CN111163051A - Service ordering method, device and terminal equipment - Google Patents

Service ordering method, device and terminal equipment Download PDF

Info

Publication number
CN111163051A
CN111163051A CN201911197073.3A CN201911197073A CN111163051A CN 111163051 A CN111163051 A CN 111163051A CN 201911197073 A CN201911197073 A CN 201911197073A CN 111163051 A CN111163051 A CN 111163051A
Authority
CN
China
Prior art keywords
management platform
verification result
validity verification
validity
network address
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201911197073.3A
Other languages
Chinese (zh)
Other versions
CN111163051B (en
Inventor
张鹏
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China United Network Communications Group Co Ltd
Original Assignee
China United Network Communications Group Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China United Network Communications Group Co Ltd filed Critical China United Network Communications Group Co Ltd
Priority to CN201911197073.3A priority Critical patent/CN111163051B/en
Publication of CN111163051A publication Critical patent/CN111163051A/en
Application granted granted Critical
Publication of CN111163051B publication Critical patent/CN111163051B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/12Applying verification of the received information
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/12Applying verification of the received information
    • H04L63/126Applying verification of the received information the source of the received data

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Power Engineering (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

The embodiment of the invention provides a service ordering method, a device and terminal equipment, wherein the method comprises the following steps: when a value added service ordering request sent by a management platform is received, acquiring management platform information and an ordering message from the value added service ordering request, wherein the ordering message comprises an ordering message serial number, carrying out validity verification on the management platform according to the management platform information and the ordering message serial number to obtain a verification result, stopping ordering processing according to the value added service ordering request if the verification result is an illegal platform, carrying out ordering processing according to the value added service ordering request if the verification result is a legal platform, and not directly verifying the validity of the management platform by only using an original end equipment identifier of the management platform, so that the accuracy of the verification result is improved, the safety of service ordering can be improved, and the condition that a user orders an unnecessary value added service forcibly is avoided.

