Terminal verification method, terminal verification device, and computer storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-29
- Publication Date
- 2026-08-14
AI Technical Summary
[0003]然而,现有技术高度依赖IMEI这一终端标识的安全性,而IMEI由终端生产厂商以明文形式存储于终端内部,易被恶意攻击者窃取或通过终端模拟软件伪造,从而导致SIM卡与IMEI的绑定关系被非法绕过,造成身份冒用或非法接入风险
[0015]与现有技术相比,本申请的有益效果是:在验证待识别终端是否是目标终端时,根据所述待识别终端所装载的SIM卡的唯一标识,即国际移动用户识别码,从识别码库中提取目标安全识别码,并将该目标安全识别码与所述待识别终端的待校验安全识别码进行比对,以获得该待识别终端是否是合法装载该SIM卡的目标终端的验证结果。其中,所述目标安全识别码为所述目标终端的唯一识别码,且由所述通信平台加密生成,是一种不依赖于终端固有硬件标识的新型认证机制。并且,所述目标安全识别码由受信的通信平台统一生成、加密并管理,能够从根本上规避因硬件标识明文存储、易于被窃取和仿冒所带来的安全风险,实现认证凭证的中心化控制,显著提升终端身份验证的防伪能力和系统的整体安全性。此外,通信平台通过用户信息、安全识别码、和SIM卡之间的绑定关系,在验证过程中实现了基于用户信息、SIM卡身份识别码与终端安全识别码的联合鉴权,能够有效验证终端和SIM卡之间的绑定关系是否合乎预期,确保只有经过合法注册的终端在对应SIM卡及合法用户的操作下才能通过认证,进一步提升了身份验证的精确性与可靠性。
Smart Images

Figure CN122579134A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and in particular to a terminal verification method, a terminal verification device, and a computer storage medium. Background Technology
[0002] To achieve secure access and service authentication for terminals in mobile communication networks, existing technologies primarily rely on a dual authentication mechanism between the SIM (Subscriber Identity Module) card and the IMEI (International Mobile Equipment Identity). First, when a terminal accesses the mobile communication network, it verifies the legitimacy of the SIM card through the operator's authentication system, ensuring the security and reliability of the communication link. Then, the operator binds the SIM card number to the IMEI, and when the terminal accesses the mobile communication network, it compares the IMEI reported by the terminal with the IMEI corresponding to the SIM card number to determine whether the SIM card is being used legitimately in the terminal, thereby deciding whether the terminal can conduct communication services.
[0003] However, existing technologies heavily rely on the security of the IMEI, the terminal identifier. The IMEI is stored in plaintext by the terminal manufacturer, making it vulnerable to theft by malicious attackers or forgery using terminal emulation software. This allows the binding relationship between the SIM card and the IMEI to be illegally bypassed, leading to identity theft or unauthorized access risks. More critically, existing technologies, whether verifying at the network or terminal side, do not fundamentally address the inherent vulnerability of the IMEI to forgery. This leaves the entire SIM card binding authentication mechanism susceptible to breaches, severely impacting the reliability of mobile communication network access authentication and the security of terminal services. Therefore, there is an urgent need for a terminal verification method that can break free from reliance on the plaintext IMEI identifier to achieve more secure and reliable terminal identity verification. Summary of the Invention
[0004] To address the aforementioned technical problems, this application provides a terminal verification method, a terminal verification device, and a computer storage medium.
[0005] To address the aforementioned technical problems, this application provides a terminal verification method, comprising: obtaining an authentication request from a terminal to be identified; when the authentication information in the authentication request meets preset verification conditions, obtaining a security identification code and an International Mobile Subscriber Identity (IMSI) code to be verified from the authentication request; or sending a security identification code verification instruction to the terminal to be identified to obtain the security identification code and the IMSI code; comparing the security identification code to be verified with a target security identification code; wherein the target security identification code is extracted from an identification code database based on the IMSI code; if the comparison results are consistent, determining that the terminal to be identified is the target terminal; wherein the target security identification code is a unique identifier of the target terminal and is encrypted and generated by the communication platform.
[0006] The authentication information includes a username and a password; obtaining the security identification code and the International Mobile Subscriber Identity (IMSI) from the authentication request when the authentication information in the authentication request meets the preset verification conditions includes: obtaining the security identification code and the IMSI from the authentication request when the username and the password match successfully.
