Communication methods, devices, electronic equipment, storage media and computer program products

CN122579104APending Publication Date: 2026-08-14BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

然而,目前终端设备仅通过向码号管理平台发送漫游请求并接收码号数据进行漫游,这种方式容易导致码号数据被泄露,从而无法保证码号数据的安全性

Benefits of technology

[0045]本公开实施例,终端设备先向第一服务器发送第一证书请求,在接收到第一服务器反馈的第一设备证书后,再向第二服务器发送携带有第一设备证书的漫游请求,以使第二服务器基于第一设备证书验证终端设备与第二服务器之间通信的安全性,并接收第二服务器在安全性验证通过后反馈的码号数据,并基于码号数据进行漫游。本公开实施例中,终端设备接收的码号数据为第二服务器基于第一设备证书验证通信安全性通过后反馈的数据,能够有效降低因第二服务器与终端设备之间通信不安全而导致的码号数据被泄露的风险,从而提高码号数据的安全性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122579104A_ABST
    Figure CN122579104A_ABST
Patent Text Reader

Abstract

This disclosure relates to a communication method, apparatus, electronic device, storage medium, and computer program product. The method includes: sending a first certificate request to a first server; receiving a first device certificate from the first server based on the first certificate request; sending a roaming request to a second server; wherein the roaming request carries the first device certificate, which is used by the second server to verify the security of communication between a terminal device and the second server; receiving code data from the second server based on the roaming request; wherein the code data is sent by the second server after the security verification is successful, and the code data is used to support roaming of the terminal device; and performing roaming based on the code data. This method can improve the security of the code data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a communication method, apparatus, electronic device, storage medium, and computer program product. Background Technology

[0002] With the continuous development of network technology, roaming for internet access has become commonplace for terminal devices. Roaming code data is crucial for this process. For example, some terminal devices, such as smartphones, need to obtain local code data to access the network when roaming internationally. Other terminal devices, such as IoT devices, need to dynamically switch code numbers to achieve seamless connectivity when roaming in different regions. However, currently, terminal devices only roam by sending roaming requests to the code management platform and receiving code data. This method is prone to code data leakage, thus compromising code data security. Summary of the Invention

[0003] To overcome the problems existing in related technologies, this disclosure provides a communication method, apparatus, electronic device, storage medium, and computer program product.

[0004] According to a first aspect of the present disclosure, a communication method is provided, the method comprising:

[0005] Send the first certificate request to the first server;

[0006] Receive the first device certificate returned by the first server based on the first certificate request;

[0007] Send a roaming request to the second server; wherein the roaming request carries the first device certificate, the first device certificate being used by the second server to verify the security of communication between the terminal device and the second server;

[0008] The system receives code data from the second server based on the roaming request; wherein the code data is sent by the second server after the security verification is passed, and the code data is used to support the roaming of the terminal device.

[0009] Roaming is performed based on the code number data.

[0010] According to a second aspect of the present disclosure, a communication method is provided, applied in a first server, the method comprising:

[0011] Receive the first certificate request sent by the terminal device;

[0012] Based on the first certificate request, determine the first device certificate;

[0013] The first device certificate is sent to the terminal device; wherein, the first device certificate is carried by the terminal device when sending a roaming request to the second server to verify the security of the communication between the terminal device and the second server, and after the security verification is passed, the terminal device obtains the roaming support code number data from the second server.

[0014] According to a third aspect of the present disclosure, a communication method is provided, applied in a second server, the method comprising:

[0015] Receive a roaming request sent by a terminal device; wherein the roaming request carries a first device certificate obtained by the terminal device through a first server;

[0016] Based on the first device certificate in the roaming request, verify the security of the communication between the terminal device and the second server;

[0017] After the security verification is passed, code number data supporting the roaming of the terminal device is sent to the terminal device.

[0018] According to a fourth aspect of the present disclosure, a communication device is provided, the device comprising:

[0019] The first certificate request sending module is configured to send a first certificate request to the first server;

[0020] The first device certificate receiving module is configured to receive the first device certificate fed back by the first server based on the first certificate request.

[0021] A roaming request sending module is configured to send a roaming request to a second server; wherein the roaming request carries the first device certificate, and the first device certificate is used by the second server to verify the security of communication between the terminal device and the second server;

[0022] The code number data receiving module is configured to receive code number data fed back by the second server based on the roaming request; wherein the code number data is sent by the second server after the security verification is passed, and the code number data is used to support the roaming of the terminal device;

[0023] The roaming module is configured to roam based on the code number data.

[0024] According to a fifth aspect of the present disclosure, a communication apparatus is provided, applied in a first server, the apparatus comprising:

[0025] The first certificate request receiving module is configured to receive the first certificate request sent by the terminal device.

[0026] The first device certificate determination module is configured to determine the first device certificate based on the first certificate request;

[0027] The first device certificate sending module is configured to send the first device certificate to the terminal device; wherein, the first device certificate is carried by the terminal device when sending a roaming request to the second server to verify the security of the communication between the terminal device and the second server, and after the security verification is passed, the terminal device obtains roaming-supporting code number data from the second server.

[0028] According to a sixth aspect of the present disclosure, a communication apparatus is provided, applied in a second server, the apparatus comprising:

[0029] A roaming request receiving module is configured to receive a roaming request sent by a terminal device; wherein the roaming request carries a first device certificate obtained by the terminal device through a first server;

[0030] The security verification module is configured to verify the security of communication between the terminal device and the second server based on the first device certificate in the roaming request.

[0031] The code number data sending module is configured to send code number data supporting the roaming of the terminal device to the terminal device after the security verification is passed.

[0032] According to a seventh aspect of the present disclosure, a communication system is provided, the system comprising:

[0033] The terminal device is used to send a first certificate request to the first server;

[0034] The first server is configured to determine a first device certificate based on the first certificate request, and send the first device certificate to the terminal device;

[0035] The terminal device is also used to send a roaming request carrying the certificate of the first device to the second server;

[0036] The second server is used to verify the security of the communication between the terminal device and the second server based on the first device certificate in the roaming request, and send code number data supporting the roaming of the terminal device to the terminal device after the security verification is passed;

[0037] The terminal device is also used for roaming based on the code number data.

[0038] According to an eighth aspect of the present disclosure, an electronic device is provided, comprising:

[0039] processor;

[0040] Memory used to store computer programs or instructions;

[0041] The processor executes the computer program or instructions to implement the steps of the communication method described in the first aspect; or to implement the steps of the communication method described in the second aspect; or to implement the steps of the communication method described in the third aspect.

[0042] According to a ninth aspect of the present disclosure, a non-transitory computer-readable storage medium is provided, the storage medium storing a computer program or instructions, which, when executed by a processor, implement the steps of the communication method described in the first aspect; or, implement the steps of the communication method described in the second aspect; or, implement the steps of the communication method described in the third aspect.

[0043] According to a tenth aspect of the present disclosure, a computer program product is provided, comprising a computer program or instructions, which, when executed by a processor, implement the steps of the communication method described in the first aspect; or, implement the steps of the communication method described in the second aspect; or, implement the steps of the communication method described in the third aspect.

[0044] The technical solutions provided by the embodiments of this disclosure may include the following beneficial effects:

[0045] In this embodiment, the terminal device first sends a first certificate request to a first server. After receiving the first device certificate from the first server, it then sends a roaming request carrying the first device certificate to a second server. This allows the second server to verify the security of communication between the terminal device and the second server based on the first device certificate, and to receive code data returned by the second server after successful security verification. Roaming is then performed based on this code data. In this embodiment, the code data received by the terminal device is the data returned by the second server after successful communication security verification based on the first device certificate. This effectively reduces the risk of code data leakage due to insecure communication between the second server and the terminal device, thereby improving the security of the code data.

[0046] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0047] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0048] Figure 1This is a flowchart of a communication method according to an exemplary embodiment. Figure 1 .

[0049] Figure 2 This is a flowchart of a communication method according to an exemplary embodiment. Figure 2 .

[0050] Figure 3 This is an example diagram of a framework for a first server according to an exemplary embodiment.

[0051] Figure 4 This is a flowchart illustrating the interaction between a first server and a terminal device according to an exemplary embodiment.

[0052] Figure 5 This is a flowchart of a communication method according to an exemplary embodiment. Figure 3 .

[0053] Figure 6 This is an example diagram of a framework for a second server, according to an exemplary embodiment.

[0054] Figure 7 This is an interactive flowchart between a first server and a second server according to an exemplary embodiment.

[0055] Figure 8 This is an interactive flowchart illustrating a second server and a terminal device according to an exemplary embodiment.

[0056] Figure 9 This is a flowchart illustrating a communication method according to an exemplary embodiment.

[0057] Figure 10 This is a framework example of a communication method illustrated according to an exemplary embodiment. Figure 1 .

[0058] Figure 11 This is a framework example of a communication method illustrated according to an exemplary embodiment. Figure 2 .

[0059] Figure 12 This is a communication device frame illustrated according to an exemplary embodiment. Figure 1 .

[0060] Figure 13 This is a communication device frame illustrated according to an exemplary embodiment. Figure 2 .

[0061] Figure 14 This is a communication device frame illustrated according to an exemplary embodiment. Figure 3 .

[0062] Figure 15 This is a structural block diagram of a terminal device according to an exemplary embodiment.

[0063] Figure 16 This is a structural block diagram of a server according to an exemplary embodiment. Detailed Implementation

[0064] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.

[0065] Figure 1 This is a flowchart of a communication method according to an exemplary embodiment. Figure 1 .like Figure 1 As shown, the method mainly includes the following steps:

[0066] S11. Send the first certificate request to the first server;

[0067] S12. Receive the first device certificate fed back by the first server based on the first certificate request;

[0068] S13. Send a roaming request to the second server; wherein the roaming request carries the first device certificate, and the first device certificate is used by the second server to verify the security of communication between the terminal device and the second server;

[0069] S14. Receive code number data fed back by the second server based on the roaming request; wherein, the code number data is sent by the second server after the security verification is passed, and the code number data is used to support the roaming of the terminal device;

[0070] S15. Roaming is performed based on the code number data.

[0071] In this embodiment of the disclosure, the communication method can be applied to a terminal device, which may include user equipment (UE), mobile device, user terminal, mobile phone, tablet computer, personal digital assistant (PDA), handheld device, computing device, vehicle device, wearable device, and other electronic devices capable of Internet roaming. The following description uses a terminal device as an example.

[0072] The application scenarios of this disclosure are scenarios where terminal devices need to roam, such as when a user with a terminal device is traveling abroad and needs to connect the terminal device to a foreign mobile communication network to access the Internet, or, for example, when a terminal device on a ship or airplane needs to roam to mobile communication networks in different countries or regions to maintain communication with the ground control center, depending on the operation of the ship or airplane.

[0073] In step S11, the terminal device sends a first certificate request to the first server. The first server can be a server capable of issuing a device certificate that identifies the device, such as a certificate issuing center. It should be noted that the first server can be a preset server, such as a self-developed server or a public server. This embodiment of the disclosure does not impose any restrictions on this.

[0074] In this embodiment of the disclosure, the terminal device sends a first certificate request to a first server. The first certificate request may carry a device identifier of the terminal device, so that the first server can issue a device certificate for the corresponding device based on the device identifier. The first certificate request may be a Secure Sockets Layer (SSL) certificate request and / or a Transport Layer Security (TLS) certificate request.

[0075] In step S12, the terminal device receives a first device certificate from the first server based on the first certificate request. The first server can generate a first device certificate for the terminal device based on the first certificate request; the first device certificate can also be a device certificate for the terminal device pre-generated and stored in the first server. After receiving the first certificate request from the terminal device, the first server determines the first device certificate corresponding to the terminal device.