Description

Service ordering method, device and terminal equipment
Technical Field
The embodiment of the invention relates to the technical field of communication, in particular to a service ordering method, a service ordering device and terminal equipment.
Background
The value added service is higher level information requirement provided by an operator to a consumer than the basic service, and meets the personalized requirements of different consumer groups. When a user orders a value added service, generally, an order operation is initiated through a value added service management platform, the value added service management platform generates a corresponding order request according to the order operation and sends the order request to a value added service authentication center platform, and the value added service authentication center platform performs related service processing according to the order request to realize the order of the value added service.
In the prior art, in order to ensure the security of value added service subscription, when the value added service authentication center platform performs the relevant service subscription processing according to the subscription request, it is verified whether the value added service management platform is a legal value added service management platform by verifying whether the original end device identifier in the subscription request is a real original end device identifier, and if the value added service management platform is determined to be a legal value added service management platform, the relevant service subscription processing is performed according to the subscription request.
However, the inventors found that at least the following problems exist in the prior art: because the original end equipment identification corresponding to the legal value added service management platform is public, an illegal service provider can modify the original end equipment identification of the illegal value added service management platform into the original end equipment identification corresponding to the legal value added service platform, so that the illegal value added service management platform imitates the real value added service platform to send an order request to the value added service authentication center platform, and forcibly orders the value added service which is not needed by the user, and the security of value added service order is low.
Disclosure of Invention
The embodiment of the invention provides a service ordering method, a device and terminal equipment, which aim to solve the problem of low security of value-added service ordering in the prior art.
In a first aspect, an embodiment of the present invention provides a service subscription method, including:
when a value added service ordering request sent by a management platform is received, acquiring management platform information and an ordering message from the value added service ordering request, wherein the ordering message comprises an ordering message serial number;
carrying out validity verification on the management platform according to the management platform information and the order message serial number to obtain a verification result;
if the verification result is an illegal platform, stopping ordering according to the value added service ordering request;
and if the verification result is a legal platform, performing order processing according to the value added service order request.
In one possible design, the validity verification includes platform information validity verification and subscription message validity verification;
the validity verification of the management platform according to the management platform information and the order message serial number comprises the following steps:
carrying out platform information validity verification on the management platform according to the management platform information to obtain a first verification result;
carrying out order message validity verification on the management platform according to the management platform information and the order message serial number to obtain a second verification result;
if the first verification result is that the platform information is legal and the second verification result is that the order message is legal, determining that the verification result is a legal platform;
and if the first verification result is that the platform information is illegal or the second verification result is that the order message is illegal, determining that the verification result is an illegal platform.
In one possible design, the management platform information includes a first network address of a management platform;
the method for verifying the validity of the order message on the management platform according to the management platform information and the order message serial number to obtain a second verification result comprises the following steps:
acquiring an actual network address, and judging whether a target actual network address identical to the first network address exists or not;
if the target actual network address exists, acquiring an order message serial number range corresponding to the target actual network address;
if the serial number of the order message is not in the serial number range of the order message, determining that the second verification result is that the order message is illegal;
and if the order message serial number is within the range of the order message serial number, determining that the second verification result is that the order message is legal.
In one possible design, the management platform information includes a first network address, a first device type, and a first device identifier of the management platform, and accordingly, the platform information validity verification includes address validity verification, type validity verification, and identifier validity verification;
the performing platform information validity verification on the management platform according to the management platform information to obtain a first verification result, including:
carrying out address validity verification on the management platform according to the management platform information to obtain an address validity verification result;
performing type validity verification on the management platform according to the management platform information to obtain a type validity verification result;
carrying out identification validity verification on the management platform according to the management platform information to obtain an identification validity verification result;
if the address validity verification result is that the network address is legal, the type validity verification result is that the equipment type is legal, and the identification validity verification result is that the equipment identification is legal, determining that the first verification result is that the platform information is legal;
and if the address validity verification result is that the network address is illegal, the type validity verification result is that the equipment type is illegal or the identification validity verification result is that the equipment identification is illegal, determining that the first verification result is that the platform information is illegal.
In a possible design, the performing address validity verification on the management platform according to the management platform information to obtain an address validity verification result includes:
acquiring an actual network address, and judging whether a target actual network address identical to the first network address exists or not;
if the target actual network address does not exist, determining that the address validity verification result is that the network address is illegal;
and if the target actual network address exists, determining that the address validity verification result is that the network address is legal.
In a possible design, the performing, according to the management platform information, an identifier validity verification on the management platform to obtain an identifier validity verification result includes:
acquiring an actual device type, and judging whether a target actual device type identical to the first device type exists or not;
if the target actual device type exists, acquiring an actual device identification range corresponding to the target actual device type;
if the first equipment identification is not in the range of the actual equipment identification, determining that the identification validity verification result is that the equipment identification is illegal;
and if the first equipment identifier is within the range of the actual equipment identifier, determining that the identifier validity verification result is that the equipment identifier is valid.
In a second aspect, an embodiment of the present invention provides a service subscription apparatus, including:
the system comprises a request processing module, a management platform and a service processing module, wherein the request processing module is used for acquiring management platform information and an ordering message from a value-added service ordering request when receiving the value-added service ordering request sent by the management platform, and the ordering message comprises an ordering message serial number;
the platform verification module is used for verifying the validity of the management platform according to the management platform information and the order message serial number to obtain a verification result;
the first processing module is used for stopping ordering processing according to the value added service ordering request if the verification result is an illegal platform;
and the second processing module is used for carrying out ordering processing according to the value-added service ordering request if the verification result is a legal platform.
In one possible design, the validity verification includes platform information validity verification and subscription message validity verification;
the platform verification module is specifically configured to:
carrying out platform information validity verification on the management platform according to the management platform information to obtain a first verification result;
carrying out order message validity verification on the management platform according to the management platform information and the order message serial number to obtain a second verification result;
if the first verification result is that the platform information is legal and the second verification result is that the order message is legal, determining that the verification result is a legal platform;
and if the first verification result is that the platform information is illegal or the second verification result is that the order message is illegal, determining that the verification result is an illegal platform.
In one possible design, the management platform information includes a first network address of a management platform;
the platform verification module is specifically configured to:
acquiring an actual network address, and judging whether a target actual network address identical to the first network address exists or not;
if the target actual network address exists, acquiring an order message serial number range corresponding to the target actual network address;