[0007] The authentication information includes user biometric information; the step of obtaining the security identification code and International Mobile Subscriber Identity (IMSI) from the authentication request when the authentication information in the authentication request meets the preset verification conditions includes: obtaining the security identification code and IMSI from the authentication request when the user biometric information successfully matches the preset user biometric information.
[0008] The terminal verification method further includes: obtaining a terminal registration request from the target terminal; generating a target security identification code uniquely corresponding to the target terminal when the terminal registration request meets preset verification conditions; and sending the target security identification code to the target terminal so that the target terminal stores it for identity verification.
[0009] The step of generating a target security identification code that uniquely corresponds to the target terminal includes: generating an initial security identification code based on dynamic information, encrypting the initial security identification code to obtain the target security identification code, and storing the encrypted target security identification code in the identification code library; wherein the dynamic information includes one or more of the following: the physical address of the target terminal, the current timestamp of the registration time, a random number, a station number, or train information.
[0010] The step of generating a target security identification code that uniquely corresponds to the target terminal includes: obtaining a user-defined basic identification code, and having the communication platform encrypt the basic identification code to generate the target security identification code; or, the communication platform generating the target security identification code through a high random number algorithm; wherein the target security identification code is stored in the identification code library.
[0011] The step of sending the target security identification code to the target terminal includes: sending the target security identification code to the target terminal through an encrypted communication channel.
[0012] The terminal verification method is applied to a terminal verification system, which includes a terminal and a communication platform. The terminal verification method includes: in response to a network verification pass command, establishing an authentication session between the terminal and the communication platform; the terminal sending an authentication request to the communication platform based on the authentication session; when the authentication information in the authentication request meets preset verification conditions, the communication platform obtaining a security identification code to be verified and an International Mobile Subscriber Identity (IMSI) from the authentication request; the communication platform comparing the security identification code to be verified with a target security identification code; wherein the target security identification code is extracted from an identification code database based on the IMSI; if the comparison results match, the communication platform determines that the terminal is the target terminal; or, in response to a network verification pass command, the terminal and the communication platform... An authentication session is established between the terminal and the communication platform. Based on the authentication session, the terminal sends an authentication request to the communication platform. When the authentication information in the authentication request meets preset verification conditions, the communication platform sends a security identification code verification instruction to the terminal. In response to the security identification code verification instruction, the terminal sends a security identification code verification request to the communication platform. The communication platform obtains the security identification code to be verified and the International Mobile Subscriber Identity (IMSI) from the security identification code verification request. The communication platform compares the security identification code to be verified with the target security identification code. The target security identification code is extracted from the identification code database based on the IMSI. If the comparison results are consistent, the communication platform determines that the terminal is the target terminal. The target security identification code is the unique identifier of the target terminal and is generated by the communication platform through encryption.
[0013] To address the aforementioned technical problems, this application also provides a terminal verification device, which includes a memory and a processor coupled to the memory; wherein the memory is used to store program data, and the processor is used to execute the program data to implement the terminal verification method described above.
[0014] To address the aforementioned technical problems, this application also provides a computer storage medium storing a computer program, which, when executed by a processor, implements the steps in the terminal verification method described above.
[0015] Compared with existing technologies, the beneficial effects of this application are as follows: When verifying whether a terminal to be identified is a target terminal, a target security identification code is extracted from the identification code database based on the unique identifier of the SIM card installed in the terminal to be identified, namely the International Mobile Subscriber Identity (IMSI). This target security identification code is then compared with the security identification code to be verified of the terminal to be identified to obtain a verification result as to whether the terminal to be identified is a legitimate target terminal with the SIM card installed. The target security identification code is the unique identifier of the target terminal and is encrypted and generated by the communication platform, representing a novel authentication mechanism that does not rely on the inherent hardware identifier of the terminal. Furthermore, the target security identification code is uniformly generated, encrypted, and managed by the trusted communication platform, fundamentally avoiding the security risks caused by plaintext storage of hardware identifiers, which are easily stolen and counterfeited. This achieves centralized control of authentication credentials, significantly improving the anti-counterfeiting capabilities of terminal identity verification and the overall security of the system. Furthermore, the communication platform, through the binding relationship between user information, security identification code, and SIM card, achieves joint authentication based on user information, SIM card identification code, and terminal security identification code during the verification process. This effectively verifies whether the binding relationship between the terminal and SIM card is as expected, ensuring that only legally registered terminals can pass authentication under the operation of the corresponding SIM card and a legitimate user, further improving the accuracy and reliability of identity verification. Attached Figure Description
[0016] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein: Figure 1 This is a flowchart illustrating an embodiment of the terminal verification method provided in this application; Figure 2 This is a flowchart illustrating another embodiment of the terminal verification method provided in this application; Figure 3 This is a schematic diagram of the structure of an embodiment of the terminal verification device provided in this application; Figure 4 This is a schematic diagram of the structure of an embodiment of the computer storage medium provided in this application. Detailed Implementation
[0017] To make the above-mentioned objectives, features, and advantages of this application more apparent and understandable, the specific embodiments of this application will be described in detail below with reference to the accompanying drawings. It is to be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of this application. Furthermore, it should be noted that, for ease of description, only the parts relevant to this application are shown in the accompanying drawings, not all structures. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0018] The terms “first,” “second,” etc. (if applicable) in this application are used to distinguish different objects, not to describe a particular order. Furthermore, the terms “comprising” and “featured,” and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.