[0076] In some embodiments, when the first certificate request is an SSL and / or TLS certificate request, the first device certificate is an SSL and / or TLS certificate; in other embodiments, the first device certificate may also be a certificate characterizing the legitimacy of the terminal device.

[0077] In this embodiment of the disclosure, after the first server generates or determines the first device certificate, it sends the first device certificate to the terminal device, and the terminal device receives the first device certificate fed back by the first server.

[0078] In step S13, the terminal device sends a roaming request carrying the first device certificate to the second server; wherein, the first device certificate is used by the second server to verify the security of communication between the terminal device and the second server. The second server may be a server capable of assigning code data to the terminal device, such as a code management service platform (Subscription Manager Data Preparation Plus, SM-DP+).

[0079] In this embodiment of the disclosure, after receiving the first device certificate from the first server, the terminal device sends a roaming request carrying the first device certificate to the second server. The roaming request may also carry information such as the terminal device's device identifier, device location information, and IP address.

[0080] In this embodiment, the second server verifies the security of communication between the terminal device and the second server based on the first device certificate. In some embodiments, the second server can verify whether the issuing center of the first device certificate is a preset server, such as the first server. If the issuing center is the preset server, it indicates secure communication; if the issuing center is not the preset server, it indicates insecure communication. In other embodiments, the second server can also verify the validity of the first device certificate, such as verifying whether the issuance time limit of the first device certificate is within a preset time limit, such as 5 minutes. If it is within the preset time limit, it indicates secure communication; if it is not within the preset time limit, it indicates insecure communication.

[0081] In other embodiments, the second server may also send a certificate request to the first server to obtain the device certificate of the terminal device returned by the first server, and verify the security of the communication based on the device certificate of the terminal device returned by the first server and the first device certificate carried in the roaming request. If the device certificate of the terminal device returned by the first server is the same as the first device certificate carried in the roaming request, the communication is secure. If the device certificate of the terminal device returned by the first server is different from the first device certificate carried in the roaming request, the communication is insecure.

[0082] In step S14, the terminal device receives code number data from the second server based on the roaming request; wherein, the code number data is sent by the second server after the security verification is passed. The second server may store code number data. After receiving the roaming request and passing the security verification, the second server may assign code number data belonging to the terminal device based on the roaming request and send the code number data to the terminal device. The terminal device receives the code number data fed back by the second server.

[0083] In this embodiment of the disclosure, the code data is data that supports roaming of the terminal device. For example, the code data may include the telephone number used for roaming, the International Mobile Subscriber Identification Number (IMSI), the Mobile Subscriber International Integrated Service Digital Network number (MSISDN), the Location Area Identity (LAI), the Mobile Country Code (MCC), the Mobile Network Code (MNC), the Globally Unique Temporary UE Identity (GUTI), the Service Area Identifier, etc.

[0084] In step S15, after obtaining the code number data, the terminal device performs roaming based on the code number data. In some embodiments, the terminal device can select a network that matches the code number data for roaming; in other embodiments, when the terminal device sends an access request to the network to be accessed, it can carry the code number data, and the terminal device can access the network after verifying the code number data; in other embodiments, as mentioned above, the code number data may also include a location area code, and when the terminal device sends an access request to the network to be accessed, it can carry the location area code, and the network to be accessed can provide corresponding roaming services to the terminal device based on the location of the terminal device.

[0085] In this embodiment, the terminal device first sends a first certificate request to a first server. After receiving the first device certificate from the first server, it then sends a roaming request carrying the first device certificate to a second server. This allows the second server to verify the security of communication between the terminal device and the second server based on the first device certificate, and to receive code data returned by the second server after successful security verification. Roaming is then performed based on this code data. In this embodiment, the code data received by the terminal device is the data returned by the second server after successful communication security verification based on the first device certificate. This effectively reduces the risk of code data leakage due to insecure communication between the second server and the terminal device, thereby improving the security of the code data.

[0086] In some embodiments, the first certificate request carries a first password, and the first device certificate is a certificate encrypted by the first server using the first password.

[0087] The method further includes:

[0088] The first device certificate is decrypted using the first key generated by pairing with the first password;

[0089] Sending a roaming request to the second server includes:

[0090] Send a roaming request carrying the decrypted certificate of the first device to the second server.

[0091] In this embodiment of the disclosure, the first password and the first key corresponding to the first password can be generated by the terminal device before sending the first certificate request, or they can be generated by other electronic devices that have established a connection with the terminal device and then sent to the terminal device. The first password and the first key corresponding to the first password can be generated based on asymmetric encryption algorithms (AEA), such as RSA encryption algorithm, digital signature algorithm (DSA), elliptic curve cryptography (ECC), etc. The first password and the first key corresponding to the first password can also be generated based on symmetric encryption algorithms (SEA), such as Data Encryption Standard (DES) algorithm, Advanced Encryption Standard (AES) algorithm, Blowfish encryption algorithm, etc. This embodiment of the disclosure does not limit the scope of the first password.

[0092] In this embodiment of the disclosure, when the terminal device sends a first certificate request to the first server, it carries a first password. After receiving the first certificate request sent by the terminal device, the first server generates or determines a first device certificate and encrypts the first device certificate using the first password. After receiving the encrypted first device certificate, the terminal device decrypts the encrypted first device certificate using a first key and carries the decrypted first device certificate when sending a roaming request to the second server.

[0093] In this embodiment of the disclosure, the terminal device sends the first password to the first server and receives the certificate encrypted by the first server using the first password. The terminal device then decrypts the certificate using the first key generated by pairing the first password to obtain the first device certificate. Since the first device certificate is encrypted with the first password, transmitting the encrypted first device certificate can improve the confidentiality of the first device certificate during transmission. Even if the encrypted first device certificate is intercepted during transmission, its content cannot be deciphered without the corresponding decryption key, thus providing higher security.

[0094] In some embodiments, the method further includes:

[0095] Receive a first signature sent by the first server; wherein the first signature is generated by the third server using the encrypted first device certificate sent by the first server and a preset second password, and then sent to the first server;

[0096] The first signature is verified based on the encrypted first device certificate and the second password pre-stored in the terminal device;

[0097] The step of decrypting the first device certificate using the first key generated by pairing with the first password includes:

[0098] After the first signature verification is successful, the first device certificate is decrypted using the first key generated by pairing with the first password.

[0099] In this embodiment of the disclosure, the first server generates a first device certificate, encrypts the first device certificate using a first password, and sends the encrypted first device certificate to a third server. The third server uses the encrypted first device certificate and a preset second password to generate a first signature and sends it to the first server. The third server may be a Trust Zone (TZ) server. Before the terminal device sends a first certificate request to the first server, the third server may interact with the terminal device to generate a second password associated with the terminal device and send the second password to the terminal device. The terminal device stores the second password. The third server may generate the second password based on the aforementioned symmetric encryption algorithm.

[0100] In this embodiment of the disclosure, after the third server generates the first signature, it sends the first signature to the first server. After receiving the first signature sent by the third server, the first server sends the first signature to the terminal device. After receiving the first signature sent by the first server, the terminal device verifies the first signature based on the received encrypted first device certificate and the pre-stored second password. The terminal device can compare the received encrypted first device certificate and the pre-stored second password with the encrypted first device certificate and the second password in the first signature. If they are the same, the verification is successful.

[0101] In this embodiment of the disclosure, after the first signature verification is passed, the terminal device decrypts the first device certificate using the first key generated by pairing with the first password.

[0102] In this embodiment of the disclosure, the terminal device receives and verifies the first signature. By verifying the first signature, the terminal device can confirm that the first device certificate was sent by the expected sender (such as the first server) and not forged by a malicious third party. After the first signature is verified, the first device certificate is decrypted, which can reduce the unnecessary decryption processing of invalid or tampered data by the terminal device, thereby improving the overall processing efficiency.

[0103] In some embodiments, the method further includes:

[0104] A second signature is generated based on the pre-stored second password;

[0105] Sending the first certificate request to the first server includes:

[0106] A first certificate request carrying the second signature is sent to the first server; wherein the second signature is used by the first server to send to the third server for verification.

[0107] Receiving the first device certificate returned by the first server based on the first certificate request includes:

[0108] The system receives the first device certificate generated and fed back by the first server after receiving the first notification message; wherein the first notification message is sent to the first server by the third server after the second signature has been verified.

[0109] In this embodiment of the present disclosure, the terminal device may further generate a second signature based on a stored second password before sending a first certificate request to the first server. The second password can be obtained as described above. After generating the first signature, the terminal device sends a first certificate request carrying the second signature to the first server. Upon receiving the first certificate request carrying the second signature from the terminal device, the first server sends the second signature to a third server. The third server verifies the second signature based on a preset second password. The third server may compare the preset second password stored in the third server with the second password in the second signature; if they are the same, the verification is successful.

[0110] In this embodiment of the disclosure, after the third server verifies the second signature, it sends a first notification message indicating that the second signature verification is successful to the first server. After receiving the first notification message indicating that the second signature verification is successful from the third server, the first server generates a first device certificate and sends the first device certificate back to the terminal device. The terminal device receives the first device certificate generated and sent back by the first server after receiving the first notification message.

[0111] In this embodiment, when a terminal device sends a first certificate request to a first server, it carries a second signature generated based on a stored second password. The terminal device also receives a first device certificate generated and returned by the first server after receiving a first notification message indicating successful verification of the second signature. This confirms that the first certificate request was sent by the intended sender (such as the terminal device) and not forged by a malicious third party. After the second signature verification is successful, the first device certificate is generated and returned to the terminal device. On the one hand, this further enhances the security and reliability of the generated and transmitted first device certificate, reducing the possibility of malicious attacks and data tampering. On the other hand, the first server does not need to pre-store the first device certificate; instead, it generates it after verification. If verification fails, the first server does not need to generate the first device certificate, reducing the computational burden and memory usage of the first server, thus demonstrating high intelligence.

[0112] In some embodiments, the method further includes:

[0113] A third signature is generated based on the first key;

[0114] Upon receiving the code number data, the third signature and / or the decrypted first device certificate is sent to the second server; wherein, the third signature and / or the decrypted first device certificate is used by the second server for verification.

[0115] The roaming based on the code number data includes:

[0116] In response to receiving a second notification message from the second server, roaming is performed based on the code number data; wherein, the second notification message is sent by the second server after the verification of the first device certificate after the third signature and / or decryption is successful.

[0117] In this embodiment of the disclosure, the terminal device generates a third signature based on a first key. The terminal device may generate the third signature before sending the first certificate request, after sending the first certificate request and before sending the roaming request, after sending the roaming request and before receiving the code number data, or after receiving the code number data. This embodiment of the disclosure does not limit the third signature in this respect.

[0118] In this embodiment of the disclosure, after receiving code data sent by the second server, the terminal device sends a third signature and / or a decrypted first device certificate to the second server. After receiving the third signature and / or the decrypted first device certificate, the second server verifies the third signature and / or the decrypted first device certificate. The second server may obtain a first password from the first server and use the first password to verify the third signature generated based on the first key. The second server may also obtain a second device certificate of the terminal device and a second root certificate corresponding to the second device certificate from the first server, and use the second device certificate and / or the second root certificate to verify the first device certificate.