if the serial number of the order message is not in the serial number range of the order message, determining that the second verification result is that the order message is illegal;
and if the order message serial number is within the range of the order message serial number, determining that the second verification result is that the order message is legal.
In one possible design, the management platform information includes a first network address, a first device type, and a first device identifier of the management platform, and accordingly, the platform information validity verification includes address validity verification, type validity verification, and identifier validity verification;
the platform verification module is specifically configured to:
carrying out address validity verification on the management platform according to the management platform information to obtain an address validity verification result;
performing type validity verification on the management platform according to the management platform information to obtain a type validity verification result;
carrying out identification validity verification on the management platform according to the management platform information to obtain an identification validity verification result;
if the address validity verification result is that the network address is legal, the type validity verification result is that the equipment type is legal, and the identification validity verification result is that the equipment identification is legal, determining that the first verification result is that the platform information is legal;
and if the address validity verification result is that the network address is illegal, the type validity verification result is that the equipment type is illegal or the identification validity verification result is that the equipment identification is illegal, determining that the first verification result is that the platform information is illegal.
In one possible design, the platform verification module is specifically configured to:
acquiring an actual network address, and judging whether a target actual network address identical to the first network address exists or not;
if the target actual network address does not exist, determining that the address validity verification result is that the network address is illegal;
and if the target actual network address exists, determining that the address validity verification result is that the network address is legal.
In one possible design, the platform verification module is specifically configured to:
acquiring an actual device type, and judging whether a target actual device type identical to the first device type exists or not;
if the target actual device type exists, acquiring an actual device identification range corresponding to the target actual device type;
if the first equipment identification is not in the range of the actual equipment identification, determining that the identification validity verification result is that the equipment identification is illegal;
and if the first equipment identifier is within the range of the actual equipment identifier, determining that the identifier validity verification result is that the equipment identifier is valid.
In a third aspect, an embodiment of the present invention provides a terminal device, including: at least one processor and memory;
the memory stores computer-executable instructions;
the at least one processor executing the computer-executable instructions stored by the memory causes the at least one processor to perform the service subscription method of any of the first aspects.
In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, where a computer executes instructions, and when a processor executes the computer to execute the instructions, the service subscription method according to any one of the first aspect is implemented.
The embodiment of the invention provides a service ordering method, a device and terminal equipment, wherein the method jointly verifies the legality of a management platform by using management platform information and an ordering message serial number corresponding to the management platform to obtain a corresponding verification result, then determines whether to order a corresponding value-added service for a user according to the verification result, the legality of the management platform is not directly verified by only using an original terminal equipment identifier of the management platform, and the accuracy of the verification result is improved, so that the safety of service ordering can be improved, and the situation that the user orders the unnecessary value-added service forcibly is avoided.
Drawings
In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the embodiments or the prior art will be briefly described below, and it is obvious that the drawings in the following description are only some embodiments of the present invention, and for those skilled in the art, other drawings can be obtained according to these drawings without creative efforts.
Fig. 1 is a first schematic diagram of a service subscription system according to an embodiment of the present invention;
fig. 2 is a second schematic diagram of a service subscription system according to an embodiment of the present invention;
fig. 3 is a first flowchart of a service subscription method according to an embodiment of the present invention;
fig. 4 is a second flowchart of a service subscription method according to an embodiment of the present invention;
fig. 5 is a schematic structural diagram of a service subscription apparatus according to an embodiment of the present invention;
fig. 6 is a schematic diagram of a hardware structure of a terminal device according to an embodiment of the present invention.
Detailed Description
The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention, and it is obvious that the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments. All other embodiments, which can be derived by a person skilled in the art from the embodiments given herein without making any creative effort, shall fall within the protection scope of the present invention.
The terms "first," "second," "third," "fourth," and the like in the description and in the claims, as well as in the drawings, if any, are used for distinguishing between similar elements and not necessarily for describing a particular sequential or chronological order. It is to be understood that the data so used is interchangeable under appropriate circumstances such that the embodiments of the invention described herein are, for example, capable of operation in sequences other than those illustrated or otherwise described herein. Furthermore, the terms "comprises," "comprising," and "having," and any variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, system, article, or apparatus that comprises a list of steps or elements is not necessarily limited to those steps or elements expressly listed, but may include other steps or elements not expressly listed or inherent to such process, method, article, or apparatus.
With the progress of society, operators and internet companies provide rich value-added services for users. When using these value added services, a user needs to subscribe the corresponding value added service through the service subscription system. As shown in fig. 1 or fig. 2, the Service subscription System generally includes a user terminal (MS), a Value-added Service Management platform, a Value-added Service Authentication Center terminal (VAC), a Service Provider terminal (SP), a Customer relationship Management platform (CRM), an Online Charging terminal (OCS), and a Charging terminal (Charging).
When a user subscribes the value-added service, as shown in figure 1, the user can directly send a request for subscribing the value-added service to a value-added service management platform, the value-added service management platform sends a secondary confirmation request and a price declaration to the user, the user returns corresponding confirmation subscription information to the value-added service management platform, the value-added service platform generates a corresponding value-added service subscription request and sends the value-added service subscription request to a VAC, the VAC performs authentication of SP, service, user, subscription relationship and the like, after the authentication is successful, the VAC sends the value-added service subscription request to a CRM, the CRM performs corresponding subscription processing according to the value-added service subscription request, after the subscription processing is completed, corresponding subscription relationship and subscription response information are generated, the subscription response information is returned to the VAC, when the user is a prepaid user, the CRM notifies the OCS of the subscription relationship, when the user is a postpaid user, the CRM notifies the Billing about the subscription relationship. After receiving the ordering response information, the VAC generates a corresponding ordering relationship, returns ordering success information to the value added service management platform, and also sends a corresponding ordering notice to the SP, and after receiving the ordering success information returned by the VAC, the value added service management platform sends the ordering success notice to the user.
The subscription relationship refers to a deduction certificate generated by an operator after the user subscribes the value-added service.
Optionally, when the user subscribes to the value added service, the user may also directly send a request for subscribing to the value added service to the CRM, the CRM generates a corresponding value added service subscription request, and sends the value added service subscription request to the VAC, and then the VAC performs corresponding subscription processing by using the value added service subscription request, which is similar to the value added service subscription process shown in fig. 1 and is not described herein again.
In the prior art, in order to ensure security of value-added service subscription, when performing relevant service processing according to a subscription request sent by a management platform, that is, before performing authentication on SP, service, user, subscription relationship, and the like, a VAC verifies whether a corresponding management platform is legal by verifying whether an original end device identifier in the subscription request is a real original end device identifier, and performs relevant service subscription processing according to the subscription request if the original end device identifier is determined to be a legal management platform. However, because the original end equipment identifier corresponding to the legal management platform is public, the illegal service provider can modify the original end equipment identifier of the illegal management platform into the original end equipment identifier corresponding to the legal management platform, so that the illegal management platform imitates the real management platform to send an order request to the value added service authentication center platform, and forcibly orders the value added service which is not needed by the user, and the security of the value added service order is low.
The management platform can be a value added service management platform or CRM.