[0019] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0020] The terminal verification method of this application is applied to a terminal verification device, wherein the terminal verification device can be a server, a terminal device, or a system in which the server and the terminal device cooperate with each other. Accordingly, the various parts of the terminal verification device, such as various units, sub-units, modules, and sub-modules, can all be set in the server, all in the terminal device, or separately in the server and the terminal device.
[0021] Furthermore, the aforementioned server can be either hardware or software. When the server is hardware, it can be implemented as a distributed server cluster consisting of multiple servers, or as a single server. When the server is software, it can be implemented as multiple software programs or software modules, such as software or software modules used to provide distributed server functionality, or as a single software program or software module; no specific limitations are made here.
[0022] Please see Figure 1 , Figure 1 This is a flowchart illustrating an embodiment of the terminal verification method provided in this application.
[0023] Specifically, such as Figure 1 As shown, the specific steps are as follows: Step S11: Obtain the authentication request of the terminal to be identified.
[0024] In this embodiment, the authentication interface module of the communication platform continuously listens for or passively receives various connection requests from the network. When a user attempts to access resources or services protected by the communication platform using their terminal, the client application or system module on their terminal proactively constructs a structured authentication request and sends it to the communication platform through the communication channel.
[0025] Optionally, all communication channels used in this embodiment can be secure encrypted transmission channels based on Secure Sockets Layer (SSL) or Transport Layer (TL) security protocols, such as secure encrypted transmission channels based on Hypertext Transfer Protocol Security (HTTP). Using such encrypted communication channels enables end-to-end encryption protection of all request data during the transmission of authentication requests, effectively preventing data from being eavesdropped on, tampered with, or replayed during the transmission link, thus laying a reliable transmission security foundation for the overall verification process.
[0026] Upon receiving an authentication request, the communication platform will consider the terminal that sent the authentication request as the terminal to be identified and further verify the security of the terminal to be identified.
[0027] Step S12: When the authentication information in the authentication request meets the preset verification conditions, obtain the security identification code and International Mobile Subscriber Identity (IMSI) to be verified from the authentication request; or when the authentication information in the authentication request meets the preset verification conditions, send a security identification code verification instruction to the terminal to be identified to obtain the security identification code and IMSI to be verified.
[0028] In this embodiment of the application, the communication platform will parse the authentication information from the authentication request to perform the first identity verification on the terminal to be identified.
[0029] The authentication information can be a username and password, or it can be the user's biometric information, such as fingerprints or faces.
[0030] When the authentication information is a username and a password, if the username and password match successfully, it indicates that the terminal to be identified has passed the first identity verification.
[0031] When the authentication information is user biometric information, if the user biometric information matches the preset user biometric information stored in the communication platform, it indicates that the terminal to be identified has passed the first identity verification.
[0032] Optionally, to meet the needs of application scenarios with higher security levels, the communication platform can adopt a multi-factor authentication strategy. That is, after completing the initial identity verification based on the username and password, the terminal to be identified can be further required to submit the user's biometric information for a second identity verification, thereby improving the reliability of the terminal's identity confirmation and the strength of system protection.
[0033] After the terminal to be identified passes the first identity verification, the communication platform will obtain the security identification code and international mobile subscriber identification code from the identity verification request to perform a second identity verification on the terminal to be identified.
[0034] Optionally, the communication platform will only send a security identification code verification command to the terminal after it has passed the first identity verification, in order to further obtain the security identification code and the International Mobile Subscriber Identity Code to be verified, thereby completing the second identity verification of the terminal to be identified.
[0035] Step S13: Compare the security identification code to be verified with the target security identification code; wherein the target security identification code is extracted from the identification code library based on the International Mobile Subscriber Identity.