[0119] In this embodiment of the present disclosure, in response to receiving a second notification message from a second server indicating that the verification of the first device certificate after the third signature and / or decryption has been passed, the terminal device performs roaming based on the code number data. This enables the second server to confirm whether the code number data has been received by a preset device (terminal device). Only after the second server confirms that the code number data has been received by the preset device can the device (terminal device) receiving the code number data perform roaming based on the code number data. The solution of this embodiment of the present disclosure can further improve the legality and security of the terminal device's roaming.

[0120] In some embodiments, the code data received by the terminal device is data encrypted by the second server using the first password obtained from the first server;

[0121] The method further includes:

[0122] The encrypted code data is decrypted using the first key;

[0123] The roaming based on the code number data includes:

[0124] Roaming is performed based on the decrypted code data.

[0125] In this embodiment of the disclosure, the code data received by the terminal device is data encrypted by the second server using a first password obtained from the first server. After receiving the encrypted code data, the terminal device decrypts the code data using a first key and performs roaming based on the decrypted code data. As mentioned above, the first key is generated by the terminal device, and only the terminal device has the first key. Therefore, transmitting the encrypted code data can improve the confidentiality of the code data during transmission. Even if the encrypted code data is intercepted during transmission, its content cannot be deciphered without the corresponding decryption key, resulting in higher security.

[0126] In some embodiments, the method further includes:

[0127] Receive a third password sent by the first server; wherein the third password is generated by the second server and then sent to the first server;

[0128] Receive a fourth signature sent by the second server; wherein the fourth signature is generated by the second server using a third key generated in conjunction with the third cryptography;

[0129] The fourth signature is verified based on the third cryptography;

[0130] The step of decrypting the encrypted code data using the first key includes:

[0131] After the fourth signature verification is successful, the encrypted code number data is decrypted using the first key.

[0132] In this embodiment, the second server generates a third password and a corresponding third key. The second server may use the aforementioned encryption algorithms, such as RSA encryption, digital signature algorithms, elliptic curve cryptography, Data Encryption Standard (DES), Advanced Encryption Standard (AES), Blowfish encryption, etc., to generate the third password and corresponding third key. This embodiment does not limit the scope of the invention. After generating the third password and corresponding third key, the second server sends the third password to the first server. Upon receiving the third password, the first server sends it to the terminal device.

[0133] In this embodiment of the disclosure, after generating a third password and a third key corresponding to the third password, the second server generates a fourth signature based on the third key and sends the fourth signature to the terminal device.

[0134] In this embodiment of the disclosure, after the terminal device receives the third password sent by the first server and the fourth signature sent by the second server, it verifies the fourth signature based on the third password, and after the verification is successful, it decrypts the encrypted code data using the first key.

[0135] In this embodiment of the disclosure, the terminal device verifies the fourth signature to confirm that the code number data is sent by the expected sender (such as the second server) and is not forged by a malicious third party. After the fourth signature is verified, the encrypted code number data is decrypted using the first key. This reduces the need for the terminal device to perform unnecessary decryption processing on invalid or tampered data, thereby improving the overall processing efficiency.

[0136] In some embodiments, the method further includes:

[0137] Receive the first certificate corresponding to the first device certificate from the first server based on the first certificate request;

[0138] The system receives a second device certificate stored in the second server, which is fed back by the second server based on the roaming request; wherein the second device certificate is sent by the first server to the second server.

[0139] The second device certificate is verified based on the first root certificate;

[0140] The step of decrypting the encrypted code data using the first key includes:

[0141] After the second device certificate is verified, the encrypted code number data is decrypted using the first key; wherein, the successful verification of the second device certificate indicates that the first device certificate and the second device certificate are associated with the same terminal device.

[0142] In some embodiments, after receiving a first certificate request from a terminal device, the first server may generate a first root certificate corresponding to the first device certificate and send the first certificate to the terminal device. In other embodiments, the first root certificate may be a certificate pre-generated and stored on the first server. The first root certificate and the first device certificate may be generated simultaneously or not, and this disclosure does not impose any restrictions on this. After receiving the first certificate request from the terminal device, the first server also determines the first root certificate corresponding to the first device certificate. It should be noted that the root certificate is a digital certificate belonging to the certificate authority (here, the first server). It is self-signed, issued and verified by the root certificate authority, and is a core component of the digital certificate system. It is located at the top of the certificate chain and is the starting point of the trust chain.

[0143] In this embodiment of the disclosure, the second server may send a second certificate request to the first server. The second certificate request may carry the device identifier of the terminal device. After receiving the second certificate request from the second server, the first server may generate a second device certificate for the device corresponding to the device identifier carried in the second certificate request and send it to the second server. After receiving the second device certificate, the second server stores it and sends the stored second device certificate to the terminal device after receiving a roaming request sent by the terminal device.

[0144] In this embodiment of the disclosure, after the terminal device receives the first certificate sent by the first server and the second device certificate stored in the second server based on the roaming request feedback from the second server, it verifies the second device certificate based on the first certificate. For example, it can be determined whether the first device certificate and the second device certificate corresponding to the first certificate are associated with the same terminal device. If they are associated with the same terminal device, the verification passes; if they are associated with different terminal devices, the verification fails.

[0145] In this embodiment of the disclosure, after the second device certificate is verified, the terminal device uses the first key to decrypt the encrypted code data.

[0146] In this embodiment of the disclosure, the terminal device uses the first certificate sent by the first server to verify the second device certificate sent by the second server. After the verification is successful, the code number data is decrypted. This confirms that the code number data is sent by the expected sender (such as the second server) and is not forged by a malicious third party. After the second device certificate is verified, the encrypted code number data is decrypted using the first key. This reduces the need for the terminal device to perform unnecessary decryption processing on invalid or tampered data, thereby improving the overall processing efficiency.

[0147] This disclosure also provides a communication method applied in a first server. Figure 2 This is a flowchart of a communication method according to an exemplary embodiment. Figure 2 ,like Figure 2 As shown, it includes the following steps:

[0148] S21. Receive the first certificate request sent by the terminal device;

[0149] S22. Based on the first certificate request, determine the first device certificate;

[0150] S23. Send the first device certificate to the terminal device; wherein, the first device certificate is carried by the terminal device when sending a roaming request to the second server to verify the security of the communication between the terminal device and the second server, and after the security verification is passed, the terminal device obtains roaming-supporting code number data from the second server.

[0151] In this embodiment of the disclosure, as described above, the first server can be a server capable of issuing device certificates that identify the device, such as a certificate issuing center. It should be noted that the first server can be a pre-defined server, such as a self-developed server or a publicly available server; this embodiment of the disclosure does not impose any limitations on this.

[0152] In step S21, the first server receives a first certificate request sent by the terminal device. The first certificate request may carry a device identifier of the terminal device, enabling the first server to issue a device certificate for the corresponding device based on the device identifier. The first certificate request may be a Secure Sockets Layer (SSL) certificate request and / or a Transport Layer Security (TLS) certificate request.

[0153] In step S22, the first server determines the first device certificate based on the first certificate request. As mentioned above, the first server can generate the first device certificate of the terminal device based on the first certificate request. The first device certificate can also be a device certificate of the terminal device that is pre-generated by the first server and stored in the first server. After the first server receives the first certificate request of the terminal device, it determines the first device certificate corresponding to the terminal device.

[0154] In step S23, the first server sends the first device certificate to the terminal device. In some embodiments, when the first certificate request is an SSL and / or TLS certificate request, the first device certificate is an SSL and / or TLS certificate; in other embodiments, the first device certificate may also be a certificate representing the legitimacy of the terminal device.

[0155] In this embodiment of the disclosure, the first device certificate is carried by the terminal device when sending a roaming request to the second server to verify the security of the communication between the terminal device and the second server, and after the security verification is passed, the terminal device obtains roaming-supporting code number data from the second server. The security verification of the communication between the terminal device and the second server using the first device certificate can be performed in the manner described above.

[0156] In this embodiment of the disclosure, the first server receives a first certificate request sent by the terminal device and determines the first device certificate to be fed back to the terminal device so that the terminal device can carry it when sending a roaming request to the second server to verify the security of the communication between the terminal device and the second server. After the security verification is passed, the terminal device can obtain roaming-supporting code number data from the second server. This can effectively reduce the risk of code number data being leaked due to insecure communication between the second server and the terminal device, thereby improving the security of code number data.

[0157] In some embodiments, the first certificate request carries a first password; determining the first device certificate based on the first certificate request includes:

[0158] Based on the first certificate request, the first device certificate is determined, and the first device certificate is encrypted using the first password;

[0159] Sending the first device certificate to the terminal device includes:

[0160] The encrypted first device certificate is sent to the terminal device.

[0161] In this embodiment of the disclosure, the first certificate request received by the first server carries a first password, wherein the first password is generated as described above. Based on the first certificate request, the first server determines the first device certificate, encrypts the first device certificate using the first password, and sends the encrypted first device certificate to the terminal device.

[0162] In this embodiment of the disclosure, transmitting the encrypted first device certificate can improve the confidentiality of the first device certificate during transmission. Even if the encrypted first device certificate is intercepted during transmission, its content cannot be deciphered without the corresponding decryption key, thus providing higher security.

[0163] In some embodiments, the method further includes:

[0164] Send the encrypted first device certificate to the third server;

[0165] Receive the first signature generated by the third server using the encrypted first device certificate and the preset second password;

[0166] The first signature is sent to the terminal device, wherein the first signature is used by the terminal device to decrypt the encrypted first device certificate after the terminal device has verified the certificate.

[0167] In this embodiment of the disclosure, the first server encrypts the first device certificate using a first password and sends the encrypted first device certificate to the third server. After receiving the encrypted first device certificate, the third server generates a first signature based on the encrypted first device certificate and a preset second password, and sends the first signature to the first server. As mentioned above, the third server can be a trusted zone server. Before the terminal device sends the first certificate request to the first server, the third server can interact with the terminal device to generate a second password associated with the terminal device and send the second password to the terminal device. The terminal device stores the second password, and the third server can generate the second password based on the aforementioned symmetric encryption algorithm.

[0168] In this embodiment of the disclosure, after receiving the first signature, the first server sends the first signature to the terminal device, which is used to decrypt the encrypted first device certificate after the terminal device verifies it. The verification method of the first signature and the decryption method of the first device certificate by the terminal device are as described above.

[0169] In this embodiment of the disclosure, the first server sends a first signature generated by the third server based on the encrypted first device certificate and the preset second password to the terminal device, so that the terminal device can decrypt the encrypted first device certificate after verification. This can reduce the unnecessary decryption processing of invalid or tampered data by the terminal device, thereby improving the overall processing efficiency.

[0170] In some embodiments, the first certificate request carries a second signature generated by the terminal device based on a pre-stored second password; determining the first device certificate based on the first certificate request includes:

[0171] The second signature is sent to the third server; wherein the second signature is used by the third server to verify the second password based on a preset password.

[0172] In response to receiving a first notification message from the third server indicating that the second signature verification has passed, the first device certificate is generated.

[0173] In this embodiment of the disclosure, the first certificate request carries a second signature generated by the terminal device based on a pre-stored second password, wherein the second password and the second signature are generated as described above. After receiving the first certificate request carrying the second signature from the terminal device, the first server sends the second signature to the third server, so that the third server can verify the second signature based on a preset second password. After the second signature is verified, the third server sends a first notification message indicating that the second signature verification is successful to the first server. As described above, the third server can compare the preset second password stored in the third server with the second password in the second signature. If they are the same, the verification is successful.

[0174] In this embodiment of the disclosure, after the first server receives the first notification message sent by the third server indicating that the second signature verification has passed, it generates the first device certificate. This can further improve the security and reliability of the generated and transmitted first device certificate, reduce the possibility of malicious attacks and data tampering, and at the same time, if the verification fails, the first device certificate is not generated, which can also reduce the computing burden and memory of the first server.