The method comprises the steps of verifying the legality of a management platform by using management platform information and an order message serial number corresponding to the management platform together to obtain a corresponding verification result, then determining whether to order a corresponding value added service for a user according to the verification result, and not directly verifying the legality of the management platform by using an original end equipment identifier of the management platform, so that the accuracy of the verification result is improved, the safety of service ordering can be improved, and the situation that the user orders the unnecessary value added service forcibly is avoided.
The technical solution of the present invention will be described in detail below with specific examples. The following several specific embodiments may be combined with each other, and details of the same or similar concepts or processes may not be repeated in some embodiments.
Fig. 3 is a first flowchart of a service subscription method according to an embodiment of the present invention, where an execution subject of the embodiment may be a value added service authentication center terminal in the embodiment shown in fig. 1 or fig. 2, and the embodiment is not limited herein. As shown in fig. 3, the method of this embodiment may include:
s301: when a value added service ordering request sent by a management platform is received, acquiring management platform information and an ordering message from the value added service ordering request, wherein the ordering message comprises an ordering message serial number.
In this embodiment, after receiving a value added service subscription request sent by a management platform, the management platform information and the subscription message in the value added service subscription request are obtained, where the subscription message includes a serial number of the subscription message.
The management platform information is management platform information corresponding to the management platform and comprises a first network address, a first device type and a first device identifier of the management platform.
The first network address of the management platform is a network address of the management platform, for example, an IP address.
The device type is a type of a management platform, such as a short message gateway (SMS GW).
The first device identifier is an identifier of the management platform, and for example, the identifier may be a number + an area code + a serial number corresponding to a device type, where a length of the area code may be a preset area length, for example, a length of 3, that is, including 3 characters, and a length of the serial number may be a preset serial number length, for example, a length of 1.
The ordering message serial number is generated when the management platform performs value-added service ordering interaction with a user, and when the user returns corresponding order confirmation information to the management platform, the management platform generates the corresponding ordering message serial number. The management platform is a value added service management platform or a customer relationship management platform.
S302: and carrying out validity verification on the management platform according to the management platform information and the order message serial number to obtain a verification result.
In this embodiment, the management platform information and the order message serial number are used to perform validity verification on the management platform, that is, the authenticity of the management platform is verified, and a corresponding verification result is obtained, where the verification result includes an illegal platform and a legal platform.
And when the verification result is an illegal platform, indicating that the management platform is an illegal platform. And when the verification result is a legal platform, indicating that the management platform is a legal platform.
The validity verification comprises platform information validity verification and order message validity verification.
Optionally, when the validity verification includes platform information validity verification and subscription message validity verification, the process of performing validity verification on the management platform includes: and carrying out platform information validity verification on the management platform according to the management platform information to obtain a first verification result. And verifying the validity of the order message to the management platform according to the information of the management platform and the serial number of the order message to obtain a second verification result. And if the first verification result is that the platform information is legal and the second verification result is that the order message is legal, determining that the verification result is a legal platform. And if the first verification result is that the platform information is illegal or the second verification result is that the order message is illegal, determining that the verification result is an illegal platform.
In this embodiment, the management platform information is used to perform platform information validity verification on the management platform, that is, the authenticity of the management platform information is verified, so as to obtain a first verification result, where the first verification result includes that the platform information is legal and the platform information is illegal.
Wherein, the platform information legally indicates that the management platform information of the management platform is real. The platform information illegally represents that false information exists in the management platform information of the management platform.
In this embodiment, the management platform may further perform validity verification on the order message by using the management platform information and the order message serial number to obtain a second verification result, that is, verify the authenticity of the order message to obtain a second verification result, where the second verification result includes that the order message is legal and the order message is illegal.
The legality of the order message indicates that the order message generated by the management platform is real, and the illegally indicating that the order message generated by the management platform is false.
In this embodiment, the process of verifying the validity of the order message for the management platform according to the management platform information and the order message serial number to obtain the second verification result includes: and acquiring the actual network address, and judging whether a target actual network address identical to the first network address exists or not. And if the target actual network address exists, acquiring the order message serial number range corresponding to the target actual network address. And if the serial number of the order message is not in the range of the serial number of the order message, determining that the second verification result is that the order message is illegal. And if the serial number of the order message is within the range of the serial number of the order message, determining that the second verification result is that the order message is legal.
In this embodiment, the value added service authentication terminal obtains the network addresses of all management platforms connected to the value added service authentication terminal, and obtains the actual network address. And judging whether a target actual network address identical to the first network address exists in the actual network addresses, and if the target actual network address exists in the actual network addresses, indicating that the first network address is the real network address of the management platform.
Each actual network address can only correspond to the order message serial number within a certain range, namely each management platform can only generate the order message serial number within a certain range, the order message serial number range corresponding to the target actual network address is obtained, and whether the order message serial number in the value-added service order request is in the order message serial number range or not is judged.
When the order message serial number is not in the order message serial number range, which indicates that the order message serial number is possibly false, the order message serial number is determined to be false, namely the second verification result is determined to be that the order message is illegal.
When the order message serial number is in the order message serial number range, the order message serial number is true, and the order message serial number is determined to be legal, namely the second verification result is determined to be the order message legal.
Optionally, the platform information validity verification includes address validity verification, type validity verification, and identification validity verification. Correspondingly, the specific process of carrying out the platform information validity verification on the management platform comprises the following steps:
and carrying out address validity verification on the management platform according to the management platform information to obtain an address validity verification result.
And performing type validity verification on the management platform according to the management platform information to obtain a type validity verification result.
And carrying out identification validity verification on the management platform according to the management platform information to obtain an identification validity verification result.
And if the address validity verification result is that the network address is legal, the type validity verification result is that the equipment type is legal, and the identification validity verification result is that the equipment identification is legal, determining that the first verification result is that the platform information is legal.
And if the address validity verification result is that the network address is illegal, the type validity verification result is that the equipment type is illegal or the identification validity verification result is that the equipment identification is illegal, determining that the first verification result is that the platform information is illegal.
In this embodiment, address validity verification, type validity verification, and identifier validity verification are performed on the management platform by using the management platform information, respectively, so as to obtain an address validity verification result corresponding to the address validity verification, a type validity verification result corresponding to the type validity verification, and an identifier validity verification result corresponding to the identifier validity verification.
The address validity verification is to verify the validity of the network address of the management platform. The address validity verification result comprises that the network address is legal and the network address is illegal. When the address validity verification result is that the network address is legal, the management platform corresponding to the network address is real, and when the address validity verification result is that the network address is illegal, the management platform corresponding to the network address is not real, namely the management platform has no authority to carry out value-added service subscription.
