File download method and device
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-27
- Publication Date
- 2026-08-14
AI Technical Summary
[0003]现有的文件下载方法,虽然5G消息包含在消息体内部的文件下载链接是不呈现给用户的,但通过专业破解工具,可从终端侧提取出下载链接数据,存在被第三方用户攫取链接并从5G消息系统网络侧下载文件的安全隐患
[0026]本发明还提供一种非暂态计算机可读存储介质,其上存储有计算机程序,所述计算机程序被处理器执行时实现如上述任一种所述文件下载方法。
Smart Images

Figure CN120730286B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to a method and apparatus for downloading files. Background Technology
[0002] The 5G messaging system can provide users with 5G messaging services that include media files. When a user receives a message and requests to download the message body file, the 5G messaging network side performs Generic Bootstrapping Architecture (GBA) authentication on the requesting user. Users of this (operator's) network can all pass the GBA authentication process and download the file.
[0003] Existing file download methods, although the file download link included in the 5G message body is not presented to the user, can still be extracted from the terminal side using professional cracking tools. This poses a security risk that third-party users may seize the link and download the file from the 5G messaging system network side. Summary of the Invention
[0004] This invention provides a file download method and apparatus to improve the security of the file download process in a 5G messaging system.
[0005] This invention provides a file download method applied to a 5G messaging network, comprising:
[0006] Receive a file download request from the target terminal and perform Generic Bootstrapping Architecture (GBA) authentication on the requesting user corresponding to the file download request;
[0007] If the GBA authentication is successful, the Mobile Subscriber Identity (MSISDN) number of the target terminal is obtained, and it is determined whether the whitelist contains the MSISDN number of the target terminal. The whitelist is determined based on the MSISDN number of the called user. The MSISDN number of the called user is extracted from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal, based on the 5G Message Center (5GMC) on the 5G Message Network side.
[0008] If the whitelist contains the MSISDN number of the target terminal, the download service corresponding to the file download request is provided to the target terminal.
[0009] According to a file download method provided by the present invention, the process of constructing a whitelist includes:
[0010] Based on the 5GMC on the 5G messaging network side, when forwarding a file transfer message sent from the calling user terminal to the called user terminal, the file transfer message is copied to the file server on the 5G messaging network side.
[0011] The file server extracts the MSISDN number of the called user terminal based on the file transfer message, and constructs the whitelist based on the MSISDN number of the called user terminal.
[0012] According to a file download method provided by the present invention, the whitelist is constructed based on the MSISDN number of the called user terminal, including:
[0013] Associating the MSISDN number of the called user with the message digest of the file to be transferred in the file transfer message yields the association information;
[0014] Based on the association information, the whitelist is constructed.
[0015] According to a file download method provided by the present invention, determining whether the whitelist contains the MSISDN number of the target terminal further includes:
[0016] The MSISDN number of the target terminal is matched with the MSISDN number in the associated information of the whitelist. If the match is successful, it is determined whether the whitelist contains the MSISDN number of the target terminal.
[0017] According to a file download method provided by the present invention, after determining whether the whitelist contains the MSISDN number of the target terminal, the method further includes:
[0018] If the target terminal's MSISDN number is not included in the whitelist, the download service corresponding to the file download request will be refused to the target terminal.
[0019] According to a file download method provided by the present invention, in the case of successful GBA authentication, obtaining the MSISDN number of the target terminal includes:
[0020] Based on the file server, the MSISDN number corresponding to the target terminal's reported business transaction identifier B-TID is extracted from the cache to obtain the target terminal's MSISDN number.
[0021] The present invention also provides a file download device, applied to a 5G messaging network side, comprising:
[0022] The authentication module is used to receive file download requests from the target terminal and perform Generic Bootstrap Architecture (GBA) authentication on the requesting user corresponding to the file download request.
[0023] The comparison module is used to obtain the Mobile Subscriber Identity Code (MSISDN) number of the target terminal when the GBA authentication is passed, and to determine whether the whitelist contains the MSISDN number of the target terminal. The whitelist is determined based on the MSISDN number of the called user. The MSISDN number of the called user is extracted from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal, based on the 5G Message Center (5GMC) on the 5G Message Network side.
[0024] The authorization module is used to provide the target terminal with the download service corresponding to the file download request when the target terminal's MSISDN number is included in the whitelist.
[0025] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement any of the file download methods described above.
[0026] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the file download method as described above.
[0027] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements any of the file download methods described above.