[0036] Step S14: If the comparison results are consistent, the terminal to be identified is determined to be the target terminal; wherein, the target security identification code is the unique identifier of the target terminal and is generated by the communication platform through encryption.
[0037] In this embodiment of the application, when performing a second identity verification on the terminal to be identified, the security identification code to be verified of the terminal to be identified is compared with the target security identification code.
[0038] In this embodiment of the application, the target security identification code is 16 to 32 bytes long, uses a string format, and consists of uppercase and lowercase letters and numbers, such as "AB12-CD34-EF56-GH78".
[0039] The security identification code to be verified for the terminal to be identified is issued by the communication platform through the communication channel when the terminal first accesses and registers. It is used by the communication platform to verify whether the terminal accessing its resources is a legitimate target terminal.
[0040] Specifically, when a user installs and logs into the communication platform client on their terminal for the first time, a terminal registration request is sent to the communication platform through an encrypted communication channel.
[0041] After receiving the terminal registration request from the terminal, the communication platform will parse the authentication information from the terminal registration request to determine whether to allow the terminal to register as a target terminal.
[0042] The specific content of the identity verification information, as well as the specific verification conditions that the identity verification information needs to meet to pass verification, can be found in step S12, and will not be repeated here.
[0043] If the terminal's authentication information is verified, it indicates that it has been authorized and registered by the communication platform as a target terminal, and thus can obtain access to resources or services protected by the communication platform.
[0044] Subsequently, the communication platform further parses the International Mobile Subscriber Identity (IMSI) from the terminal's registration request, or sends an instruction to the terminal to obtain the IMSI.
[0045] The International Mobile Subscriber Identity (IMSI) is the unique identifier of the SIM card used in this terminal.
[0046] Next, the communication platform binds the International Mobile Subscriber Identity (IMSI) with the user's identity information and generates a unique target security identifier for the IMSI. This target security identifier also serves as a unique identification credential for the target terminal carrying the SIM card, uniquely corresponding to the target terminal, thus achieving a one-to-one binding between the SIM card and the terminal device using the SIM card.
[0047] Finally, the communication platform sends the target security identification code to the terminal through an encrypted communication channel. This code serves as the core security credential used by the terminal to prove its legitimate identity in all subsequent access requests, i.e., the security identification code to be verified.
[0048] In an optional embodiment, generating a target security identification code uniquely corresponding to the target terminal includes: obtaining a user-defined basic identification code, and having the communication platform encrypt the basic identification code to generate the target security identification code; or, the communication platform generating the target security identification code using a high random number algorithm; wherein the target security identification code is stored in the identification code library.
[0049] In this embodiment, if the user has previously defined a security identification code, the communication platform obtains the user's unused customized security identification code as the basic identification code and encrypts it to generate a target security identification code that uniquely corresponds to the target terminal.
[0050] If the user has not customized a security identification code, the communication platform will call a high random number algorithm to instantly generate a set of high-strength random codes as the initial security identification code, and immediately encrypt the initial security identification code, using the encrypted result as the target security identification code that uniquely corresponds to the target terminal.
[0051] After the communication platform generates the target security identification code, it will bind the target security identification code with the user's identity information and International Mobile Subscriber Identity (IMSI) and store it synchronously in the identification code database for subsequent identity verification processes.
[0052] In another optional embodiment, generating a target security identification code uniquely corresponding to the target terminal includes: generating an initial security identification code based on dynamic information, encrypting the initial security identification code to obtain the target security identification code, and storing the encrypted target security identification code in the identification code library; wherein, the dynamic information includes one or more of the following: the physical address of the target terminal, the current timestamp of the registration time, a random number, a station number, or train information.
[0053] In this embodiment, the target security identification code that uniquely corresponds to the target terminal is generated by the communication platform based on dynamic information.
[0054] Optionally, the communication platform can generate an initial security identification code unique to the user's terminal when the user logs into the platform and selects the automatic security identification code generation function; alternatively, it can generate an initial security identification code unique to the terminal when the terminal makes a registration request.
[0055] Specifically, when a communication platform determines that it needs to generate an initial security identification code for a target terminal, it will collect one or more dynamic information related to the current time, the current characteristics of the target terminal, or the business scenario in real time to generate the initial security identification code.
[0056] For terminal devices without a specific application scenario, the communication platform can generate the initial security identification code of the target terminal based on the target terminal's physical address, the current timestamp of the target terminal's registration time accurate to the millisecond, the random number sequence generated by a high random number algorithm, or a combination of the above three factors.