Wherein, the type validity verification is to verify the validity of the device type of the management platform. The type validity verification result includes that the device type is valid and the device type is invalid. And when the type validity verification result is that the equipment type is legal, the management platform corresponding to the equipment type is real, and when the type validity verification result is that the equipment type is illegal, the management platform corresponding to the equipment type is not real, namely the management platform has no authority to carry out value added service subscription.
The identification validity verification is to verify the validity of the equipment identification of the management platform. The identification validity verification result comprises that the equipment identification is legal and the equipment identification is illegal. When the identification validity verification result is that the equipment identification is legal, the management platform corresponding to the equipment identification is real, and when the identification validity verification result is that the equipment identification is illegal, the management platform corresponding to the equipment identification is not real, namely the management platform has no authority to carry out value added service subscription.
In this embodiment, when verifying the validity of the management platform information of the management platform, address validity verification, type validity verification, and identifier validity verification need to be performed respectively, and then whether the management platform information is valid or not is determined jointly according to the obtained address validity verification result, type validity verification result, and identifier validity verification result, so that the validity verification accuracy of the management platform information is improved, that is, the accuracy of the first verification result is improved.
In order to improve the efficiency of the validity verification of the management platform information, when the validity of the management platform information of the management platform is verified, only at least one of address validity verification, type validity verification and identification validity verification is required.
Optionally, when performing address validity verification on the management platform, the first network address in the management platform information needs to be used, and the specific process is as follows: and acquiring the actual network address, and judging whether a target actual network address identical to the first network address exists or not. And if the target actual network address does not exist, determining that the address validity verification result is that the network address is illegal. And if the target actual network address exists, determining that the address validity verification result is that the network address is legal.
In this embodiment, the value added service authentication terminal obtains the network addresses of all management platforms connected to the value added service authentication terminal, and obtains the actual network address. And judging whether a target actual network address identical to the first network address exists in the actual network address, if the target actual network address exists in the actual network address, indicating that the first network address is the real network address of the management platform, namely the first network address is a legal network address, and determining that the address validity verification result is that the network address is legal. If the target actual network address does not exist in the actual network address, the first network address is not the real network address of the management platform, namely the first network address is not a legal network address, and the address validity verification result is determined to be that the network address is illegal.
Optionally, when performing type validity verification on the management platform, the first device type in the management platform information needs to be used, and the specific process is as follows: and acquiring the actual device type, and judging whether a target actual device type identical to the first device type exists or not. And if the target actual equipment type does not exist, determining that the type validity verification result is that the equipment type is illegal. And if the target actual equipment type exists, determining that the type validity verification result is that the equipment type is legal.
In this embodiment, the value added service authentication terminal obtains the device types of all management platforms connected to the value added service authentication terminal, and obtains the actual device types. And judging whether a target actual device type identical to the first device type exists in the actual device types, if the target actual device type exists in the actual device types, indicating that the first device type is the device type of the real management platform, namely indicating that the first device type exists really and is legal. If the target actual device type does not exist in the actual device types, the first device type is not the real device type of the management platform, namely the first device type is illegal, so that the type validity verification result is directly determined to be that the device type is illegal, and the identification validity verification result can be directly determined to be that the device identification is illegal.
S303: and if the verification result is an illegal platform, stopping ordering according to the value added service ordering request.
In this embodiment, when the verification result is an illegal platform, which indicates that the management platform is an illegal platform, the corresponding subscription processing according to the value-added service subscription request sent by the management platform is stopped, that is, the value-added service corresponding to the value-added service subscription request is not subscribed to the user, so that the phenomenon that the user is forcibly subscribed to the value-added service which is not needed by the user is avoided, and the security of value-added service subscription is improved.
S304: and if the verification result is a legal platform, performing order processing according to the value added service order request.
In this embodiment, when the verification result is a legal platform, indicating that the management platform is a legal platform, the user is subscribed with the corresponding value-added service according to the value-added service subscription request.
Optionally, the subscription message in the value added service subscription request may further include a value added service identifier. When the corresponding value added service is ordered to the user according to the value added service ordering request, the value added service corresponding to the value added service identifier in the value added service ordering request can be ordered to the user.
The method includes the steps that a user can subscribe the corresponding value added service according to a value added service subscription request according to the existing value added service subscription method, and the process of subscribing the value added service is not described any more.
As can be seen from the above description, the method verifies the validity of the management platform by using the management platform information and the subscription message serial number corresponding to the management platform together to obtain a corresponding verification result, and then determines whether to subscribe the corresponding value-added service to the user according to the verification result, without directly verifying the validity of the management platform by using only the original end device identifier of the management platform, so as to improve the accuracy of the verification result, thereby improving the security of service subscription and avoiding the situation of forcibly subscribing the value-added service which is not needed by the user.
When the identification validity of the management platform is verified, whether the first device type is legal or not needs to be performed, after the first device type is determined to be legal, the device identification range corresponding to the first device type is used, and then whether the first device identification is legal or not is determined by using the device identification range, so that an identification validity verification result is obtained.
Fig. 4 is a second flowchart of a service subscription method provided in an embodiment of the present invention, as shown in fig. 4, a detailed description is made on a specific implementation process of performing identification validity verification on the basis of the foregoing embodiment, and as shown in fig. 4, the method includes:
s401: and acquiring the actual device type, and judging whether a target actual device type identical to the first device type exists or not.
In this embodiment, the value added service authentication terminal obtains the device types of all management platforms connected to the value added service authentication terminal, and obtains the actual device types. And judging whether a target actual device type identical to the first device type exists in the actual device types, if the target actual device type exists in the actual device types, indicating that the first device type is the device type of the real management platform, namely indicating that the first device type exists really and is legal.
If the target actual device type does not exist in the actual device type, the first device type is not the real device type of the management platform, that is, the first device type is not legal, so that the type validity verification result is directly determined to be that the device type is illegal, and the identification validity verification result can be directly determined to be that the device identification is illegal.
S402: and if the target actual equipment type exists, acquiring an actual equipment identification range corresponding to the target actual equipment type.
In this embodiment, each device type can only correspond to a device identifier within a certain range, so that when a target actual device type exists in the actual device types, that is, when the type validity verification result indicates that the device type is valid, an actual device identifier range corresponding to the target actual device type can be obtained, and then whether the first device identifier is a valid device identifier is determined according to the actual device identifier range.
S403: and if the first equipment identifier is not in the range of the actual equipment identifier, determining that the identifier validity verification result is that the equipment identifier is illegal.
In this embodiment, when the first device identifier is not within the range of the actual device identifier, it indicates that the first device identifier is not authentic, and it may be determined that the identifier validity verification result is that the device identifier is illegal.
S404: and if the first equipment identifier is within the range of the actual equipment identifier, determining that the identifier validity verification result is that the equipment identifier is legal.
