WO2012075873A1 - 一种由电信网为互联网业务提供用户身份标识和用户身份认证的方法 - Google Patents

一种由电信网为互联网业务提供用户身份标识和用户身份认证的方法 Download PDF

Info

Publication number
WO2012075873A1
WO2012075873A1 PCT/CN2011/082064 CN2011082064W WO2012075873A1 WO 2012075873 A1 WO2012075873 A1 WO 2012075873A1 CN 2011082064 W CN2011082064 W CN 2011082064W WO 2012075873 A1 WO2012075873 A1 WO 2012075873A1
Authority
WO
WIPO (PCT)
Prior art keywords
identity
user
telecommunication network
internet service
internet
Prior art date
Application number
PCT/CN2011/082064
Other languages
English (en)
French (fr)
Inventor
袁永亮
Original Assignee
Yuan Yongliang
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Yuan Yongliang filed Critical Yuan Yongliang
Publication of WO2012075873A1 publication Critical patent/WO2012075873A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3247Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements

Definitions

  • the invention relates to the field of telecommunication equipment and the field of internet business.
  • the account number is the identity of the user on the Internet. This identity is generally useful in the form of account name, email address, number and other forms.
  • the user identity is not uniform, different types of Internet services, and Internet services of the same type but operated by different companies use different forms.
  • the second is that the user needs to set a password for each service. When using each service, you need to enter the account and password to log in. The operation is cumbersome, and the user needs to memorize different accounts and passwords.
  • Internet services are becoming more and more abundant, and many traditional services are also being transferred to the Internet. However, this inconvenience of the Internet has caused some troubles for users.
  • the Internet service does not record the true identity information of users, and some of them involve The business of real identity information needs to be carried out separately, such as online payment, item delivery and so on.
  • the invention proposes a method for providing user identity and user identity authentication for the Internet service by the telecommunication network.
  • the method adopts the unified identification and authentication of the user identity by the telecommunication network and transmits the user identity and authentication information to the Internet, so as to achieve the effect of the user-free account-free authentication to log in to the Internet service, and if promoted, the user identity of the unified Internet service can be achieved. Identify the purpose of the system.
  • the invention discloses a telecommunication network identity management server developed according to the above method, which is used for managing and designating a user identity identifier provided by the telecommunication network to the internet service.
  • the invention also discloses a telecommunication network gateway developed according to the above method, which is located in a telecommunication network, and forwards a message between a user and the Internet, and is special in that a message that the user logs in to the Internet service can be identified and in the message. Join the user's telecommunications network identity.
  • the invention also discloses an internet service server developed according to the above method, the function of which comprises extracting a telecommunication network gateway to add a user identity in the message and finding a corresponding account and providing an internet service for the account.
  • the present invention also discloses a system developed in accordance with the above method, comprising the telecommunications network identity management server, telecommunications network gateway and internet service server described above.
  • the system can achieve the purpose of providing user identity and user identity authentication for the Internet service by the telecommunication network.
  • the specific technical solution of the method for providing user identity and user identity authentication for the Internet service by the telecommunication network disclosed in the present invention is as follows: The current Internet service does not have a unified user identity and authentication system, but the main access service of the Internet is assumed by the party.
  • a telecommunications network has a complete and unified user identity and authentication system.
  • the telecommunications network operator assigns each user a unique identity (such as a mobile number in a 3G network) and authenticates the identity of the user when they access the network (for example, a 3G network user passes the USIM card when attached to the network). Key and encryption algorithm for identity authentication).
  • Step 1 The user configures an identity to be used for the Internet service on the telecommunication network;
  • Step 2 The user sets up one or more identity identifiers of the telecommunication network and the account of the service on the Internet service server, and can set different service rights for each different identity, where each identity
  • the identifier includes the following information: a telecommunication network operator number, a telecommunication network number, an identity type, and an identity value;
  • Step 3 The user connects to the telecommunication network;
  • Step 4 The telecommunications network authenticates the user identity;
  • Step 5 The user connects to the Internet through the telecommunication network, starts to use the Internet service, and sends a message to the Internet according to the Internet protocol;
  • Step 6 The sent message passes through the gateway of the telecommunication network;
  • Step 7 The gateway of the telecommunication network identifies whether the message is a message for logging in to the Internet service and identifies the corresponding Internet service ID;
  • Step 8 If the gateway of the telecommunication network recognizes that it is a message for logging in to the Internet service, the user adds the identity information to be provided to the Internet service and the signature information and message integrity summary information of the telecommunication network gateway, and then Forwarding to the Internet;
  • Step 9 The Internet Service Server receives the message, verifies whether the message is from the trusted telecommunications network gateway by the signature information, and ensures that the message has not been changed by verifying the message integrity digest;
  • Step 10 After the foregoing signature information and the message integrity digest are verified, the Internet service server extracts the user identity information from the message.
  • Step 11 The Internet service server searches for the service account bound to the service identity and the identity granted to the identity identifier according to the obtained user identity information, and marks that the account has passed the login authentication. If the account does not exist, the user is prompted to create an account. If the user selects yes, an account is created for the user, and the account is directly bound to the user identity information obtained this time. If the user identity of the telecommunication network is directly used as an account with the telecommunication network operator, the user identity of the telecommunication network is directly used as the account, and the account has been authenticated by the login. If the corresponding account does not exist, Then prompt the user to create an account;
  • Step 12 The user starts to use the Internet service directly with the account and the right to grant the identity; wherein step 1 further includes the following sub-steps:
  • Step 101 The telecommunication network operator defines and maintains an Internet service list.
  • Each Internet service item in this list contains information such as Internet service ID, service login URL address, or service login TCP/IP address and port number.
  • the telecommunication network operator can also classify the items in this list at multiple levels, such as classifying the classes first, subclassing them under the major classes, and subclasses below the subclasses;
  • Step 102 The telecommunication network operator defines a list of identity types that the user can use.
  • the types of identity types that can be used include a customer number, an identity card number, a mobile phone number, a fixed phone number, an ADSL account, a LAN broadband account, and a WIFI account.
  • the identity type is divided into a real identity and a virtual identity.
  • the customer number, ID number, mobile phone number, fixed phone number, ADSL account, LAN broadband account, WIFI account is the real identity, the network name, etc.
  • Step 103 The telecommunication network operator assigns a value to each type of real identity of the user according to the real identity information of the user, and the virtual identity identifier is valued by the user, but the telecommunication network operator guarantees that the virtual identity of the user under the same type is not Same as other users.
  • Each type of identity of a user may have multiple values, and the operator ensures that each real identity of the user is indeed the true identity information of the user;
  • Step 104 The telecommunication network operator uniformly specifies which type or identity identifier of a certain type of Internet service or an internet service is used. This designation is valid for all users, but the priority is lower than the user's designation, and the telecommunication network operator may also specify a certain The Internet-like service or an Internet service uses the account number of the telecommunication network access mode currently used by the user. At this time, the operator's designated priority is higher than the user's designation;
  • Step 105 The user can define the telecommunication network operator.
  • the Internet service items in the Internet service list are further grouped according to their own standards;
  • Step 106 The user specifies which Internet service or a certain group of Internet services use which identity according to their own preferences.
  • the user needs to select one when there are multiple values under the same type of identity.
  • the user-specified identity is used with a higher priority than the operator's unified identity.
  • the user can also specify an Internet service or a group of Internet services to use the "account of the telecom access mode currently used by the user";
  • Step 107 The operator saves the user identity setting policy set by itself and the user; wherein step 2 may also be: an agreement is reached between the telecommunication network operator and the Internet service provider, and the Internet service directly uses the user identity of the telecommunication network as an account. .
  • the "Telecom network authenticates the user identity" mentioned in step 4 includes: inputting the username and password for DSL, ADSL, LAN, WLAN, WIFI login; directly identifying and authenticating the user identity through the physical connection of the optical fiber; through GSM, CDMA, The authentication algorithm in the WCDMA and LTE standards identifies and authenticates the identity of the user; and other methods of authenticating the identity of the user.
  • the "user access to the Internet through the telecommunications network” in step 5 includes DSL, ADSL, LAN, fiber, WLAN, WIFI, GPRS, EDGE, WCDMA, CDMA, HSPA, LTE, power lines, cable TV lines and other public Internet. Access mode is connected to the Internet.
  • the "Starting to use the Internet service, sending messages to the Internet according to the Internet Protocol" in Step 6 includes various standard Internet protocols such as FTP, TELNET, SMTP, POP, etc., or through the TCP/IP-based private through HTTP or WEBSERVICE protocols. The protocol is connected to an internet service server.
  • the "the gateway identification message of the telecommunication network is a message for logging in to the Internet service and identifying the corresponding Internet service ID" according to step 7 includes: identifying the login message and the corresponding Internet service ID according to the URL address in the HTTP and WEBSERVICE, according to The port number in the private protocol based on the TCP/IP protocol identifies the Internet service ID and other means to identify the message that is logged into the Internet service.
  • the step of adding the user identity and the signature information and message integrity summary information of the telecommunication network gateway in the message 8 includes: the telecommunication network gateway adds the user identity information and the digital signature information in the HTTP and WEBSERVICE messages.
  • the telecommunication gateway adds user identity information and digital signature information and user identity in a private protocol based on TCP/IP messages; wherein the "user identity information" described in steps 8, 9, 10, and 11 Including the telecommunication network operator number, telecommunication network number, user identity type, and user identity value.
  • the user if the user originally has an account on an Internet service server, he can enter the account and password to log in to the Internet service server and set the account and his or her own one or more telecommunication network identity.
  • the identifier is bound (each telecommunication network identity includes four values of a telecommunication network operator number, a telecommunication network number, a user identity type, and a user identity value, and may use a real identity or a virtual identity), and Configuring which type of identity to be transmitted to the Internet service server when accessing the Internet service on the corresponding telecommunication network operator network, after which the network of the telecommunication network operator in the configuration list is connected to the Internet, The account is not logged in to the Internet service server.
  • the Internet service directly uses the telecommunication network operator identity of the telecommunication network operator as an account
  • the user may first log in to the Internet through the telecommunication network of the operator.
  • the service server directly creates an account with the telecommunication network identity.
  • After connecting to the Internet service server through the operator's telecommunication network there is no need to log in to the account, and no password is required. It can be seen from the above description that, by using the method disclosed by the present invention, one can unify the user identity on the Internet, and the two can enable the user to log in to the Internet service without a password-free password, thereby eliminating the trouble of the user remembering the account and the password.
  • the step of inputting an account and a password when the user logs in to the Internet service is omitted, which brings convenience to the user.
  • the three Internet services can be charged from the user's telecommunication network account according to the user's telecommunication network identity, thereby providing a kind of Internet service.
  • the invention also discloses a telecommunication network identity management server, which comprises the following units:
  • An Internet service list maintenance unit for the power supply network operator to define and manage the Internet service list
  • An identity type defining unit configured to provide a list of identity type types for the power supply network operator
  • An identity definition unit configured to provide a value for the network operator and the user to define and manage the user identity;
  • the unified identity usage policy definition unit is used by the power supply network operator to uniformly specify which type of Internet service or each Internet service uses which identity identifier;
  • the identity usage policy definition unit is used for the user to divide the Internet service group and specify which identity to use for a single Internet service; the Internet service identification and identity query unit is used for other devices to query a certain URL or a certain port. Whether it is the service login URL and service login port of an Internet service item in the Internet service list. If yes, the user identity identifier to be used is returned according to the checked Internet service ID and the user key value input by other devices. device.
  • the invention also discloses a telecommunication network gateway, which comprises the following units:
  • the service login message identifying unit is configured to identify which of the messages sent by the user are service login messages sent to the Internet and identify which Internet service is currently accessed;
  • An identity obtaining unit configured to read a user pre-configured identity to be used by the currently accessed Internet service; and an identity information adding unit, configured to add a user identity and signature information to the service login message sent to the Internet, Integrity verification information;
  • the message forwarding unit is configured to receive other messages than the service login message sent by the user and forward the message to the Internet for receiving the message sent by the Internet to the user and forwarding the message to the user.
  • the invention also discloses an internet service server, which comprises the following units:
  • the login-free processing unit is configured to extract a user identity added by the telecommunication network gateway in the service login message and complete the login-free process.
  • Other sub-service processing units for processing other sub-services of the Internet service.
  • the login-free processing unit includes:
  • the identity identifier extracting unit is configured to verify the signature information and the integrity verification information in the service login message, and extract the user identity identifier;
  • the account mapping unit is configured to search for the service account bound to the user identity identifier according to the user identity identifier and find the identity granted to the identity Identification of business authority;
  • the login status modification unit is used to set the account to be logged in.
  • the invention also discloses a system for providing user identity and user identity authentication for the Internet service by the telecommunication network, comprising: a telecommunication network identity management server, configured to manage and specify a user identity of the telecommunication network provided to the internet service;
  • a telecommunication network gateway configured to identify a message that the user logs in to the Internet service and add a telecommunication network identity of the user to the message;
  • the Internet service server is configured to extract the user identity of the telecommunication network gateway and add the user identity in the message
  • the corresponding account and the authority to grant the identity and provide Internet services for the account.
  • FIG. 1 is a schematic flowchart of a method for providing a user identity and user identity authentication for an Internet service by a telecommunication network according to the present invention
  • FIG. 2 is another method for providing a user identity and user identity authentication for an Internet service by a telecommunication network according to the present invention
  • a schematic diagram of a process of implementation
  • FIG. 3 is a flowchart of Embodiment 1 of a method for providing user identity and user identity authentication for an Internet service by a telecommunication network according to the present invention
  • FIG. 4 is a schematic diagram of a user identity and user identity authentication provided by a telecommunication network for an Internet service in the present invention
  • FIG. 5 is a flowchart of Embodiment 3 of a method for providing user identity and user identity authentication for an Internet service by a telecommunication network according to the present invention
  • FIG. 6 is a plurality of telecommunication network operators and multiple telecommunication networks.
  • FIG. 7 is a schematic diagram of a system for providing user identity and user identity authentication for an Internet service by a telecommunication network according to the present invention. detailed description
  • the user Zhang San is connected to the Internet through the WCDMA 3G network of the telecommunication network operator A, and the specific steps of the user-free account-free authentication login service are as follows:
  • Step 301 The telecommunication network operator A manages the Internet list, and adds a new internet service item, such as "Sina blog", whose internet service ID is 1, and the business login URL address is http: //blog. sina. com. cn/ Noacctlogin.
  • Step 302 The telecommunication network operator A adds an identity type to the identity type list: the mobile phone number.
  • Step 303 The telecommunication network operator A assigns the identity of the "mobile phone number" type identity of the user Zhang San according to the number of the user Zhang San: 18606061122.
  • Step 304 The telecommunications network operator A specifies that the "Sina blog” service uses the identity of the "mobile number” type.
  • Step 305 User Zhang San sets the identity of the user's account Jackson and the telecommunication network on the "Sina blog": telecommunication network operator number one A; network number one WCDMA 3G network; identity type one mobile phone number ; identity value one 18606061122 binding.
  • Step 306 The user opens the mobile phone and connects to the WCDMA 3G network by using the USIM card of the number 18606061122.
  • Step 307 The WCDMA 3G network of the telecommunication network operator A authenticates the USIM card, passes the authentication, and recognizes that it is the user.
  • Step 309 The gateway of the WCDMA 3G network of the telecommunication network operator A queries the Internet service list according to the URL address http: //blog.sina.com.cn/noacctlogin, and finds the login URL of the "Sina blog" service, corresponding to the Internet The service ID is 1.
  • Step 310 The gateway of the WCDMA 3G network of the telecommunication network operator A queries the telecommunication network operator A and the user Zhang to specify the identity usage policy, and finds that the telecommunication network operator A needs to uniformly specify the strategy: "Type identity, the telecommunication network gateway obtains the identity of Zhang San's "mobile phone number” type, and then adds the identity in the HTTP message header: telecommunication network operator number one A; network number one WCDMA 3G network; Identity type - one mobile number; identity value - 18606061122 and its own digital signature information and a summary of the entire message and forwarded to the Internet.
  • Step 311 The server of "Sina blog" receives the message forwarded by the WCDMA 3G network gateway of the telecommunication network operator A, verifies the digital signature and the message integrity digest thereof, and ensures that the message is from the WCDMA 3G network gateway of the telecommunication network operator A. And has not been maliciously modified.
  • Step 312 The server of "Sina blog” extracts the user identity of the telecommunication network from the message: type one mobile phone number; value one by one 18606061122.
  • Step 313 "Sina blog" according to the user identity of the telecommunication network: telecommunication network operator number one A; network number one WCDMA 3G network; identity type one mobile phone number; identity value one by one 18606061122 found tied to it The user account is set to Jackson, and the login is marked as successful.
  • Step 314 The user Zhang San uses the account Jackson to start using the "Sina blog” business.
  • Example 2 The user Zhang San uses the account Jackson to start using the “Sina blog” business.
  • the user Li Si is connected to the Internet through the ADSL broadband network of the telecommunication network operator B, and the specific steps of the user-free account-free authentication login service are as follows:
  • Step 401 The telecommunication network operator B manages the Internet list, and adds a new internet service item, such as "Ctrip Travel", whose Internet service ID is 2, the classified categories are "life class", and the small class is "travel class".
  • the business login URL address is http://www.ctrip.com/noacctlogin.
  • Step 402 The telecommunication network operator B adds two identity identification types in the identity identification type list: an ADSL account number and a mobile phone number.
  • Step 403 The telecommunication network operator B assigns a value to the user's "ADSL account” type identity according to the user's ADSL account of Li Si: szdsl52316938@163. gd.
  • the user Li Si also used the TD-CDMA mobile phone of the telecommunication network operator B, the number is: 18902020505, so the telecommunication network operator B also assigns the value of the "mobile phone number” type identity of Li Si: 18902020505.
  • the telecommunication network operator B also specifies that the "lifetime" Internet service uniformly uses the "mobile phone number” type of identity.
  • Step 404 The user Li Si grouped the Internet service, and the "Ctrip Travel” grouped into a “travel group”, and designated the group of services to use the "ADSL account” type of identity.
  • Step 405 The telecommunication network operator B and Ctrip wireless sign an agreement, and the Ctrip service uses the ADSL account or the mobile phone number carried by the operator B as the user's account.
  • Step 406 The user Li Si dials the Internet through the ADSL account szdsl52316938@163. gd.
  • Step 407 The ADSL access device of the telecommunication network operator B authenticates the user, passes the authentication, and identifies the user Li Si.
  • Step 409 The gateway of the ADSL network of the telecommunication network operator B queries the Internet service list according to the URL address http: ⁇ stomach. ctrip.com/noacctlogin, and finds the login URL of the "Ctrip Travel" service, and the corresponding Internet service ID is 2 .
  • Step 410 The telecommunication network gateway queries the telecommunication network operator B and the user Li Si to specify the identity usage policy, and finds that the user needs to use the strategy specified by the user Li Si: using the "ADSL account” type identity, the telecommunication network gateway obtains Zhang San's "ADSL account” type identity, and add the identity in the HTTP header: telecommunication network operator number one-B; network number one ADSL network; type one ADSL account; value one szdsl52316938@ 163. The gd and its own digital signature information and a summary of the entire message are forwarded to the Internet.
  • Step 411 The server of "Ctrip Travel” receives the message forwarded by the ADSL network gateway of the telecommunication network operator B, verifies the digital signature and the message integrity digest thereof, and ensures that the message is from the ADSL network gateway of the telecommunication network operator B. Modified by malicious.
  • Step 412 The server of "Ctrip Travel” extracts the user identity of the telecommunication network from the message: telecommunication network operator number one-B; network number one ADSL network; identity type one-to-one ADSL account; identity value one-to-one szdsl52316938@ 163. gd.
  • Step 413 The server of "Ctrip Travel” directly assembles the account "Telecom Network Operator Number - Network Number - Identity Type - Identity Value" according to the protocol of the user identity of the telecommunication network: B - ADSL - adsl - S zdsl52316938 @163. gd is the account number and the login is successful.
  • Step 414 User Li Si takes the account B—ADSL— adsl—szdsl52316938 group 63. gd starts to use the “Ctrip Travel” service.
  • Step 501 The telecommunication network operator C manages the Internet list and adds a new Internet service item.
  • "XX Online Banking” has an Internet business ID of 3, a classified category of "Lifestyle", and a small category of "Online Banking”.
  • the business login URL address is http://www.anetbank.com/noacctlogin.
  • Step 502 The telecommunication network operator C adds two identity types in the identity type list: a home ADSL account and a mobile phone number.
  • Step 503 User Wang Wu opened a family ADSL account at operator C: szdsl52316938@163. gd, and opened his own mobile phone number on carrier C's CDMA network: 18302020505.
  • the telecommunications network operator C assigns the identity of the "family ADSL account” type of Wang Wu according to the real information of Wang Wu: szdsl52316938@163. gd, the identity of the "mobile number" type is assigned: 18302020505.
  • Step 504 The telecommunication network operator C specifies that the "XX online banking" service uses the identity of the type "account of the telecommunication network access mode currently used by the user".
  • Step 505 User Wang Wu configures his bank account number 18181818 and the telecommunication network operator C's telecommunication network identity family ADSL account on the "XX Online Banking" Internet service server: szdsl52316938@163. gd and mobile number: 18302020505 Ding, which family ADSL account: szdsl52316938@163. gd only grants permission to check the balance, and mobile phone number: 18302020505 grants all permissions.
  • Step 506 The user Wang Wu accesses the WEB address of the "XX Online Banking" by connecting his own number to the mobile phone of 18302020505: http://www.netbank.com/noacct login 0
  • Step 507 The CDMA network gateway of the telecommunication network operator C queries the Internet service list according to the URL address http: ⁇ www. anetbank.com/noacctlogin, and finds the login URL of the "XX online banking" service, and the corresponding Internet service ID is 3. .
  • Step 508 The CDMA network gateway of the telecommunication network operator C queries the telecommunication network operator C and the user Wang Wu to specify the identity usage policy, and finds that the strategy specified by the telecommunication network operator C should be used: "Use the current user is actually using The identity of the telecommunication network access mode "type identity, the telecommunication network gateway obtains the identity of the type "the account of the telecommunication network access mode currently used by the user" and is added in the HTTP message header: telecommunication network Carrier number one C; network number one CDMA network; type one mobile phone number; value one 18302020505 and its own digital signature information and a summary of the entire message and forwarded to the Internet.
  • Step 509 The server of the "XX Online Bank” receives the message forwarded by the CDMA network gateway of the telecommunication network operator C, verifies the digital signature and the message integrity digest, and takes out the user identity of the user as: telecommunication network operator No. one C; network number one CDMA network; type one mobile phone number; value one by one 18302020505.
  • Step 510 "XX Online Banking" finds that the associated bank account number is 18181818 according to the user identity of the telecommunication network, and the authority for granting the identity identity is all rights.
  • Step 511 User Wang Wu performs balance inquiry, transfer, and the like on the bank account number 18181818.
  • Step 512 The user Wang Wu's wife is at home through the family ADSL account szdsl52316938@163. gd dial-up Internet access.
  • Step 513 The home ADSL access device of the telecommunication network operator C authenticates the user, passes the authentication, and recognizes that the user is "Wang Wu” or “Wang Wu Family", and the "Wang Wu Family” can also access the "King" Five" business.
  • Step 514 The user Wang Wu's wife connects to the "XX Online Banking" account-free login WEB address: http: //www. anetbank.com/noacctlogin.
  • Step 515 The home ADSL network gateway of the telecommunication network operator C queries the Internet service list according to the URL address http: ⁇ www. anetbank.com/noacctlogin, and finds the login URL of the "XX online banking" service, and the corresponding Internet service ID is 3.
  • Step 516 The home ADSL network gateway of the telecommunication network operator C queries the telecommunication network operator C and the user Wang Wu to specify the identity usage policy, and finds that the policy specified by the telecommunication network operator C should be used:
  • the type of identity of the account used by the telecommunication network access method the telecommunication network gateway obtains the identity of the type "the account of the telecommunication network access mode currently used by the user" and adds it in the HTTP message header: Network operator number one C; network number one family ADSL network; type one ADSL account; value one szdsl52316938@163. gd and its own digital signature information and a summary of the entire message and forwarded to the Internet.
  • Step 517 The server of "XX Online Bank” receives the message forwarded by the home ADSL network gateway of the telecommunication network operator C, verifies the digital signature and the message integrity digest, and takes out the user identity of the user as: telecommunication network operation Business number one C; network number one family ADSL network; type one ADSL account; value one szdsl52316938@163. gd.
  • Step 518 "XX Online Bank” finds that the associated bank account number is 18181818 according to the user identity of the telecommunication network, and the authority for granting the identity identifier is the query balance.
  • Step 519 The user Wang Wu's wife can only perform the balance inquiry operation on the bank account number 18181818.
  • Step 601 The telecommunication network operator D manages the Internet list, and adds a new internet service item, such as "Tian Ya Forum", whose Internet service ID is 4, and the classified category is "forum class", and the service login URL address is http: ⁇ Stomach. tianya. com/noacctlogin.
  • Step 602 The telecommunication network operator D adds an identity type to the identity type list: a network name, which is a virtual identity.
  • Step 603 The telecommunication network operator D and the Tianya Forum sign an agreement to stipulate that the Tianya Forum service uses the network name carried by the operator D as the user's account.
  • Step 604 User Ma Liu takes the value of his "net name" type identity on the network of the telecommunication network operator D: MaLiu. The name is verified, and other users do not have the same name.
  • Step 605 The telecommunication network operator D also specifies that the "forum type” Internet service uniformly uses the "net name” type identity.
  • Step 606 The user Ma Liu accesses the Internet through the WCDMA 3G mobile phone number 18606061122 of the operator D.
  • Step 607 The WCDMA 3G network of the telecommunication network operator D authenticates the number 18606061122, passes the authentication, and recognizes that the user is a horse.
  • Step 608 The user Ma Liu connects to the "Tianya Forum" free account login WEB address through the HTTP protocol: http: //www.tianya.com/noacctlogin.
  • Step 609 The gateway of the WCDMA 3G network of the telecommunication network operator D queries the Internet service list according to the URL address http: ⁇ stomach. tianya.com/noacctlogin, and finds the login URL of the "Tianya Forum" service, and the corresponding Internet service ID is 4.
  • Step 610 The gateway of the WCDMA 3G network of the telecommunication network operator D queries the telecommunication network operator D and the user's own designated identity usage policy, and finds that the policy specified by the telecommunication network operator D needs to be used: Using the "net name" Type identification, the telecommunication network gateway obtains the identity of the "net name” type of Ma Liu, and adds the identity in the HTTP message header: telecommunication network operator number one D; network number one WCDMA 3G network; type One-to-one net name; the value of MaLiu and its own digital signature information and a summary of the entire message and forwarded to the Internet.
  • Step 611 The server of the "Tianya Forum" receives the message forwarded by the WCDMA 3G network gateway of the telecommunication network operator D, verifies the digital signature and the message integrity digest therein, and then extracts the user identity of the telecommunication network from the message: Carrier number one D; network number one WCDMA 3G network; identity type one by one network name; identity value one MaLiu.
  • Step 612 The server of "Tian Ya Forum" directly assembles the account "Telecom Network Operator Number - Identity Value" according to the protocol of the user identity of the telecommunication network: D - MaLiu is used as an account and the login is successfully marked.
  • Step 613 User Ma Liu starts using the "Tian Ya Forum" business with the account D-MaLiu.
  • Example 5 User Ma Liu starts using the "Tian Ya Forum" business with the account D-MaLiu.
  • Step 701 The telecommunication network operator E manages the Internet list, adding a new Internet service item, such as "XX instant message", its Internet service ID is 5, the classification is "immediate message class", the business login mode is private protocol, and the TCP port 12345 of the server. xxim.com is logged in according to the private protocol.
  • Step 702 The telecommunication network operator E adds an identity type to the identity type list: E-mai l address, which is a virtual identity.
  • Step 703 The telecommunication network operator E and XX instant message sign the agreement, and define the interface for transmitting the user identity information, the gateway signature information, and the message integrity summary information.
  • Step 704 The user money seven gives the value of the "E-mail address" type identity on the network of the telecommunication network operator E: qianqi@163.com. The name is verified, and other users do not have the same name.
  • Step 705 The telecommunication network operator 3 also specifies that the "instant messaging class" Internet service uniformly uses the identity identifier of the "E-mai l address” type.
  • Step 706 The user money seven goes online through the operator's WCDMA 3G mobile phone number 18606061122.
  • Step 707 The WCDMA 3G network of the telecommunication network operator E authenticates the number 18606061122, passes the authentication, and recognizes that the user is money seven.
  • Step 708 The user money seven connects to the "XX instant messaging" server through the private protocol of the XX instant message: stomach. xxim.com, the port is 12345.
  • Step 709 Query the Internet service list of the server address and port of the WCDMA 3G network of the telecommunication network operator E, and find that it is "XX"
  • the instant message "the login URL of the service, the corresponding Internet service ID is 5.
  • Step 710 The gateway of the WCDMA 3G network of the telecommunication network operator E queries the telecommunication network operator E and the user's own designated identity usage policy, and finds that the policy specified by the telecommunication network operator E is required: Use "E-mai l Address "type identity, the telecommunication network gateway obtains the identity of the "E-mai l address" type of money seven, and adds the identity in the TCP message according to the private protocol: telecommunication network operator number one E; network number One-to-one WCDMA 3G network; Type one-E-mai l address; value one-by-one qianqi@163.com and its own digital signature information and a summary of the entire message and forwarded to the Internet.
  • Step 711 The server of the "XX instant message" receives the message forwarded by the WCDMA 3G network gateway of the telecommunication network operator D, verifies the digital signature and the message integrity digest therein, and then extracts the user identity of the telecommunication network from the message: Network operator number one E; network number one WCDMA 3G network; identity type one-E- mai l address; identity value one qianqi@163. com.
  • Step 712 The server of the "XX instant message” directly assembles the account "identity value" according to the protocol of the user identity of the telecommunication network: qianqi@163.com as an account and marks the login success of the account.
  • Step 713 The user starts to use the "XX instant messaging" service with the account qianqi@163.com.
  • FIG. 7 is a schematic structural diagram of a system for providing user identity and user identity authentication for an Internet service by a telecommunication network, which includes a structure diagram of a telecommunication network identity management server, a schematic structure of a telecommunication network gateway, and an internet service. Schematic diagram of server structure.
  • the telecommunication network identity management server 70 in this embodiment includes an Internet service list maintenance unit 703, an identity identification type definition unit 702, an identity identification definition unit 704, a unified identity usage policy definition unit 706, an identity usage policy definition unit 705, and the Internet.
  • the service identification and identity query unit 701 further describes its internal structure and connection relationship in conjunction with specific embodiments.
  • the Internet service list maintenance unit 703 provides an interface for the operator to define an Internet service list.
  • Each Internet service includes information such as an Internet service ID, a service login URL address, or a service login TCP/IP address and port number, and then saves the list.
  • the identity type definition unit 702 then provides an interface for the operator to define the identity type, including the customer number, ID number, mobile phone number, fixed phone number, ADSL account, LAN broadband account, WIFI account, network name, etc., and then save These types of data.
  • the identity type definition unit 704 provides an interface for the operator to input the value of each user's real identity type, and may also be imported from another table.
  • the identity type definition unit 704 shall ensure each user under each type of identity.
  • the identification values are different and can uniquely represent the user.
  • the identity type definition unit 704 also allows the user to take the value themselves. There can be more than one identity of the same type.
  • the identity type definition unit 704 holds these data.
  • the unified identity usage policy definition unit 706 provides an interface for the operator to classify the Internet service, and specifies which type or identity of the Internet service or a certain Internet service is used, and the unified identity usage policy definition unit 706 stores the data. .
  • the identity usage policy definition unit 705 then provides an interface for the user to group Internet services and specify which Internet service or group of Internet services to use according to their own preferences.
  • the identity usage policy definition unit 705 stores the data.
  • the identity network obtaining unit 712 of the telecommunication network gateway sends a request to the Internet service identification and identity query unit 701 to identify whether it is a configured Internet service and return the telecommunication network identity that should be used.
  • the request carries the user key value, the URL address accessed by the user, or the server address and port number.
  • the Internet service identification and identity query unit 701 searches the Internet service list according to the URL address or the server address and the port number in the request, and if the URL address or the server address and the port number are equal to the value in an item, the identifier is identified. Is the Internet service ID of the Internet service and obtaining the Internet service.
  • the identity identification obtaining unit 712 returns to the telecommunication network gateway. Not an identifiable internet business." If the Internet service ID is obtained, the data stored in the unified identity usage policy definition unit 706 and the identity usage policy definition unit 705 are queried according to the Internet service ID and the user key value, according to the principle in step 104 ⁇ 106 of the invention content. Determine which identity should be used this time. The identity type and identity value of this identity are then returned to the identity acquisition unit 712 of the telecommunications network gateway.
  • the telecommunication network gateway 71 in this embodiment includes a service login message identification unit 711, an identity identification acquisition unit 712, and identity information attachment. The unit 713 and the message forwarding unit 714, the internal structure and the connection relationship are further described below in conjunction with the specific embodiments.
  • the user When a user uses an Internet service, the user first accesses the telecommunication network through the telecommunication network access device 73. At this time, the telecommunication network uses the identity of the telecommunication network to authenticate the user identity. Then, the user sends a message to the Internet through the telecommunication network access device 73, and the message is sent to the service login message identifying unit 711 of the telecommunication network gateway 71, and the service login message identifying unit 711 adjusts the identity obtaining unit 712 to the telecommunication network identity management server.
  • the 70 request identifies whether it is a configured internet service and returns the type and value of the telecommunications network identity that should be used.
  • the identification is a configured Internet service and the returned telecommunication network identity type and value that should be used are obtained, it is determined whether the identity is the "account of the telecommunication network access mode currently used by the user", if yes Obtaining the current access mode and the access account from the telecommunication network access device 73, and then transmitting the identity type and value together with the message to the identity information adding unit 713, and the identity information adding unit 713 receives the message and should use the message.
  • the identity identification information of the user includes the telecommunication network operator number, the telecommunication network number, and the user identity.
  • the type and user identity value are then forwarded to the message forwarding unit 714, which forwards the message to the Internet and finally to the Internet service server 72. If it is identified that the Internet service is not configured, the service login message identifying unit 711 forwards the message directly to the message forwarding unit 714, and the message forwarding unit 714 forwards it to the Internet and finally to the Internet service server 72.
  • the message sent to the user by the Internet service server 72 is forwarded by the message forwarding unit 714 to the telecommunication network access device 73, and the telecommunication network access device 73 forwards the message to the user.
  • the Internet service server 72 in this embodiment includes a login-free processing unit 721 and other sub-service processing units 722, wherein the login-free processing unit 721 further includes an identity identification extraction unit 7213, an account mapping unit 7212, and a login status modification unit 7211, which are combined below.
  • the detailed description further describes its internal structure and connection relationship.
  • the message forwarded by the message forwarding unit 714 of the telecommunication network gateway 71 first arrives at the identity identifier extracting unit 7213 of the login-free processing unit 721.
  • the identity identifier extracting unit 7213 determines whether it is an account-free login message according to the requested URL address, and if not, directly forwards it to the message.
  • the other business processing unit 722 performs processing. If yes, it verifies whether the message is from the telecommunication network gateway 71 according to the signature information in the message, and then verifies whether the message is changed in the delivery path from the telecommunication network gateway 71 to the current location through the message integrity digest, if the signature information If the message integrity summary information fails to pass, the message is discarded. Otherwise, the user identity information in the message is extracted, and the content thereof is as follows: telecommunication network operator number, telecommunication network number, user identity type, and user identity value.
  • the user identification information is passed to the account number mapping unit 7212.
  • the account mapping unit 7212 determines whether there is a user identity that requires direct use of the telecommunication network as an account, and if so, directly uses the user identity information to combine the account according to the required format, otherwise, according to the user identity information, all user settings are used.
  • the binding relationship between the user identity of the telecommunication network and the account find out which account corresponds to the user identity information of the current time, and find out the authority information granted to the user identity.
  • the account mapping unit 7212 passes the combined or found account and the rights information to be granted to the login status modifying unit 7211, and the login status modifying unit 7211 updates the status of the account to log in and save the granted rights information.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Telephonic Communication Services (AREA)

Description

一种由电信网为互联网业务提供用户身份标识和用户身份认证的方法 技术领域
本发明涉及电信设备领域、 互联网业务领域。
背景技术
当前大多数的互联网业务如博客、 微博、 社交网络、 邮箱、 即时消息等都要求用户注册一个账号并设 置一个密码用于用户身份的标识和认证。 账号就是用户在互联网上面的身份标识, 这个身份标识一般有用 户名、 邮箱地址、 数字编号等几种形式。
可以发现, 当前的互联网业务的用户身份标识和认证系统存在几个问题: 一是用户身份标识不统一, 不同类型的互联网业务、 以及同一类型但由不同公司运营的互联网业务之间会使用不同形式的身份标识; 二是用户需要为每个业务设置一个密码, 使用每个业务时都需要输入账号和密码进行登录, 操作较繁琐, 用户需要记忆不同的账号和密码。 当前互联网业务越来越丰富, 很多传统的业务也在向互联网上转移, 但 是互联网的这种不方便却给用户带来了一定的困扰; 三是互联网业务没有记录用户的真实身份信息, 一些 涉及真实身份信息的业务就需要另外单独开展, 如在线支付、 物品快递等。
发明内容
本发明提出了一种由电信网为互联网业务提供用户身份标识和用户身份认证的方法。 该方法采用由电 信网统一标识和认证用户身份并且把用户身份标识和认证信息传递给互联网, 从而达到用户免账号免认证 登录互联网业务的效果, 并且如果推广之则可以达到统一互联网业务的用户身份标识系统的目的。
本发明公开了一种依据上面的方法开发的电信网身份管理服务器, 用于管理和指定电信网提供给互联 网业务的用户身份标识。
本发明还公开了一种依据上面的方法开发的电信网网关, 其处于电信网中, 在用户和互联网之间转发 消息, 其特殊之处在于可以识别出用户登录互联网业务的消息并在消息中加入用户的电信网身份标识。
本发明还公开了一种依据上面的方法开发的互联网业务服务器, 其功能包括提取电信网网关增加在消 息中的用户身份标识并以之査找出对应的账号并为该账号提供互联网业务。
本发明还公开了一种依据上面的方法开发的系统, 其包括上面所述的电信网身份管理服务器、 电信网 网关和互联网业务服务器。 该系统可以实现由电信网为互联网业务提供用户身份标识和用户身份认证的目 的。 本发明公开的由电信网为互联网业务提供用户身份标识和用户身份认证的方法的具体技术方案如下: 当前互联网业务没有一个统一的用户身份标识和认证系统, 但是互联网的主要接入服务承担方一一电 信网却有一个完善和统一的用户身份标识和认证系统。 电信网运营商会对每个用户分配一个唯一的身份标 识 (如 3G网络中的手机号码), 并且在用户接入网络时对其身份进行认证 (例如 3G网络用户在附加到网 络时会通过 USIM卡中的密钥和加密算法进行身份认证)。
此外, 当前绝大多数普通用户接入到互联网都是通过电信网运营商, 只有少数用户如教育科研网的用 户才通过专门的线路接入互联网。
因此, 如果互联网业务由电信网提供用户身份标识和用户身份认证, 则既可以解决互联网上用户身份 标识不统一的问题, 又可以免除用户使用每个互联网业务之前还要登录的不便。 该方法具体的步骤为: 步骤 1 : 用户在电信网上配置要给互联网业务使用的身份标识;
步骤 2 : 用户在互联网业务服务器上设置将自己在电信网的一个或多个身份标识和该业务的账号进行 绑定, 并且可以为每个不同的身份标识设置不同的业务权限, 其中每个身份标识包括如下信息: 电信网运 营商编号、 电信网络编号、 身份标识类型、 身份标识值;
步骤 3 : 用户连接到电信网; 步骤 4: 电信网对用户身份进行认证;
步骤 5 : 用户通过电信网连接到互联网, 开始使用互联网业务, 按照互联网协议向互联网发送消息; 步骤 6: 所发送的消息经过电信网的网关;
步骤 7 : 电信网的网关识别消息是否是登录互联网业务的消息并识别出对应的互联网业务 ID;
步骤 8 : 电信网的网关如果识别出是登录互联网业务的消息, 则在消息中加入用户指定的要提供给该 互联网业务的身份标识信息以及电信网网关的签名信息和消息完整性摘要信息, 然后转发到互联网; 步骤 9: 互联网业务服务器收到消息, 通过签名信息验证消息是否来自信任的电信网网关, 通过验证 消息完整性摘要来确保消息未被更改;
步骤 10: 上述的签名信息和消息完整性摘要通过验证以后, 互联网业务服务器再从消息中提取其中的 用户身份标识信息;
步骤 11:互联网业务服务器根据取得的用户身份标识信息査找出与其绑定的业务账号及授予该身份标 识的权限, 并标记该账号已通过登录认证, 如果账号不存在, 则提示用户是否创建账号, 如果用户选择是, 则为用户创建一个账号, 并直接将该账号和本次取得的用户身份标识信息相绑定。 如果是事先和电信网运 营商有协议直接使用电信网的用户身份标识作为账号的, 则直接使用电信网的用户身份标识作为账号, 并 标记该账号已通过登录认证, 如果对应的账号不存在, 则提示用户是否创建账号;
步骤 12 : 用户直接以所述账号以及授予该身份标识的权限开始使用互联网业务; 其中步骤 1又包含如下的子步骤:
步骤 101 : 电信网运营商定义和维护一个互联网业务列表。 这个列表中的每一个互联网业务项包含互 联网业务 ID、 业务登录 URL地址或业务登录 TCP/IP地址与端口号等信息。 电信网运营商还可以对这个列 表中的项进行多个级别的分类, 如首先分大类, 大类下面再划分小类, 小类下面再划分子类;
步骤 102:电信网运营商定义一个用户可以使用的身份标识类型列表,可以使用的身份标识类型包括客 户编号、 身份证号码、 移动电话号码、 固定电话号码、 ADSL账号、 LAN宽带账号、 WIFI账号、 网名以及其 他类型的身份标识, 运营商要保证每类身份标识下每个用户的标识值各不相同, 可以唯一代表该用户。 身 份标识类型分为真实身份标识和虚拟身份标识, 上面的类型中客户编号、 身份证号码、 移动电话号码、 固 定电话号码、 ADSL账号、 LAN宽带账号、 WIFI账号为真实身份标识, 网名等为虚拟身份标识;
步骤 103 : 电信网运营商根据所掌握的用户真实身份信息给用户的每类真实身份标识赋值, 虚拟身份 标识由用户自己取值, 但电信网运营商保证同一个类型下面用户的虚拟身份标识不和其他用户的相同。 一 个用户的每类身份标识可以有多个值, 运营商保证用户的每个真实身份标识确实是属于该用户的真实身份 信息;
步骤 104: 电信网运营商统一指定某类互联网业务或某个互联网业务使用哪类或哪个身份标识, 这个 指定对所有用户有效, 但优先级低于用户的指定, 电信网运营商也可以指定某类互联网业务或某个互联网 业务使用 "当前用户实际在使用的电信网接入方式的账号", 此时运营商的指定优先级高于用户的指定; 步骤 105:用户可对电信网运营商定义的互联网业务列表中的互联网业务项按自己的标准再进行分组; 步骤 106: 用户根据自己的偏好指定某个互联网业务或者某组互联网业务使用哪个身份标识。 同一个 类型的身份标识下面有多个值时需要用户选择一个。 对某一个互联网业务, 用户指定的使用哪个身份标识 优先级高于运营商统一指定的使用哪个身份标识。 用户也可以指定某个互联网业务或者某组互联网业务使 用 "当前用户实际在使用的电信网接入方式的账号";
步骤 107 : 运营商保存自己和用户设置好的用户身份标识使用策略; 其中步骤 2也可以是: 由电信网运营商和互联网业务提供商达成协议, 互联网业务直接使用电信网的 用户身份标识作为账号。 请参阅图 2中该种方法的流程示意图。 其中步骤 4所说的 "电信网对用户身份进行认证"包括: 输入 DSL、 ADSL, LAN, WLAN、 WIFI登录的 用户名和密码; 通过光纤的物理连接直接标识和认证用户身份; 通过 GSM、 CDMA, WCDMA、 LTE标准中的鉴 权算法标识和鉴别用户的身份; 以及其他认证用户身份的方法。 其中步骤 5所说的 "用户通过电信网接入互联网"包括通过 DSL、 ADSL, LAN, 光纤、 WLAN、 WIFI, GPRS, EDGE, WCDMA、 CDMA, HSPA、 LTE、 电力线、 有线电视线以及其他公众互联网接入方式接入到互联网。 其中步骤 6所说的 "开始使用互联网业务, 按照互联网协议向互联网发送消息"包括通过 HTTP或者 WEBSERVICE协议, 通过 FTP、 TELNET, SMTP, POP等各种标准互联网协议或者通过基于 TCP/IP协议的私有 协议连接到某个互联网业务服务器。 其中步骤 7所说的 "电信网的网关识别消息是否是登录互联网业务的消息并识别出对应的互联网业 务 ID"包括根据 HTTP、 WEBSERVICE中的 URL地址识别是登录消息和对应的互联网业务 ID,根据基于 TCP/IP 协议的私有协议中的端口号识别互联网业务 ID及其他方式识别出是登录互联网业务的消息。 其中步骤 8所说的 "在消息中加入用户身份标识以及电信网网关的签名信息和消息完整性摘要信息" 包括:电信网网关在 HTTP和 WEBSERVICE消息中加入用户身份标识信息以及自身的数字签名信息和消息完 整性摘要; 电信网关在基于 TCP/IP消息的私有协议中加入用户身份标识信息以及数字签名信息和用户身 份标识; 其中步骤 8、 9、 10、 11所说的 "用户身份标识信息"包括电信网运营商编号、 电信网络编号、 用户 身份标识类型和用户身份标识值。 从上面的步骤中可以看出, 如果是用户原来在某个互联网业务服务器上已经有账号了, 则可以输入账 号、 密码登录互联网业务服务器后设置将该账号和自己的一个或多个电信网身份标识相绑定(每个电信网 身份标识包括电信网运营商编号、 电信网络编号、 用户身份标识类型和用户身份标识值四个值, 可以使用 真实身份标识, 也可以使用虚拟身份标识), 并且在对应的电信网运营商网络上配置当访问该互联网业务 时传递哪类身份标识给该互联网业务服务器, 这之后凡是通过这配置列表中的电信网运营商的网络连接到 互联网的, 都可以不输账号不输密码登录到这个互联网业务服务器了。
更进一步, 如果电信网运营商和互联网业务提供商达成了协议, 该互联网业务直接使用该电信网运营 商的电信网用户身份标识作为账号, 则用户可以首先通过该运营商的电信网登录到互联网业务服务器, 直 接以电信网身份标识创建一个账号, 后面只要通过该运营商的电信网连接到该互联网业务服务器, 就都不 需要输账号登录, 也不需要设置任何密码。 从上面的描述可以看出, 使用本发明公开的方法, 一个可以统一互联网上的用户身份标识, 二个可以 使用户免账号免密码登录到互联网业务, 可以免去用户记忆账号和密码的麻烦, 省去用户登录互联网业务 时输入账号和密码的步骤, 为用户带来方便, 三个互联网业务可以根据用户的电信网身份标识从用户的电 信网账号中计费, 从而可以为互联网业务提供一种统一的支付方式。 本发明还公开了一种电信网身份管理服务器, 其包含如下单元:
互联网业务列表维护单元, 用于供电信网运营商定义和管理互联网业务列表;
身份标识类型定义单元, 用于供电信网运营商定义和管理身份标识类型列表;
身份标识定义单元, 用于供电信网运营商和用户定义和管理用户身份标识的值; 统一身份标识使用策略定义单元, 用于供电信网运营商统一指定某类互联网业务或每个互联网业务使 用哪个身份标识;
身份标识使用策略定义单元,用于供用户分互联网业务组、分单个互联网业务指定使用哪个身份标识; 互联网业务识别及身份标识査询单元, 用于供其他设备査询某个 URL或某个端口是否是互联网业务列 表中某个互联网业务项的业务登录 URL、 业务登录端口, 如果是, 根据査得的互联网业务 ID和其他设备输 入的用户键值査询得到要使用的用户身份标识返回给其他设备。 本发明还公开了一种电信网网关, 其包含如下单元:
业务登录消息识别单元, 用于识别出用户发出的消息中哪些是发送到互联网的业务登录消息并识别出 当前访问的是哪个互联网业务;
身份标识获取单元, 用于读取用户预先配置的要给当前在访问的互联网业务使用的身份标识; 身份信息附加单元, 用于在发送到互联网的业务登录消息中加入用户身份标识以及签名信息、 完整性 验证信息;
消息转发单元, 用于接收用户发送的业务登录消息之外的其他消息并转发到互联网上, 用于接收互联 网发送给用户的消息并转发给用户。 本发明还公开了一种互联网业务服务器, 其包含如下单元:
免登录处理单元, 用于提取业务登录消息中的电信网网关加入的用户身份标识并完成免登录处理。 其他子业务处理单元, 用于处理互联网业务的其他子业务。
其中免登陆处理单元包括:
身份标识提取单元,用于验证业务登录消息中的签名信息、完整性验证信息, 并提取出用户身份标识; 账号映射单元, 用于根据用户身份标识査找与其绑定的业务账号并且査找授予该身份标识的业务权 限;
登录状态修改单元, 用于设置账号为已登录状态。 本发明还公开了一种由电信网为互联网业务提供用户身份标识和用户身份认证的系统, 其包括: 电信网身份管理服务器, 用于管理和指定电信网提供给互联网业务的用户身份标识;
电信网网关, 用于识别出用户登录互联网业务的消息并在消息中加入用户的电信网身份标识; 互联网业务服务器, 用于提取电信网网关增加在消息中的用户身份标识并以之査找出对应的账号和授 予该身份标识的权限并为该账号提供互联网业务。 附图说明
图 1为本发明中由电信网为互联网业务提供用户身份标识和用户身份认证的方法的流程示意图; 图 2为本发明中由电信网为互联网业务提供用户身份标识和用户身份认证的方法的另一种实现方式的 流程示意图;
图 3为本发明中由电信网为互联网业务提供用户身份标识和用户身份认证的方法实施例 1的流程图; 图 4为本发明中由电信网为互联网业务提供用户身份标识和用户身份认证的方法实施例 2的流程图; 图 5为本发明中由电信网为互联网业务提供用户身份标识和用户身份认证的方法实施例 3的流程图; 图 6为多个电信网运营商、 多个电信网络和一个互联网业务服务器组成的示意图;
图 7为本发明中由电信网为互联网业务提供用户身份标识和用户身份认证的系统的示意图; 具体实施方式
实施例 1
在本实施例中, 用户张三是通过电信网运营商 A的 WCDMA 3G网络连接到互联网的, 用户免账号免认 证登录业务的具体步骤如下:
步骤 301 : 电信网运营商 A管理互联网列表, 增加一个新的互联网业务项, 如 "新浪博客", 其互联网 业务 ID为 1, 业务登录 URL地址为 http : //blog. sina. com. cn/noacctlogin。
步骤 302 : 电信网运营商 A在身份标识类型列表中增加一个身份标识类型: 手机号码。
步骤 303 : 电信网运营商 A根据用户张三的号码给用户张三的 "手机号码"类型身份标识赋值为: 18606061122。
步骤 304: 电信网运营商 A指定 "新浪博客"业务使用 "手机号码"类型的身份标识。
步骤 305 : 用户张三在 "新浪博客"上设置将自己的账号 Jackson和电信网的用户身份标识: 电信网 运营商编号一一 A;网络编号一一 WCDMA 3G网络;身份标识类型一一手机号码;身份标识值一一 18606061122 绑定。
步骤 306: 用户张三手机开机, 使用 18606061122号码的 USIM卡连接 WCDMA 3G网络。
步骤 307: 电信网运营商 A的 WCDMA 3G网络对 USIM卡进行身份认证, 认证通过, 并识别出是用户张 步骤 308 : 用户张三通过 3G网络的数据连接连接到互联网, 通过 HTTP协议连接 "新浪博客" 的免账 号登录 WEB地址: http : //blog. sina. com. cn/noacctlogin。
步 骤 309 : 电 信 网 运 营 商 A 的 WCDMA 3G 网 络 的 网 关 根 据 URL 地 址 http : //blog. sina. com. cn/noacctlogin査询互联网业务列表, 发现是 "新浪博客"业务的登录 URL, 对 应的互联网业务 ID为 1。
步骤 310: 电信网运营商 A的 WCDMA 3G网络的网关査询电信网运营商 A和用户张三自己指定的身份标 识使用策略, 发现需要使用电信网运营商 A统一指定的策略: 使用 "手机号码"类型的身份标识, 电信网 网关获得张三的 "手机号码"类型的身份标识, 然后在 HTTP消息头中加入该身份标识: 电信网运营商编 号一一 A ; 网络编号一一 WCDMA 3G网络; 身份标识类型一一手机号码; 身份标识值一一 18606061122及自 身的数字签名信息以及整个消息的摘要并转发到互联网。
步骤 311 : "新浪博客" 的服务器收到电信网运营商 A的 WCDMA 3G网络网关转发来的消息, 验证其中 的数字签名和消息完整性摘要, 确保消息来自电信网运营商 A的 WCDMA 3G网络网关并且未被恶意修改。
步骤 312 : "新浪博客" 的服务器从消息提取电信网的用户身份标识: 类型一一手机号码; 值一一 18606061122。
步骤 313 : "新浪博客"根据电信网的用户身份标识: 电信网运营商编号一一 A ; 网络编号一一 WCDMA 3G 网络; 身份标识类型一一手机号码; 身份标识值一一 18606061122査找到与其绑定的用户账号 Jackson, 并标记 Jackson登录成功。
步骤 314: 用户张三以账号 Jackson开始使用 "新浪博客"业务。 实施例 2
在本实施例中, 用户李四是通过电信网运营商 B的 ADSL宽带网络连接到互联网的, 用户免账号免认 证登录业务的具体步骤如下:
步骤 401 : 电信网运营商 B管理互联网列表, 增加一个新的互联网业务项, 如 "携程旅行", 其互联网 业务 ID 为 2, 分类大类为 "生活类 ", 小类为 "旅行类 ", 业务登录 URL 地址为 http: //www. ctrip. com/noacctlogin。 步骤 402 : 电信网运营商 B在身份标识类型列表中增加两个身份标识类型: ADSL账号、 手机号码。 步骤 403: 电信网运营商 B根据用户李四的 ADSL账号给用户李四的 "ADSL账号"类型身份标识赋值: szdsl52316938@163. gd。此外,用户李四还使用了电信网运营商 B的 TD-CDMA手机,号码为: 18902020505, 因此电信网运营商 B还给李四的 "手机号码"类型身份标识赋值: 18902020505。 电信网运营商 B还指定 "生活类"互联网业务统一使用 "手机号码"类型的身份标识。
步骤 404: 用户李四对互联网业务分组, "携程旅行"分组为 "旅行组", 并指定该组业务使用 "ADSL 账号"类型的身份标识。
步骤 405 : 电信网运营商 B和携程无线签订协议, 约定携程旅行业务就使用运营商 B携带的 ADSL账号 或手机号码作为用户的账号。
步骤 406: 用户李四通过 ADSL账号 szdsl52316938@163. gd拨号上网。
步骤 407 : 电信网运营商 B的 ADSL接入设备对用户进行身份认证, 认证通过, 并识别出是用户李四。 步骤 408: 用户李四通过 ADSL连接连接到互联网, 通过 HTTP协议连接"携程旅行"的免账号登录 WEB 地址: http : //www. ctrip. com/noacctlogin。
步骤 409: 电信网运营商 B的 ADSL网络的网关根据 URL地址 http :〃胃. ctrip. com/noacctlogin査 询互联网业务列表, 发现是 "携程旅行"业务的登录 URL, 对应的互联网业务 ID为 2。
步骤 410: 电信网网关査询电信网运营商 B和用户李四自己指定的身份标识使用策略, 发现需要使用 用户李四自己指定的策略: 使用 "ADSL账号"类型的身份标识, 电信网网关获得张三的 "ADSL账号"类 型的身份标识, 并在 HTTP消息头中加入该身份标识: 电信网运营商编号一一 B; 网络编号一一 ADSL网络; 类型一一 ADSL账号; 值一一 szdsl52316938@163. gd及自身的数字签名信息以及整个消息的摘要并转发到 互联网。
步骤 411 : "携程旅行" 的服务器收到电信网运营商 B的 ADSL网络网关转发来的消息, 验证其中的数 字签名和消息完整性摘要, 确保消息来自电信网运营商 B的 ADSL网络网关并且未被恶意修改。
步骤 412 : "携程旅行" 的服务器从消息提取电信网的用户身份标识: 电信网运营商编号一一 B; 网络 编号一一 ADSL网络; 身份标识类型一一 ADSL账号; 身份标识值一一 szdsl52316938@163. gd。
步骤 413 : "携程旅行"的服务器根据协议, 直接以电信网的用户身份标识组装出账号 "电信网运营商 编号—网络编号―身份标识类型—身份标识值" : B— ADSL— adsl— Szdsl52316938@163. gd作为账号并标记该账 号登录成功。
步骤 414: 用户李四以账号 B— ADSL— adsl— szdsl52316938組 63. gd开始使用 "携程旅行"业务。 实施例 3
在本实施例中,描述了使用不同的网络连接方式,免登录后获得的权限也不同的例子, 具体步骤如下: 步骤 501 : 电信网运营商 C管理互联网列表, 增加一个新的互联网业务项, 如 " XX网上银行", 其互 联网业务 ID 为 3, 分类大类为 "生活类", 小类为 "网上银行类", 业务登录 URL 地址为 http: //www. anetbank. com/noacctlogin。
步骤 502 : 电信网运营商 C在身份标识类型列表中增加两个身份标识类型:家庭 ADSL账号、手机号码。 步骤 503 : 用户王五在运营商 C开了个家庭 ADSL账号: szdsl52316938@163. gd, 并且在运营商 C的 CDMA网络上开了个自己用的手机号码: 18302020505。 电信网运营商 C根据王五的真实信息给王五的 "家 庭 ADSL 账号"类型的身份标识赋值: szdsl52316938@163. gd, "手机号码"类型的身份标识赋值: 18302020505。
步骤 504: 电信网运营商 C指定 "XX网上银行"业务使用 "当前用户实际在使用的电信网接入方式的 账号"类型的身份标识。
步骤 505 : 用户王五在 "XX网上银行" 的互联网业务服务器上配置将自己的银行账号 18181818和电 信网运营商 C的电信网身份标识家庭 ADSL账号: szdsl52316938@163. gd和 手机号码: 18302020505绑 定, 其中家庭 ADSL账号: szdsl52316938@163. gd只授予査询余额的权限, 而手机号码: 18302020505授 予全部权限。
步骤 506:用户王五通过自己的号码为 18302020505手机上网,连接" XX网上银行"的免账号登录 WEB 地址: http : //www. anetbank. com/noacct login 0
步骤 507 : 电信网运营商 C的 CDMA网络网关根据 URL地址 http:〃 www. anetbank. com/noacctlogin 査询互联网业务列表, 发现是 "XX网上银行"业务的登录 URL, 对应的互联网业务 ID为 3。
步骤 508:电信网运营商 C的 CDMA网络网关査询电信网运营商 C和用户王五自己指定的身份标识使用 策略, 发现应该使用电信网运营商 C指定的策略: 使用 "当前用户实际在使用的电信网接入方式的账号" 类型的身份标识, 电信网网关获得王五的 "当前用户实际在使用的电信网接入方式的账号"类型的身份标 识并添加在 HTTP消息头中:电信网运营商编号一一 C;网络编号一一 CDMA网络;类型一一手机号码;值一一 18302020505及自身的数字签名信息以及整个消息的摘要并转发到互联网。
步骤 509: "XX网上银行"的服务器收到电信网运营商 C的 CDMA网络网关转发来的消息, 验证其中的 数字签名和消息完整性摘要, 并取出其中的用户身份标识为: 电信网运营商编号一一 C; 网络编号一一 CDMA 网络; 类型一一手机号码; 值一一 18302020505。
步骤 510: "XX网上银行"根据电信网的用户身份标识査得其关联的银行账号为 18181818, 并且授予 该身份标识的权限为全部权限。
步骤 511 : 用户王五在银行账号 18181818上做余额査询、 转账等操作。
步骤 512 : 用户王五的妻子在家里通过家庭 ADSL账号 szdsl52316938@163. gd拨号上网。
步骤 513 :电信网运营商 C的家庭 ADSL接入设备对用户进行身份认证,认证通过,并识别出是用户"王 五"或者 "王五家庭", 其中 "王五家庭"也可以访问 "王五" 的业务。
步骤 514: 用户王五的妻子连接 " XX 网上银行 " 的免账号登录 WEB 地址: http : //www. anetbank. com/noacctlogin。
步骤 515 :电信网运营商 C的家庭 ADSL网络网关根据 URL地址 http:〃 www. anetbank. com/noacctlogin 査询互联网业务列表, 发现是 "XX网上银行"业务的登录 URL, 对应的互联网业务 ID为 3。
步骤 516:电信网运营商 C的家庭 ADSL网络网关査询电信网运营商 C和用户王五自己指定的身份标识 使用策略, 发现应该使用电信网运营商 C指定的策略: 使用 "当前用户实际在使用的电信网接入方式的账 号"类型的身份标识, 电信网网关获得王五的 "当前用户实际在使用的电信网接入方式的账号"类型的身 份标识并添加在 HTTP消息头中: 电信网运营商编号一一 C; 网络编号一一家庭 ADSL网络; 类型一一 ADSL 账号; 值一一 szdsl52316938@163. gd及自身的数字签名信息以及整个消息的摘要并转发到互联网。
步骤 517 : "XX网上银行"的服务器收到电信网运营商 C的家庭 ADSL网络网关转发来的消息, 验证其 中的数字签名和消息完整性摘要, 并取出其中的用户身份标识为: 电信网运营商编号一一 C; 网络编号一一 家庭 ADSL网络; 类型一一 ADSL账号; 值一一 szdsl52316938@163. gd。
步骤 518 : "XX网上银行"根据电信网的用户身份标识査得其关联的银行账号为 18181818, 并且授予 该身份标识的权限为査询余额。
步骤 519: 用户王五的妻子在银行账号 18181818上只能做余额査询操作。 实施例 4
在本实施例中, 描述了用户使用虚拟身份免账号免认证登录互联网业务的场景:
步骤 601 : 电信网运营商 D管理互联网列表, 增加一个新的互联网业务项, 如 "天涯论坛", 其互联网 业务 ID为 4, 分类大类为 "论坛类", 业务登录 URL地址为 http :〃胃. tianya. com/noacctlogin。
步骤 602 : 电信网运营商 D在身份标识类型列表中增加一个身份标识类型: 网名, 为虚拟身份标识。 步骤 603 : 电信网运营商 D和天涯论坛签订协议, 约定天涯论坛业务就使用运营商 D携带的网名作为 用户的账号。 步骤 604: 用户马六在电信网运营商 D的网络上给自己的 "网名 "类型的身份标识取值: MaLiu。 该 名字通过验证, 和别的用户不重名。
步骤 605 : 电信网运营商 D还指定 "论坛类"互联网业务统一使用 "网名"类型的身份标识。
步骤 606: 用户马六通过运营商 D的 WCDMA 3G手机号码 18606061122上网。
步骤 607: 电信网运营商 D的 WCDMA 3G网络对号码 18606061122进行身份认证, 认证通过, 并识别 出是用户马六。
步骤 608: 用户马六通过 HTTP 协议连接 "天涯论坛 " 的免账号登录 WEB 地址: http : //www. tianya. com/noacctlogin。
步骤 609 : 电信网运营商 D 的 WCDMA 3G 网络的 网关根据 URL 地址 http:〃 胃. tianya. com/noacctlogin査询互联网业务列表, 发现是 "天涯论坛"业务的登录 URL, 对应的互联网 业务 ID为 4。
步骤 610: 电信网运营商 D的 WCDMA 3G网络的网关査询电信网运营商 D和用户马六自己指定的身份 标识使用策略, 发现需要使用电信网运营商 D指定的策略: 使用 "网名"类型的身份标识, 电信网网关获 得马六的 "网名"类型的身份标识, 并在 HTTP消息头中加入该身份标识: 电信网运营商编号一一 D; 网络 编号一一 WCDMA 3G 网络; 类型一一网名; 值一一 MaLiu及自身的数字签名信息以及整个消息的摘要并转 发到互联网。
步骤 611 : "天涯论坛"的服务器收到电信网运营商 D的 WCDMA 3G网络网关转发来的消息, 验证其中 的数字签名和消息完整性摘要, 然后从消息提取电信网的用户身份标识: 电信网运营商编号一一 D; 网络 编号一一 WCDMA 3G网络; 身份标识类型一一网名; 身份标识值一一 MaLiu。
步骤 612 : "天涯论坛"的服务器根据协议, 直接以电信网的用户身份标识组装出账号 "电信网运营商 编号—身份标识值" : D— MaLiu作为账号并标记该账号登录成功。
步骤 613 : 用户马六以账号 D— MaLiu开始使用 "天涯论坛"业务。 实施例 5
上面描述的都是使用 HTTP协议的例子, 本实施例中, 描述一个基于 TCP/IP协议的私有协议的例子: 步骤 701 : 电信网运营商 E管理互联网列表, 增加一个新的互联网业务项, 如 " XX即时消息", 其互 联网业务 ID为 5, 分类大类为 "即时消息类", 业务登录方式为私有协议, 连接服务器胃 . xxim. com的 TCP端口 12345按私有协议收发消息进行登录。
步骤 702: 电信网运营商 E在身份标识类型列表中增加一个身份标识类型: E-mai l地址, 为虚拟身份 标识。
步骤 703: 电信网运营商 E和 XX即时消息签订协议, 定义好用户身份标识信息、 网关签名信息和消息 完整性摘要信息传递的接口。
步骤 704: 用户钱七在电信网运营商 E 的网络上给自己的 "E-mail 地址"类型的身份标识取值: qianqi@163. com。 该名字通过验证, 和别的用户不重名。
步骤 705 : 电信网运营商 3还指定 "即时消息类"互联网业务统一使用 "E-mai l地址"类型的身份标 识。
步骤 706: 用户钱七通过运营商 E的 WCDMA 3G手机号码 18606061122上网。
步骤 707: 电信网运营商 E的 WCDMA 3G网络对号码 18606061122进行身份认证, 认证通过, 并识别 出是用户钱七。
步骤 708 : 用户钱七通过 XX即时消息的私有协议连接 " XX即时消息" 的服务器: 胃. xxim. com, 端 口为 12345。
步骤 709: 电信网运营商 E的 WCDMA 3G网络的服务器地址和端口査询互联网业务列表, 发现是 "XX 即时消息"业务的登录 URL, 对应的互联网业务 ID为 5。
步骤 710: 电信网运营商 E的 WCDMA 3G网络的网关査询电信网运营商 E和用户钱七自己指定的身份 标识使用策略, 发现需要使用电信网运营商 E指定的策略: 使用 " E-mai l地址"类型的身份标识, 电信网 网关获得钱七的 "E-mai l地址"类型的身份标识, 根据私有协议在 TCP消息中加入该身份标识: 电信网运 营商编号一一 E; 网络编号一一 WCDMA 3G网络; 类型一—E-mai l地址; 值一一 qianqi@163. com及自身的 数字签名信息以及整个消息的摘要并转发到互联网。
步骤 711 : "XX即时消息" 的服务器收到电信网运营商 D的 WCDMA 3G网络网关转发来的消息, 验证 其中的数字签名和消息完整性摘要, 然后从消息提取电信网的用户身份标识: 电信网运营商编号一一 E; 网络编号一一 WCDMA 3G网络; 身份标识类型一一 E- mai l地址; 身份标识值一一 qianqi@163. com。
步骤 712 : "XX即时消息" 的服务器根据协议, 直接以电信网的用户身份标识组装出账号 "身份标识 值" : qianqi@163. com作为账号并标记该账号登录成功。
步骤 713 : 用户钱七以账号 qianqi@163. com开始使用 "XX即时消息"业务。 请参阅图 7, 其为本发明一种由电信网为互联网业务提供用户身份标识和用户身份认证的系统的结构 示意图, 其中包括电信网身份管理服务器结构示意图, 电信网网关结构示意图, 以及互联网业务服务器结 构示意图。
本实施例中的电信网身份管理服务器 70包括互联网业务列表维护单元 703、 身份标识类型定义单元 702、 身份标识定义单元 704、 统一身份标识使用策略定义单元 706、 身份标识使用策略定义单元 705以及 互联网业务识别及身份标识査询单元 701, 下面结合具体实施方式进一步介绍其内部结构以及连接关系。
首先互联网业务列表维护单元 703提供界面供运营商定义互联网业务列表, 每个互联网业务包括互联 网业务 ID、 业务登录 URL地址或业务登录 TCP/IP地址与端口号等信息, 然后保存该列表。
然后身份标识类型定义单元 702提供界面供运营商定义身份标识类型, 包括客户编号、 身份证号码、 移动电话号码、 固定电话号码、 ADSL账号、 LAN宽带账号、 WIFI账号、 网名等类型, 然后保存这些类型数 据。
再然后身份标识类型定义单元 704提供界面供运营商输入每个用户各个真实身份标识类型的值, 也可 以从别的表中导入, 身份标识类型定义单元 704要保证每类身份标识下每个用户的标识值各不相同, 可以 唯一代表该用户。 当身份标识为虚拟身份标识时, 身份标识类型定义单元 704还允许用户自己取值。 同一 类型的身份标识可以有多个。 身份标识类型定义单元 704保存这些数据。
再然后统一身份标识使用策略定义单元 706提供界面供运营商对互联网业务分类, 并指定某类互联网 业务或某个互联网业务使用哪类或哪个身份标识, 统一身份标识使用策略定义单元 706保存这些数据。
再然后身份标识使用策略定义单元 705提供界面供用户对互联网业务分组, 并根据自己的偏好指定某 个互联网业务或者某组互联网业务使用哪个身份标识, 身份标识使用策略定义单元 705保存这些数据。
用户在使用业务时, 电信网网关的身份标识获取单元 712发送请求给互联网业务识别及身份标识査询 单元 701, 要求识别是否是已配置的互联网业务并返回应该使用的电信网身份标识。请求中携带用户键值、 用户访问的 URL地址或者服务器地址和端口号。 此时互联网业务识别及身份标识査询单元 701根据请求中 的 URL地址或者服务器地址和端口号査找互联网业务列表, 如果找到 URL地址或者服务器地址和端口号和 某个项中的值相等, 则识别是该互联网业务并获得该互联网业务的互联网业务 ID, 如果在互联网业务列表 中没有找到 URL地址或者服务器地址和端口号和请求中相等的项,则向电信网网关的身份标识获取单元 712 返回 "不是可识别的互联网业务"。 如果获得了互联网业务 ID, 则根据互联网业务 ID和用户键值査询统一 身份标识使用策略定义单元 706、 身份标识使用策略定义单元 705 前面保存的数据, 按发明内容中步骤 104^106中的原则确定本次应该使用哪个身份标识。 然后把这个身份标识的身份标识类型和身份标识值返 回给电信网网关的身份标识获取单元 712。 本实施例中的电信网网关 71包括业务登录消息识别单元 711、 身份标识获取单元 712、 身份信息附加 单元 713和消息转发单元 714, 下面结合具体实施方式进一步介绍其内部结构以及连接关系。
用户使用某个互联网业务时, 首先通过电信网网络接入设备 73接入到电信网, 此时电信网使用电信 网的身份标识会对用户身份进行认证。 然后用户通过电信网网络接入设备 73 向互联网发送消息, 消息被 送到电信网网关 71的业务登录消息识别单元 711, 由业务登录消息识别单元 711调身份标识获取单元 712 向电信网身份管理服务器 70请求识别是否是已配置的互联网业务并返回应该使用的电信网身份标识的类 型和值。 如果识别是已配置的互联网业务并且取得了返回的应该使用的电信网身份标识类型和值, 则判断 身份标识是否是 "当前用户实际在使用的电信网接入方式的账号"类型, 如果是则从电信网网络接入设备 73获取当前的接入方式及接入账号,然后把该身份标识类型和值和消息一起发送给身份信息附加单元 713, 身份信息附加单元 713收到消息和应该使用的身份标识类型和值后, 在消息中添加电信网网关 71的数字 签名信息和完整性摘要信息以及用户的身份标识信息, 用户的身份标识信息包括电信网运营商编号、 电信 网络编号、 用户身份标识类型和用户身份标识值, 然后再把消息转发给消息转发单元 714, 由消息转发单 元 714将消息转发到互联网最终到达互联网业务服务器 72。如果识别出不是已配置的互联网业务, 则业务 登录消息识别单元 711直接把消息转发给消息转发单元 714, 有消息转发单元 714转发到互联网最终到达 互联网业务服务器 72。 对于互联网业务服务器 72发给用户的消息, 由消息转发单元 714转发给电信网网 络接入设备 73, 电信网网络接入设备 73再转发给用户。 本实施例中的互联网业务服务器 72包括免登录处理单元 721和其他子业务处理单元 722,其中免登录 处理单元 721又包括身份标识提取单元 7213、 账号映射单元 7212和登录状态修改单元 7211, 下面结合具 体实施方式进一步介绍其内部结构以及连接关系。
电信网网关 71 的消息转发单元 714转发的消息首先到达免登录处理单元 721 的身份标识提取单元 7213, 身份标识提取单元 7213根据请求的 URL地址判断是否是免账号登录消息, 如果不是, 直接转发给 其他业务处理单元 722进行处理。 如果是, 则根据消息中的签名信息验证消息是否是来电信网网关 71, 然 后再通过消息完整性摘要来验证消息在从电信网网关 71 到当前位置的传递途径中是否被更改, 如果签名 信息或消息完整性摘要信息验证不通过, 则丢弃消息。 否则提取消息中用户身份标识信息, 其内容如下: 电信网运营商编号、 电信网络编号、 用户身份标识类型和用户身份标识值。 将用户身份标识信息传递给账 号映射单元 7212。
账号映射单元 7212判断是否有要求直接使用电信网的用户身份标识作为账号, 如果有, 则直接用用 户身份标识信息根据要求的格式组合出账号, 否则根据用户身份标识信息査找之前全部用户设定的电信网 用户身份标识和账号间的绑定关系, 査找出本次的用户身份标识信息对应哪个账号, 并査找出给用户身份 标识授予的权限信息。 账号映射单元 7212把组合出或者査找到的账号以及应授予的权限信息传递给登录 状态修改单元 7211, 由登录状态修改单元 7211更新账号的状态为登录并保存授予的权限信息。 最后应当说明的是: 以上实施例仅用以说明本发明的技术方案而非对其限制; 尽管参照较佳实施例对 本发明进行了详细的说明, 所属领域的普通技术人员应当理解: 依然可以对本发明的具体实施方式进行修 改或者对部分技术特征进行等同替换; 而不脱离本发明技术方案的精神和原则所作的修改、 等同替换和改 进等, 均应涵盖在本发明请求保护的技术方案范围之内。

Claims

1、 一种用户在电信网上定制要给互联网业务使用的身份标识的方法, 其特征在于, 包括: 步骤 1 : 电信网运营商定义和维护一个互联网业务列表;
步骤 2: 电信网运营商定义一个用户可以使用的身份标识类型列表;
步骤 3 : 电信网运营商根据所掌握的用户真实身份信息给用户的每类身份标识赋值;
步骤 4: 电信网运营商统一指定某个互联网业务使用哪类身份标识;
步骤 5: 电信网运营商保存设置好的上述数据。
2、 根据权利要求 1所述的方法, 其特征在于, 还包含:
用户可以根据自己的偏好指定某个互联网业务使用哪类或哪个身份标识, 此时用户的指定优先级高于电信 运营商的统一指定;
3、 根据权利要求 1和权利要求 2中任意一项所述的方法, 其特征在于:
用户身份标识类型分为真实身份标识和虚拟身份标识。 真实身份标识由电信网运营商根据所掌握的用户真 实身份信息赋值, 虚拟身份标识由用户自己取值, 但电信网运营商要保证同一个类型下面某个用户的虚拟 身份标识不和其他用户的相同, 即能唯一标识所述用户。 所述的身份标识包括如下类型: 客户编号、 身份 证号码、 移动电话号码、 固定电话号码、 ADSL账号、 LAN宽带账号、 WIFI账号、 电视线上网账号、 电 力线上网账号、 网名以及其他类型。
4、 根据权利要求 3所述的方法, 其特征在于:
所述互联网业务列表中的每一个互联网业务项包含互联网业务 ID、 免账号登录 URL地址或者服务器地址 加端口号等信息;
5、 根据权利要求 4所述的方法, 其特征在于, 还包含:
电信网运营商还可以对互联网业务列表中的项进行多个级别的分类,如首先分大类,大类下面再划分小类, 小类下面再划分子类。 电信网运营商可以统一指定某类互联网业务使用哪种类型的用户身份标识。
6、 根据权利要求 5所述的方法, 其特征在于, 还包含:
用户可对电信网运营商定义的互联网业务列表中的互联网业务项按自己的标准再进行分组。 用户可以指定 某组互联网业务使用哪类或哪个身份标识 (当同一类型的身份标识有多个时)。
7、 一种电信网身份管理服务器, 其特征在于, 包括:
互联网业务列表维护单元, 用于供电信网运营商定义和管理互联网业务列表;
身份标识类型定义单元, 用于供电信网运营商定义和管理用户身份标识类型列表;
身份标识定义单元, 用于供电信网运营商和用户定义和管理用户身份标识的值;
统一身份标识使用策略定义单元, 用于供电信网运营商统一指定某类互联网业务或者某个互联网业务使用 哪个身份标识;
身份标识使用策略定义单元, 用于供用户分互联网业务组、 分单个互联网业务指定使用哪个身份标识; 互联网业务识别及身份标识査询单元, 用于供其他设备査询某个 URL或某个服务器地址加端口是否是互 联网业务列表中某个互联网业务项的免账号登录 URL、 服务器地址加端口, 如果是, 则根据该项的互联网 业务 ID和其他设备输入的用户键值査询得到要使用的用户身份标识并返回给其他设备。
8、 一种电信网将用户身份标识携带给互联网的方法, 其特征在于, 包括:
互联网业务和用户间收发的消息都经过电信网转发;
电信网识别出所述用户发送给互联网业务的业务登录消息和互联网业务 ID;
电信网获取所述用户预先配置的要给当前在访问的互联网业务使用的身份标识;
电信网在发送到互联网的业务登录消息中加入所述用户预先配置的要给当前在访问的互联网业务使用的 身份标识。
9、 根据权利要求 8所述的方法, 其特征在于, 还包括: 电信网在发送到互联网的业务登录消息中加入签名信息及完整性摘要信息, 所述签名信息用于确立互联网 对电信网的信任, 所述完整性摘要信息用于防止消息中加入的用户身份标识在消息传递过程中被篡改。
10、 根据权利要求 8 和权利要求 9 中任意一项所述的方法, 其特征在于, 所述消息包括: HTTP、 WEBSERVICE, FTP/TELNET/SMTP等标准 TCP/IP协议以及其他基于 TCP/IP协议的私有协议。
11、 一种电信网网关, 其特征在于:
该网关是电信网用户接入互联网的必经途径, 用户发送到互联网的消息都经过该网关;
该网关包含:
业务登录消息识别单元, 用于识别出用户发出的消息中哪些是发送到互联网的业务登录消息并识别出当前 访问的是哪个互联网业务;
用户身份标识获取单元, 用于读取用户预先配置的要给当前在访问的互联网业务使用的身份标识; 用户身份信息附加单元, 用于在发送到互联网的业务登录消息中加入用户身份标识信息以及签名信息、 完 整性验证信息;
消息转发单元, 用于在用户和互联网业务之间转发消息。
12、 一种互联网业务获取电信网携带的用户身份标识和用户身份认证信息的方法, 其特征在于, 包括: 电信网运营商和互联网业务提供商达成协议, 互联网业务直接使用电信网的用户身份标识作为账号; 互联网业务服务器判断电信网转发给互联网的业务登录消息中是否包含有电信网的签名信息; 如果有签名信息, 则验证签名是否合法;
如果签名合法, 则验证消息的完整性摘要信息看消息是否被篡改;
如果消息未被篡改, 则认为消息和消息中用户身份标识都是可信的;
如果消息中的签名信息验证不通过, 则忽略消息中用户身份标识, 如果完整性摘要信息验证不通过, 则丢 弃消息。
互联网业务从电信网转发给互联网的业务登录消息中提取出电信网加入的用户身份标识信息; 互联网业务服务器根据所述用户身份标识信息按照商定的格式组合出业务账号;
标记所述账号已通过登录认证并使用所述账号来访问后继互联网业务。
13、 一种互联网业务获取电信网携带的用户身份标识和认证信息的方法, 其特征在于, 包括: 用户在互联网业务服务器上设置将业务账号和自己在电信网的一个或多个身份标识相绑定;
互联网业务服务器判断电信网转发给互联网的业务登录消息中是否包含有电信网的签名信息; 如果有签名信息, 则验证签名是否合法;
如果签名合法, 则验证消息的完整性摘要信息看消息是否被篡改;
如果消息未被篡改, 则认为消息和消息中用户身份标识都是可信的;
如果消息中的签名信息验证不通过, 则忽略消息中用户身份标识, 如果完整性摘要信息验证不通过, 则丢 弃消息。
互联网业务从电信网转发给互联网的业务登录消息中提取出电信网加入的用户身份标识信息; 互联网业务服务器根据所述用户身份标识信息査找出与其绑定的业务账号;
标记所述账号已通过登录认证并使用所述账号来访问后继互联网业务。
14、 根据权利要求 13所述的方法, 其特征在于, 还包括:
用户可以在互联网业务服务器上设置每个电信网的身份标识授予哪些权限;
互联网业务服务器还可以根据所述用户身份标识信息査找授予了该标识哪些权限;
15、 一种互联网业务服务器, 其特征在于, 包括:
免登录处理单元, 用于提取业务登录消息中的电信网网关加入的用户身份标识信息并完成免登录处理。 业务处理子单元, 用于提供互联网业务的业务功能。
16、 根据权利要求 15所述的互联网业务服务器, 其特征在于, 所述免登陆处理单元包括:
身份标识提取单元,用于验证业务登录消息中的签名信息、完整性验证信息,并提取出用户身份标识信息; 账号映射单元, 用于根据用户身份标识信息査找与其绑定的业务账号;
登录状态修改单元, 用于设置所述业务账号为已登录状态。
17、 根据权利要求 16所述的互联网业务服务器, 其特征在于:
所述账号映射单元还包括査找授予所述用户身份标识的业务权限的功能。
18、 一种由电信网为互联网业务提供用户身份标识和用户身份认证的方法, 其特征在于, 至少包括如下步 骤:
步骤 1 : 用户在电信网上配置要给互联网业务使用的身份标识;
步骤 2: 用户在互联网业务服务器上设置将业务账号和自己在电信网的一个或多个身份标识相行绑定; 步骤 3 : 用户连接到电信网;
步骤 4: 电信网对用户身份进行认证;
步骤 5: 用户通过电信网连接到互联网, 开始使用互联网业务, 按照互联网协议向互联网发送消息; 步骤 6: 所发送的消息经过电信网的网关;
步骤 7: 电信网的网关识别消息是否是登录互联网业务的消息并识别出对应的互联网业务 ID;
步骤 8: 电信网的网关如果识别出是登录互联网业务的消息, 则在消息中加入用户指定的要提供给该互联 网业务的身份标识信息以及自身的签名信息、 完整性验证信息, 告诉互联网该用户身份标识是经过电信网 验证的, 然后转发到互联网;
步骤 9: 互联网业务服务器收到消息, 从消息中提取其中的用户身份标识信息;
步骤 10: 互联网业务服务器根据取得的用户身份标识信息査找出与其绑定的业务账号, 并标记该账号已通 过登录认证;
步骤 11 : 用户直接以所述账号开始使用互联网业务;
19、 一种由电信网为互联网业务提供用户身份标识和用户身份认证的系统, 其特征在于, 包括: 电信网身份管理服务器, 用于管理和指定电信网提供给互联网业务的用户身份标识;
电信网网关, 用于识别出用户登录互联网业务的消息并在消息中加入用户的电信网身份标识信息和电信网 网关的签名信息;
互联网业务服务器, 用于提取电信网网关增加在消息中的用户身份标识信息并以之査找出与之绑定的账号 和授予该用户身份标识的权限, 然后为该账号按指定的权限提供互联网业务。
20、 根据权利要求 1、 权利要求 8、 权利要求 12、 权利要求 13、 权利要求 18中任意一项所述的方法, 其 特征在于, 所述 "电信网"包括: DSL、 ADSL, 固定电话网络、 移动电话网络、 小区 LAN 宽带网络、 WLAN网络、 WIFI网络、 光纤接入网络、 有线电视线上网网络、 电力线上网网络以及其他为公众提供互 联网接入的网络。
21、 根据权利要求 7、 权利要求 11、 权利要求 15、 权利要求 19中任意一项所述的设备或系统, 其特征在 于, 所述 "电信网"包括: DSL、 ADSL, 固定电话网络、 移动电话网络、 小区 LAN宽带网络、 WLAN网 络、 WIFI 网络、 光纤接入网络、 有线电视线上网网络、 电力线上网网络以及其他为公众提供互联网接入 的网络。
PCT/CN2011/082064 2010-12-08 2011-11-10 一种由电信网为互联网业务提供用户身份标识和用户身份认证的方法 WO2012075873A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201010579782.0 2010-12-08
CN2010105797820A CN102437914B (zh) 2010-12-08 2010-12-08 一种由电信网为互联网业务提供用户身份标识和用户身份认证的方法

Publications (1)

Publication Number Publication Date
WO2012075873A1 true WO2012075873A1 (zh) 2012-06-14

Family

ID=45985798

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2011/082064 WO2012075873A1 (zh) 2010-12-08 2011-11-10 一种由电信网为互联网业务提供用户身份标识和用户身份认证的方法

Country Status (2)

Country Link
CN (1) CN102437914B (zh)
WO (1) WO2012075873A1 (zh)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103338320A (zh) * 2013-07-24 2013-10-02 联创亚信科技(南京)有限公司 一种移动用户充值数据处理方法及装置
CN104243286A (zh) * 2014-09-23 2014-12-24 上海佰贝科技发展有限公司 通过微信进行公共wifi认证的方法
CN104980922A (zh) * 2014-04-02 2015-10-14 陈煜军 一种基于公众平台的无线互联网接入方法及系统
CN106717107A (zh) * 2015-08-04 2017-05-24 华为技术有限公司 连接网络的方法和终端
US11877218B1 (en) 2021-07-13 2024-01-16 T-Mobile Usa, Inc. Multi-factor authentication using biometric and subscriber data systems and methods

Families Citing this family (19)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103138935B (zh) * 2013-01-25 2016-05-04 宝利数码有限公司 一种基于电信运营商的身份认证系统
CN104639321B (zh) * 2013-11-12 2018-03-23 中国移动通信集团公司 一种身份认证方法、设备及系统
CN103746792B (zh) * 2013-12-31 2017-11-07 郑盈盈 一种第三方应用账号与手机号码绑定、解除和更新方法
CN104902531B (zh) * 2014-03-03 2019-11-05 腾讯科技(深圳)有限公司 连接网络的方法、应用认证服务器、终端及路由器
CN104144111B (zh) * 2014-03-14 2016-12-21 腾讯科技(深圳)有限公司 社交网络应用中获取用户相关信息的方法和系统
CN105099729B (zh) * 2014-04-22 2018-07-20 阿里巴巴集团控股有限公司 一种识别用户身份标识的方法和装置
CN103916403A (zh) * 2014-04-22 2014-07-09 成都嘉盟科技有限公司 支持sip协议的免输入密码客户端的登录方法
CN105281906B (zh) * 2014-07-04 2020-11-06 腾讯科技(深圳)有限公司 安全验证方法及装置
CN107040495B (zh) * 2016-02-03 2021-07-13 重庆小目科技有限责任公司 一种应用于工业通信和业务的多级联合身份认证方法
CN106453349B (zh) * 2016-10-31 2019-06-14 北京小米移动软件有限公司 账号登录方法及装置
CN106657045B (zh) * 2016-12-13 2020-10-13 翁印嵩 多网融合的安全与认证方法及系统
CN108990059B (zh) * 2017-06-02 2021-06-29 创新先进技术有限公司 一种验证方法及装置
CN107222487B (zh) * 2017-06-13 2020-09-08 杭州奇亿云计算有限公司 一种混合云环境的账号对接系统
CN107257556A (zh) * 2017-08-15 2017-10-17 世纪龙信息网络有限责任公司 验证用户本机号码的方法、系统和平台
CN107864134A (zh) * 2017-11-03 2018-03-30 世纪龙信息网络有限责任公司 账号登录方法和系统
WO2020004494A1 (ja) * 2018-06-26 2020-01-02 日本通信株式会社 オンラインサービス提供システム、icチップ、アプリケーションプログラム
TR202004363A2 (tr) * 2020-03-20 2021-09-21 Crenno Bilisim Hizmetleri Ar Ge Sanayi Ve Ticaret Ltd Sirketi GSM Mobil Şebeke alanında olan Mobil Cihaz ile GSM Mobil Şebekesi dışında Kablolu/Kablosuz bir ağ geçidi ile internete bağlanan kullanıcıların cep telefonu bilgilerini doğrulama yöntemi ve sistemi
CN114301870A (zh) * 2021-12-28 2022-04-08 中国电信股份有限公司 用户身份标识管理方法及相关产品
CN115150157A (zh) * 2022-06-30 2022-10-04 中国电信股份有限公司 免密认证方法、装置、系统及深度包检测设备

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100518195C (zh) * 2001-03-09 2009-07-22 艾利森电话股份有限公司 在业务网内映射ip地址到msisdn号码的方法和设备
CN100579023C (zh) * 2006-06-07 2010-01-06 华为技术有限公司 实现互联网接入和内容服务器访问的方法
US20100024019A1 (en) * 2006-05-03 2010-01-28 Emillion Oy Authentication
CN1852094B (zh) * 2005-12-13 2010-09-29 华为技术有限公司 网络业务应用账户的保护方法和系统

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6700960B1 (en) * 2000-08-30 2004-03-02 At&T Corp. Apparatus for tracking connection of service provider customers via customer use patterns
CN101399813B (zh) * 2007-09-24 2011-08-17 中国移动通信集团公司 身份联合方法
CN101867589B (zh) * 2010-07-21 2012-11-28 深圳大学 一种网络身份认证服务器及其认证方法与系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100518195C (zh) * 2001-03-09 2009-07-22 艾利森电话股份有限公司 在业务网内映射ip地址到msisdn号码的方法和设备
CN1852094B (zh) * 2005-12-13 2010-09-29 华为技术有限公司 网络业务应用账户的保护方法和系统
US20100024019A1 (en) * 2006-05-03 2010-01-28 Emillion Oy Authentication
CN100579023C (zh) * 2006-06-07 2010-01-06 华为技术有限公司 实现互联网接入和内容服务器访问的方法

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103338320A (zh) * 2013-07-24 2013-10-02 联创亚信科技(南京)有限公司 一种移动用户充值数据处理方法及装置
CN104980922A (zh) * 2014-04-02 2015-10-14 陈煜军 一种基于公众平台的无线互联网接入方法及系统
CN104243286A (zh) * 2014-09-23 2014-12-24 上海佰贝科技发展有限公司 通过微信进行公共wifi认证的方法
CN106717107A (zh) * 2015-08-04 2017-05-24 华为技术有限公司 连接网络的方法和终端
US11877218B1 (en) 2021-07-13 2024-01-16 T-Mobile Usa, Inc. Multi-factor authentication using biometric and subscriber data systems and methods

Also Published As

Publication number Publication date
CN102437914A (zh) 2012-05-02
CN102437914B (zh) 2013-12-04

Similar Documents

Publication Publication Date Title
WO2012075873A1 (zh) 一种由电信网为互联网业务提供用户身份标识和用户身份认证的方法
RU2342700C2 (ru) Повышение уровня автоматизации при инициализации компьютерной системы для доступа к сети
CN105357242B (zh) 接入无线局域网的方法和系统、短信推送平台、门户系统
WO2010075761A1 (zh) 一种向访问用户提供资源的方法、服务器和系统
US11838269B2 (en) Securing access to network devices utilizing authentication and dynamically generated temporary firewall rules
WO2008067013A2 (en) System and method to associate a private user identity with a public user identity
TWI632798B (zh) 伺服器、行動終端機、網路實名認證系統及方法
CN108900484B (zh) 一种访问权限信息的生成方法和装置
DK2924944T3 (en) Presence authentication
US20090019517A1 (en) Method and System for Restricting Access of One or More Users to a Service
CN101986598B (zh) 认证方法、服务器及系统
US20110041166A1 (en) Method of Password Assignment
CA2647684A1 (en) Secure wireless guest access
US20070255815A1 (en) Software, Systems, and Methods for Secure, Authenticated Data Exchange
EP2786607A1 (en) Mutually authenticated communication
JP2015503303A (ja) セキュリティで保護された通信システムおよび通信方法
CN110401951B (zh) 认证无线局域网中终端的方法、装置和系统
JP2009163546A (ja) ゲートウェイ、中継方法及びプログラム
CN107864475A (zh) 基于Portal+动态密码的WiFi快捷认证方法
CN101883106A (zh) 基于数字证书的网络接入认证方法和网络接入认证服务器
US8769623B2 (en) Grouping multiple network addresses of a subscriber into a single communication session
CN106559785A (zh) 认证方法、设备和系统以及接入设备和终端
CN101227477A (zh) 一种用户终端接入认证的实现方法
KR20050071768A (ko) 원타임 패스워드 서비스 시스템 및 방법
KR101506594B1 (ko) 신원과 위치 정보가 분리된 네트워크에서 사용자가 icp 웹사이트에 로그인 하는 방법, 시스템 및 로그인 장치

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11847448

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 11847448

Country of ref document: EP

Kind code of ref document: A1