[0175] In some embodiments, the method further includes:

[0176] Receive a second certificate request sent by a second server; wherein the second certificate request carries the device identifier of the terminal device;

[0177] Determine the second certificate of the terminal device based on the second certificate request;

[0178] The second root certificate is sent to the second server; wherein the second root certificate is used by the second server to verify the first device certificate carried in the roaming request, so as to verify the security of the communication between the terminal device and the second server.

[0179] In this embodiment of the disclosure, the first server receives a second certificate request sent by the second server; wherein the second certificate request carries the device identifier of the terminal device; before sending the second certificate request to the first server, the second server may obtain the device identifier of the terminal device, which may include the International Mobile Equipment Identity (IMEI), the manufacturing date of the terminal device, the model and serial number of the terminal device, etc.

[0180] In this embodiment, the first server determines the second root certificate of the terminal device based on the second certificate request. As mentioned earlier, the root certificate is a digital certificate belonging to a certificate authority (here, the first server). It is self-signed, issued and verified by the root certificate authority, and is a core component of the digital certificate system, located at the top of the certificate chain and serving as the starting point of the trust chain. In some embodiments, the first server may generate the second root certificate of the terminal device based on the second certificate request; in other embodiments, the second root certificate may also be a root certificate of the terminal device pre-generated and stored on the first server. After receiving the second certificate request from the second server, the first server determines the second root certificate of the terminal device. It should be noted that for the same terminal device, the device certificate and root certificate determined or generated by the first server based on the first certificate request or the second certificate request are identical. The first server may also determine or generate the second device certificate of the terminal device based on the second certificate request.

[0181] In this embodiment of the disclosure, after the first server determines the second root certificate, it sends the second root certificate to the second server. The second server verifies the first device certificate carried in the roaming request to verify the security of communication between the terminal device and the second server. The second server verifies the first device certificate to demonstrate the security of communication between the terminal device and the second server, and the second device certificate verification demonstrates that the first device certificate and the second root certificate are associated with the same terminal device.

[0182] In this embodiment, the first server determines the second root certificate based on the second certificate request to verify the first device certificate, thereby verifying the security of communication between the terminal device and the second server. The solution is simple, effective, and highly intelligent.

[0183] In some embodiments, the roaming-supporting code data obtained by the terminal device from the second server is encrypted data; the method further includes:

[0184] Based on the first certificate request, determine the first root certificate corresponding to the first device certificate, and send the first certificate to the terminal device;

[0185] Based on the second certificate request, the second device certificate corresponding to the second root certificate is determined, and the second device certificate is sent to the second server; wherein, the second device certificate is used by the second server to send to the terminal device, so that the terminal device can use the first root certificate to verify the second device certificate, and decrypt the code number data after the verification is successful.

[0186] In this embodiment of the disclosure, a first server determines a first root certificate corresponding to a first device certificate based on a first certificate request, and sends the first root certificate to a terminal device. It then determines a second device certificate corresponding to a second root certificate based on a second certificate request. The second device certificate is the certificate of the terminal device corresponding to the device identifier carried in the second certificate request. The method for determining the first root certificate can be the same as described above for determining the first device certificate, and the method for determining the second device certificate can be the same as described above for determining the second certificate. Therefore, this embodiment of the disclosure will not elaborate further on this aspect.

[0187] It should be noted that the second server may also include the generated fourth password in the second certificate request. After the first server generates the second device certificate, it can encrypt the second device certificate based on the fourth password and send the encrypted second device certificate to the second server. After the second server obtains the encrypted second device certificate, it can decrypt the encrypted second device certificate using the fourth key generated by pairing with the fourth password.

[0188] In this embodiment of the disclosure, after the first server determines the second device certificate, it sends the second device certificate to the second server, which then sends it to the terminal device so that the terminal device can verify the second device certificate using the first certificate and decrypt the code number data after successful verification. The methods for the terminal device to verify the second device certificate and decrypt the code number data after successful verification are as described above.

[0189] In this embodiment, the first server also generates a first root certificate and a second device certificate, and sends the first certificate to the terminal device and the second device certificate to the second server, so that the second server sends the second device certificate to the terminal device, allowing the terminal device to verify the second device certificate using the first certificate, and decrypt the code number data after successful verification. The method of this embodiment can reduce the unnecessary decryption processing of invalid or tampered code number data by the terminal device, thereby improving the overall processing efficiency.

[0190] In some embodiments, the method further includes:

[0191] Receive the fifth signature sent by the second server;

[0192] The step of determining the second root certificate of the terminal device based on the second certificate request includes:

[0193] The fifth signature is verified based on the pre-stored signature negotiated with the second server, and the second root certificate is generated based on the second certificate request after the verification is successful.

[0194] In this embodiment of the disclosure, the first server may negotiate with the second server to determine the signature and store the signature. It should be noted that this embodiment of the disclosure does not limit the way the first server and the second server negotiate the signature.

[0195] In this embodiment of the disclosure, the first server also receives a fifth signature sent by the second server, and verifies the fifth signature based on a pre-stored signature negotiated with the second server. For example, it can compare whether the pre-stored signature negotiated with the second server in the first server is the same as the fifth signature. If they are the same, the verification passes; if they are different, the verification fails. It can also determine whether the pre-stored signature negotiated with the second server in the first server is associated with the fifth signature. If they are associated, the verification passes; if they are not associated, the verification fails.

[0196] In this embodiment of the disclosure, after the first server passes the verification, it generates a second root certificate based on the second certificate request. On the one hand, this confirms that the second certificate request is sent by the expected sender (such as the second server) and not forged by a malicious third party, thus improving security. On the other hand, if the second server fails the verification, it does not generate a second root certificate, which also reduces the computational burden and memory usage of the first server.

[0197] Figure 3 This is an example diagram of a framework for a first server according to an exemplary embodiment, wherein L31 is a data processing module and L32 is a data storage module, as shown below. Figure 3As shown, the first server includes a data processing module L31 and a data storage module L32. The data processing module L31 includes a root certificate generation submodule L311, used to generate root certificates (including a first root certificate and / or a second root certificate), store root certificates, and store root keys; a device certificate generation submodule L312, used to generate device certificates (including a first device certificate and / or a second device certificate), store device certificates, and store device keys; a monitoring submodule L312, used for service monitoring, interface monitoring, and alarms; a terminal (terminal device) interface submodule L314, used to interact with the terminal device and obtain a first certificate request; a card management adapter interface submodule L315, used to interact with the card management adapter and receive requests from the card management adapter to obtain and update certificates; a code number management service (second server) interface submodule L316, used to interact with the code number management service and receive a second certificate request sent by the code number management service; and a trusted zone server (third server) interface submodule L317, used to interact with the trusted zone server and send the terminal device's signature to the trusted zone server so that the trusted zone server can verify the validity of the device. The data storage module L32 includes a remote dictionary service and a MySQL database system, which are used to store the root certificate, device certificate, and data from various databases.

[0198] Figure 4 This is a flowchart illustrating the interaction between a first server and a terminal device according to an exemplary embodiment. L41 is the terminal device; root security application L411, business security application L412, and internet access application L413 are functional modules within the terminal device L41; certificate issuance center L42 is the first server; trusted zone server L43 is the third server; public key 1 is the first password; private key 1 is the first key; and device root key 0 and device root public key 0 are the second passwords. Figure 4 It is known that the Internet application L413 first calls the certificate acquisition interface to the business security application L412. After receiving the call interface instruction from the Internet application L413, the business security application L412 generates public-private key 1 and sends a signature generation instruction to the root security application L411. After receiving the signature generation instruction, the root security application L411 generates a signature (second signature) using the pre-stored device root key 0 and returns it to the business security application L412. The business security application L412 sends the second signature, public key 1, and the device identifier of the terminal device to the Internet application L413. The Internet application L413 requests a certificate from the certificate issuing center L42 (sends the first certificate request), carrying the signature (second signature), public key 1, and the device identifier of the terminal device.

[0199] After receiving the certificate request, the Certificate Issuance Center (CEC) L42 sends the terminal device's device identifier and signature (second signature) to the Trusted Zone Server (TZServer) L43. The TZServer L43 verifies the signature (second signature) using the device's root public key 0 and returns the verification result to the CEC L42. Upon receiving the signature verification result from the TZServer L43, the CEC L42 generates a device certificate (first device certificate) and a root certificate (first root certificate), encrypts the device certificate (first device certificate) using public key 1, and sends both the root certificate (first root certificate) and the encrypted device certificate (first device certificate) to the TZServer L43. The TZServer L43 uses the encrypted device certificate (first device certificate) and the device root key 0 to generate a signature (first signature) and sends the signature (first signature) to the TZServer L43. The signature (first signature), root certificate (first root certificate), and encrypted device certificate (first device certificate) are sent to the Internet application L413. The Internet application L413 sends the signature (first signature), root certificate (first root certificate), and encrypted device certificate (first device certificate) to the business security application L412. The business security application L412 sends the signature (first signature) to the root security application L411. The root security application L411 verifies the signature (first signature) using the device root key 0 and sends the verification result back to the business security application L412. After the verification result received by the business security application L412 indicates that the verification is successful, it decrypts and stores the encrypted device certificate (first device certificate) using the private key 1, and also stores the root certificate (first root certificate).

[0200] This disclosure also provides a communication method applied in a second server. Figure 5 This is a flowchart of a communication method according to an exemplary embodiment. Figure 3 ,like Figure 5 As shown, it includes the following steps:

[0201] S51. Receive a roaming request sent by a terminal device; wherein the roaming request carries a first device certificate obtained by the terminal device through a first server;

[0202] S52. Based on the first device certificate in the roaming request, verify the security of the communication between the terminal device and the second server;

[0203] S53. After the security verification is passed, send the code number data supporting the roaming of the terminal device to the terminal device.

[0204] In this embodiment of the disclosure, as described above, the second server may be a server capable of allocating code data to terminal devices, such as a code management service platform.

[0205] In step S51, the second server receives a roaming request sent by the terminal device, which carries a first device certificate obtained by the terminal device through the first server. The method of obtaining the first device certificate can be as described above. The roaming request may also carry information such as the terminal device's device identifier, device location information, and IP address.

[0206] In step S22, the second server verifies the security of communication between the terminal device and the second server based on the first device certificate in the roaming request. In some embodiments, the second server may verify whether the issuing center of the first device certificate is a preset server. If the first server (e.g., the issuing center) is a preset server, it indicates that the communication is secure; if the first server (e.g., the issuing center) is not a preset server, it indicates that the communication is insecure. In other embodiments, the second server may also verify the validity of the first device certificate, such as verifying whether the issuance time limit of the first device certificate is within a preset time limit, such as 5 minutes. If it is within the preset time limit, it indicates that the communication is secure; if it is not within the preset time limit, it indicates that the communication is insecure.

[0207] In other embodiments, the second server may also send a certificate request to the first server to obtain the device certificate of the terminal device returned by the first server, and verify the security of the communication based on the device certificate of the terminal device returned by the first server and the first device certificate carried in the roaming request. If the device certificate of the terminal device returned by the first server is the same as the first device certificate carried in the roaming request, the communication is secure. If the device certificate of the terminal device returned by the first server is different from the first device certificate carried in the roaming request, the communication is insecure.

[0208] In step S53, after the security verification is passed, the second server sends roaming code data to the terminal device. As mentioned above, the code data may include the telephone number used for roaming, International Mobile Subscriber Identity (IMSI), Mobile Subscriber Integrated Services Digital Network (MSDN) number, Location Area Code (LAC), Mobile Country Code, Mobile Network Code, Globally Unique Temporary User Equipment Identifier (GUE), Service Area Code, etc.