In this embodiment, when the first device identifier is within the range of the actual device identifier, it indicates that the first device identifier is authentic, and it may be determined that the identifier validity verification result is that the device identifier is valid.
In this embodiment, it is determined whether a target actual device type identical to the first device type exists, that is, a type validity verification result is determined, when the type validity verification result is that the device type is valid, it is determined whether the first device identifier is within a range of an actual device identifier corresponding to the target actual device type, so as to obtain an identifier validity verification result, and on the basis of verifying the device type validity, the validity of the device identifier is verified, so that the accuracy of the identifier validity verification result is improved, and thus the security of value added service subscription is improved.
Fig. 5 is a schematic structural diagram of a service subscription device according to an embodiment of the present invention, and as shown in fig. 5, the service subscription device 500 according to this embodiment may include: a request processing module 501, a platform verification module 502, a first processing module 503, and a second processing module 504.
The request processing module 501 is configured to, when receiving a value added service subscription request sent by a management platform, obtain management platform information and a subscription message from the value added service subscription request, where the subscription message includes a serial number of the subscription message.
And the platform verification module 502 is configured to perform validity verification on the management platform according to the management platform information and the order message serial number to obtain a verification result.
The first processing module 503 is configured to stop performing the subscription processing according to the value added service subscription request if the verification result is an illegal platform.
The second processing module 504 is configured to perform an ordering process according to the value added service ordering request if the verification result is a legal platform.
In one possible design, the validity verification includes platform information validity verification and subscription message validity verification.
The platform verification module is specifically configured to:
and carrying out platform information validity verification on the management platform according to the management platform information to obtain a first verification result.
And verifying the validity of the order message to the management platform according to the information of the management platform and the serial number of the order message to obtain a second verification result.
And if the first verification result is that the platform information is legal and the second verification result is that the order message is legal, determining that the verification result is a legal platform.
And if the first verification result is that the platform information is illegal or the second verification result is that the order message is illegal, determining that the verification result is an illegal platform.
In one possible design, the management platform information includes a first network address of the management platform.
The platform verification module is specifically configured to:
and acquiring the actual network address, and judging whether a target actual network address identical to the first network address exists or not.
And if the target actual network address exists, acquiring the order message serial number range corresponding to the target actual network address.
And if the serial number of the order message is not in the range of the serial number of the order message, determining that the second verification result is that the order message is illegal.
And if the serial number of the order message is within the range of the serial number of the order message, determining that the second verification result is that the order message is legal.
In one possible design, the management platform information includes a first network address, a first device type, and a first device identifier of the management platform, and accordingly, the platform information validity verification includes address validity verification, type validity verification, and identifier validity verification.
The platform verification module is specifically configured to:
and carrying out address validity verification on the management platform according to the management platform information to obtain an address validity verification result.
And performing type validity verification on the management platform according to the management platform information to obtain a type validity verification result.
And carrying out identification validity verification on the management platform according to the management platform information to obtain an identification validity verification result.
And if the address validity verification result is that the network address is legal, the type validity verification result is that the equipment type is legal, and the identification validity verification result is that the equipment identification is legal, determining that the first verification result is that the platform information is legal.
And if the address validity verification result is that the network address is illegal, the type validity verification result is that the equipment type is illegal or the identification validity verification result is that the equipment identification is illegal, determining that the first verification result is that the platform information is illegal.
In one possible design, the platform verification module is specifically configured to:
and acquiring the actual network address, and judging whether a target actual network address identical to the first network address exists or not.
And if the target actual network address does not exist, determining that the address validity verification result is that the network address is illegal.
And if the target actual network address exists, determining that the address validity verification result is that the network address is legal.
In one possible design, the platform verification module is specifically configured to:
and acquiring the actual device type, and judging whether a target actual device type identical to the first device type exists or not.
And if the target actual equipment type exists, acquiring an actual equipment identification range corresponding to the target actual equipment type.
And if the first equipment identifier is not in the range of the actual equipment identifier, determining that the identifier validity verification result is that the equipment identifier is illegal.
And if the first equipment identifier is within the range of the actual equipment identifier, determining that the identifier validity verification result is that the equipment identifier is legal.
The service ordering apparatus provided in the embodiment of the present invention can implement the method in the above-described embodiment, and the implementation principle and technical effect are similar, which are not described herein again.
Fig. 6 is a schematic diagram of a hardware structure of a terminal device according to an embodiment of the present invention. As shown in fig. 6, the terminal device 600 provided in the present embodiment includes: at least one processor 601 and memory 602. The processor 601 and the memory 602 are connected by a bus 603.
In a specific implementation, the at least one processor 601 executes computer-executable instructions stored by the memory 602, so that the at least one processor 601 performs the service subscription method in the above-described method embodiments.
For a specific implementation process of the processor 601, reference may be made to the above method embodiments, which implement the principle and the technical effect similarly, and details of this embodiment are not described herein again.
In the embodiment shown in fig. 6, it should be understood that the Processor may be a Central Processing Unit (CPU), other general purpose Processor, a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), etc. A general purpose processor may be a microprocessor or the processor may be any conventional processor or the like. The steps of a method disclosed in connection with the present invention may be embodied directly in a hardware processor, or in a combination of the hardware and software modules within the processor.
The memory may comprise high speed RAM memory and may also include non-volatile storage NVM, such as at least one disk memory.
The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended ISA (EISA) bus, or the like. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, the buses in the figures of the present application are not limited to only one bus or one type of bus.
The embodiment of the present invention further provides a computer-readable storage medium, where a computer execution instruction is stored in the computer-readable storage medium, and when a processor executes the computer execution instruction, the service ordering method according to the above method embodiment is implemented.
The computer-readable storage medium may be implemented by any type of volatile or non-volatile memory device or combination thereof, such as Static Random Access Memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic or optical disk. Readable storage media can be any available media that can be accessed by a general purpose or special purpose computer.
An exemplary readable storage medium is coupled to the processor such the processor can read information from, and write information to, the readable storage medium. Of course, the readable storage medium may also be an integral part of the processor. The processor and the readable storage medium may reside in an Application Specific Integrated Circuits (ASIC). Of course, the processor and the readable storage medium may also reside as discrete components in the apparatus.
Those of ordinary skill in the art will understand that: all or a portion of the steps of implementing the above-described method embodiments may be performed by hardware associated with program instructions. The program may be stored in a computer-readable storage medium. When executed, the program performs steps comprising the method embodiments described above; and the aforementioned storage medium includes: various media that can store program codes, such as ROM, RAM, magnetic or optical disks.
Finally, it should be noted that: the above embodiments are only used to illustrate the technical solution of the present invention, and not to limit the same; while the invention has been described in detail and with reference to the foregoing embodiments, it will be understood by those skilled in the art that: the technical solutions described in the foregoing embodiments may still be modified, or some or all of the technical features may be equivalently replaced; and the modifications or the substitutions do not make the essence of the corresponding technical solutions depart from the scope of the technical solutions of the embodiments of the present invention.

