provided in this embodiment;
[0057] Figure 7 A structural block diagram of a cloud terminal service registration device provided in this embodiment;
[0058] Figure 8 A structural block diagram of another cloud terminal service registration device provided in this embodiment;
[0059] Figure 9 This is a diagram of the internal structure of the computer device provided in this embodiment. DETAILED DESCRIPTION
[0060] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0061] The cloud terminal service registration method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown, cloud terminal 104 sends a registration request to a message server. The registration request carries at least a target network application function key and / or a target bootstrap transaction identifier. The target network application function key and / or the target bootstrap transaction identifier are obtained by cloud terminal 104 by sending a GBA authentication result acquisition request to local physical terminal 102. The registration request instructs message server 106 to authenticate the cloud terminal based on the target network application function key and / or the target bootstrap transaction identifier, and to return a registration response message to cloud terminal 104 based on the authentication result. Cloud terminal 104 receives the registration response message sent by message server 106.
[0062] The term "local physical terminal" refers to a physical terminal, which can be a smart terminal such as a mobile phone or computer, or a smart wearable device such as a smart watch or smart bracelet. A cloud terminal refers to a virtual terminal corresponding to a local physical terminal, which runs on a cloud server based on cloud computing virtualization technology, for example, a cloud phone. A message server refers to a server that can send short messages; the message server of this application can be a 5G message server, or a message server based on the sixth generation mobile communication technology (6G) or future mobile communication technology.
[0063] In one embodiment, Figure 2 This is a flow chart of a cloud terminal service registration method provided in accordance with an embodiment of the present application, in which the method is applied to Figure 1 Taking the cloud terminal in FIG. 1 as an example, the method includes the following steps:
[0064] S201, sending a registration request to a message server.
[0065] The registration request, when a cloud terminal has a message service registration requirement, is a request message sent to a message server. The registration request carries at least the target network application function key (i.e., target Ks_NAF (Key for Network Application Function)) and / or target bootstrapping transaction identifier (i.e., target B-TID (Bootstrapping Transaction Identifier)). The target network application function key and / or target bootstrapping transaction identifier are obtained by the cloud terminal by sending a GBA (Generic Bootstrapping Architecture) authentication result acquisition request to the local physical terminal. The registration request instructs the message server to authenticate the cloud terminal based on the target network application function key and / or target bootstrapping transaction identifier and, based on the authentication result, to send a registration response message back to the cloud terminal.
[0066] Optionally, in this embodiment, the registration request carries the target network application function key and / or the target bootstrap transaction identifier. Preferably, the registration request carries the target network application function key and the target bootstrap transaction identifier.
[0067] An optional implementation method of the embodiment of the present application is to send a registration request directly to the message server.
[0068] Another optional implementation of the embodiment of the present application is to send a registration request directly to the message server.
[0069] In this embodiment, an optional implementation method for the message server to authenticate the cloud terminal based on the target network application function key and / or target bootstrapping transaction identifier is to authenticate the cloud terminal based on the target network application function key and target bootstrapping transaction identifier. Specifically, the registration request also carries a user identifier (e.g., IMPI (International Mobile Subscriber Identity) or IMPU (IP Multimedia Private Identity)). Based on the user identifier, the message server obtains the verification network application function key and verification bootstrapping transaction identifier corresponding to the user identifier from the BSF (Bootstrapping Service Function) network element. The target network application function key and target bootstrapping transaction identifier are matched with the verification network application function key and verification bootstrapping transaction identifier to verify the legitimacy of the target bootstrapping transaction identifier and the validity of the target network application function key. Based on the verification results, an authentication result is generated.
[0070] In another optional implementation of the message server authenticating the cloud terminal based on the target network application function key and / or target bootstrapped transaction identifier in this embodiment, the target network application function key and target bootstrapped transaction identifier are sent to a BSF network element, which then authenticates the cloud terminal based on the target network application function key and target bootstrapped transaction identifier. In another optional implementation, the BSF network element matches the target network application function key and target bootstrapped transaction identifier with a locally stored local network application function key and local bootstrapped transaction identifier to verify the legitimacy of the target bootstrapped transaction identifier and the validity of the target network application function key, and generates an authentication result based on the verification result. In another optional implementation, the message server also sends the user identifier of the cloud terminal to the BSF network element. The BSF network element obtains the verification network application function key and verification bootstrapped transaction identifier corresponding to the user identifier based on the user identifier, matches the target network application function key and target bootstrapped transaction identifier with the verification network application function key and verification bootstrapped transaction identifier to verify the legitimacy of the target bootstrapped transaction identifier and the validity of the target network application function key, and generates an authentication result based on the verification result.
[0071] Optionally, in this embodiment, the message server generates a registration response message based on the authentication result. If the authentication result is authentication successful, the message server allocates message service resources (e.g., 5G message service resources) to the cloud terminal and generates a registration success response message. If the authentication result is authentication failure, the message server generates a registration failure response message.
[0072] S202: Receive a registration response message sent by the message server.
[0073] The registration response message refers to a response message carrying the registration result that is fed back to the cloud terminal after authentication and verification of the registration request to the cloud terminal.
[0074] The above-mentioned cloud terminal service registration method sends a registration request to the message server; wherein, the registration request carries at least the first network application function key and / or the first boot transaction identifier; the first network application function key and / or the first boot transaction identifier are obtained by the cloud terminal by sending a first general boot architecture GBA authentication result acquisition request to the local physical terminal; the registration request is used to instruct the message server to authenticate the cloud terminal based on the first network application function key and / or the first boot transaction identifier, and based on the authentication result, feedback a registration response message to the cloud terminal. Receive the registration response message sent by the message server. Based on this application, the message server can realize authentication and authorization of the cloud terminal, thereby solving the problem of 5G message service registration faced when configuring the 5G message service in the cloud terminal, and providing a good technical foundation for the application of 5G message service in the cloud terminal.
[0075] In one embodiment, to increase security during the registration process, Figure 3 As shown, an optional implementation of S201 includes:
[0076] S301: Obtain the current usage duration and validity duration of a first network application function key.
[0077] The current usage duration refers to the duration between the time when the target network application function key is received and the current time. The reception time refers to the time when the target network application function key is received from the local physical terminal.
[0078] Optionally, in this embodiment, the validity period is configured by the local physical terminal. When the local physical terminal sends the CBA authentication result, it carries the validity period of the network application function key.
[0079] S302: If the current usage duration does not exceed the valid duration, a registration request is sent to the message server.
[0080] The target network application function key is the first network application function key, and / or the target bootstrapping transaction identifier is the first bootstrapping transaction identifier. The first network application function key and / or the first bootstrapping transaction identifier are obtained by the cloud terminal by sending a first GBA authentication result acquisition request to the local physical terminal. The first GBA authentication result acquisition request is the last GBA authentication result acquisition request sent by the cloud terminal to the local physical terminal. The local physical terminal feeds back a GBA authentication result to the cloud terminal based on the first GBA authentication result acquisition request. The GBA authentication result carries at least the first network application function key and / or the first bootstrapping transaction identifier, as well as the validity period.
[0081] Optionally, in this embodiment, if the current usage duration does not exceed the valid duration, the cloud terminal uses the first network application function key as the target network application function key and the first bootstrapping transaction identifier as the target bootstrapping transaction identifier. Based on the target network application function key and the bootstrapping transaction identifier, a registration request is generated and sent to the message server.
[0082] It should be noted that in this embodiment, the cloud terminal sends the first GBA authentication result to the local physical terminal to obtain hydrogen. The method for obtaining the authentication result can refer to the following embodiment in which the cloud terminal sends the second GBA authentication result acquisition request to the local physical terminal to obtain the authentication result. The same method is not repeated here.
[0083] In this embodiment, the current usage duration and validity duration of the first network application function key are obtained. If the current usage duration does not exceed the validity duration, a registration request is sent to the message server. The current usage duration refers to the duration between the time the target network application function key was received and the current time; the target network application function key is the first network application function key, and / or the target bootstrapping transaction identifier is the first bootstrapping transaction identifier; the first network application function key and / or the first bootstrapping transaction identifier are obtained by the cloud terminal by sending a first GBA authentication result acquisition request to the local physical terminal. In this embodiment, before sending the registration request to the message server, the validity of the first network function key must be verified, which increases security during registration.
[0084] In one embodiment, when the current usage duration does not exceed the valid duration, in order to generate a registration request, such as Figure 4 As shown, an optional implementation of sending a registration request to a message server includes:
[0085] S401: When the current usage duration exceeds the valid duration, a second GBA authentication result acquisition request is sent to the local physical terminal.
[0086] The second GBA authentication result acquisition request is a GBA authentication result acquisition request sent to the current physical terminal when the current reception duration of the first network application function key exceeds the validity duration. The second GBA authentication result acquisition request is used to instruct the local physical terminal to send a GBA bootstrapping request carrying the user identifier to the BSF network element. The GBA bootstrapping request instructs the BSF network element to obtain the authentication vector corresponding to the user identifier from the HSS (Home Subscriber Server) network element, generate a second bootstrapping transaction identifier based on the authentication vector, which includes a random number and an authentication token, and then feedback the random number, authentication token, and second bootstrapping transaction identifier to the local physical terminal.
[0087] In this embodiment, a second GBA authentication result acquisition request is sent to the local physical terminal. The second GBA authentication result acquisition request instructs the local physical terminal to send a GBA bootstrapping request carrying a user identifier (e.g., IMPI or IMPU) to the BSF network element. Based on the user identifier, the BSF network element obtains an authentication vector (AV) corresponding to the user identifier from the HSS network element. The AV includes at least a random challenge (RAND), an authentication token (AUTN), an integrity key (IK), and a cipher key (CK). Based on the AV, the BSF network element generates a local session key (i.e., local Ks) and a second bootstrapping transaction identifier (i.e., second B-TID). The BSF network element also generates a verification network application function key (VAN) based on the local session key. The BSF network element uses the second bootstrapping transaction identifier as the verification bootstrapping transaction identifier, establishes a mapping between the VAN and the VAN bootstrapping transaction identifier and the user identifier, and stores the AV locally for subsequent verification of the legitimacy and validity of the target bootstrapping transaction identifier and the target network application function key. In this embodiment, the BSF network element sends the second bootstrapping transaction identifier, random number, and authentication token to the local physical terminal. The local physical terminal first verifies the legitimacy of the authentication token. If the legitimacy verification passes, it calculates a session key based on the SIM card key, random number, and authentication token in the SIM card, using the GBA algorithm. The second network application function key is then generated based on the calculated session key.
[0088] S402: Receive a second bootstrapping transaction identifier and a second network application function key sent by the local physical terminal, wherein the second network application function key is determined by the local physical terminal based on a SIM card key in the SIM card, a random number, and an authentication token.
[0089] Optionally, in this embodiment, when a secure connection is established between the cloud terminal and the local physical terminal via HTTPS (HyperText Transfer Protocol Secure) or TLS (Transport Layer Security), a GBA authentication result sent by the local physical terminal is received. The GBA authentication result includes the second bootstrapping transaction identifier and the second network application function key.
[0090] S403: Generate a registration request.
[0091] The target network application function key is the second network application function key, and / or the target bootstrapping transaction identifier is the second bootstrapping transaction identifier.
[0092] Optionally, in this embodiment, a registration request is generated based on the target network application function key and the target boot transaction identifier, and the registration request is sent to the message server.
[0093] In this embodiment, if the current usage duration does not exceed the valid duration, a second GBA authentication result acquisition request is sent to the local physical terminal. Based on the second GBA authentication result acquisition request, the local physical terminal sends a GBA bootstrapping request carrying a user identifier to the BSF network element. The BSF network element obtains the authentication vector corresponding to the user identifier from the HSS network element and generates a second bootstrapping transaction identifier based on the authentication vector. The authentication vector includes a random number and an authentication token. The BSF network element feeds back the random number, authentication token, and second bootstrapping transaction identifier to the local physical terminal. The local physical terminal obtains a second network application function key based on the SIM card key in the SIM card, the random number, and the authentication token. Upon receiving the second bootstrapping transaction identifier and second network application function key sent by the local physical terminal, and upon determining that the current reception duration of the second network application function key does not exceed the valid duration, the local physical terminal uses the second network application function key as the target network application function key and / or uses the second bootstrapping transaction identifier as the target bootstrapping transaction identifier. A registration request is generated based on the target bootstrapping transaction identifier and / or the target network application function key. This not only enhances the security of the authentication process but also ensures efficiency.
[0094] In one embodiment, Figure 5 This is a flow chart of a cloud terminal service registration method provided in accordance with an embodiment of the present application, in which the method is applied to Figure 1 Taking the local physical terminal in the example as an example, the method includes the following steps:
[0095] S501: Receive a first GBA authentication result acquisition request sent by a cloud terminal.
[0096] The first GBA authentication result acquisition request is the GBA authentication result acquisition request sent by the cloud terminal to the local physical terminal last time.
[0097] S502: Feedback the GBA authentication result to the cloud terminal.
[0098] Among them, the GBA authentication result is used to instruct the cloud terminal to obtain the target network application function key and / or target boot transaction identifier, generate a registration request based on the target network application function key and / or target boot transaction identifier, and send the registration request to the message server; the registration request is used to instruct the message server to authenticate the cloud terminal and, based on the authentication result, feedback a registration response message to the cloud terminal.
[0099] Optionally, in this embodiment, the GBA authentication result is used to instruct the cloud terminal to obtain a target network application function key and a target boot transaction identifier.
[0100] Optionally, in this embodiment, the GBA authentication result carries the first network application function key; the GBA authentication result is used to instruct the cloud terminal to obtain the current usage time and validity time of the first network application function key; and when the current usage time does not exceed the validity time, a registration request is generated based on the target network application function key and / or the target boot transaction identifier; wherein the current usage time refers to the time between the reception time of the target network application function key and the current time; the target network application function key is the first network application function key, and / or the target boot transaction identifier is the first boot transaction identifier.
[0101] Optionally, in this embodiment, when the current usage duration exceeds the valid duration, a cloud terminal service registration method includes receiving a second GBA authentication result acquisition request sent by the cloud terminal; wherein the second GBA authentication result acquisition request is sent by the cloud terminal when the current usage duration exceeds the valid duration. Sending a GBA bootstrapping request carrying a user identifier to a BSF network element; wherein the GBA bootstrapping request instructs the BSF network element to obtain an authentication vector corresponding to the user identifier from an HSS network element and generate a second bootstrapping transaction identifier based on the authentication vector; the authentication vector includes a random number and an authentication token. Receive the random number, authentication token, and second bootstrapping transaction identifier fed back by the BSF network element. Determine a second network application function key based on a SIM card key in the SIM card, the random number, and the authentication token. Feedback the second bootstrapping transaction identifier and / or the second network application function key to the cloud terminal, so that the cloud terminal uses the second bootstrapping transaction identifier as a target bootstrapping transaction identifier and / or the second network application function key as a target network application function key, and generates a registration request based on the target network application function key and / or the target bootstrapping transaction identifier. Specifically, the local physical terminal sends a GBA bootstrapping request carrying a user identifier (e.g., IMPI or IMPU) to the BSF network element. Based on the user identifier, the BSF network element obtains an authentication vector corresponding to the user identifier from the HSS network element. The authentication vector includes at least a random number, an authentication token, an integrity key, and an encryption key. Based on the authentication vector, the BSF network element generates a local session key (i.e., local Ks) and a second bootstrapping transaction identifier. The BSF network element also generates a verification network application function key based on the local session key. The BSF network element uses the second bootstrapping transaction identifier as the verification bootstrapping transaction identifier and maps the verification network application function key and the verification bootstrapping transaction identifier to the user identifier. The key is then stored locally for subsequent verification of the legitimacy and validity of the target bootstrapping transaction identifier and target network application function key. In this embodiment, the BSF network element sends the second bootstrapping transaction identifier, random number, and authentication token to the local physical terminal. The local physical terminal first verifies the legitimacy of the authentication token. If the legitimacy verification passes, a session key is calculated based on the SIM card key, random number, and authentication token in the SIM card, in conjunction with the GBA algorithm, and a second network application function key is generated based on the calculated session key. It should be noted that the specific implementation of the above-mentioned cloud terminal receiving the first GBA authentication result acquisition request sent by the cloud terminal and feeding back the GBA authentication result to the cloud terminal is similar to the specific implementation of receiving the second GBA authentication result acquisition request sent by the cloud terminal and feeding back the GBA authentication result to the cloud terminal in this embodiment, and will not be repeated here.
[0102] It should be noted that the process of the message server authenticating the cloud terminal is described in detail in the above embodiment and will not be repeated here.
[0103] In this embodiment, a first GBA authentication result acquisition request sent by the cloud terminal is received. The GBA authentication result is fed back to the cloud terminal. The GBA authentication result is used to instruct the cloud terminal to obtain the target network application function key and / or the target boot transaction identifier, generate a registration request based on the target network application function key and / or the target boot transaction identifier, and send the registration request to the message server; the registration request is used to instruct the message server to authenticate the cloud terminal, and based on the authentication result, feed back a registration response message to the cloud terminal. Based on this application, the GBA authentication result can be fed back to the cloud terminal, and the message server can authenticate the cloud terminal based on the GBA authentication result, thereby solving the problem of 5G message service registration faced when configuring the 5G message service on the cloud terminal, and providing a good technical foundation for the application of 5G message service on the cloud terminal.
[0104] In one embodiment, Figure 6 As shown, an optional implementation of a cloud terminal service registration method includes:
[0105] The cloud terminal obtains the current usage duration and validity duration of the first network application function key. The validity duration, the first network application function key, and the first bootstrapping transaction identifier are obtained from the GBA authentication result fed back by the local physical terminal when the cloud terminal sends a first GBA result acquisition request to the local physical terminal.
[0106] If the current usage duration does not exceed the validity duration, the cloud terminal uses the first network application function key as the target network application function key and the first bootstrap transaction identifier as the target bootstrap transaction identifier. The cloud terminal generates a registration request based on the target network application function key and the bootstrap transaction identifier and sends the registration request to the message server.
[0107] When the current usage duration exceeds the valid duration, the cloud terminal sends a second GBA authentication result acquisition request to the local physical terminal.
[0108] The local physical terminal sends a GBA bootstrapping request carrying the user identifier to the BSF network element. The GBA bootstrapping request instructs the BSF network element to obtain the authentication vector corresponding to the user identifier from the HSS network element, generate a second bootstrapping transaction identifier based on the authentication vector, which includes a random number and an authentication token, and feedback the random number, authentication token, and second bootstrapping transaction identifier to the local physical terminal.
[0109] The local physical terminal receives the random number, the authentication token, and the second boot transaction identifier.
[0110] The local physical terminal obtains the second network application function key based on the SIM card key in the SIM card, the random number and the authentication token.
[0111] The cloud terminal receives the second boot transaction identifier and the second network application function key sent by the local physical terminal.
[0112] The cloud terminal uses the second network application function key as the target network application function key and the second bootstrapping transaction identifier as the target bootstrapping transaction identifier; the cloud terminal generates a registration request based on the target network application function key and the bootstrapping transaction identifier; and sends the registration request to the message server.
[0113] The message server sends the target network application function key and the target boot transaction identifier to the BSF network element, so that the BSF network element authenticates the cloud terminal based on the target network application function key and the target boot transaction identifier, and feeds back the authentication result to the message server.
[0114] The message server generates a registration response message based on the authentication result.
[0115] The message server sends a registration response message to the cloud terminal.
[0116] The cloud terminal service registration method of this embodiment sends a registration request to the message server; wherein, the registration request carries at least a first network application function key and / or a first boot transaction identifier; the first network application function key and / or the first boot transaction identifier are obtained by the cloud terminal by sending a first general boot architecture GBA authentication result acquisition request to the local physical terminal; the registration request is used to instruct the message server to authenticate the cloud terminal based on the first network application function key and / or the first boot transaction identifier, and based on the authentication result, feedback a registration response message to the cloud terminal. Receive the registration response message sent by the message server. Based on this application, the message server can authenticate the cloud terminal, thereby solving the problem of 5G message service registration faced when configuring the 5G message service in the cloud terminal, and providing a good technical foundation for the application of 5G message service in the cloud terminal.
[0117] It should be understood that, although the steps in the flowcharts of the above embodiments are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the flowcharts of the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times. The execution order of these steps or stages is not necessarily to be performed in sequence, but can be performed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0118] Based on the same inventive concept, the embodiments of the present application also provide a cloud terminal service registration device for implementing the cloud terminal service registration method mentioned above. The implementation solution provided by this device is similar to the implementation solution described in the above method. Therefore, the specific limitations of one or more cloud terminal service registration device embodiments provided below can be found in the above limitations of the cloud terminal service registration method and will not be repeated here.
[0119] In one embodiment, by Figure 7 FIG. 1 shows a structural block diagram of a cloud terminal service registration device in an embodiment. Figure 7 As shown, a cloud terminal service registration device 1 is provided, which includes: a first sending module 11 and a second sending module 12, wherein:
[0120] A first sending module 11 is configured to send a registration request to a message server. The registration request carries at least a target network application function key and / or a target bootstrapping transaction identifier. The target network application function key and / or the target bootstrapping transaction identifier are obtained by the cloud terminal by sending a GBA authentication result acquisition request to the local physical terminal. The registration request instructs the message server to authenticate the cloud terminal based on the target network application function key and / or the target bootstrapping transaction identifier, and to feed back a registration response message to the cloud terminal based on the authentication result.
[0121] The second sending module 12 is configured to receive a registration response message sent by the message server.
[0122] In one embodiment, in one embodiment, the Figure 7 The first sending module is further specifically configured to:
[0123] Obtaining the current usage duration and validity duration of the first network application function key; wherein the current usage duration refers to the duration between the time when the target network application function key is received and the current time;
[0124] When the current usage duration does not exceed the valid duration, a registration request is sent to the message server; wherein, the target network application function key is the first network application function key, and / or the target boot transaction identifier is the first boot transaction identifier; the first network application function key and / or the first boot transaction identifier are obtained by the cloud terminal by sending a first GBA authentication result acquisition request to the local physical terminal.
[0125] In one embodiment, the Figure 7 The first sending module is further specifically configured to:
[0126] When the current usage duration exceeds the valid duration, a second GBA authentication result acquisition request is sent to the local physical terminal; wherein the second GBA authentication result acquisition request is used to instruct the local physical terminal to send a GBA bootstrapping request carrying the user identifier to the BSF network element; the GBA bootstrapping request is used to instruct the BSF network element to obtain the authentication vector corresponding to the user identifier through the HSS network element, generate a second bootstrapping transaction identifier based on the authentication vector, the authentication vector including a random number and an authentication token, and feedback the random number, authentication token, and second bootstrapping transaction identifier to the local physical terminal;
[0127] Receiving a second boot transaction identifier and a second network application function key sent by the local physical terminal; wherein the second network application function key is determined by the local physical terminal based on a SIM card key in the SIM card, a random number, and an authentication token;
[0128] Generate a registration request; wherein the target network application function key is the second network application function key, and / or the target boot transaction identifier is the second boot transaction identifier.
[0129] In one of the embodiments, the registration request is specifically used to instruct the message server to send the target network application function key and / or the target boot transaction identifier to the BSF network element, so that the BSF network element authenticates the cloud terminal based on the target network application function key and / or the target boot transaction identifier, and feeds back the authentication result to the message server.
[0130] In one embodiment, by Figure 8 FIG. 1 shows a structural block diagram of a cloud terminal service registration device in an embodiment. Figure 8 As shown, a cloud terminal service registration device 2 is provided, which includes: a first receiving module 21 and a third sending module 22, wherein:
[0131] The first receiving module 21 is configured to receive a first GBA authentication result acquisition request sent by the cloud terminal;
[0132] The third sending module 22 is used to feed back the GBA authentication result to the cloud terminal; wherein the GBA authentication result is used to instruct the cloud terminal to obtain the target network application function key and / or the target boot transaction identifier, generate a registration request based on the target network application function key and / or the target boot transaction identifier, and send the registration request to the message server; the registration request is used to instruct the message server to authenticate the cloud terminal and, based on the authentication result, feed back a registration response message to the cloud terminal.
[0133] In one embodiment, the GBA authentication result carries a first network application function key; the GBA authentication result is used to instruct the cloud terminal to obtain the current usage time and validity time of the first network application function key; and when the current usage time does not exceed the validity time, a registration request is generated based on the target network application function key and / or the target boot transaction identifier; wherein the current usage time refers to the time between the time when the target network application function key is received and the current time; the target network application function key is the first network application function key, and / or the target boot transaction identifier is the first boot transaction identifier.
[0134] In one embodiment, the Figure 8 A cloud terminal service registration device, further comprising:
[0135] A second receiving module is configured to receive a second GBA authentication result acquisition request sent by the cloud terminal; wherein the second GBA authentication result acquisition request is sent by the cloud terminal when the current usage duration exceeds the valid duration;
[0136] a fourth sending module, configured to send a GBA bootstrapping request carrying a user identifier to a BSF network element; wherein the GBA bootstrapping request is used to instruct the BSF network element to obtain an authentication vector corresponding to the user identifier through an HSS network element, and to generate a second bootstrapping transaction identifier based on the authentication vector; the authentication vector includes a random number and an authentication token;
[0137] The third receiving module is configured to receive the random number, the authentication token and the second boot transaction identifier fed back by the BSF network element;
[0138] A determination module, configured to determine a second network application function key based on a SIM card key in the SIM card, a random number, and an authentication token;
[0139] The fifth sending module is used to feed back the second boot transaction identifier and / or the second network application function key to the cloud terminal, so that the cloud terminal uses the second boot transaction identifier as the target boot transaction identifier and / or the second network application function key as the target network application function key, and generates a registration request based on the target network application function key and / or the target boot transaction identifier.
[0140] Each module in the aforementioned cloud terminal service registration device may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in the form of hardware, or may be stored in a memory in the computer device in the form of software, so that the processor can call and execute the corresponding operations of each module.
[0141] In one embodiment, a computer device is provided. The computer device may be a platform side, and its internal structure diagram may be as follows: Figure 9 As shown. The computer device includes a processor, a memory, and a network interface connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store cloud terminal service registration information. The network interface of the computer device is used to communicate with an external user side via a network connection. When the computer program is executed by the processor, a cloud terminal service registration method is implemented.
[0142] Those skilled in the art will understand that Figure 9 The structure shown in the figure is merely a block diagram of a portion of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. Specifically, the computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0143] In one embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the following steps are implemented:
[0144] Sending a registration request to a message server; wherein the registration request carries at least a target network application function key and / or a target bootstrap transaction identifier; the target network application function key and / or the target bootstrap transaction identifier are obtained by the cloud terminal by sending a GBA authentication result acquisition request to the local physical terminal; the registration request is used to instruct the message server to authenticate the cloud terminal based on the target network application function key and / or the target bootstrap transaction identifier, and to feed back a registration response message to the cloud terminal based on the authentication result;
[0145] Receive the registration response message sent by the message server.
[0146] In one embodiment, when the processor executes the computer program, the processor further implements the following steps: sending a registration request to the message server, including:
[0147] Obtaining the current usage duration and validity duration of the first network application function key; wherein the current usage duration refers to the duration between the time when the target network application function key is received and the current time;
[0148] When the current usage duration does not exceed the valid duration, a registration request is sent to the message server; wherein, the target network application function key is the first network application function key, and / or the target boot transaction identifier is the first boot transaction identifier; the first network application function key and / or the first boot transaction identifier are obtained by the cloud terminal by sending a first GBA authentication result acquisition request to the local physical terminal.
[0149] In one embodiment, when the processor executes the computer program, the processor further implements the following steps: sending a registration request to the message server, including:
[0150] When the current usage duration exceeds the valid duration, a second GBA authentication result acquisition request is sent to the local physical terminal; wherein the second GBA authentication result acquisition request is used to instruct the local physical terminal to send a GBA bootstrapping request carrying the user identifier to the BSF network element; the GBA bootstrapping request is used to instruct the BSF network element to obtain the authentication vector corresponding to the user identifier through the HSS network element, generate a second bootstrapping transaction identifier based on the authentication vector, the authentication vector including a random number and an authentication token, and feedback the random number, authentication token, and second bootstrapping transaction identifier to the local physical terminal;
[0151] Receiving a second boot transaction identifier and a second network application function key sent by the local physical terminal; wherein the second network application function key is determined by the local physical terminal based on a SIM card key in the SIM card, a random number, and an authentication token;
[0152] Generate a registration request; wherein the target network application function key is the second network application function key, and / or the target boot transaction identifier is the second boot transaction identifier.
[0153] In one embodiment, when the processor executes the computer program, the following steps are further implemented: the registration request is specifically used to instruct the message server to send the target network application function key and / or the target boot transaction identifier to the BSF network element, so that the BSF network element authenticates the cloud terminal based on the target network application function key and / or the target boot transaction identifier, and feeds back the authentication result to the message server.
[0154] In one embodiment, another computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the following steps are implemented:
[0155] Receiving a first GBA authentication result acquisition request sent by the cloud terminal;
[0156] Feedback the GBA authentication result to the cloud terminal; wherein the GBA authentication result is used to instruct the cloud terminal to obtain the target network application function key and / or target boot transaction identifier, generate a registration request based on the target network application function key and / or target boot transaction identifier, and send the registration request to the message server; the registration request is used to instruct the message server to authenticate the cloud terminal, and based on the authentication result, feedback a registration response message to the cloud terminal.
[0157] In one embodiment, when the processor executes the computer program, the following steps are further implemented: the GBA authentication result carries the first network application function key; the GBA authentication result is used to instruct the cloud terminal to obtain the current usage time and validity time of the first network application function key; and when the current usage time does not exceed the validity time, a registration request is generated based on the target network application function key and / or the target boot transaction identifier; wherein the current usage time refers to the time between the time when the target network application function key is received and the current time; the target network application function key is the first network application function key, and / or the target boot transaction identifier is the first boot transaction identifier.
[0158] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:
[0159] Receiving a second GBA authentication result acquisition request sent by the cloud terminal; wherein the second GBA authentication result acquisition request is sent by the cloud terminal when the current usage duration exceeds the valid duration;
[0160] Sending a GBA bootstrapping request carrying a user identifier to the BSF network element; wherein the GBA bootstrapping request is used to instruct the BSF network element to obtain an authentication vector corresponding to the user identifier through the HSS network element and generate a second bootstrapping transaction identifier based on the authentication vector; the authentication vector includes a random number and an authentication token;
[0161] Receive the random number, authentication token and second boot transaction identifier fed back by the BSF network element;
[0162] Determine a second network application function key based on a SIM card key in the SIM card, a random number, and an authentication token;
[0163] Feedback the second bootstrapping transaction identifier and / or the second network application function key to the cloud terminal, so that the cloud terminal uses the second bootstrapping transaction identifier as the target bootstrapping transaction identifier and / or the second network application function key as the target network application function key, and generates a registration request based on the target network application function key and / or the target bootstrapping transaction identifier.
[0164] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are performed:
[0165] Sending a registration request to a message server; wherein the registration request carries at least a target network application function key and / or a target bootstrap transaction identifier; the target network application function key and / or the target bootstrap transaction identifier are obtained by the cloud terminal by sending a GBA authentication result acquisition request to the local physical terminal; the registration request is used to instruct the message server to authenticate the cloud terminal based on the target network application function key and / or the target bootstrap transaction identifier, and to feed back a registration response message to the cloud terminal based on the authentication result;
[0166] Receive the registration response message sent by the message server.
[0167] In one embodiment, when the computer program is executed by the processor, the computer program further implements the following steps: sending a registration request to the message server, including:
[0168] Obtaining the current usage duration and validity duration of the first network application function key; wherein the current usage duration refers to the duration between the time when the target network application function key is received and the current time;
[0169] When the current usage duration does not exceed the valid duration, a registration request is sent to the message server; wherein, the target network application function key is the first network application function key, and / or the target boot transaction identifier is the first boot transaction identifier; the first network application function key and / or the first boot transaction identifier are obtained by the cloud terminal by sending a first GBA authentication result acquisition request to the local physical terminal.
[0170] In one embodiment, when the computer program is executed by the processor, the computer program further implements the following steps: sending a registration request to the message server, including:
[0171] When the current usage duration exceeds the valid duration, a second GBA authentication result acquisition request is sent to the local physical terminal; wherein the second GBA authentication result acquisition request is used to instruct the local physical terminal to send a GBA bootstrapping request carrying the user identifier to the BSF network element; the GBA bootstrapping request is used to instruct the BSF network element to obtain the authentication vector corresponding to the user identifier through the HSS network element, generate a second bootstrapping transaction identifier based on the authentication vector, the authentication vector including a random number and an authentication token, and feedback the random number, authentication token, and second bootstrapping transaction identifier to the local physical terminal;
[0172] Receiving a second boot transaction identifier and a second network application function key sent by the local physical terminal; wherein the second network application function key is determined by the local physical terminal based on a SIM card key in the SIM card, a random number, and an authentication token;
[0173] Generate a registration request; wherein the target network application function key is the second network application function key, and / or the target boot transaction identifier is the second boot transaction identifier.
[0174] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: the registration request is specifically used to instruct the message server to send the target network application function key and / or the target boot transaction identifier to the BSF network element, so that the BSF network element authenticates the cloud terminal based on the target network application function key and / or the target boot transaction identifier, and feeds back the authentication result to the message server.
[0175] In one embodiment, another computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are performed:
[0176] Receiving a first GBA authentication result acquisition request sent by the cloud terminal;
[0177] Feedback the GBA authentication result to the cloud terminal; wherein the GBA authentication result is used to instruct the cloud terminal to obtain the target network application function key and / or target boot transaction identifier, generate a registration request based on the target network application function key and / or target boot transaction identifier, and send the registration request to the message server; the registration request is used to instruct the message server to authenticate the cloud terminal, and based on the authentication result, feedback a registration response message to the cloud terminal.
[0178] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: the GBA authentication result carries the first network application function key; the GBA authentication result is used to instruct the cloud terminal to obtain the current usage time and validity time of the first network application function key; and when the current usage time does not exceed the validity time, a registration request is generated based on the target network application function key and / or the target boot transaction identifier; wherein the current usage time refers to the time between the time when the target network application function key is received and the current time; the target network application function key is the first network application function key, and / or the target boot transaction identifier is the first boot transaction identifier.
[0179] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0180] Receiving a second GBA authentication result acquisition request sent by the cloud terminal; wherein the second GBA authentication result acquisition request is sent by the cloud terminal when the current usage duration exceeds the valid duration;
[0181] Sending a GBA bootstrapping request carrying a user identifier to the BSF network element; wherein the GBA bootstrapping request is used to instruct the BSF network element to obtain an authentication vector corresponding to the user identifier through the HSS network element and generate a second bootstrapping transaction identifier based on the authentication vector; the authentication vector includes a random number and an authentication token;
[0182] Receive the random number, authentication token and second boot transaction identifier fed back by the BSF network element;
[0183] Determine a second network application function key based on a SIM card key in the SIM card, a random number, and an authentication token;
[0184] Feedback the second bootstrapping transaction identifier and / or the second network application function key to the cloud terminal, so that the cloud terminal uses the second bootstrapping transaction identifier as the target bootstrapping transaction identifier and / or the second network application function key as the target network application function key, and generates a registration request based on the target network application function key and / or the target bootstrapping transaction identifier.
[0185] In one embodiment, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the following steps:
[0186] Sending a registration request to a message server; wherein the registration request carries at least a target network application function key and / or a target bootstrap transaction identifier; the target network application function key and / or the target bootstrap transaction identifier are obtained by the cloud terminal by sending a GBA authentication result acquisition request to the local physical terminal; the registration request is used to instruct the message server to authenticate the cloud terminal based on the target network application function key and / or the target bootstrap transaction identifier, and to feed back a registration response message to the cloud terminal based on the authentication result;
[0187] Receive the registration response message sent by the message server.
[0188] In one embodiment, when the computer program is executed by the processor, the computer program further implements the following steps: sending a registration request to the message server, including:
[0189] Obtaining the current usage duration and validity duration of the first network application function key; wherein the current usage duration refers to the duration between the time when the target network application function key is received and the current time;
[0190] When the current usage duration does not exceed the valid duration, a registration request is sent to the message server; wherein, the target network application function key is the first network application function key, and / or the target boot transaction identifier is the first boot transaction identifier; the first network application function key and / or the first boot transaction identifier are obtained by the cloud terminal by sending a first GBA authentication result acquisition request to the local physical terminal.
[0191] In one embodiment, when the computer program is executed by the processor, the computer program further implements the following steps: sending a registration request to the message server, including:
[0192] When the current usage duration exceeds the valid duration, a second GBA authentication result acquisition request is sent to the local physical terminal; wherein the second GBA authentication result acquisition request is used to instruct the local physical terminal to send a GBA bootstrapping request carrying the user identifier to the BSF network element; the GBA bootstrapping request is used to instruct the BSF network element to obtain the authentication vector corresponding to the user identifier through the HSS network element, generate a second bootstrapping transaction identifier based on the authentication vector, the authentication vector including a random number and an authentication token, and feedback the random number, authentication token, and second bootstrapping transaction identifier to the local physical terminal;
[0193] Receiving a second boot transaction identifier and a second network application function key sent by the local physical terminal; wherein the second network application function key is determined by the local physical terminal based on a SIM card key in the SIM card, a random number, and an authentication token;
[0194] Generate a registration request; wherein the target network application function key is the second network application function key, and / or the target boot transaction identifier is the second boot transaction identifier.
[0195] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: the registration request is specifically used to instruct the message server to send the target network application function key and / or the target boot transaction identifier to the BSF network element, so that the BSF network element authenticates the cloud terminal based on the target network application function key and / or the target boot transaction identifier, and feeds back the authentication result to the message server.
[0196] In one embodiment, another computer program product is provided, comprising a computer program, which, when executed by a processor, implements the following steps:
[0197] Receiving a first GBA authentication result acquisition request sent by the cloud terminal;
[0198] Feedback the GBA authentication result to the cloud terminal; wherein the GBA authentication result is used to instruct the cloud terminal to obtain the target network application function key and / or target boot transaction identifier, generate a registration request based on the target network application function key and / or target boot transaction identifier, and send the registration request to the message server; the registration request is used to instruct the message server to authenticate the cloud terminal, and based on the authentication result, feedback a registration response message to the cloud terminal.
[0199] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: the GBA authentication result carries the first network application function key; the GBA authentication result is used to instruct the cloud terminal to obtain the current usage time and validity time of the first network application function key; and when the current usage time does not exceed the validity time, a registration request is generated based on the target network application function key and / or the target boot transaction identifier; wherein the current usage time refers to the time between the time when the target network application function key is received and the current time; the target network application function key is the first network application function key, and / or the target boot transaction identifier is the first boot transaction identifier.
[0200] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0201] Receiving a second GBA authentication result acquisition request sent by the cloud terminal; wherein the second GBA authentication result acquisition request is sent by the cloud terminal when the current usage duration exceeds the valid duration;
[0202] Sending a GBA bootstrapping request carrying a user identifier to the BSF network element; wherein the GBA bootstrapping request is used to instruct the BSF network element to obtain an authentication vector corresponding to the user identifier through the HSS network element and generate a second bootstrapping transaction identifier based on the authentication vector; the authentication vector includes a random number and an authentication token;
[0203] Receive the random number, authentication token and second boot transaction identifier fed back by the BSF network element;
[0204] Determine a second network application function key based on a SIM card key in the SIM card, a random number, and an authentication token;
[0205] Feedback the second bootstrapping transaction identifier and / or the second network application function key to the cloud terminal, so that the cloud terminal uses the second bootstrapping transaction identifier as the target bootstrapping transaction identifier and / or the second network application function key as the target network application function key, and generates a registration request based on the target network application function key and / or the target bootstrapping transaction identifier.
[0206] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), data processing logic devices based on quantum computing, and the like.
[0207] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0208] The above embodiments merely illustrate several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A cloud terminal service registration method, characterized in that: Applied to a cloud terminal, the method includes: Sending a registration request to a message server; wherein the registration request carries at least a target network application function key and / or a target bootstrapping transaction identifier; the target network application function key and / or the target bootstrapping transaction identifier are obtained by the cloud terminal by sending a Generic Bootstrapping Architecture (GBA) authentication result acquisition request to the local physical terminal; the registration request is used to instruct the message server to authenticate the cloud terminal based on the target network application function key and / or the target bootstrapping transaction identifier, and to feed back a registration response message to the cloud terminal based on the authentication result; Receive the registration response message sent by the message server.
2. The method according to claim 1, characterized in that The sending of a registration request to the message server includes: Obtaining the current usage duration and validity duration of the first network application function key; wherein the current usage duration refers to the duration between the time when the target network application function key is received and the current time; When the current usage duration does not exceed the valid duration, a registration request is sent to the message server; wherein the target network application function key is the first network application function key, and / or the target boot transaction identifier is the first boot transaction identifier; the first network application function key and / or the first boot transaction identifier are obtained by the cloud terminal by sending a first GBA authentication result acquisition request to the local physical terminal.
3. The method according to claim 2, characterized in that The sending of a registration request to the message server includes: When the current usage duration exceeds the valid duration, a second GBA authentication result acquisition request is sent to the local physical terminal; wherein the second GBA authentication result acquisition request is used to instruct the local physical terminal to send a GBA bootstrapping request carrying a user identifier to a bootstrapping service function (BSF) network element; the GBA bootstrapping request is used to instruct the BSF network element to obtain an authentication vector corresponding to the user identifier through a home subscriber server (HSS) network element, generate a second bootstrapping transaction identifier based on the authentication vector, the authentication vector including a random number and an authentication token, and feedback the random number, authentication token, and the second bootstrapping transaction identifier to the local physical terminal; Receiving the second boot transaction identifier and the second network application function key sent by the local physical terminal; wherein the second network application function key is determined by the local physical terminal based on the SIM card key in the user identification card SIM card, the random number and the authentication token; Generate a registration request; wherein the target network application function key is the second network application function key, and / or the target boot transaction identifier is the second boot transaction identifier.
4. The method according to claim 1, wherein The registration request is specifically used to instruct the message server to send the target network application function key and / or target boot transaction identifier to the BSF network element, so that the BSF network element authenticates the cloud terminal based on the target network application function key and / or target boot transaction identifier, and feeds back the authentication result to the message server.
5. A cloud terminal service registration method, characterized in that: Applied to a local physical terminal, the method includes: Receiving a first GBA authentication result acquisition request sent by the cloud terminal; Feedback a GBA authentication result to the cloud terminal; wherein the GBA authentication result is used to instruct the cloud terminal to obtain a target network application function key and / or a target boot transaction identifier, generate a registration request based on the target network application function key and / or the target boot transaction identifier, and send the registration request to the message server; the registration request is used to instruct the message server to authenticate the cloud terminal, and based on the authentication result, feedback a registration response message to the cloud terminal.
6. The method according to claim 5, characterized in that The GBA authentication result carries the first network application function key; the GBA authentication result is used to instruct the cloud terminal to obtain the current usage duration and validity duration of the first network application function key; and generating a registration request based on the target network application function key and / or the target boot transaction identifier if the current usage duration does not exceed the validity duration; wherein the current usage duration refers to the duration between the time when the target network application function key is received and the current time; The target network application function key is a first network application function key, and / or the target bootstrapping transaction identifier is a first bootstrapping transaction identifier.
7. The method according to claim 6, characterized in that The method further comprises: Receiving a second GBA authentication result acquisition request sent by the cloud terminal; wherein the second GBA authentication result acquisition request is sent by the cloud terminal when the current usage duration exceeds the valid duration; Sending a GBA bootstrapping request carrying a user identifier to a BSF network element; wherein the GBA bootstrapping request is used to instruct the BSF network element to obtain an authentication vector corresponding to the user identifier through an HSS network element, and generate a second bootstrapping transaction identifier based on the authentication vector; the authentication vector includes a random number and an authentication token; receiving a random number, an authentication token, and a second bootstrapping transaction identifier fed back by the BSF network element; Determine a second network application function key based on a SIM card key in the SIM card, the random number, and the authentication token; The second bootstrapping transaction identifier and / or the second network application function key are fed back to the cloud terminal, so that the cloud terminal uses the second bootstrapping transaction identifier as a target bootstrapping transaction identifier and / or the second network application function key as a target network application function key, and generates a registration request based on the target network application function key and / or the target bootstrapping transaction identifier.
8. A cloud terminal service registration device, characterized in that: Configured in a cloud terminal, the device includes: A first sending module is configured to send a registration request to a message server; wherein the registration request carries at least a target network application function key and / or a target bootstrapping transaction identifier; the target network application function key and / or the target bootstrapping transaction identifier are obtained by the cloud terminal by sending a Generic Bootstrapping Architecture (GBA) authentication result acquisition request to the local physical terminal; the registration request is configured to instruct the message server to authenticate the cloud terminal based on the target network application function key and / or the target bootstrapping transaction identifier, and to feed back a registration response message to the cloud terminal based on the authentication result; The second sending module is used to receive the registration response message sent by the message server.
9. A cloud terminal service registration device, characterized in that: Configured at a local physical terminal, the device includes: A first receiving module is configured to receive a first GBA authentication result acquisition request sent by a cloud terminal; A third sending module is configured to feed back a GBA authentication result to the cloud terminal; wherein the GBA authentication result is used to instruct the cloud terminal to obtain a target network application function key and / or a target boot transaction identifier, generate a registration request based on the target network application function key and / or the target boot transaction identifier, and send the registration request to the message server; the registration request is used to instruct the message server to authenticate the cloud terminal, and based on the authentication result, feed back a registration response message to the cloud terminal.
10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
12. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.