[0057] For terminal devices with specific application scenarios, especially in specific industry scenarios such as rail transit, the communication platform can generate an initial security identification code for the target terminal based on business environment parameters.
[0058] For example, in the case of a target terminal used in subway business scenarios, its initial security identification code can be embedded with the station number of the current line, such as "STATION_A_LINE_1", so that the identification code is only valid within the range of Station A of Metro Line 1. If the terminal moves to other lines or other stations, it will automatically become invalid, which can prevent unauthorized terminals from accessing the communication platform across lines.
[0059] For example, in the case of a target terminal used in high-speed rail business scenarios, the initial security identification code can be embedded with the current high-speed rail train number information, such as "G1234", so that the terminal can only pass the identity verification when it matches the current train number, which can prevent unauthorized terminals from crossing train lines from accessing the communication platform.
[0060] After the communication platform generates an initial security identification code, it will be encrypted using an encryption algorithm to obtain a target security identification code. This target security identification code will then be bound to the user's identity information and International Mobile Subscriber Identity (IMSI) and stored synchronously in the identification code database for subsequent identity verification processes.
[0061] In the embodiments of this application, the encryption algorithm used to encrypt the initial security identification code or the basic identification code is usually the AES-256 (Advanced Encryption Standard-256, an advanced encryption standard based on a 256-bit key length) symmetric encryption algorithm. The encryption key is managed independently by the communication platform, while the decryption key is stored separately by the communication platform and the target terminal.
[0062] Optionally, in scenarios where Chinese information security standards need to be met, the AES-256 symmetric encryption algorithm can be replaced with a packet data algorithm based on the wireless LAN standard from the national cryptographic algorithms.
[0063] Optionally, in highly sensitive scenarios, such as train dispatching, the AES-256 symmetric encryption algorithm can be replaced with an asymmetric encryption algorithm. In this case, the public key is publicly disclosed by the communication platform, while the private key is securely stored by the platform. When the target terminal receives the target security identification code from the communication platform, it will encrypt the code again using the public key.
[0064] In the embodiments of this application, the target terminal is equipped with a hardware security module, such as a TPM (Trusted Platform Module) or an HSM (Hardware Security Module), for storing the target security identification code and the target security identification code key.
[0065] Once the target terminal receives the target security identification code issued by the communication platform, it will store the target security identification code in its hardware security module for subsequent authentication.
[0066] In this embodiment of the application, when a user subsequently uses the terminal to access the resources or services of the communication platform, the terminal will carry its security identification code and International Mobile Subscriber Identity (IMSI) in its authentication request. After the communication platform verifies the authentication information, it will regard the security identification code carried in the authentication request as the security identification code to be verified and verify it.
[0067] Optionally, when a user subsequently accesses the resources or services of the communication platform using the terminal, the terminal may also send its security identification code and International Mobile Subscriber Identity (IMSI) to the communication platform after the communication platform verifies its identity information.
[0068] Specifically, the communication platform will retrieve the user's security identification code list from the identification code library that stores security identification codes, based on the user's identity information, and then find the target security identification code that uniquely corresponds to the International Mobile Subscriber Identity (IMSI) in the security identification code list to verify whether the terminal to be identified is a legitimate target terminal with the current SIM card installed.
[0069] Optionally, the communication platform can also directly obtain the target security identification code that uniquely corresponds to the International Mobile Subscriber Identity (IMSI) from the identification code database to verify whether the terminal to be identified is a legitimate target terminal with the current SIM card installed.
[0070] Then, the communication platform compares the target security identification code with the security identification code to be verified of the terminal to be identified.
[0071] If the comparison results match, it indicates that the terminal to be identified is the target terminal that is legally equipped with the current SIM card, and it can be allowed to access services or resources protected by the communication platform.
[0072] If the comparison results are inconsistent, it indicates that the terminal to be identified is not a legitimate target terminal with the current SIM card installed. The communication platform will return an error message to the terminal to be identified and refuse its access.
[0073] Optionally, after the communication platform confirms that the terminal to be identified is the target terminal, it can regenerate and issue a new target security identification code for the terminal to prevent attackers from forging identities by replaying old authentication requests; alternatively, during the communication process between the two parties, a new target security identification code can be regenerated and issued for the terminal according to a preset interval.
[0074] Optionally, the communication platform can regenerate a new target security identifier for the terminal by adding the current timestamp or a random number to the original target security identifier.