Claims (10)

1. A method for subscribing to a service, comprising:
when a value added service ordering request sent by a management platform is received, acquiring management platform information and an ordering message from the value added service ordering request, wherein the ordering message comprises an ordering message serial number;
carrying out validity verification on the management platform according to the management platform information and the order message serial number to obtain a verification result;
if the verification result is an illegal platform, stopping ordering according to the value added service ordering request;
and if the verification result is a legal platform, performing order processing according to the value added service order request.
2. The method of claim 1, wherein the validity verification comprises platform information validity verification and subscription message validity verification;
the validity verification of the management platform according to the management platform information and the order message serial number comprises the following steps:
carrying out platform information validity verification on the management platform according to the management platform information to obtain a first verification result;
carrying out order message validity verification on the management platform according to the management platform information and the order message serial number to obtain a second verification result;
if the first verification result is that the platform information is legal and the second verification result is that the order message is legal, determining that the verification result is a legal platform;
and if the first verification result is that the platform information is illegal or the second verification result is that the order message is illegal, determining that the verification result is an illegal platform.
3. The method of claim 2, wherein the management platform information comprises a first network address of a management platform;
the method for verifying the validity of the order message on the management platform according to the management platform information and the order message serial number to obtain a second verification result comprises the following steps:
acquiring an actual network address, and judging whether a target actual network address identical to the first network address exists or not;
if the target actual network address exists, acquiring an order message serial number range corresponding to the target actual network address;
if the serial number of the order message is not in the serial number range of the order message, determining that the second verification result is that the order message is illegal;
and if the order message serial number is within the range of the order message serial number, determining that the second verification result is that the order message is legal.
4. The method of claim 2, wherein the management platform information comprises a first network address, a first device type and a first device identification of the management platform, and accordingly, the platform information validity verification comprises address validity verification, type validity verification and identification validity verification;
the performing platform information validity verification on the management platform according to the management platform information to obtain a first verification result, including:
carrying out address validity verification on the management platform according to the management platform information to obtain an address validity verification result;
performing type validity verification on the management platform according to the management platform information to obtain a type validity verification result;
carrying out identification validity verification on the management platform according to the management platform information to obtain an identification validity verification result;
if the address validity verification result is that the network address is legal, the type validity verification result is that the equipment type is legal, and the identification validity verification result is that the equipment identification is legal, determining that the first verification result is that the platform information is legal;
and if the address validity verification result is that the network address is illegal, the type validity verification result is that the equipment type is illegal or the identification validity verification result is that the equipment identification is illegal, determining that the first verification result is that the platform information is illegal.
5. The method of claim 4, wherein the performing address validity verification on the management platform according to the management platform information to obtain an address validity verification result comprises:
acquiring an actual network address, and judging whether a target actual network address identical to the first network address exists or not;
if the target actual network address does not exist, determining that the address validity verification result is that the network address is illegal;
and if the target actual network address exists, determining that the address validity verification result is that the network address is legal.
6. The method of claim 4, wherein the performing the identification validity verification on the management platform according to the management platform information to obtain an identification validity verification result comprises:
acquiring an actual device type, and judging whether a target actual device type identical to the first device type exists or not;
if the target actual device type exists, acquiring an actual device identification range corresponding to the target actual device type;
if the first equipment identification is not in the range of the actual equipment identification, determining that the identification validity verification result is that the equipment identification is illegal;
and if the first equipment identifier is within the range of the actual equipment identifier, determining that the identifier validity verification result is that the equipment identifier is valid.
7. A service subscription device, comprising:
the system comprises a request processing module, a management platform and a service processing module, wherein the request processing module is used for acquiring management platform information and an ordering message from a value-added service ordering request when receiving the value-added service ordering request sent by the management platform, and the ordering message comprises an ordering message serial number;
the platform verification module is used for verifying the validity of the management platform according to the management platform information and the order message serial number to obtain a verification result;
the first processing module is used for stopping ordering processing according to the value added service ordering request if the verification result is an illegal platform;
and the second processing module is used for carrying out ordering processing according to the value-added service ordering request if the verification result is a legal platform.
8. The apparatus of claim 7, wherein the validity verification comprises platform information validity verification and subscription message validity verification;
the platform verification module is specifically configured to:
carrying out platform information validity verification on the management platform according to the management platform information to obtain a first verification result;
carrying out order message validity verification on the management platform according to the management platform information and the order message serial number to obtain a second verification result;
if the first verification result is that the platform information is legal and the second verification result is that the order message is legal, determining that the verification result is a legal platform;
and if the first verification result is that the platform information is illegal or the second verification result is that the order message is illegal, determining that the verification result is an illegal platform.
9. A terminal device, comprising: at least one processor and memory;
the memory stores computer-executable instructions;
the at least one processor executing the computer-executable instructions stored by the memory causes the at least one processor to perform the service subscription method of any of claims 1 to 6.
10. A computer-readable storage medium, having stored thereon computer-executable instructions, which, when executed by a processor, implement a service subscription method as claimed in any one of claims 1 to 6.
CN201911197073.3A 2019-11-29 2019-11-29 Service ordering method, device and terminal equipment Active CN111163051B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201911197073.3A CN111163051B (en) 2019-11-29 2019-11-29 Service ordering method, device and terminal equipment