[0028] The file download method and apparatus provided by this invention, after receiving a file transfer message at the 5G Message Center (5GMC) on the 5G Message Network side, extracts the MSISDN number of the called user from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal, constructs a whitelist for file download, and confirms the user's download permission when providing the file download service. This determines that the target terminal making the file request is the called terminal receiving the file transfer message, thereby realizing a further authentication process for the file requesting end, fully ensuring the confidentiality of the 5G Message file download service, and improving the service security level. Attached Figure Description
[0029] To more clearly illustrate the technical solutions in this invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly described below. Obviously, the accompanying drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0030] Figure 1 This is a schematic diagram of the file download process for GBA authentication using relevant methods;
[0031] Figure 2 This is a flowchart illustrating the file download method provided by the present invention;
[0032] Figure 3 This is a schematic diagram of the whitelist construction process provided by the present invention;
[0033] Figure 4 This is a flowchart illustrating the file download method provided by the present invention;
[0034] Figure 5 This is a schematic diagram of the file download device provided by the present invention;
[0035] Figure 6 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation
[0036] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0037] The mobile network can provide users with 5G messaging services that include media files. Users first receive a link to the message file and download the file by following the link. When a user requests to download, the 5G messaging network only performs GBA authentication on the user. This process does not guarantee that the requesting user is the called user.
[0038] The relevant methods include a file download process that incorporates GBA authentication, such as... Figure 1The diagram illustrates the GBA authentication file download process for related methods. The 5G messaging system can provide users with 5G messaging services that include files containing media. When a user receives a message and requests to download the file corresponding to the message body, the 5G messaging network performs GBA authentication on the requesting user. The GBA authentication process may include: communication between the 5G messaging user (called user) and the Bootstrapping Server Function (BSF), returning authentication data; the 5G messaging user initiating GBA authentication on the Application Server (AS) side to the file server; after completing the AS-side GBA authentication, the 5G messaging user, carrying the authentication data, sends a download request to the file server; and the file server, upon receiving the authentication data and the download request, provides the download service to the 5G messaging user.
[0039] Although the file download link included within the 5G message body is not presented to the user, it can be extracted from the terminal using specialized hacking tools. In certain specific business scenarios with high security requirements, there is a security risk that third-party users could seize the link and download files from the 5G messaging system network.
[0040] To address the shortcomings of related methods, this invention provides a file download method. Figure 2 A schematic flowchart illustrating the file download method provided by this invention. (Refer to...) Figure 2 The file download method provided by this invention may include:
[0041] Step 210: Receive the file download request from the target terminal and perform General Bootstrap Architecture (GBA) authentication on the requesting user corresponding to the file download request;
[0042] Step 220: If the GBA authentication is successful, obtain the Mobile Subscriber Identity (MSISDN) number of the target terminal and determine whether the whitelist contains the MSISDN number of the target terminal. The whitelist is determined based on the MSISDN number of the called user. The MSISDN number of the called user is extracted from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal, based on the 5G Message Network Side Message Center 5GMC.
[0043] Step 230: If the whitelist contains the MSISDN number of the target terminal, provide the download service corresponding to the file download request to the target terminal.
[0044] The file download method provided by this invention can be implemented by a 5G messaging network. The 5G messaging network supports SMS, multimedia messages, and other data transmissions between devices, and typically includes the following components and functions:
[0045] Message Passing Agent: As part of the core network, the message passing agent is responsible for control plane signaling transmission and message passing.
[0046] User plane functions: responsible for handling data transmission and message exchange between devices;
[0047] Session management function: Responsible for session management, including message routing and forwarding functions;
[0048] Application Server (AS): An AS may act as an application server for a messaging service, responsible for message processing, forwarding, and storage.
[0049] Identity authentication and security features: The message network side also involves identity authentication, security policies, and encryption / decryption functions to ensure the security and reliability of messages.
[0050] The following example, using the file download method provided by this invention executed on the 5G messaging network side, illustrates the technical solution of this invention in detail.
[0051] In step 210, a file download request from the target terminal is received, and the requesting user corresponding to the file download request is authenticated using the General Bootstrap Architecture (GBA).
[0052] Before the target terminal sends a file download request to the 5G messaging network, the calling user terminal sends a file transfer message to the called user terminal. After receiving the file transfer message, the called user terminal clicks on the file transfer message to obtain the file to be downloaded from the file server on the 5G messaging network.
[0053] The file acquisition process for the called user terminal in the relevant method is as follows: the called user terminal sends a file download request to the 5G messaging network side; the 5G messaging network side receives the file download request from the called user terminal and performs GBA authentication on the requesting user corresponding to the file download request; after successful GBA authentication, the file download server is opened to the called user terminal.
[0054] It is understandable that, regarding the implementation process of the relevant methods, if the called user terminal forwards the file transfer message to other terminals, or if other terminals obtain the file transfer message of the called user terminal through illegal means, other terminals can download the file based on the file transfer message of the called user terminal, which poses a security risk.
[0055] In this embodiment of the invention, the target terminal can be any terminal that may download files, such as the called user terminal mentioned above, or other terminals.
[0056] The target terminal sends a file download request to the 5G messaging network based on a file transfer message. This can be triggered by the user corresponding to the target terminal clicking on the file transfer message.
[0057] The 5G messaging network receives file download requests from the target terminal and performs GBA authentication on the requesting user corresponding to the file download request.
[0058] In step 220, if the GBA authentication is successful, the Mobile Subscriber Identity (MSISDN) number of the target terminal is obtained, and it is determined whether the whitelist contains the MSISDN number of the target terminal. The whitelist is determined based on the MSISDN number of the called user. The MSISDN number of the called user is extracted from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal by the 5G Message Network Side Message Center 5GMC.
[0059] If GBA certification is passed, further certification procedures will be performed, including:
[0060] The MSISDN number of the target terminal on the 5G messaging network side. An MSISDN number is a globally unique identifier for mobile phone users, typically used to identify and locate them. An MSISDN number usually consists of a country code, area code (if any), and subscriber number; it is a numeric string containing an international telephone number.
[0061] After obtaining the MSISDN number of the target terminal, determine whether the whitelist contains the MSISDN number of the target terminal.
[0062] The whitelist is determined based on the called user's MSISDN number. The calling user terminal sends a file transfer message to the called user terminal via the 5G messaging network. After receiving the file transfer message, the 5GMC (5G Message Center) on the 5G messaging network forwards the file transfer message from the calling user terminal to the called user terminal, extracting the called user's MSISDN number from the file transfer message. The called user terminal's MSISDN number is then added to the whitelist, resulting in the whitelist. It's understood that there can be one or more called user terminals, so the obtained MSISDN numbers can be one or more, and the constructed whitelist may contain one or more MSISDN numbers.
[0063] In step 230, if the whitelist contains the MSISDN number of the target terminal, the download service corresponding to the file download request is provided to the target terminal.
[0064] If GBA authentication is successful, the Mobile Subscriber Identity DN (MSISDN) number of the target terminal is obtained. If the MSISDN number of the target terminal is found in the whitelist, the target terminal can be identified as the called terminal receiving the file transfer message, thus completing a further authentication process for the target terminal. At this point, the 5G messaging network can provide the download service corresponding to the file download request to the target terminal.
[0065] The file download method provided in this embodiment of the invention, after receiving a file transfer message at the 5G Message Center (5GMC) on the 5G Message Network side, extracts the MSISDN number of the called user from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal, constructs a whitelist for file download, and confirms the user's download permission when providing the file download service. This determines that the target terminal making the file request is the called terminal receiving the file transfer message, thereby realizing a further authentication process for the file requesting end, fully ensuring the confidentiality of the 5G Message file download service, and improving the service security level.
[0066] In one embodiment, the process of constructing the whitelist includes: when forwarding a file transfer message sent from a calling user terminal to a called user terminal based on the 5GMC on the 5G messaging network side, copying the file transfer message to the file server on the 5G messaging network side; the file server extracts the MSISDN number of the called user terminal based on the file transfer message, and constructs the whitelist based on the MSISDN number of the called user terminal.
[0067] The diagram illustrating the whitelist construction process is as follows: Figure 3 The whitelist construction process provided by this invention is illustrated in the diagram. When the calling user terminal sends a file transfer message to the called user terminal, the 5GMC is responsible for receiving and processing these messages. While forwarding the file transfer message to the called user terminal, the 5GMC also copies these messages to the file server.
[0068] After receiving the copied file transfer message, the file server will parse the message content and extract the MSISDN number information of the called user terminal contained therein.
[0069] The file server extracts the MSISDN number of the called user terminal from the information in the file transfer message. This number is a globally unique identifier used to uniquely identify the called user terminal.
[0070] The file server uses the extracted MSISDN number of the called user terminal to add it to the whitelist, thereby constructing the whitelist list.
[0071] The file download method provided in this embodiment of the invention, after receiving the copied file transfer message through the file server, parses the message content, extracts the MSISDN number information of the called user terminal contained therein, and constructs a whitelist, which provides a basis for further authentication of the file requesting party.
[0072] In one embodiment, constructing the whitelist based on the MSISDN number of the called user terminal includes: associating the MSISDN number of the called user with the message digest of the file to be transmitted corresponding to the file transfer message to obtain association information; and constructing the whitelist based on the association information.
[0073] When processing file transfer messages, the file server can associate the called user's MSISDN number with the message digest of the transferred file. The message digest is a short representation of the file, usually generated by a hash algorithm, and is used to verify the file's integrity and uniqueness.
[0074] By associating MSISDN numbers with message digests, the file server obtains an association information table that records the MSISDN number of each called user terminal and the message digest of the corresponding file. The file server can then build a whitelist based on this association information table.
[0075] In one embodiment, determining whether the whitelist contains the MSISDN number of the target terminal further includes: matching the MSISDN number of the target terminal with the MSISDN number in the associated information of the whitelist; if the match is successful, determining whether the whitelist contains the MSISDN number of the target terminal.
[0076] The target terminal's MSISDN number is matched against the MSISDN numbers in the associated information of the whitelist. This can be done by checking if the target terminal's MSISDN number exists in the associated information. If a match is successful, it can be determined whether the whitelist contains the target terminal's MSISDN number.
[0077] For the specific matching process, the most direct method is to perform an exact match, that is, to directly compare the MSISDN number of the target terminal with each MSISDN number in the whitelist. If an exact match is found, it can be confirmed that the MSISDN number of the target terminal is in the whitelist. Regular expressions can also be used to more flexibly match MSISDN numbers that conform to specific rules. By defining matching rules, MSISDN numbers that meet the conditions can be quickly filtered out, thereby determining whether the target terminal's number is included.
[0078] In one embodiment, after determining whether the whitelist contains the MSISDN number of the target terminal, the method further includes: if the whitelist does not contain the MSISDN number of the target terminal, refusing to provide the download service corresponding to the file download request to the target terminal.
[0079] Understandably, if the target terminal's MSISDN number is not included in the whitelist, it can be determined that the target terminal is not the called user's terminal. In this case, enabling file download services could pose a security risk.
[0080] Therefore, when it is determined that the target terminal is not the called user terminal, the download service corresponding to the file download request is refused to be provided to the target terminal.
[0081] In one embodiment, if the GBA authentication is successful, obtaining the MSISDN number of the target terminal includes: extracting the MSISDN number corresponding to the B-TID reported by the target terminal from the cache based on the file server, so as to obtain the MSISDN number of the target terminal.
[0082] Based on the B-TID reported by the target terminal, a query operation is performed in the cache to find the MSISDN number corresponding to that B-TID. Once the MSISDN number corresponding to the target B-TID is found, the information for that number can be retrieved from the file server's cache.
[0083] Specifically, in the GBA process, BSF sends a BIA message to the file server, which includes IMPI, IMPU, Ks_NAF, usslist, keyExpiryTime, bootstrappingInfo Creation Time, and uiccKeyMaterial. The file server extracts the user's MSISDN from the IMPU and generates a set of data corresponding to the user's reported B-TID, which is then placed in the file server's local cache. The cache time can be set, but it should not exceed the validity period of the GBA authentication.
[0084] The following is a flowchart illustrating a file download method provided by this invention, used as an example to illustrate the technical solution provided by this invention:
[0085] like Figure 4 As shown, the specific process includes:
[0086] The terminal corresponding to the 5G messaging user (called user) communicates with the BSF (Browser Service Function) and returns authentication data. The 5G messaging user initiates GBA authentication on the AS side to the file server. After completing the GBA authentication on the AS side, the B-TID and MSISDN numbers are associated and cached.
[0087] When the called user terminal initiates a file download request, the MSISDN number is extracted from the cache and compared with the MSISDN numbers in the whitelist to determine whether the extracted MSISDN number is in the whitelist.
[0088] If the extracted MSISDN number is confirmed to be on the whitelist, the download service will be provided; if the extracted MSISDN number is confirmed to be off the whitelist, the download service will be refused.
[0089] Figure 5 This is a schematic diagram of the file download device provided by the present invention, as shown below. Figure 5 The device includes:
[0090] The authentication module 510 is used to receive file download requests from the target terminal and perform General Bootstrap Architecture (GBA) authentication on the requesting user corresponding to the file download request.
[0091] The comparison module 520 is used to obtain the Mobile Subscriber Identity Code (MSISDN) number of the target terminal when the GBA authentication is passed, and to determine whether the whitelist contains the MSISDN number of the target terminal. The whitelist is determined based on the MSISDN number of the called user. The MSISDN number of the called user is extracted from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal by the 5G message network side message center 5GMC.
[0092] The authorization module 530 is used to provide the target terminal with the download service corresponding to the file download request when the target terminal's MSISDN number is included in the whitelist.
[0093] The file download device provided in this embodiment of the invention, after receiving a file transfer message in the 5G Message Center (5GMC) on the 5G Message Network side, extracts the MSISDN number of the called user from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal, constructs a whitelist for file download, and confirms the user's download permission when providing the file download service. This determines that the target terminal making the file request is the called terminal receiving the file transfer message, thereby realizing a further authentication process for the file requesting end, fully ensuring the confidentiality of the 5G Message file download service, and improving the service security level.
[0094] In one embodiment, the comparison module 520 is specifically used for:
[0095] The process of constructing the whitelist includes:
[0096] Based on the 5GMC on the 5G messaging network side, when forwarding a file transfer message sent from the calling user terminal to the called user terminal, the file transfer message is copied to the file server on the 5G messaging network side.
[0097] The file server extracts the MSISDN number of the called user terminal based on the file transfer message, and constructs the whitelist based on the MSISDN number of the called user terminal.
[0098] In one embodiment, the comparison module 520 is further configured to:
[0099] Based on the MSISDN number of the called user terminal, the whitelist is constructed, including:
[0100] Associating the MSISDN number of the called user with the message digest of the file to be transferred in the file transfer message yields the association information;
[0101] Based on the association information, the whitelist is constructed.
[0102] In one embodiment, the comparison module 520 is further configured to:
[0103] Determining whether the whitelist contains the MSISDN number of the target terminal further includes:
[0104] The MSISDN number of the target terminal is matched with the MSISDN number in the associated information of the whitelist. If the match is successful, it is determined whether the whitelist contains the MSISDN number of the target terminal.
[0105] In one embodiment, the authorization module 530 is specifically used for:
[0106] After determining whether the whitelist contains the MSISDN number of the target terminal, the process also includes:
[0107] If the target terminal's MSISDN number is not included in the whitelist, the download service corresponding to the file download request will be refused to the target terminal.
[0108] In one embodiment, the comparison module 520 is further configured to:
[0109] If the GBA authentication is successful, obtain the MSISDN number of the target terminal, including:
[0110] Based on the file server, the MSISDN number corresponding to the target terminal's reported business transaction identifier B-TID is extracted from the cache to obtain the target terminal's MSISDN number.
[0111] Figure 6 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 6 As shown, the electronic device may include: a processor 610, a communication interface 620, a memory 630, and a communication bus 640, wherein the processor 610, the communication interface 620, and the memory 630 communicate with each other via the communication bus 640. The processor 610 can call logical instructions in the memory 630 to execute a file download method, which includes:
[0112] Receive a file download request from the target terminal and perform Generic Bootstrapping Architecture (GBA) authentication on the requesting user corresponding to the file download request;
[0113] If the GBA authentication is successful, the Mobile Subscriber Identity (MSISDN) number of the target terminal is obtained, and it is determined whether the whitelist contains the MSISDN number of the target terminal. The whitelist is determined based on the MSISDN number of the called user. The MSISDN number of the called user is extracted from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal, based on the 5G Message Center (5GMC) on the 5G Message Network side.
[0114] If the whitelist contains the MSISDN number of the target terminal, the download service corresponding to the file download request is provided to the target terminal.
[0115] Furthermore, the logical instructions in the aforementioned memory 630 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0116] On the other hand, the present invention also provides a computer program product, the computer program product comprising a computer program stored on a non-transitory computer-readable storage medium, the computer program comprising program instructions, wherein when the program instructions are executed by a computer, the computer is able to execute the file download method provided by the above methods, the method comprising:
[0117] Receive a file download request from the target terminal and perform Generic Bootstrapping Architecture (GBA) authentication on the requesting user corresponding to the file download request;
[0118] If the GBA authentication is successful, the Mobile Subscriber Identity (MSISDN) number of the target terminal is obtained, and it is determined whether the whitelist contains the MSISDN number of the target terminal. The whitelist is determined based on the MSISDN number of the called user. The MSISDN number of the called user is extracted from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal, based on the 5G Message Center (5GMC) on the 5G Message Network side.
[0119] If the whitelist contains the MSISDN number of the target terminal, the download service corresponding to the file download request is provided to the target terminal.
[0120] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform the file download methods provided above, the method comprising:
[0121] Receive a file download request from the target terminal and perform Generic Bootstrapping Architecture (GBA) authentication on the requesting user corresponding to the file download request;
[0122] If the GBA authentication is successful, the Mobile Subscriber Identity (MSISDN) number of the target terminal is obtained, and it is determined whether the whitelist contains the MSISDN number of the target terminal. The whitelist is determined based on the MSISDN number of the called user. The MSISDN number of the called user is extracted from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal, based on the 5G Message Center (5GMC) on the 5G Message Network side.
[0123] If the whitelist contains the MSISDN number of the target terminal, the download service corresponding to the file download request is provided to the target terminal.
[0124] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0125] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0126] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A file download method, characterized in that, Applied to the 5G messaging network side, the method includes: Receive a file download request from the target terminal and perform Generic Bootstrapping Architecture (GBA) authentication on the requesting user corresponding to the file download request; If the GBA authentication is successful, the Mobile Subscriber Identity (MSISDN) number of the target terminal is obtained, and it is determined whether the whitelist contains the MSISDN number of the target terminal. The whitelist is determined based on the MSISDN number of the called user. The MSISDN number of the called user is extracted from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal, based on the 5G Message Center (5GMC) on the 5G Message Network side. If the whitelist contains the MSISDN number of the target terminal, the download service corresponding to the file download request is provided to the target terminal. The process of constructing the whitelist includes: Based on the 5GMC on the 5G messaging network side, when forwarding a file transfer message sent from the calling user terminal to the called user terminal, the file transfer message is copied to the file server on the 5G messaging network side. The file server extracts the MSISDN number of the called user terminal based on the file transfer message, and constructs the whitelist based on the MSISDN number of the called user terminal.
2. The file download method according to claim 1, characterized in that, The process of constructing the whitelist based on the MSISDN number of the called user terminal includes: Associating the MSISDN number of the called user with the message digest of the file to be transferred in the file transfer message yields the association information; Based on the association information, the whitelist is constructed.
3. The file download method according to claim 2, characterized in that, The step of determining whether the whitelist contains the MSISDN number of the target terminal further includes: The MSISDN number of the target terminal is matched with the MSISDN number in the associated information of the whitelist. If the match is successful, it is determined whether the whitelist contains the MSISDN number of the target terminal.
4. The file download method according to claim 1, characterized in that, After determining whether the whitelist contains the MSISDN number of the target terminal, the process further includes: If the target terminal's MSISDN number is not included in the whitelist, the download service corresponding to the file download request will be refused to the target terminal.
5. The file download method according to claim 1, characterized in that, If the GBA authentication is successful, obtaining the MSISDN number of the target terminal includes: Based on the file server, the MSISDN number corresponding to the target terminal's reported business transaction identifier B-TID is extracted from the cache to obtain the target terminal's MSISDN number.
6. A file download device, characterized in that, Applied to the 5G messaging network side, including: The authentication module is used to receive file download requests from the target terminal and perform Generic Bootstrap Architecture (GBA) authentication on the requesting user corresponding to the file download request. The comparison module is used to obtain the Mobile Subscriber Identity Code (MSISDN) number of the target terminal when the GBA authentication is passed, and to determine whether the whitelist contains the MSISDN number of the target terminal. The whitelist is determined based on the MSISDN number of the called user. The MSISDN number of the called user is extracted from the file transfer message when forwarding the file transfer message sent by the calling user terminal to the called user terminal, based on the 5G Message Center (5GMC) on the 5G Message Network side. The authorization module is used to provide the target terminal with the download service corresponding to the file download request when the target terminal's MSISDN number is included in the whitelist; The process of constructing the whitelist includes: Based on the 5GMC on the 5G messaging network side, when forwarding a file transfer message sent from the calling user terminal to the called user terminal, the file transfer message is copied to the file server on the 5G messaging network side. The file server extracts the MSISDN number of the called user terminal based on the file transfer message, and constructs the whitelist based on the MSISDN number of the called user terminal.
7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the file download method as described in any one of claims 1 to 5.
8. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the file download method as described in any one of claims 1 to 5.
9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the file download method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
File transfer method and server
CN104202411A
Identity authentication method, device and equipment and computer readable storage medium
CN113542193A