[0075] In another optional embodiment, the terminal verification method is applied to a terminal verification system, the terminal verification system including a terminal and a communication platform; the terminal verification method includes: in response to a network verification pass instruction, establishing an authentication session between the terminal and the communication platform; the terminal sending an authentication request to the communication platform based on the authentication session; when the authentication information in the authentication request meets preset verification conditions, the communication platform obtaining a security identification code to be verified and an International Mobile Subscriber Identity (IMSI) from the authentication request; the communication platform comparing the security identification code to be verified with a target security identification code; wherein the target security identification code is extracted from an identification code database based on the IMSI; if the comparison results are consistent, the communication platform determines that the terminal is the target terminal; or, in response to a network verification pass instruction, the terminal and the communication platform establish an authentication session between the terminal and the communication platform. An authentication session is established between the communication platforms; the terminal sends an authentication request to the communication platform based on the authentication session; when the authentication information in the authentication request meets preset verification conditions, the communication platform sends a security identification code verification instruction to the terminal; in response to the security identification code verification instruction, the terminal sends a security identification code verification request to the communication platform; the communication platform obtains the security identification code to be verified and the International Mobile Subscriber Identity (IMSI) from the security identification code verification request; the communication platform compares the security identification code to be verified with the target security identification code; wherein, the target security identification code is extracted from the identification code database based on the IMSI; if the comparison results are consistent, the communication platform determines that the terminal is the target terminal; wherein, the target security identification code is the unique identifier of the target terminal and is generated by the communication platform through encryption.
[0076] In this embodiment, the terminal first needs to complete access layer authentication through the operator's mobile communication network to obtain network access permission and trigger a network verification pass command, and establish an authentication session with the communication platform based on this command.
[0077] Based on this session channel, the terminal initiates an authentication request containing authentication information to the communication platform.
[0078] The communication platform verifies the received authentication information. If it meets the preset verification rules, such as the username and password matching successfully, the first verification is deemed successful, and the security identification code and international mobile subscriber identification code to be verified are parsed from the authentication request.
[0079] Then, the communication platform retrieves the target security identification code that uniquely corresponds to the International Mobile Subscriber Identity (IMSI) from the identification code database. This ISI is the unique identifier of the target terminal that is legally equipped with the current SIM card. The platform then compares the target security identification code with the security identification code to be verified.
[0080] If the security identification code to be verified is completely consistent with the target security identification code, the communication platform will finally confirm that the terminal is a legitimate target terminal with the current SIM card installed, and allow it to access and use the corresponding services.
[0081] Optionally, the communication platform may only allow the terminal to send complete registration information, including the security identification code to be verified and the International Mobile Subscriber Identity, after verifying the terminal's authentication request.
[0082] Please refer to the details. Figure 2 , Figure 2 This is a flowchart illustrating another embodiment of the terminal verification method provided in this application.
[0083] Specifically, such as Figure 2 As shown, the steps are as follows: Step S21: Mobile communication network authentication and authorization by the operator.
[0084] In this embodiment, the terminal to be identified first undergoes authentication and authorization through the operator's mobile communication network, such as SIM card identity authentication and network access authorization, to ensure that the terminal to be identified is qualified to legally access the mobile communication network.
[0085] After the terminal to be identified is verified by the operator's mobile communication network, the terminal to be identified and the communication platform will respond to the network verification pass instruction and establish an identity verification session, laying the communication foundation for subsequent secondary verification requests.
[0086] Step S22: The terminal sends an authentication request.
[0087] In this embodiment, the terminal to be identified sends an authentication request to the communication platform based on an authentication session, wherein the information carried in the authentication request is the username and the user password.
[0088] Step S23: The communication platform verifies the authentication request of the terminal.
[0089] In this embodiment, after receiving an authentication request, the communication platform parses the username and password from the request and performs a matching verification.
[0090] Step S24: Determine whether the authentication request of the terminal is approved.
[0091] If the username is a legitimate username pre-stored in the legitimate user database, and the password matches the username, the communication platform will send a security identification code verification instruction to the terminal to be identified through the authentication request of the terminal to be identified, so that the terminal to be identified can perform a second authentication, i.e., proceed to step S25.
[0092] If the user is not a valid username pre-stored in the valid user database, or if the user's password does not match the username, the communication platform will not accept the authentication request of the terminal to be identified and will proceed to step S29.
[0093] Step S25: The terminal sends a security identification code verification request.
[0094] In this embodiment, when the terminal receives a security identification code verification command from the communication platform, it extracts the stored security identification code to be verified from its own hardware security module. Simultaneously, it obtains the unique identifier of its installed SIM card, namely the International Mobile Subscriber Identity (IMSI). Subsequently, the terminal encapsulates the security identification code to be verified and the IMSI in a security identification code verification request and sends it to the communication platform.
[0095] Step S26: The communication platform verifies the security identification code to be verified on the terminal.
[0096] After receiving a security identification code verification request, the communication platform will parse out the security identification code and International Mobile Subscriber Identity (IMSI) to be verified in the request, and compare the security identification code to be verified with the target security identification code corresponding to the IMSI in the identification code database.
[0097] Step S27: Determine whether the security identification code verification request of the terminal is approved.
[0098] If the security identification code to be verified of the terminal to be identified is consistent with the target security identification code, then the verification request of the security identification code is passed and the process proceeds to step S28.
[0099] If the security identification code to be verified of the terminal to be identified is inconsistent with the target security identification code, the security identification code verification request will not be approved, and the process will proceed to step S29.
[0100] Step S28: The communication platform allows the terminal to access.
[0101] After the communication platform verifies the security identification code of the terminal to be identified, it will return a verification success response to the terminal, allowing the terminal to access the communication platform to perform communication tasks.
[0102] Step S29: The communication platform rejects terminal access.
[0103] If the communication platform fails to verify the identity or security code of the terminal to be identified, it will return a verification failure response to the terminal, denying the terminal access to the communication platform to perform communication tasks.
[0104] The terminal verification method provided in this application effectively overcomes the security flaws of existing technologies that rely on plaintext IMEI for identity verification by introducing a unique security identifier generated and issued by the communication platform as the core verification credential. This method constructs a multi-layered, progressive verification system consisting of operator network authentication, platform identity information verification, International Mobile Subscriber Identity (IMSI), and security identifier verification. It shifts the core of identity verification from the easily stolen or forged terminal hardware identifier to a high-strength encrypted, dynamically updatable security identifier that is strongly bound to the user and business scenarios. Furthermore, the communication platform, through the binding relationship between user information, the security identifier, and the SIM card, achieves joint authentication based on user information, the SIM card identity identifier, and the terminal security identifier during the verification process. This effectively verifies whether the binding relationship between the terminal and the SIM card is as expected, ensuring that only legally registered terminals can pass authentication under the operation of the corresponding SIM card and a legitimate user, further improving the accuracy and reliability of identity verification. This method not only significantly improves the anti-forgery and anti-replay attack capabilities of terminal identity authentication, but also generates dynamic identification codes by combining timestamps, random numbers, and business scenario information, realizing the scenario-based and temporary nature of authentication credentials. This further enhances the security protection level of the system in specific high-risk scenarios such as rail transit, thus providing a more reliable and flexible solution for secure access and business authentication of terminals in mobile communication networks.
[0105] Those skilled in the art will understand that, in the above-described method of the specific implementation, the order in which each step is written does not imply a strict execution order and does not constitute any limitation on the implementation process. The specific execution order of each step should be determined by its function and possible internal logic.
[0106] To implement the above-mentioned terminal verification method, this application also proposes a terminal verification device, for details please refer to [link / reference]. Figure 3 , Figure 3 This is a schematic diagram of an embodiment of the terminal verification device provided in this application.
[0107] The terminal verification device 400 in this embodiment includes a processor 41, a memory 42, an input / output device 43, and a bus 44.
[0108] The processor 41, memory 42, and input / output device 43 are respectively connected to the bus 44. The memory 42 stores program data, and the processor 41 is used to execute the program data to implement the terminal verification method described in the above embodiments.
[0109] In this embodiment, processor 41 can also be referred to as a CPU (Central Processing Unit). Processor 41 may be an integrated circuit chip with signal processing capabilities. Processor 41 can also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The general-purpose processor can be a microprocessor, or processor 41 can be any conventional processor.
[0110] This application also provides a computer storage medium; please refer to the following: Figure 4 , Figure 4 This is a schematic diagram of a computer storage medium according to an embodiment of the present application. The computer storage medium 600 stores a computer program 61, which, when executed by a processor, is used to implement the terminal verification method of the above embodiment.
[0111] When the embodiments of this application are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0112] The above description is merely an embodiment of this application and does not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.
Claims
1. A terminal verification method, characterized in that, The terminal verification method is applied to a communication platform, and the terminal verification method includes: Obtain the authentication request from the terminal to be identified; When the authentication information in the authentication request meets the preset verification conditions, the security identification code and the International Mobile Subscriber Identity (IMSI) to be verified are obtained from the authentication request; or when the authentication information in the authentication request meets the preset verification conditions, a security identification code verification instruction is sent to the terminal to be identified in order to obtain the security identification code and the IMSI to be verified. The security identification code to be verified is compared with the target security identification code; wherein the target security identification code is extracted from the identification code database based on the International Mobile Subscriber Identity (IMSI). If the comparison results match, the terminal to be identified is determined to be the target terminal; The target security identification code is a unique identifier for the target terminal and is generated by the communication platform through encryption.
2. The terminal verification method according to claim 1, characterized in that, The authentication information includes the username and password; When the authentication information in the authentication request meets the preset verification conditions, the security identification code and the International Mobile Subscriber Identity (IMSI) to be verified are obtained from the authentication request, including: When the username and password match successfully, the security identification code and international mobile subscriber identification code to be verified are obtained from the authentication request.
3. The terminal verification method according to claim 1 or 2, characterized in that, The authentication information includes the user's biometric information; When the authentication information in the authentication request meets the preset verification conditions, the security identification code and the International Mobile Subscriber Identity (IMSI) to be verified are obtained from the authentication request, including: When the user's biometric information successfully matches the preset user biometric information, the security identification code and the International Mobile Subscriber Identity (IMSI) to be verified are obtained from the authentication request.
4. The terminal verification method according to claim 1, characterized in that, The terminal verification method further includes: Obtain the terminal registration request of the target terminal; When the terminal registration request meets the preset verification conditions, a target security identification code uniquely corresponding to the target terminal is generated; The target security identification code is sent to the target terminal so that the target terminal stores it for authentication.
5. The terminal verification method according to claim 4, characterized in that, The generation of a target security identifier that uniquely corresponds to the target terminal includes: An initial security identification code is generated based on dynamic information, and the initial security identification code is encrypted to obtain the target security identification code, and the encrypted target security identification code is stored in the identification code library; The dynamic information includes one or more of the following: the physical address of the target terminal, the current timestamp of the registration time, a random number, a station number, or train information.
6. The terminal verification method according to claim 4, characterized in that, The generation of a target security identifier that uniquely corresponds to the target terminal includes: Obtain a user-defined basic identification code, and have the communication platform encrypt the basic identification code to generate the target security identification code; or, The communication platform generates a target security identification code using a high random number algorithm. The target security identification code is stored in the identification code library.
7. The terminal verification method according to claim 4, characterized in that, The step of sending the target security identification code to the target terminal includes: The target security identification code is sent to the target terminal through an encrypted communication channel.
8. A terminal verification method, characterized in that, The terminal verification method is applied to a terminal verification system, the terminal verification system including a terminal and a communication platform; the terminal verification method includes: In response to a network verification pass command, an authentication session is established between the terminal and the communication platform; The terminal sends an authentication request to the communication platform based on the authentication session; When the authentication information in the authentication request meets the preset verification conditions, the communication platform obtains the security identification code and the International Mobile Subscriber Identity Code to be verified from the authentication request. The communication platform compares the security identification code to be verified with the target security identification code; wherein the target security identification code is extracted from the identification code database based on the International Mobile Subscriber Identity (IMSI). If the comparison results match, the communication platform determines that the terminal is the target terminal; Alternatively, in response to a network verification pass command, an authentication session is established between the terminal and the communication platform; The terminal sends an authentication request to the communication platform based on the authentication session; When the authentication information in the authentication request meets the preset verification conditions, the communication platform sends a security identification code verification instruction to the terminal. In response to the security identification code verification command, the terminal sends a security identification code verification request to the communication platform; The communication platform obtains the security identification code and the International Mobile Subscriber Identity (IMSI) to be verified from the security identification code verification request. The communication platform compares the security identification code to be verified with the target security identification code; wherein the target security identification code is extracted from the identification code database based on the International Mobile Subscriber Identity (IMSI). If the comparison results match, the communication platform determines that the terminal is the target terminal; The target security identification code is a unique identifier for the target terminal and is generated by the communication platform through encryption.
9. A terminal verification device, characterized in that, The terminal verification device includes a memory and a processor, wherein the memory is coupled to the processor; The memory is used to store program data, and the processor is used to execute the program data to implement the terminal verification method according to any one of claims 1 to 8.
10. A computer storage medium, characterized in that, The computer storage medium stores a computer program, which, when executed by a processor, implements the steps of the terminal verification method as described in any one of claims 1 to 8.