[0209] In this embodiment of the disclosure, after the second server verifies the communication security based on the first device certificate, it then sends the code number data back to the terminal device. This can effectively reduce the risk of code number data being leaked due to insecure communication between the second server and the terminal device, thereby improving the security of the code number data.

[0210] In some embodiments, the method further includes:

[0211] Obtain the device identifier of the terminal device;

[0212] Send a second certificate request carrying the device identifier to the first server;

[0213] Receive the second root certificate returned by the first server based on the second certificate request;

[0214] The step of verifying the security of communication between the terminal device and the second server based on the first device certificate in the roaming request includes:

[0215] The first device certificate is verified based on the second root certificate to verify the security of communication between the terminal device and the second server.

[0216] In this embodiment of the disclosure, the second server obtains the device identifier of the terminal device and sends a second certificate request carrying the device identifier to the first server. As mentioned above, the device identifier of the terminal device may include the International Mobile Equipment Identity (IMEI), the manufacturing date of the terminal device, the model number and serial number of the terminal device, etc.

[0217] In this embodiment, the second server receives a second root certificate from the first server based on a second certificate request, wherein the method for determining the second root certificate is as described above. The second server verifies the first device certificate based on the second root certificate to verify the security of communication between the terminal device and the second server. It should be noted that for the same terminal device, the device certificate and root certificate generated or determined by the first server based on the first certificate request or the second certificate request are identical. The first server may also generate a second device certificate for the terminal device based on the second certificate request. The second server verifies the first device certificate by indicating the security of communication between the terminal device and the second server, and verifies the second device certificate by indicating that the first device certificate and the second root certificate are associated with the same terminal device.

[0218] In this embodiment, the second server uses a second root certificate to verify the first device certificate in order to verify the security of communication between the terminal device and the second server. The solution is simple, effective, and highly intelligent.

[0219] In some embodiments, the method further includes:

[0220] Receive a first password sent by the first server; wherein the first password is sent by the terminal device to the first server;

[0221] After the security verification is passed, the step of sending code number data supporting the roaming of the terminal device to the terminal device includes:

[0222] After the security verification is passed, the code number data encrypted based on the first password is sent to the terminal device.

[0223] In this embodiment, the second server receives a first password sent by the first server. The first password is sent by the terminal device to the first server, and the second server uses the first password to encrypt the code data. After security verification is passed, the second server sends the encrypted code data based on the first password to the terminal device. This embodiment improves the confidentiality of the code data during transmission. Even if the encrypted code data is intercepted during transmission, its content cannot be deciphered without the corresponding decryption key, thus enhancing security.

[0224] In some embodiments, the method further includes:

[0225] Receive a first password sent by the first server; wherein the first password is sent by the terminal device to the first server;

[0226] After sending the code number data to the terminal device, the terminal device receives a third signature and / or the first device certificate sent by the terminal device; wherein the third signature is generated by the terminal device based on a first key generated by pairing with the first password;

[0227] The third signature is verified based on the first password, and / or the first device certificate is verified based on the second root certificate. After the third signature and / or the first device certificate are verified, a second notification message is sent to the terminal device. The second notification message is used by the terminal device to roam based on the code number data after receiving it.

[0228] In this embodiment of the disclosure, the second server receives a first password sent by the first server; wherein the first password is sent by the terminal device to the first server. After sending code data to the terminal device, the second server also receives a third signature and / or a first device certificate sent by the terminal device; wherein the third signature is generated by the terminal device based on a first key generated in conjunction with the first password.

[0229] In this embodiment, the second server verifies the third signature based on the first password and / or verifies the first device certificate based on the second root certificate. After verifying the third signature and / or the first device certificate, the server sends a second notification message to the terminal device, allowing the terminal device to roam based on the code number data upon receiving the second notification message. This embodiment enables the second server to confirm whether the code number data has been received by the preset device (terminal device). Only after the second server confirms that the code number data has been received by the preset device can the receiving device (terminal device) roam based on the code number data, thereby further improving the legitimacy and security of the terminal device's roaming.

[0230] In some embodiments, the method further includes:

[0231] Generate a third password and send the third password to the first server;

[0232] A fourth signature is generated using a third key generated by pairing with the third cryptography;

[0233] The fourth signature is sent to the terminal device; wherein the fourth signature is used by the terminal device to decrypt the code number data after the third password obtained from the first server has been successfully verified.

[0234] In this embodiment of the disclosure, the second server generates a third password and sends the third password to the first server. The second server may use the aforementioned encryption algorithms, such as RSA encryption algorithm, digital signature algorithm, elliptic curve cryptography algorithm, data encryption standard algorithm, advanced encryption standard algorithm, Blowfish encryption algorithm, etc., to generate the third password and the third key corresponding to the third password. This embodiment of the disclosure does not limit this.

[0235] In this embodiment of the disclosure, the second server generates a fourth signature using a third key and sends the fourth signature to the terminal device. After receiving the third key sent by the first server and the fourth signature sent by the second server, the terminal device verifies the fourth signature based on the third key, and after successful verification, decrypts the encrypted code data.

[0236] In this embodiment of the disclosure, the second server generates a fourth signature and sends it to the terminal device. The terminal device verifies the fourth signature and can confirm that the code number data is sent by the expected sender (such as the second server) and is not forged by a malicious third party. After the fourth signature is verified, the encrypted code number data is decrypted using the first key. This can reduce unnecessary decryption processing of invalid or tampered data by the terminal device, thereby improving the overall processing efficiency.

[0237] In some embodiments, the method further includes:

[0238] Receive the second device certificate corresponding to the second root certificate from the first server based on the second certificate request;

[0239] The second device certificate is sent to the terminal device; wherein the second device certificate is used by the terminal device to decrypt the code number data after successful verification.

[0240] In this embodiment of the disclosure, the second server receives the second device certificate corresponding to the second root certificate fed back by the first server based on the second certificate request, and sends the second device certificate to the terminal device. After the terminal device verifies the certificate, it decrypts the code data. The terminal device can use the first root certificate sent by the first server to verify the second device certificate. If it can be determined whether the first device certificate and the second device certificate corresponding to the first certificate are associated with the same terminal device, the verification is successful if they are associated with the same terminal device, and unsuccessful if they are associated with different terminal devices.

[0241] This embodiment of the present disclosure enables the terminal device to confirm that the code number data is sent by the expected sender (such as a second server) and is not forged by a malicious third party. After the second device certificate is verified, the encrypted code number data is decrypted. This can reduce the need for the terminal device to perform unnecessary decryption processing on invalid or tampered data, thereby improving the overall processing efficiency.

[0242] In some embodiments, the method further includes:

[0243] Negotiate with the first server and generate a sixth signature;

[0244] The sixth signature is sent to the first server; wherein the sixth signature is used by the first server to verify the sixth signature based on a pre-stored signature negotiated with the second server, so as to generate the second root certificate after the verification is successful.

[0245] In this embodiment of the disclosure, the second server negotiates with the first server to generate a sixth signature, and the second server sends the sixth signature to the first server. The second server may include the sixth signature when sending the second certificate request. It should be noted that this embodiment of the disclosure does not limit the way the first server and the second server negotiate the signature.

[0246] In this embodiment of the disclosure, the sixth signature is used by the first server to verify the sixth signature based on a pre-stored signature negotiated with the second server, so as to generate a second root certificate after the verification is successful. The first server can compare whether the pre-stored signature negotiated with the second server in the first server is the same as the sixth signature. If they are the same, the verification is successful; if they are different, the verification is unsuccessful. The first server can also determine whether the pre-stored signature negotiated with the second server in the first server is associated with the sixth signature. If they are associated, the verification is successful; if they are not associated, the verification is unsuccessful.

[0247] In this embodiment of the disclosure, after the first server passes the verification, it generates a second root certificate based on the second certificate request. On the one hand, this confirms that the second certificate request is sent by the expected sender (such as the second server) and not forged by a malicious third party, thus improving security. On the other hand, by not generating a second root certificate after the first server fails to verify the sixth signature, the computational burden and memory usage of the first server can be reduced.

[0248] Figure 6 This is an example diagram illustrating the framework of a second server according to an exemplary embodiment, wherein L61 is a data processing module, L62 is a data storage module, the PIN is code data, the algorithm set is a set of algorithms used to generate passwords and keys, the certificate includes a second root certificate and a second device certificate, and the terminal is a terminal device, such as... Figure 6 As shown, the second server includes a data processing module L61 and a data storage module L62. The data processing module L61 includes a service registration submodule L611 for registering services, reporting activity, and changing partners; a code management submodule L612 for card key management, code import / deletion, and algorithm set storage; a key and certificate management submodule L613 for key generation / storage, certificate acquisition, and certificate update; a terminal interface submodule L614 for interacting with terminals, issuing cards (issuing code data), and receiving card issuance callbacks from terminals; a partner service interface submodule L615 for interacting with partner services, sending or receiving commands from partner services to check traffic / status, issue cards, cancel accounts, and stop / start services; a business server interface submodule L616 for interacting with the business server, sending messages such as account cancellation / recycling and card issuance notifications; and a card management adapter interface submodule L617 for interacting with the card management adapter, sending messages such as service registration, partner changes, and activity reporting. The data storage module L62 includes a remote dictionary service and a MySQL database system, which are used to store the root certificate, device certificate, and data from various databases.

[0249] Figure 7 This is a flowchart illustrating the interaction between a first server and a second server according to an exemplary embodiment. In this flowchart, the code management service L71 is the second server, the certificate issuance center L72 is the first server, public key 2 is the third cryptography, and private key 2 is the third key. It should be noted that before requesting a certificate, the code management service L71 negotiates with the certificate issuance center L72 to determine the signature and obtains the device identifier of the terminal device. Figure 7It is known that the code management service L71 first generates public and private key 2. After generating public and private key 2, code management service L71 requests a certificate from certificate issuing center L72 (sending a second certificate request), carrying a signature, device identifier, and public key 2. After receiving the request, certificate issuing center L72 verifies whether the signature is a negotiated signature. After the signature verification is successful, it generates a device certificate (second device certificate) and a root certificate (second root certificate) for the terminal device associated with the device identifier. It then uses public key 2 to encrypt the device certificate (second device certificate) and sends the signature (the signature stored in certificate issuing center L72), the root certificate (second root certificate), and the encrypted device certificate (second device certificate) to code management service L71. After obtaining the signature, code management service L71 verifies the signature. After the verification is successful, it uses private key 2 to decrypt and store the device certificate (second device certificate), and also stores the root certificate (second root certificate).

[0250] Figure 8 This is a flowchart illustrating the interaction between a second server and a terminal device according to an exemplary embodiment. In this flowchart, business security application L81 and internet access application L82 are functional modules within the terminal device; code management service L83 is the second server; public key 1 is the first password; private key 1 is the first key; public key 2 is the third password; private key 2 is the third key; and the algorithm set is a set of algorithms used to generate passwords and keys. Figure 8 It is known that the Internet application L82 generates password 3 and encrypts password 3 using public key 2. Specifically, Internet application L82 obtains public key 2 from the first server and requests a signature from business security application L81. After receiving the signature request from Internet application L82, business security application L81 generates a signature (third signature) using private key 1 and sends the device identifier, signature (third signature), device certificate (first device certificate), and algorithm set to Internet application L82. After receiving the information, Internet application L82 sends a request to obtain the card key (roaming request) to code management service L83, carrying the password 3 encrypted with public key 2, signature (third signature), device identifier, device certificate (first device certificate), and algorithm set.