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201911197073.3A CN111163051B (en) 2019-11-29 2019-11-29 Service ordering method, device and terminal equipment

Publications (2)

Publication Number Publication Date
CN111163051A true CN111163051A (en) 2020-05-15
CN111163051B CN111163051B (en) 2022-05-03

Family

ID=70556249

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201911197073.3A Active CN111163051B (en) 2019-11-29 2019-11-29 Service ordering method, device and terminal equipment

Country Status (1)

Country Link
CN (1) CN111163051B (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115022864A (en) * 2022-05-27 2022-09-06 中移互联网有限公司 Method and device for verifying subscription service

Citations (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20060116138A1 (en) * 2004-11-29 2006-06-01 Argela Technologies Value added services creation (vasc) platform
CN101325498A (en) * 2008-07-24 2008-12-17 中国网络通信集团公司 Method and system for controlling business and charging
CN101420681A (en) * 2008-09-18 2009-04-29 中兴通讯股份有限公司 A kind of Business Management Platform is handled the method and apparatus that request is by all kinds of means ordered down
CN101600185A (en) * 2009-07-14 2009-12-09 中国联合网络通信集团有限公司 Booking method, system and the Business Management Platform of across a network territory value-added service set meal
CN101674568A (en) * 2008-09-11 2010-03-17 中兴通讯股份有限公司 Integrated service management platform and service subscription method thereof
CN101841804A (en) * 2010-04-06 2010-09-22 中兴通讯股份有限公司 Service management system and method
CN101860835A (en) * 2009-04-13 2010-10-13 中国联合网络通信集团有限公司 Value added service payment method and system
CN101877844A (en) * 2009-04-30 2010-11-03 中国联合网络通信集团有限公司 Value added service implementation method, management platform and system and card management platform
CN101888619A (en) * 2010-06-09 2010-11-17 中兴通讯股份有限公司 Method and device for preventing malicious orders by utilizing third party interactive voice response platform
CN101998372A (en) * 2009-08-21 2011-03-30 中国移动通信集团广东有限公司 Method, device and system for checking value added service ordering validity
CN102104858A (en) * 2009-12-17 2011-06-22 中国联合网络通信集团有限公司 Method and system for ordering value added service

Patent Citations (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20060116138A1 (en) * 2004-11-29 2006-06-01 Argela Technologies Value added services creation (vasc) platform
CN101325498A (en) * 2008-07-24 2008-12-17 中国网络通信集团公司 Method and system for controlling business and charging
CN101674568A (en) * 2008-09-11 2010-03-17 中兴通讯股份有限公司 Integrated service management platform and service subscription method thereof
CN101420681A (en) * 2008-09-18 2009-04-29 中兴通讯股份有限公司 A kind of Business Management Platform is handled the method and apparatus that request is by all kinds of means ordered down
CN101860835A (en) * 2009-04-13 2010-10-13 中国联合网络通信集团有限公司 Value added service payment method and system
CN101877844A (en) * 2009-04-30 2010-11-03 中国联合网络通信集团有限公司 Value added service implementation method, management platform and system and card management platform
CN101600185A (en) * 2009-07-14 2009-12-09 中国联合网络通信集团有限公司 Booking method, system and the Business Management Platform of across a network territory value-added service set meal
CN101998372A (en) * 2009-08-21 2011-03-30 中国移动通信集团广东有限公司 Method, device and system for checking value added service ordering validity
CN102104858A (en) * 2009-12-17 2011-06-22 中国联合网络通信集团有限公司 Method and system for ordering value added service
CN101841804A (en) * 2010-04-06 2010-09-22 中兴通讯股份有限公司 Service management system and method
CN101888619A (en) * 2010-06-09 2010-11-17 中兴通讯股份有限公司 Method and device for preventing malicious orders by utilizing third party interactive voice response platform

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115022864A (en) * 2022-05-27 2022-09-06 中移互联网有限公司 Method and device for verifying subscription service
CN115022864B (en) * 2022-05-27 2023-07-21 中移互联网有限公司 Verification method and device for subscription service

Also Published As

Publication number Publication date
CN111163051B (en) 2022-05-03

Similar Documents

Publication Publication Date Title
CN113112274B (en) Payment information processing method, device, equipment and medium
JP2009515403A (en) Remote activation of user accounts in telecommunications networks
CN106897606B (en) Brush machine protection method and device
CN103826155A (en) Multi-screen interaction method, server, terminal and system
CN109389383A (en) Payment processing method, device, server and the storage medium of service request
CN111885043B (en) Internet account login method, system, equipment and storage medium
CN101860835A (en) Value added service payment method and system
CN106878970B (en) Method and device for identifying service request for changing mobile phone number
CN111510908A (en) Card opening method, device, equipment and medium
CN111163051B (en) Service ordering method, device and terminal equipment
KR102145578B1 (en) Method and Apparatus for Providing Roaming Service using Block Chain
WO2014177098A1 (en) Application software online payment processing method and system
CN111542005B (en) Charging method, device, equipment and storage medium
TW202405714A (en) Payment method, apparatus and system based on 5G messaging application, and device and medium
CN103139695B (en) The telecommunication capability call method of curstomer-oriented end and the network equipment
CN105405008B (en) Fee deduction method and device
CN102149064B (en) Charging method for authenticating, mobile terminal and charging authentication server
CN112862466A (en) Resource transfer method, account settling terminal and server node
CN106487527B (en) Elastic charging method and device
CN115175165B (en) Auxiliary card number network transfer control method, equipment and storage medium of user identification card
CN111724194B (en) Substitute device detection method, system, mobile terminal and storage medium
CN112465486B (en) Payment state determination method, device and equipment
CN111242605B (en) Mobile payment method
CN109547573B (en) Payment or shopping method
CN116714463A (en) Charging service system, charging method and charging device based on third party start code

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant