File downloading method and device

By performing GBA authentication and building a whitelist on the 5G message network side, the security risks of file downloads in the 5G message system are resolved, further authentication of the file request end is achieved, and the security and confidentiality of file downloads are improved.

CN120730286AActive Publication Date: 2025-09-30CHINA MOBILE GROUP DESIGN INST +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202410360792.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-27
Publication Date
2025-09-30
Estimated Expiration
2044-03-27

AI Technical Summary

Technical Problem

In the existing 5G messaging system, the file download method has the security risk of third-party users using cracking tools to grab the download link and download the file, which cannot effectively guarantee the security of file downloads.

Method used

After receiving the file download request on the 5G message network side, GBA authentication is performed, and the MSISDN number of the called user is extracted through the 5G message center to build a whitelist list. The download service is only provided to the target terminals included in the whitelist to achieve further user authentication and authority confirmation.

Benefits of technology

By building a whitelist and GBA authentication, the file download request end is ensured to be the called user terminal, which improves the security and confidentiality of the 5G message file download service and enhances the service security level.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120730286A_ABST
    Figure CN120730286A_ABST
Patent Text Reader

Abstract

The invention provides a file downloading method and device, and the method comprises the steps: receiving a file downloading request of a target terminal, and carrying out the GBA authentication of a request user corresponding to the file downloading request; under the condition that the GBA authentication is passed, obtaining a mobile subscriber identification number MSISDN number of the target terminal; and under the condition that the white list comprises the MSISDN number of the target terminal, providing a downloading service corresponding to the file downloading request for the target terminal. According to the file downloading method and device provided by the invention, the target terminal for requesting the file is determined as the called terminal for receiving the file transmission message by confirming the downloading permission of the user when the file downloading service is provided, so that the further authentication process of the file requesting terminal is realized; the confidentiality of the 5G message file downloading business service is fully guaranteed, and the business security level is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a file downloading method and device. Background Art

[0002] The 5G message system can provide users with 5G message business services including media files. When a user receives a message and applies to download the message body file, the 5G message network side performs Generic Bootstrapping Architecture (GBA) authentication on the applicant. All users of this (operator) network can pass the GBA authentication process and download the file.

[0003] With existing file download methods, although the file download link contained in the message body of 5G messages is not presented to users, the download link data can be extracted from the terminal side through professional cracking tools. However, there is a security risk that third-party users can grab the link and download files from the 5G message system network side. Summary of the Invention

[0004] The present invention provides a file downloading method and device to improve the security of the file downloading process in the 5G messaging system.

[0005] The present invention provides a file download method, which is applied to the 5G message network side, comprising:

[0006] Receive a file download request from a target terminal, and perform General Bootstrapping Architecture (GBA) authentication on a requesting user corresponding to the file download request;

[0007] If the GBA authentication is passed, obtaining the mobile user identification code MSISDN number of the target terminal, and determining whether the MSISDN number of the target terminal is included in the whitelist, wherein the whitelist is determined based on the MSISDN number of the called user, and the MSISDN number of the called user is extracted from the file transfer message sent by the calling user terminal to the called user terminal when forwarding the file transfer message based on the message center 5GMC on the 5G message network side;

[0008] In a case where the whitelist includes the MSISDN number of the target terminal, the download service corresponding to the file download request is provided to the target terminal.

[0009] According to a file download method provided by the present invention, a process of constructing a whitelist includes:

[0010] Based on the 5GMC on the 5G message network side, when forwarding the file transfer message sent by the calling user terminal to the called user terminal, copy the file transfer message to the file server on the 5G message network side;

[0011] The file server extracts the MSISDN number of the called user terminal based on the file transfer message, and constructs the whitelist based on the MSISDN number of the called user terminal.

[0012] According to a file downloading method provided by the present invention, the whitelist is constructed based on the MSISDN number of the called user terminal, including:

[0013] Associating the MSISDN number of the called user with the message digest of the file to be transferred corresponding to the file transfer message to obtain association information;

[0014] Based on the association information, the whitelist is constructed.

[0015] According to a file download method provided by the present invention, determining whether the whitelist includes the MSISDN number of the target terminal further includes:

[0016] The MSISDN number of the target terminal is matched with the MSISDN number in the associated information in the white list. If the match is successful, it is determined whether the white list contains the MSISDN number of the target terminal.

[0017] According to a file downloading method provided by the present invention, after determining whether the whitelist includes the MSISDN number of the target terminal, the method further includes:

[0018] In a case where the whitelist does not include the MSISDN number of the target terminal, the download service corresponding to the file download request is refused to be provided to the target terminal.

[0019] According to a file downloading method provided by the present invention, when the GBA authentication is passed, obtaining the MSISDN number of the target terminal includes:

[0020] Based on the file server, the MSISDN number corresponding to the service transaction identifier B-TID reported by the target terminal is extracted from the cache to obtain the MSISDN number of the target terminal.

[0021] The present invention also provides a file downloading device, which is applied to the 5G message network side, comprising:

[0022] an authentication module, configured to receive a file download request from a target terminal and perform a General Bootstrapping Architecture (GBA) authentication on a requesting user corresponding to the file download request;

[0023] a comparison module, configured to, if the GBA authentication is passed, obtain the mobile subscriber identification code (MSISDN) number of the target terminal, and determine whether the MSISDN number of the target terminal is included in a whitelist, wherein the whitelist is determined based on the MSISDN number of the called user, and the MSISDN number of the called user is extracted from the file transfer message sent by the calling user terminal to the called user terminal when forwarding the file transfer message based on the message center 5GMC on the 5G message network side;

[0024] The authorization module is configured to provide the target terminal with a download service corresponding to the file download request when the whitelist includes the MSISDN number of the target terminal.

[0025] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements any of the above-described file downloading methods when executing the computer program.

[0026] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements any of the above-mentioned file downloading methods.

[0027] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements any of the above-mentioned file downloading methods.

[0028] The file download method and device provided by the present invention, after receiving the file transfer message at the message center 5GMC on the 5G message network side, extract the MSISDN number of the called user from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal, build a whitelist list for file download, confirm the user download authority when providing file download service, determine that the target terminal for the file request is the called terminal that receives the file transfer message, realize further authentication process of the file request end, fully protect the confidentiality of the 5G message file download service, and improve the service security level. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly described below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0030] Figure 1 It is a schematic diagram of the file download process of GBA authentication of the related method;

[0031] Figure 2 It is a flowchart of the file downloading method provided by the present invention;

[0032] Figure 3 This is a schematic diagram of the whitelist construction process provided by the present invention;

[0033] Figure 4 This is a flow chart of the file downloading method provided by the present invention;

[0034] Figure 5 It is a structural diagram of the file downloading device provided by the present invention;

[0035] Figure 6 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0036] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0037] Mobile networks can provide users with 5G messaging services that include media files. Users first receive a message file link and download the file according to the link. When the user applies for downloading, the 5G messaging network only performs GBA authentication on the user. This process cannot guarantee that the applicant user is the called user.

[0038] The file downloading business process including GBA authentication in the related method is as follows Figure 1As shown in the flowchart of the GBA-authenticated file download process of the related method, the 5G message system can provide users with 5G message business services including media files. When the user receives a message and applies for downloading the file corresponding to the message body, the 5G message network performs GBA authentication on the applicant. The GBA authentication process may include: the 5G message user (called user) communicates with the bootstrapping server function (BSF) and returns authentication data. The 5G message user initiates GBA authentication on the application server (AS) side to the file server. After completing the GBA authentication on the AS side, the 5G message user carries the authentication data and initiates a download request to the file server. After receiving the authentication data and the download request, the file server provides download services to the 5G message user.

[0039] Although the file download link contained within the 5G message body is not displayed to the user, it can be extracted from the terminal using specialized cracking tools. However, in certain business scenarios with high security requirements, there is a security risk that a third party could steal the link and download the file from the 5G messaging system network.

[0040] Aiming at the defects in the related methods, the present invention provides a file downloading method. Figure 2 This is a flow chart of the file downloading method provided by the present invention. Figure 2 , the file downloading method provided by the present invention may include:

[0041] Step 210: Receive a file download request from a target terminal and perform Generic Bootstrapping Architecture (GBA) authentication on a requesting user corresponding to the file download request.

[0042] Step 220: If the GBA authentication passes, obtain the mobile user identification code (MSISDN) number of the target terminal, and determine whether the MSISDN number of the target terminal is included in the whitelist. The whitelist is determined based on the MSISDN number of the called user. The MSISDN number of the called user is extracted from the file transfer message sent by the calling user terminal to the called user terminal when forwarding the file transfer message based on the message center 5GMC on the 5G message network side.

[0043] Step 230: When the whitelist includes the MSISDN number of the target terminal, provide the target terminal with a download service corresponding to the file download request.

[0044] The file download method provided by the present invention can be executed by the 5G messaging network side. The 5G messaging network side is used to support SMS, multimedia messaging and other data transmission between devices, and generally includes the following components and functions:

[0045] Message delivery agent: As part of the core network, the message delivery agent is responsible for control plane signaling transmission, processing message delivery and other functions;

[0046] User plane function: responsible for processing data transmission and message exchange between devices;

[0047] Session management function: responsible for session management, including message routing and forwarding;

[0048] Application Server (AS): AS may serve as an application server for message services, responsible for message processing, forwarding, and storage;

[0049] Identity authentication and security functions: The message network side also involves identity authentication, security policies, encryption and decryption functions to ensure the security and reliability of messages.

[0050] The following takes the file download method provided by the present invention executed on the 5G message network side as an example to explain the technical solution of the present invention in detail.

[0051] In step 210, a file download request from a target terminal is received, and a Generic Bootstrapping Architecture (GBA) authentication is performed on a requesting user corresponding to the file download request.

[0052] Before the target terminal sends a file download request to the 5G message network side, the calling user terminal sends a file transfer message to the called user terminal. After receiving the file transfer message, the called user terminal clicks on the file transfer message to obtain the file to be downloaded from the file server on the 5G message network side.

[0053] The process for the called user terminal to obtain files in the relevant method is as follows: the called user terminal sends a file download request to the 5G messaging network. The 5G messaging network receives the file download request from the called user terminal and performs GBA authentication on the requesting user corresponding to the file download request. After the GBA authentication is completed, the file download server is opened to the called user terminal.

[0054] It is understandable that for the implementation process of the relevant method, if the called user terminal forwards the file transfer message to other terminals, or other terminals obtain the file transfer message of the called user terminal through illegal means, other terminals can download the file based on the file transfer message of the called user terminal, which poses a security risk.

[0055] The target terminal in the embodiment of the present invention is any terminal that may download a file, and may be the called user terminal mentioned above, or other terminals.

[0056] The target terminal sends a file download request to the 5G message network based on the file transfer message. This can be based on the user corresponding to the target terminal clicking on the file transfer message to trigger a file download request to the 5G message network.

[0057] The 5G message network side receives the file download request from the target terminal and performs GBA authentication on the requesting user corresponding to the file download request.

[0058] In step 220, if the GBA authentication is passed, the mobile user identification code MSISDN number of the target terminal is obtained, and it is determined whether the white list contains the MSISDN number of the target terminal. The white list is determined based on the MSISDN number of the called user. The MSISDN number of the called user is based on the message center 5GMC on the 5G message network side, and is extracted from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal.

[0059] If the GBA authentication is passed, further authentication process is performed, including:

[0060] The MSISDN number of the target terminal on the 5G messaging network side. The MSISDN number is a globally unique identification number for mobile phone users, commonly used to identify and locate mobile phone users. The MSISDN number usually consists of a country code, area code (if any), and user number. It is a numeric string containing an international telephone number.

[0061] After obtaining the MSISDN number of the target terminal, it is determined based on the MSISDN number of the target terminal whether the whitelist includes the MSISDN number of the target terminal.

[0062] Among them, the whitelist is determined based on the MSISDN number of the called user. The calling user terminal sends a file transfer message to the called user terminal based on the 5G message network side. After the message center 5GMC on the 5G message network side receives the file transfer message, when forwarding the file transfer message sent by the calling user terminal to the called user terminal, it extracts the MSISDN number of the called user from the file transfer message to obtain the MSISDN number of the called user. The MSISDN number of the called user terminal is added to the whitelist to obtain a whitelist. It can be understood that the called user terminal can be one or more, so the obtained MSISDN number can be one or more, and the constructed whitelist may contain one or more MSISDN numbers.

[0063] In step 230, when the whitelist includes the MSISDN number of the target terminal, the download service corresponding to the file download request is provided to the target terminal.

[0064] If GBA authentication is successful, the target terminal's mobile user identification code (MSISDN) is obtained. If the target terminal's MSISDN number is included in the whitelist, the target terminal can be determined to be the called terminal receiving the file transfer message, completing the further authentication process of the target terminal. At this point, the 5G message network can provide the target terminal with the download service corresponding to the file download request.

[0065] The file download method provided by the embodiment of the present invention, after receiving the file transfer message at the message center 5GMC on the 5G message network side, extracts the MSISDN number of the called user from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal, constructs a whitelist list for file download, confirms the user download authority when providing file download service, determines that the target terminal for the file request is the called terminal that receives the file transfer message, realizes a further authentication process of the file requesting end, fully guarantees the confidentiality of the 5G message file download service, and improves the service security level.

[0066] In one embodiment, the process of constructing a whitelist includes: based on the 5GMC on the 5G message network side, when forwarding a file transfer message sent by the calling user terminal to the called user terminal, copying the file transfer message to the file server on the 5G message network side; the file server extracts the MSISDN number of the called user terminal based on the file transfer message, and constructs the whitelist based on the MSISDN number of the called user terminal.

[0067] The whitelist construction process diagram is as follows Figure 3 The whitelist construction process provided by the present invention is shown in the following diagram. When the calling user terminal sends a file transfer message to the called user terminal, the 5GMC is responsible for receiving and processing these messages. While forwarding the file transfer message to the called user terminal, the 5GMC also copies these messages to the file server.

[0068] After receiving the copied file transfer message, the file server will parse the message content and extract the MSISDN number information of the called user terminal contained therein.

[0069] Based on the information in the file transfer message, the file server extracts the MSISDN number of the called user terminal. This number is a globally unique identification code used to uniquely identify the called user terminal.

[0070] The file server uses the extracted MSISDN number of the called user terminal to add it to the whitelist, thereby constructing a whitelist.

[0071] The file download method provided by the embodiment of the present invention, after receiving the copied file transfer message through the file server, will parse the message content, extract the MSISDN number information of the called user terminal contained therein and build a whitelist list, providing a basis for subsequent further authentication of the file requesting end.

[0072] In one embodiment, the whitelist is constructed based on the MSISDN number of the called user terminal, including: associating the MSISDN number of the called user with the message digest of the corresponding file to be transferred in the file transfer message to obtain association information; and constructing the whitelist based on the association information.

[0073] When processing a file transfer message, the file server can associate the called user's MSISDN with the message digest of the transferred file. A message digest is a short representation of a file, typically generated using a hash algorithm, and is used to verify the integrity and uniqueness of the file.

[0074] By associating the MSISDN number with the message digest, the file server obtains a correlation information table that records the MSISDN number of each called user terminal and the message digest of the corresponding file. The file server can then construct a whitelist based on this correlation information table.

[0075] In one embodiment, determining whether the whitelist includes the MSISDN number of the target terminal further includes: matching the MSISDN number of the target terminal with the MSISDN number in the associated information in the whitelist, and if the match is successful, determining whether the whitelist includes the MSISDN number of the target terminal.

[0076] The target terminal's MSISDN number is matched with the MSISDN number in the association information in the whitelist. This can be achieved by checking whether the target terminal's MSISDN number exists in the association information. If a match is successful, it can be determined whether the target terminal's MSISDN number is included in the whitelist.

[0077] The most straightforward matching method is exact matching, which directly compares the target terminal's MSISDN number with each MSISDN number in the whitelist. If an exact match is found, the target terminal's MSISDN number is confirmed to be on the whitelist. Regular expressions can also be used to more flexibly match MSISDN numbers that meet specific criteria. By defining matching rules, you can quickly filter out eligible MSISDN numbers and determine whether they include the target terminal's number.

[0078] In one embodiment, after determining whether the whitelist includes the MSISDN number of the target terminal, the method further includes: refusing to provide the target terminal with the download service corresponding to the file download request if the whitelist does not include the MSISDN number of the target terminal.

[0079] It is understandable that, when the white list does not include the MSISDN number of the target terminal, it can be determined that the target terminal is not the called user terminal. At this time, if the file download service is opened, there may be a security risk.

[0080] Therefore, when it is determined that the target terminal is not the called user terminal, the download service corresponding to the file download request is refused to be provided to the target terminal.

[0081] In one embodiment, when the GBA authentication is passed, obtaining the MSISDN number of the target terminal includes: extracting the MSISDN number corresponding to the B-TID reported by the target terminal from a cache based on a file server to obtain the MSISDN number of the target terminal.

[0082] Based on the B-TID reported by the target terminal, a query operation is performed in the cache to find the MSISDN number corresponding to the B-TID. Once the MSISDN number corresponding to the target B-TID is found, the information of the number can be extracted from the cache of the file server.

[0083] Specifically, in the GBA process, the BSF sends a BIA message to the file server, including IMPI, IMPU, Ks_NAF, usslist, keyExpiryTime, bootstrappingInfo Creation Time, and uiccKeyMaterial. The file server extracts the user's MSISDN from the IMPU and generates a set of data corresponding to the B-TID reported by the user, and puts it into the local cache of the file server. The cache time can be set, but should not be greater than the validity period of the GBA authentication.

[0084] The following is a flowchart of a file download method provided by the present invention as an example to illustrate the technical solution provided by the present invention:

[0085] like Figure 4 As shown, the specific process includes:

[0086] The terminal corresponding to the 5G message user (called user) communicates with the bootstrapping server function (BSF) and returns authentication data. The 5G message user initiates GBA authentication on the AS side to the file server. After completing GBA authentication on the AS side, the B-TID and MSISDN number are associated and cached.

[0087] When the called user terminal initiates a file download request, the MSISDN number is extracted from the cache, and the extracted MSISDN number is compared with the MSISDN numbers in the white list to determine whether the extracted MSISDN number is in the white list.

[0088] If it is determined that the extracted MSISDN number is in the whitelist, the download service is provided; if it is determined that the extracted MSISDN number is not in the whitelist, the download service is refused.

[0089] Figure 5 It is a structural diagram of the file downloading device provided by the present invention. Figure 5 The device comprises:

[0090] The authentication module 510 is configured to receive a file download request from a target terminal and perform a Generic Bootstrapping Architecture (GBA) authentication on a requesting user corresponding to the file download request.

[0091] a comparison module 520, configured to, if the GBA authentication passes, obtain the mobile subscriber identification code (MSISDN) number of the target terminal and determine whether the MSISDN number of the target terminal is included in a whitelist, wherein the whitelist is determined based on the MSISDN number of the called user, and the MSISDN number of the called user is extracted from the file transfer message sent by the calling user terminal to the called user terminal when forwarding the file transfer message based on the message center 5GMC on the 5G messaging network side;

[0092] The authorization module 530 is configured to provide the target terminal with a download service corresponding to the file download request when the whitelist includes the MSISDN number of the target terminal.

[0093] The file download device provided by the embodiment of the present invention receives the file transfer message at the message center 5GMC on the 5G message network side, and then extracts the MSISDN number of the called user from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal, builds a whitelist list for file download, confirms the user's download authority when providing file download service, and determines that the target terminal for the file request is the called terminal that receives the file transfer message, thereby realizing a further authentication process for the file requesting end, fully ensuring the confidentiality of the 5G message file download service, and improving the service security level.

[0094] In one embodiment, the comparison module 520 is specifically configured to:

[0095] The process of building a whitelist includes:

[0096] Based on the 5GMC on the 5G message network side, when forwarding the file transfer message sent by the calling user terminal to the called user terminal, copy the file transfer message to the file server on the 5G message network side;

[0097] The file server extracts the MSISDN number of the called user terminal based on the file transfer message, and constructs the whitelist based on the MSISDN number of the called user terminal.

[0098] In one embodiment, the comparison module 520 is further configured to:

[0099] Constructing the whitelist based on the MSISDN number of the called user terminal includes:

[0100] Associating the MSISDN number of the called user with the message digest of the file to be transferred corresponding to the file transfer message to obtain association information;

[0101] Based on the association information, the whitelist is constructed.

[0102] In one embodiment, the comparison module 520 is further configured to:

[0103] Determining whether the whitelist includes the MSISDN number of the target terminal further includes:

[0104] The MSISDN number of the target terminal is matched with the MSISDN number in the associated information in the white list. If the match is successful, it is determined whether the white list contains the MSISDN number of the target terminal.

[0105] In one embodiment, the authorization module 530 is specifically configured to:

[0106] After determining whether the whitelist includes the MSISDN number of the target terminal, the method further includes:

[0107] In a case where the whitelist does not include the MSISDN number of the target terminal, the download service corresponding to the file download request is refused to be provided to the target terminal.

[0108] In one embodiment, the comparison module 520 is further configured to:

[0109] If the GBA authentication is successful, obtaining the MSISDN number of the target terminal includes:

[0110] Based on the file server, the MSISDN number corresponding to the service transaction identifier B-TID reported by the target terminal is extracted from the cache to obtain the MSISDN number of the target terminal.

[0111] Figure 6 An example of a physical structure diagram of an electronic device is shown below. Figure 6 As shown, the electronic device may include: a processor 610, a communication interface 620, a memory 630, and a communication bus 640, wherein the processor 610, the communication interface 620, and the memory 630 communicate with each other via the communication bus 640. The processor 610 may call the logic instructions in the memory 630 to execute the file downloading method, which includes:

[0112] Receive a file download request from a target terminal, and perform General Bootstrapping Architecture (GBA) authentication on a requesting user corresponding to the file download request;

[0113] If the GBA authentication is passed, obtaining the mobile user identification code MSISDN number of the target terminal, and determining whether the MSISDN number of the target terminal is included in the whitelist, wherein the whitelist is determined based on the MSISDN number of the called user, and the MSISDN number of the called user is extracted from the file transfer message sent by the calling user terminal to the called user terminal when forwarding the file transfer message based on the message center 5GMC on the 5G message network side;

[0114] In a case where the whitelist includes the MSISDN number of the target terminal, the download service corresponding to the file download request is provided to the target terminal.

[0115] In addition, the logic instructions in the above-mentioned memory 630 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0116] On the other hand, the present invention further provides a computer program product, comprising a computer program stored on a non-transitory computer-readable storage medium, wherein the computer program comprises program instructions. When the program instructions are executed by a computer, the computer is capable of performing the file downloading method provided by each of the above methods, the method comprising:

[0117] Receive a file download request from a target terminal, and perform General Bootstrapping Architecture (GBA) authentication on a requesting user corresponding to the file download request;

[0118] If the GBA authentication is passed, obtaining the mobile user identification code MSISDN number of the target terminal, and determining whether the MSISDN number of the target terminal is included in the whitelist, wherein the whitelist is determined based on the MSISDN number of the called user, and the MSISDN number of the called user is extracted from the file transfer message sent by the calling user terminal to the called user terminal when forwarding the file transfer message based on the message center 5GMC on the 5G message network side;

[0119] In a case where the whitelist includes the MSISDN number of the target terminal, the download service corresponding to the file download request is provided to the target terminal.

[0120] In another aspect, the present invention further provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform the above-mentioned file downloading method, the method comprising:

[0121] Receive a file download request from a target terminal, and perform General Bootstrapping Architecture (GBA) authentication on a requesting user corresponding to the file download request;

[0122] If the GBA authentication is passed, obtaining the mobile user identification code MSISDN number of the target terminal, and determining whether the MSISDN number of the target terminal is included in the whitelist, wherein the whitelist is determined based on the MSISDN number of the called user, and the MSISDN number of the called user is extracted from the file transfer message sent by the calling user terminal to the called user terminal when forwarding the file transfer message based on the message center 5GMC on the 5G message network side;

[0123] In a case where the whitelist includes the MSISDN number of the target terminal, the download service corresponding to the file download request is provided to the target terminal.

[0124] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0125] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, or of course, by hardware. Based on this understanding, the essence of the above technical solution or the part that contributes to the existing technology can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiments.

[0126] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A file downloading method, characterized in that: Applied to the 5G messaging network side, the method includes: Receive a file download request from a target terminal, and perform General Bootstrapping Architecture (GBA) authentication on a requesting user corresponding to the file download request; If the GBA authentication is passed, obtaining the mobile user identification code MSISDN number of the target terminal, and determining whether the MSISDN number of the target terminal is included in the whitelist, wherein the whitelist is determined based on the MSISDN number of the called user, and the MSISDN number of the called user is extracted from the file transfer message sent by the calling user terminal to the called user terminal when forwarding the file transfer message based on the message center 5GMC on the 5G message network side; In a case where the whitelist includes the MSISDN number of the target terminal, the download service corresponding to the file download request is provided to the target terminal.

2. The file downloading method according to claim 1, wherein: The process of building the whitelist includes: Based on the 5GMC on the 5G message network side, when forwarding the file transfer message sent by the calling user terminal to the called user terminal, copy the file transfer message to the file server on the 5G message network side; The file server extracts the MSISDN number of the called user terminal based on the file transfer message, and constructs the whitelist based on the MSISDN number of the called user terminal.

3. The file downloading method according to claim 2, wherein: The step of constructing the whitelist based on the MSISDN number of the called user terminal includes: Associating the MSISDN number of the called user with the message digest of the file to be transferred corresponding to the file transfer message to obtain association information; Based on the association information, the whitelist is constructed.

4. The file downloading method according to claim 3, wherein: The determining whether the whitelist includes the MSISDN number of the target terminal further includes: The MSISDN number of the target terminal is matched with the MSISDN number in the associated information in the white list. If the match is successful, it is determined whether the white list contains the MSISDN number of the target terminal.

5. The file downloading method according to claim 1, wherein: After determining whether the whitelist contains the MSISDN number of the target terminal, the method further includes: In a case where the whitelist does not include the MSISDN number of the target terminal, the download service corresponding to the file download request is refused to be provided to the target terminal.

6. The file downloading method according to claim 1, wherein: When the GBA authentication is passed, obtaining the MSISDN number of the target terminal includes: Based on the file server, the MSISDN number corresponding to the service transaction identifier B-TID reported by the target terminal is extracted from the cache to obtain the MSISDN number of the target terminal.

7. A file downloading device, characterized in that: Applied to the 5G messaging network side, including: An authentication module, configured to receive a file download request from a target terminal and perform a General Bootstrapping Architecture (GBA) authentication on a requesting user corresponding to the file download request; a comparison module, configured to, if the GBA authentication is passed, obtain the mobile subscriber identification code (MSISDN) number of the target terminal, and determine whether the MSISDN number of the target terminal is included in a whitelist, wherein the whitelist is determined based on the MSISDN number of the called user, and the MSISDN number of the called user is extracted from the file transfer message sent by the calling user terminal to the called user terminal when forwarding the file transfer message based on the message center 5GMC on the 5G message network side; The authorization module is configured to provide the target terminal with a download service corresponding to the file download request when the whitelist includes the MSISDN number of the target terminal.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the file downloading method according to any one of claims 1 to 6 is implemented.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the file downloading method according to any one of claims 1 to 6 is implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the file downloading method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • File transfer method and server

    CN104202411A

  • Identity authentication method, device and equipment and computer readable storage medium

    CN113542193A

  • Application login method and device based on 5G message, equipment and storage medium

    CN115884181A

  • Providing Data File Updates Using Multimedia Broadcast Multicast Services

    US20180359612A1

  • Method for authenticating browserphone by telephone number, system for authenticating browserphone by telephone number, browserphone authentication server, program for authenticating browserphone by telephone number, service providing method,service providing system, service providing server, and service providing program

    WO2008016147A1