[0251] After receiving the card key retrieval request sent by the Internet application L82, the code management service L83 verifies the signature (third signature) using public key 1, verifies the device certificate (first device certificate) using the root certificate (second root certificate), and decrypts the password 3 using private key 2. After all verifications are successful, it retrieves the corresponding code resource (code data) based on the device identifier, encrypts specified fields (partial core data) in the code resource (code data) using public key 1 (obtained from the first server), encrypts the entire code resource (code data) using the decrypted password 3, and generates a signature (fourth signature) using private key 2. Based on the device identifier, it determines the corresponding device certificate (second device certificate) obtained by the code management service L83 from the certificate issuing center (first server). The code management service L83 then sends the double-encrypted code data, signature (fourth signature), and device certificate (second device certificate) to the Internet application L82.

[0252] After receiving data from the code management service L83, the Internet application L82 decrypts the entire card key (code data) based on password 3. It then sends the decrypted card key (code data), signature (fourth signature), and device certificate (second device certificate) to the business security application L81. The business security application L81 verifies the device certificate (second device certificate) using the root certificate (first root certificate), verifies the signature (fourth signature) using public key 2, and decrypts a specified field (partial core data) in the code resource (code data) using private key 1. Finally, it sends the decrypted card key (code data) and the signature generated by private key 1 (third signature). The device certificate (first device certificate) is sent to the Internet application L82. After receiving it, the Internet application L82 sends a card issuance callback command to the code management service L83, carrying the signature (third signature), the device certificate (first device certificate), and the order number. The code management service L83 verifies the signature (third signature) using public key 1 and verifies the device certificate (first device certificate) using the root certificate (second root certificate). After successful verification, it returns the result to the Internet application L82. After receiving the command indicating successful verification from the code management service L83, the Internet application L82 performs roaming based on the decrypted card key (code data).

[0253] It should be noted that some code number data can be stored in the partner management service platform. If the code number management service L83 does not find the corresponding code number data in its data storage module based on the device identifier, the code number management service L83 sends a card activation command to the partner management service platform, carrying a signature (third signature), device identifier, and algorithm set. The partner management service platform retrieves the corresponding code number data from the storage area based on the Sahebei identifier, encrypts the specified field using public key 1, and sends the encrypted code number data to the code number management service L83. The code number management service L83 encrypts the entire code number data using password 3, generates a signature (fourth signature) using private key 2, and sends the double-encrypted code number data, signature (fourth signature), and device certificate (second device certificate) to the Internet application L82 for subsequent steps.

[0254] Figure 9 This is a flowchart illustrating a communication method according to an exemplary embodiment, such as... Figure 9 As shown, it includes the following steps:

[0255] S91. The terminal device sends a first certificate request to the first server.

[0256] S92. The first server determines the first device certificate based on the first certificate request;

[0257] S93. The first server sends the first device certificate to the terminal device;

[0258] S94. The terminal device sends a roaming request to the second server; wherein the roaming request carries the certificate of the first device;

[0259] S95. The second server verifies the security of communication between the terminal device and the second server based on the first device certificate in the roaming request.

[0260] S96. After the security verification is passed, the second server sends the code number data supporting the roaming of the terminal device to the terminal device.

[0261] S97. The terminal device roams based on the code number data.

[0262] By employing the above method, the code number data received by the terminal device can be the data fed back by the second server after verifying the communication security based on the certificate of the first device. This can effectively reduce the risk of code number data being leaked due to insecure communication between the second server and the terminal device, thereby improving the security of the code number data.

[0263] Figure 10 This is a framework example of a communication method illustrated according to an exemplary embodiment. Figure 1Among them, Certificate Issuance Server L101 is the first server, Code Management Service Platform L102 is the second server, the root certificate within Code Management Service Platform L102 is the second root certificate, the device certificate is the second device certificate, Terminal L103 is the terminal device, Global Internet Application L1031 is the software application within Terminal L103, Secure Application Storage L1032 is the hardware module within Terminal L103, the root certificate within Secure Application Storage L1032 is the first certificate, the device certificate is the first device certificate, and Trusted Zone Server L104 is the third server. Figure 10 As shown, the certificate issuing server L101 uses the trusted zone server L104 to verify the validity of the terminal L103. The certificate issuing server L101 distributes certificates to the secure application storage L1032 and the code number management service platform L102. The code number management service platform L102 communicates with the global Internet application L1031 based on the secure hypertext transfer protocol channel.

[0264] Figure 11 This is a framework example of a communication method illustrated according to an exemplary embodiment. Figure 2 Among them, the Certificate Issuance Center (L111) is the first server, the Secure Application Storage (L112) is the hardware module within the terminal device, the Nationwide Internet Access Application (L113) is the software application within the terminal device, the Business Service (L114) and the Business Operation Support System Service (L118) are both upper-layer business services, the Management Service Platform (L115) is the platform for managing code number data, the code number management service within the Management Service Platform (L115) is the second server, the Partner (L116) is the operator, and the Trusted Zone (L117) is the third server. For example... Figure 11As shown, the security application storage L112 includes a business security application storage and a root security application storage; the nationwide internet access application L113 includes a business logic submodule, a local discovery service submodule, and a local configuration service submodule. The business logic submodule may include a code number recycling module, an order module, an authentication module, etc. The local discovery service submodule is used for data discovery and path discovery, and the local configuration service submodule is used for data configuration and path configuration. The business service L114 includes a global internet access submodule and a one-yuan traffic submodule, which are used for account management, payment management, order management, package management, etc. The management service platform L115 includes a partner management service, a code number management service, and a card management adapter. The partner management service includes an access point configuration center, a code configuration center, and a basic configuration center, etc.; the code number management service creates and protects configuration files; the card management adapter is used for event retrieval, event registration, and event deletion. The trusted zone L117 is used for signature verification and device validity verification. The Business Operation Support System Service L118 includes a billing service module, a call detail record (CDR) service module, an account service module, and a package management module. The billing service module is used for billing package management, monitoring and early warning services, etc.; the CDR service module is used for client-side CDR storage, server-side CDR storage, etc.; the account service module is used for account management, order management, real-name management, etc.; and the package management module is used for user package management, partner package management, package binding management, etc.

[0265] Figure 12 This is a communication device 1200 frame according to an exemplary embodiment. Figure 1 .like Figure 12 As shown, the communication device 1200 mainly includes:

[0266] The first certificate request sending module 1201 is configured to send a first certificate request to the first server;

[0267] The first device certificate receiving module 1202 is configured to receive the first device certificate fed back by the first server based on the first certificate request.

[0268] The roaming request sending module 1203 is configured to send a roaming request to a second server; wherein the roaming request carries the first device certificate, and the first device certificate is used by the second server to verify the security of communication between the terminal device and the second server;

[0269] The code number data receiving module 1204 is configured to receive code number data fed back by the second server based on the roaming request; wherein the code number data is sent by the second server after the security verification is passed, and the code number data is used to support the roaming of the terminal device;

[0270] The roaming module 1205 is configured to roam based on the code number data.

[0271] In some embodiments, the first certificate request carries a first password, and the first device certificate is a certificate encrypted by the first server using the first password; the apparatus further includes:

[0272] The first key decryption certificate module is configured to decrypt the first device certificate using a first key generated by pairing with the first password;

[0273] The roaming request sending module 1203 is further configured to send a roaming request carrying the decrypted first device certificate to the second server.

[0274] In some embodiments, the apparatus further includes:

[0275] The first signature receiving module is configured to receive a first signature sent by the first server; wherein the first signature is generated by the third server using the encrypted first device certificate sent by the first server and a preset second password, and then sent to the first server.

[0276] The first signature verification module is configured to verify the first signature based on the encrypted first device certificate and the second password pre-stored in the terminal device;

[0277] The first key decryption certificate module is further configured to decrypt the first device certificate using a first key generated by pairing with the first password after the first signature verification is passed.

[0278] In some embodiments, the apparatus further includes:

[0279] The second signature generation module is configured to generate a second signature based on the pre-stored second password;

[0280] The first certificate request sending module 1201 is further configured to send a first certificate request carrying the second signature to the first server; wherein the second signature is used by the first server to send to the third server for verification;

[0281] The first device certificate receiving module 1202 is further configured to receive the first device certificate generated and fed back by the first server after receiving the first notification message; wherein, the first notification message is sent to the first server by the third server after the second signature is verified.

[0282] In some embodiments, the apparatus further includes:

[0283] The third signature generation module is configured to generate a third signature based on the first key;

[0284] The third signature and / or first device certificate sending module is configured to send the third signature and / or decrypted first device certificate to the second server after receiving the code number data; wherein the third signature and / or decrypted first device certificate is used by the second server for verification;

[0285] The roaming module 1205 is further configured to roam based on the code number data in response to receiving a second notification message sent by the second server; wherein the second notification message is sent by the second server after verifying the first device certificate after the third signature and / or decryption is passed.

[0286] In some embodiments, the code data received by the terminal device is data encrypted by the second server using the first password obtained from the first server; the apparatus further includes:

[0287] The first key decryption data module is configured to use the first key to decrypt the encrypted code number data;

[0288] The roaming module 1205 is also configured to roam based on the decrypted code number data.

[0289] In some embodiments, the apparatus further includes:

[0290] The third password receiving module is configured to receive a third password sent by the first server; wherein the third password is generated by the second server and then sent to the first server.

[0291] The fourth signature receiving module is configured to receive a fourth signature sent by the second server; wherein the fourth signature is generated by the second server using a third key generated in conjunction with the third cryptography;

[0292] The fourth signature verification module is configured to verify the fourth signature based on the third password;

[0293] The first key decryption data module is further configured to decrypt the encrypted code number data using the first key after the fourth signature verification is passed.

[0294] In some embodiments, the apparatus further includes:

[0295] The first certificate receiving module is configured to receive the first certificate corresponding to the first device certificate fed back by the first server based on the first certificate request;

[0296] The second device certificate receiving module is configured to receive a second device certificate stored in the second server, which is fed back by the second server based on the roaming request; wherein the second device certificate is sent by the first server to the second server;

[0297] The second device certificate verification module is configured to verify the second device certificate based on the first certificate;

[0298] The first key decryption data module is further configured to decrypt the encrypted code number data using the first key after the second device certificate is verified; wherein, the verification of the second device certificate indicates that the first device certificate and the second device certificate are associated with the same terminal device.

[0299] Figure 13 This is a communication device 1300 frame according to an exemplary embodiment. Figure 2 .like Figure 13 As shown, the communication device 1300 mainly includes:

[0300] The first certificate request receiving module 1301 is configured to receive the first certificate request sent by the terminal device.

[0301] The first device certificate determination module 1302 is configured to determine the first device certificate based on the first certificate request;

[0302] The first device certificate sending module 1303 is configured to send the first device certificate to the terminal device; wherein, the first device certificate is carried by the terminal device when sending a roaming request to the second server to verify the security of the communication between the terminal device and the second server, and after the security verification is passed, the terminal device obtains roaming-supporting code number data from the second server.

[0303] In some embodiments, the first certificate request carries a first password; the first device certificate determination module 1302 is further configured to determine the first device certificate based on the first certificate request, and encrypt the first device certificate using the first password;

[0304] The first device certificate sending module 1303 is further configured to send the encrypted first device certificate to the terminal device.

[0305] In some embodiments, the apparatus further includes:

[0306] The encrypted first device certificate sending module is configured to send the encrypted first device certificate to a third server;

[0307] The first signature receiving module is configured to receive a first signature generated by the third server using the encrypted first device certificate and a preset second password;

[0308] The first signature sending module is configured to send the first signature to the terminal device, wherein the first signature is used by the terminal device to decrypt the encrypted first device certificate after the terminal device has verified the signature.

[0309] In some embodiments, the first certificate request carries a second signature generated by the terminal device based on a pre-stored second password; the first device certificate determination module 1302 is further configured to send the second signature to a third server; wherein the second signature is used by the third server for verification based on a preset second password; and in response to receiving a first notification message from the third server indicating that the second signature verification has passed, the first device certificate is generated.

[0310] In some embodiments, the apparatus further includes:

[0311] The second certificate request receiving module is configured to receive a second certificate request sent by a second server; wherein the second certificate request carries the device identifier of the terminal device;

[0312] The second certificate determination module is configured to determine the second certificate of the terminal device based on the second certificate request;

[0313] The second certificate sending module is configured to send the second certificate to the second server; wherein the second certificate is used by the second server to verify the first device certificate carried in the roaming request, so as to verify the security of the communication between the terminal device and the second server.

[0314] In some embodiments, the roaming-supporting code data obtained by the terminal device from the second server is encrypted data; the apparatus further includes:

[0315] The first certificate sending module is configured to determine the first certificate corresponding to the first device certificate based on the first certificate request, and send the first certificate to the terminal device.

[0316] The second device certificate sending module is configured to determine the second device certificate corresponding to the second root certificate based on the second certificate request, and send the second device certificate to the second server; wherein, the second device certificate is used by the second server to send to the terminal device, so that the terminal device can use the first root certificate to verify the second device certificate, and decrypt the code number data after the verification is successful.

[0317] In some embodiments, the apparatus further includes:

[0318] The fifth signature receiving module is configured to receive the fifth signature sent by the second server;

[0319] The second root certificate determination module is further configured to verify the fifth signature based on a pre-stored signature negotiated with the second server, and generate the second root certificate based on the second certificate request after the verification is successful.

[0320] Figure 14 This is a communication device 1400 frame according to an exemplary embodiment. Figure 3 .like Figure 14 As shown, the communication device 1400 mainly includes:

[0321] The roaming request receiving module 1401 is configured to receive a roaming request sent by a terminal device; wherein the roaming request carries a first device certificate obtained by the terminal device through a first server;

[0322] The security verification module 1402 is configured to verify the security of communication between the terminal device and the second server based on the first device certificate in the roaming request.

[0323] The code number data sending module 1403 is configured to send code number data supporting the roaming of the terminal device to the terminal device after the security verification is passed.

[0324] In some embodiments, the apparatus further includes:

[0325] The device identifier acquisition module is configured to acquire the device identifier of the terminal device.

[0326] The second certificate request sending module is configured to send a second certificate request carrying the device identifier to the first server;

[0327] The second certificate receiving module is configured to receive the second certificate returned by the first server based on the second certificate request;

[0328] The security verification module 1402 is further configured to verify the first device certificate based on the second root certificate, so as to verify the security of communication between the terminal device and the second server.

[0329] In some embodiments, the apparatus further includes:

[0330] The first password receiving module is configured to receive a first password sent by the first server; wherein the first password is sent by the terminal device to the first server;

[0331] The code number data sending module 1403 is further configured to send the code number data encrypted based on the first password to the terminal device after the security verification is passed.

[0332] In some embodiments, the apparatus further includes:

[0333] The first password receiving module is configured to receive a first password sent by the first server; wherein the first password is sent by the terminal device to the first server;

[0334] The third signature and / or first device certificate receiving module is configured to receive the third signature and / or first device certificate sent by the terminal device after sending the code number data to the terminal device; wherein, the third signature is generated by the terminal device based on the first key generated by pairing with the first password;

[0335] The third signature and / or first device certificate verification module is configured to verify the third signature based on the first password and / or verify the first device certificate based on the second root certificate, and send a second notification message to the terminal device after the third signature and / or the first device certificate are verified successfully; wherein, the second notification message is used by the terminal device to roam based on the code number data after receiving it.

[0336] In some embodiments, the apparatus further includes:

[0337] The third password sending module is configured to generate a third password and send the third password to the first server;

[0338] The fourth signature generation module is configured to generate a fourth signature using a third key generated in conjunction with the third cryptography;

[0339] The fourth signature sending module is configured to send the fourth signature to the terminal device; wherein the fourth signature is used by the terminal device to decrypt the code number data after the third password obtained from the first server has been successfully verified.

[0340] In some embodiments, the apparatus further includes:

[0341] The second device certificate receiving module is configured to receive the second device certificate corresponding to the second root certificate fed back by the first server based on the second certificate request.

[0342] The second device certificate sending module is configured to send the second device certificate to the terminal device; wherein, the second device certificate is used by the terminal device to decrypt the code number data after successful verification.

[0343] In some embodiments, the apparatus further includes:

[0344] The sixth signature generation module is configured to negotiate with the first server and generate a sixth signature;

[0345] The sixth signature sending module is configured to send the sixth signature to the first server; wherein the sixth signature is used by the first server to verify the sixth signature based on a pre-stored signature negotiated with the second server, so as to generate the second root certificate after the verification is successful.

[0346] Regarding the apparatus in the above embodiments, the specific manner in which each module performs its operation has been described in detail in the embodiments related to the method, and will not be elaborated upon here.

[0347] This disclosure also provides a communication system, the system comprising:

[0348] The terminal device is used to send a first certificate request to the first server;

[0349] The first server is configured to determine a first device certificate based on the first certificate request, and send the first device certificate to the terminal device;

[0350] The terminal device is also used to send a roaming request carrying the certificate of the first device to the second server;

[0351] The second server is used to verify the security of the communication between the terminal device and the second server based on the first device certificate in the roaming request, and send code number data supporting the roaming of the terminal device to the terminal device after the security verification is passed;

[0352] The terminal device is also used for roaming based on the code number data.

[0353] The communication system of this disclosure can effectively reduce the risk of code data leakage caused by insecure communication between the second server and the terminal device, thereby improving the security of code data.

[0354] Figure 15 This is a structural block diagram of a terminal device 1500 according to an exemplary embodiment. For example, the terminal device 1500 may be a mobile phone, computer, digital broadcasting terminal, messaging device, game console, tablet device, fitness equipment, personal digital assistant, or other roaming device, and the terminal device is the aforementioned terminal device that performs the communication method.

[0355] Reference Figure 15The terminal device 1500 may include one or more of the following components: processing component 1502, memory 1504, power supply component 1506, multimedia component 1508, audio component 1510, input / output (I / O) interface 1512, sensor component 1514, and communication component 1516.

[0356] Processing component 1502 typically controls the overall operation of terminal device 1500, such as operations associated with at least one of display, telephone call, data communication, camera operation, and recording operation. Processing component 1502 may include one or more processors 1520 to execute instructions to perform all or part of the steps of the methods described above. Furthermore, processing component 1502 may include one or more modules to facilitate interaction between processing component 1502 and other components. For example, processing component 1502 may include a multimedia module to facilitate interaction between multimedia component 1508 and processing component 1502.

[0357] Memory 1504 is configured to store various types of data to support operation on terminal device 1500. Examples of such data include at least one of the following: instructions for any application or method operating on terminal device 1500, contact data, phonebook data, messages, pictures, and videos. Memory 1504 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0358] Power supply component 1506 provides power to various components of terminal device 1500. Power supply component 1506 may include at least one of the following: a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to terminal device 1500.

[0359] Multimedia component 1508 includes a screen that provides an output interface between terminal device 1500 and the user. In some embodiments, the screen may include a Liquid Crystal Display (LCD) and a Touch Panel (TP). If the screen includes a Touch Panel, the screen may be implemented as a touchscreen to receive input signals from the user. The Touch Panel includes one or more touch sensors to sense touches, swipes, and gestures on the Touch Panel. The touch sensors may sense not only the boundaries of touch or swipe actions but also the duration and pressure associated with the touch or swipe operation. In some embodiments, multimedia component 1508 includes a front-facing camera and / or a rear-facing camera. When terminal device 1500 is in an operating mode, such as a shooting mode or a video mode, the front-facing camera and / or rear-facing camera may receive external multimedia data. Each front-facing camera and rear-facing camera may be a fixed optical lens system or have focal length and optical zoom capabilities.

[0360] Audio component 1510 is configured to output and / or input audio signals. For example, audio component 1510 includes a microphone (MIC) configured to receive external audio signals when terminal device 1500 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 1504 or transmitted via communication component 1516. In some embodiments, audio component 1510 also includes a speaker for outputting audio signals.

[0361] I / O interface 1512 provides an interface between processing component 1502 and peripheral interface modules, such as keyboards, click wheels, and buttons. These buttons may include, but are not limited to, home buttons, volume buttons, power buttons, and lock buttons.

[0362] Sensor assembly 1514 includes one or more sensors for providing state assessments of various aspects of terminal device 1500. For example, sensor assembly 1514 may detect the on / off state of terminal device 1500, the relative positioning of components such as the display and keypad of terminal device 1500, changes in position of terminal device 1500 or one of its components, the presence or absence of user contact with terminal device 1500, orientation or acceleration / deceleration of terminal device 1500, and temperature changes of terminal device 1500. Sensor assembly 1514 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 1514 may also include an optical sensor, such as a complementary metal-oxide-semiconductor (CMOS) or charge-coupled device (CCD) image sensor, for use in imaging applications. In some embodiments, sensor assembly 1514 may also include, but is not limited to, at least one of the following: an accelerometer, a gyroscope, a magnetometer, a pressure sensor, and a temperature sensor.

[0363] Communication component 1516 is configured to facilitate wired or wireless communication between terminal device 1500 and other devices. Terminal device 1500 can access wireless networks based on communication standards, such as Wi-Fi, 4G, 5G, or combinations thereof. In one exemplary embodiment, communication component 1516 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 1516 also includes a Near Field Communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on Radio Frequency Identification (RFID), Infrared Data Association (IrDA), Ultra Wide Band (UWB), Bluetooth (BT), and other technologies.

[0364] In an exemplary embodiment, the terminal device 1500 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components.

[0365] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 1504 including executable instructions or a computer program, which can be executed by the processor 1520 of the terminal device 1500 to perform the above-described method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), a compact disc read-only memory (CD-ROM), magnetic tape, floppy disk, and optical data storage device, etc.

[0366] A non-transitory computer-readable storage medium, when the instructions in the storage medium are executed by the processor of a terminal device, enables the terminal device to perform any of the communication methods described above in the embodiments of this disclosure.

[0367] This disclosure provides a computer program product comprising a computer program or executable instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer program or executable instructions from the computer-readable storage medium and executes the computer program or executable instructions, causing the computer device to perform any of the communication methods described in this disclosure. It should be noted that the computer device here includes any of the aforementioned terminal device, first server, and second server.

[0368] Figure 16 This is a structural block diagram of a server 1600 according to an exemplary embodiment. For example, the server 1600 can be provided as a server, and the server 1600 can be the aforementioned first server or second server. (Refer to...) Figure 16Server 1600 includes processing component 1622, which further includes one or more processors, and memory resources represented by memory 1632 for storing instructions, such as application programs, that can be executed by processing component 1622. The application programs stored in memory 1632 may include one or more modules, each corresponding to a set of instructions. Furthermore, processing component 1622 is configured to execute instructions to perform any of the aforementioned communication methods applied to the first server or the second server.

[0369] Server 1600 may also include a power supply component 1626 configured to perform power management for server 1600, a wired or wireless network interface 1650 configured to connect server 1600 to a network, and an input / output (I / O) interface 1658. Server 1600 can operate an operating system stored in memory 1632, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, or similar.

[0370] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the claims.

[0371] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

Claims

1. A communication method, characterized in that, The method includes: Send the first certificate request to the first server; Receive the first device certificate returned by the first server based on the first certificate request; Send a roaming request to the second server; wherein the roaming request carries the first device certificate, the first device certificate being used by the second server to verify the security of communication between the terminal device and the second server; The system receives code data from the second server based on the roaming request; wherein the code data is sent by the second server after the security verification is passed, and the code data is used to support the roaming of the terminal device. Roaming is performed based on the code number data.

2. The method according to claim 1, characterized in that, The first certificate request carries a first password, and the first device certificate is a certificate encrypted by the first server using the first password; The method further includes: The first device certificate is decrypted using the first key generated by pairing with the first password; Sending a roaming request to the second server includes: Send a roaming request carrying the decrypted certificate of the first device to the second server.

3. The method according to claim 2, characterized in that, The method further includes: Receive a first signature sent by the first server; wherein the first signature is generated by the third server using the encrypted first device certificate sent by the first server and a preset second password, and then sent to the first server; The first signature is verified based on the encrypted first device certificate and the second password pre-stored in the terminal device; The step of decrypting the first device certificate using the first key generated by pairing with the first password includes: After the first signature verification is successful, the first device certificate is decrypted using the first key generated by pairing with the first password.

4. The method according to claim 3, characterized in that, The method further includes: A second signature is generated based on the pre-stored second password; Sending the first certificate request to the first server includes: A first certificate request carrying the second signature is sent to the first server; wherein the second signature is used by the first server to send to the third server for verification. Receiving the first device certificate returned by the first server based on the first certificate request includes: The system receives the first device certificate generated and fed back by the first server after receiving the first notification message; wherein the first notification message is sent to the first server by the third server after the second signature has been verified.

5. The method according to any one of claims 2 to 4, characterized in that, The method further includes: A third signature is generated based on the first key; Upon receiving the code number data, the third signature and / or the decrypted first device certificate is sent to the second server; wherein, the third signature and / or the decrypted first device certificate is used by the second server for verification. The roaming based on the code number data includes: In response to receiving a second notification message from the second server, roaming is performed based on the code number data; wherein, the second notification message is sent by the second server after the verification of the first device certificate after the third signature and / or decryption is successful.

6. The method according to any one of claims 2 to 4, characterized in that, The code data received by the terminal device is data encrypted by the second server using the first password obtained from the first server; The method further includes: The encrypted code data is decrypted using the first key; The roaming based on the code number data includes: Roaming is performed based on the decrypted code data.

7. The method according to claim 6, characterized in that, The method further includes: Receive a third password sent by the first server; wherein the third password is generated by the second server and then sent to the first server; Receive a fourth signature sent by the second server; wherein the fourth signature is generated by the second server using a third key generated in conjunction with the third cryptography; The fourth signature is verified based on the third cryptography; The step of decrypting the encrypted code data using the first key includes: After the fourth signature verification is successful, the encrypted code number data is decrypted using the first key.

8. The method according to claim 6, characterized in that, The method further includes: Receive the first certificate corresponding to the first device certificate from the first server based on the first certificate request; The system receives a second device certificate stored in the second server, which is fed back by the second server based on the roaming request; wherein the second device certificate is sent by the first server to the second server. The second device certificate is verified based on the first root certificate; The step of decrypting the encrypted code data using the first key includes: After the second device certificate is verified, the encrypted code number data is decrypted using the first key; wherein, the successful verification of the second device certificate indicates that the first device certificate and the second device certificate are associated with the same terminal device.

9. A communication method, characterized in that, Applied to a first server, the method includes: Receive the first certificate request sent by the terminal device; Based on the first certificate request, determine the first device certificate; The first device certificate is sent to the terminal device; wherein, the first device certificate is carried by the terminal device when sending a roaming request to the second server to verify the security of the communication between the terminal device and the second server, and after the security verification is passed, the terminal device obtains the roaming support code number data from the second server.

10. The method according to claim 9, characterized in that, The first certificate request carries a first password; determining the first device certificate based on the first certificate request includes: Based on the first certificate request, the first device certificate is determined, and the first device certificate is encrypted using the first password; Sending the first device certificate to the terminal device includes: The encrypted first device certificate is sent to the terminal device.

11. The method according to claim 10, characterized in that, The method further includes: Send the encrypted first device certificate to the third server; Receive the first signature generated by the third server using the encrypted first device certificate and the preset second password; The first signature is sent to the terminal device, wherein the first signature is used by the terminal device to decrypt the encrypted first device certificate after the terminal device has verified the certificate.

12. The method according to claim 9, characterized in that, The first certificate request carries a second signature generated by the terminal device based on a pre-stored second password; determining the first device certificate based on the first certificate request includes: The second signature is sent to the third server; wherein the second signature is used by the third server to verify the second password based on a preset password. In response to receiving a first notification message from the third server indicating that the second signature verification has passed, the first device certificate is generated.

13. The method according to claim 9, characterized in that, The method further includes: Receive a second certificate request sent by a second server; wherein the second certificate request carries the device identifier of the terminal device; Determine the second certificate of the terminal device based on the second certificate request; The second root certificate is sent to the second server; wherein the second root certificate is used by the second server to verify the first device certificate carried in the roaming request, so as to verify the security of the communication between the terminal device and the second server.

14. The method according to claim 13, characterized in that, The terminal device obtains roaming-supporting code data from the second server as encrypted data; the method further includes: Based on the first certificate request, determine the first root certificate corresponding to the first device certificate, and send the first certificate to the terminal device; Based on the second certificate request, the second device certificate corresponding to the second root certificate is determined, and the second device certificate is sent to the second server; wherein, the second device certificate is used by the second server to send to the terminal device, so that the terminal device can use the first root certificate to verify the second device certificate, and decrypt the code number data after the verification is successful.

15. The method according to claim 13, characterized in that, The method further includes: Receive the fifth signature sent by the second server; The step of determining the second root certificate of the terminal device based on the second certificate request includes: The fifth signature is verified based on the pre-stored signature negotiated with the second server, and the second root certificate is generated based on the second certificate request after the verification is successful.

16. A communication method, characterized in that, When applied to a second server, the method includes: Receive a roaming request sent by a terminal device; wherein the roaming request carries a first device certificate obtained by the terminal device through a first server; Based on the first device certificate in the roaming request, verify the security of the communication between the terminal device and the second server; After the security verification is passed, code number data supporting the roaming of the terminal device is sent to the terminal device.

17. The method according to claim 16, characterized in that, The method further includes: Obtain the device identifier of the terminal device; Send a second certificate request carrying the device identifier to the first server; Receive the second root certificate returned by the first server based on the second certificate request; The step of verifying the security of communication between the terminal device and the second server based on the first device certificate in the roaming request includes: The first device certificate is verified based on the second root certificate to verify the security of communication between the terminal device and the second server.

18. The method according to claim 17, characterized in that, The method further includes: Receive a first password sent by the first server; wherein the first password is sent by the terminal device to the first server; After the security verification is passed, the step of sending code number data supporting the roaming of the terminal device to the terminal device includes: After the security verification is passed, the code number data encrypted based on the first password is sent to the terminal device.

19. The method according to claim 17, characterized in that, The method further includes: Receive a first password sent by the first server; wherein the first password is sent by the terminal device to the first server; After sending the code number data to the terminal device, the terminal device receives a third signature and / or the first device certificate sent by the terminal device; wherein the third signature is generated by the terminal device based on a first key generated by pairing with the first password; The third signature is verified based on the first password, and / or the first device certificate is verified based on the second root certificate. After the third signature and / or the first device certificate are verified, a second notification message is sent to the terminal device. The second notification message is used by the terminal device to roam based on the code number data after receiving it.

20. The method according to claim 18, characterized in that, The method further includes: Generate a third password and send the third password to the first server; A fourth signature is generated using a third key generated by pairing with the third cryptography; The fourth signature is sent to the terminal device; wherein the fourth signature is used by the terminal device to decrypt the code number data after the third password obtained from the first server has been successfully verified.

21. The method according to claim 18, characterized in that, The method further includes: Receive the second device certificate corresponding to the second root certificate from the first server based on the second certificate request; The second device certificate is sent to the terminal device; wherein the second device certificate is used by the terminal device to decrypt the code number data after successful verification.

22. The method according to claim 17, characterized in that, The method further includes: Negotiate with the first server and generate a sixth signature; The sixth signature is sent to the first server; wherein the sixth signature is used by the first server to verify the sixth signature based on a pre-stored signature negotiated with the second server, so as to generate the second root certificate after the verification is successful.

23. A communication device, characterized in that, The device includes: The first certificate request sending module is configured to send a first certificate request to the first server; The first device certificate receiving module is configured to receive the first device certificate fed back by the first server based on the first certificate request. A roaming request sending module is configured to send a roaming request to a second server; wherein the roaming request carries the first device certificate, and the first device certificate is used by the second server to verify the security of communication between the terminal device and the second server; The code number data receiving module is configured to receive code number data fed back by the second server based on the roaming request; wherein the code number data is sent by the second server after the security verification is passed, and the code number data is used to support the roaming of the terminal device; The roaming module is configured to roam based on the code number data.

24. A communication device, characterized in that, The device, used in a first server, includes: The first certificate request receiving module is configured to receive the first certificate request sent by the terminal device. The first device certificate determination module is configured to determine the first device certificate based on the first certificate request; The first device certificate sending module is configured to send the first device certificate to the terminal device; wherein, the first device certificate is carried by the terminal device when sending a roaming request to the second server to verify the security of the communication between the terminal device and the second server, and after the security verification is passed, the terminal device obtains roaming-supporting code number data from the second server.

25. A communication device, characterized in that, The device, used in a second server, includes: A roaming request receiving module is configured to receive a roaming request sent by a terminal device; wherein the roaming request carries a first device certificate obtained by the terminal device through a first server; The security verification module is configured to verify the security of communication between the terminal device and the second server based on the first device certificate in the roaming request. The code number data sending module is configured to send code number data supporting the roaming of the terminal device to the terminal device after the security verification is passed.

26. A communication system, characterized in that, The system includes: The terminal device is used to send a first certificate request to the first server; The first server is configured to determine a first device certificate based on the first certificate request, and send the first device certificate to the terminal device; The terminal device is also used to send a roaming request carrying the certificate of the first device to the second server; The second server is used to verify the security of the communication between the terminal device and the second server based on the first device certificate in the roaming request, and send code number data supporting the roaming of the terminal device to the terminal device after the security verification is passed; The terminal device is also used for roaming based on the code number data.

27. An electronic device, characterized in that, include: processor; Memory used to store computer programs or instructions; The processor executes the computer program or instructions to implement the steps of the communication method according to any one of claims 1 to 8; or to implement the steps of the communication method according to any one of claims 9 to 15; or to implement the steps of the communication method according to any one of claims 16 to 22.

28. A non-transitory computer-readable storage medium storing a computer program or instructions, characterized in that, When the computer program or instructions in the storage medium are executed by a processor, the steps of the communication method according to any one of claims 1 to 8 are implemented; or, the steps of the communication method according to any one of claims 9 to 15 are implemented; or, the steps of the communication method according to any one of claims 16 to 22 are implemented.

29. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the communication method according to any one of claims 1 to 8; or, implement the steps of the communication method according to any one of claims 9 to 15; or, implement the steps of the communication method according to any one of claims 16 to 22.