TWI441534B - A method of the data transmission of the mobile phone and the system therefore - Google Patents

A method of the data transmission of the mobile phone and the system therefore Download PDF

Info

Publication number
TWI441534B
TWI441534B TW100111903A TW100111903A TWI441534B TW I441534 B TWI441534 B TW I441534B TW 100111903 A TW100111903 A TW 100111903A TW 100111903 A TW100111903 A TW 100111903A TW I441534 B TWI441534 B TW I441534B
Authority
TW
Taiwan
Prior art keywords
communication device
mobile communication
service
service item
personal identification
Prior art date
Application number
TW100111903A
Other languages
Chinese (zh)
Other versions
TW201242391A (en
Inventor
Pao Chieh An
Chih Hung Kuo
Meng Tsung Liu
Anton Chou
Joshua Yu
Original Assignee
Abancast Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Abancast Ltd filed Critical Abancast Ltd
Priority to TW100111903A priority Critical patent/TWI441534B/en
Publication of TW201242391A publication Critical patent/TW201242391A/en
Application granted granted Critical
Publication of TWI441534B publication Critical patent/TWI441534B/en

Links

Description

行動通訊裝置的資料傳輸方法及其系統Data transmission method and system of mobile communication device

一種資料傳輸方法及其系統,特別有關於一種行動通訊裝置的資料傳輸方法及其系統。A data transmission method and system thereof, and particularly to a data transmission method and system for a mobile communication device.

隨著網際網路的興起,使得電子裝置不在是各自獨立的計算機裝置。特別是行動電話與平板電腦,透過網際網路的傳輸使得這些電子裝置可以從網路中取得所需要資料與應用程式。With the rise of the Internet, electronic devices are not separate computer devices. In particular, mobile phones and tablets, through the Internet, enable these electronic devices to obtain the data and applications needed from the Internet.

為能對不同種類的使用者提供相對應的服務,因此各廠商透過網路也紛紛的提出不同的服務項目。服務項目除了是應用程式外也可能是各項資訊。而對於透過網路提供相應的服務項目的處理模式被統稱為雲端技術。在「電腦世界」(Computer World)雜誌中的一篇標題為「雲端運算的過度混淆」(Cloud computing hype spurs confusion)的文章中,引述了知名分析公司Gartner的分類方式,將「雲端運算」區分為兩大類,分別為「雲端服務」(Cloud Computing Services)與「雲端科技」(Cloud Computing Technologies)。In order to provide corresponding services to different types of users, various vendors have also proposed different services through the Internet. Service items may be various information in addition to applications. The processing modes for providing corresponding service items through the network are collectively referred to as cloud technologies. In an article in the "Computer World" magazine titled "Cloud computing hype spurs confusion", the categorization of the well-known analysis company Gartner is cited, and the "cloud computing" is distinguished. There are two broad categories, namely Cloud Computing Services and Cloud Computing Technologies.

Gartner指出,「雲端服務」專注在於藉由網路連線從遠端取得服務。例如提供使用者安裝和使用各種不同作業系統的Amazon EC2服務。這類型的雲端計算可以視為「軟體即服務」(SaaS,Software as a Service)概念的後繼。利用這些服務,使用者甚至可以只靠一支行動電話做到許多過去只能在個人電腦上完成的工作。According to Gartner, "Cloud Services" focuses on getting services from a remote location via a network connection. For example, it provides Amazon EC2 services for users to install and use a variety of different operating systems. This type of cloud computing can be seen as a successor to the concept of "software as a service" (SaaS). With these services, users can even do a lot of work that was previously only possible on a personal computer with just one mobile phone.

以Google為例,在其網站中提供了搜尋服務、文件編輯服務、行事曆服務、電子郵件服務與網路相本服務等各種雲端服務項目。使用者可以透過手機的瀏覽器(browser)或應用程式即可使用該公司的各項服務項目。Google, for example, provides various cloud services such as search services, file editing services, calendar services, email services, and web-based services on its website. Users can use the company's services through the phone's browser or application.

雖然雲端服務可以快速的提供使用者使用各式各樣的服務項目。但在習知技術中,使用該項服務時雲端伺服器並不會進一步的確認行動通訊裝置的擁有者之身分。所以可能會發生冒名下載服務項目或使用該項服務項目等情況發生。這樣將使得真正的擁有者的權益受到損害。從使用者一端而言,如果行動通訊裝置被本人以外所使用時,行動通訊裝置也並無設置相應的身份檢驗機制。因此,也可能發生上述的冒名使用的情況。While cloud services can quickly provide users with a wide range of services. However, in the prior art, the cloud server does not further confirm the identity of the owner of the mobile communication device when using the service. Therefore, it may happen that an impersonation download service project or use of the service project occurs. This will damage the rights of the true owner. From the user's side, if the mobile communication device is used by the user, the mobile communication device does not have a corresponding identity verification mechanism. Therefore, the above-mentioned impersonation use may also occur.

習知技術中可以透過Java Specification Requests 177(JSR 177)的Java套件呼叫行動電話的應用程式。JSR177提供一組與安全相關的程式模組,該組套件提供了PKI套件、加解密套件(CRYPTO)以及APDU、JCRMI套件,其中與晶片金融卡最直接相關的是SATSA-APDU套件。SATSA-APDU中的APDUConnection類別,可以和行動電話內的晶片卡建立ISO7816通道物件。但並非所有的行動電話均可支援Java環境,因此JSR177之可用性實在有限。In the prior art, the mobile phone application can be called through the Java suite of Java Specification Requests 177 (JSR 177). JSR177 provides a set of security-related program modules, which provide PKI kits, encryption and decryption kits (CRYPTO), and APDUs, JCRMI suites. The most directly related to the wafer financial card is the SATSA-APDU kit. The APDUConnection class in the SATSA-APDU can establish an ISO7816 channel object with the chip card in the mobile phone. But not all mobile phones can support the Java environment, so the availability of JSR177 is limited.

鑒於以上的問題,本發明在於提供一種行動通訊裝置的資料傳輸方法,行動通訊裝置連接至服務端時,由服務端提供行動電話所屬的服務項目的清單,行動通訊裝置於下載服務項目時與執行服務項目時進行服務項目的驗證,藉以確定行動通訊裝置與服務項目間的對應關係。In view of the above problems, the present invention provides a data transmission method for a mobile communication device. When the mobile communication device is connected to the server, the server provides a list of service items to which the mobile phone belongs, and the mobile communication device performs and downloads the service item. The service project is verified during the service project to determine the correspondence between the mobile communication device and the service project.

本發明所揭露之行動通訊裝置的資料傳輸方法包括以下步驟:由行動通訊裝置存取識別單元中的個人辨識碼與導向資訊;行動通訊裝置根據導向資訊與個人識別碼連接至服務端;服務端根據個人識別碼查找相應的服務清單並回傳給行動通訊裝置,服務清單紀錄多筆服務項目;從服務清單中任選其中之一的服務項目,並透過服務端將安裝要求導向至雲端計算機裝置,藉以下載服務項目至行動通訊裝置,並安裝該項服務項目至行動裝置中;當行動通訊裝置運行所安裝的服務項目時,行動通訊裝置透過個人識別碼對所安裝的服務項目進行權限驗證;若所安裝的服務項目通過權限驗證,則行動通訊裝置運行服務項目;若所安裝的服務項目未通過權限驗證,則停止運行服務項目。The data transmission method of the mobile communication device disclosed by the present invention comprises the steps of: accessing the personal identification code and the navigation information in the identification unit by the mobile communication device; and connecting the mobile communication device to the server according to the navigation information and the personal identification code; Find the corresponding service list according to the personal identification number and return it to the mobile communication device. The service list records a plurality of service items; select one of the service items from the service list, and direct the installation request to the cloud computer device through the server. And downloading the service item to the mobile communication device and installing the service item into the mobile device; when the mobile communication device runs the installed service item, the mobile communication device performs permission verification on the installed service item through the personal identification code; If the installed service item passes the authority verification, the mobile communication device runs the service item; if the installed service item fails the permission verification, the service item is stopped.

其中,每一個雲端計算機裝置儲存不同的服務項目與所屬的服務清單;服務端根據個人識別碼找到相應的雲端計算機裝置,並從所找到的雲端計算機裝置取得服務清單。Each cloud computing device stores a different service item and a list of services to which it belongs; the server finds a corresponding cloud computer device according to the personal identification code, and obtains a service list from the found cloud computer device.

除了前述的資料傳輸方法外,本發明另提出一種行動通訊裝置的資料傳輸系統,其係包括:服務端、至少一雲端計算機裝置與行動通訊裝置。服務端用以儲存具有多筆服務項目的服務清單與第一驗證程式;行動通訊裝置更包括識別單元;識別單元儲存個人辨識碼、導向資訊與第二驗證程式;行動通訊裝置存取識別單元中的個人辨識碼與導向資訊;行動通訊裝置根據導向資訊與個人識別碼連接至服務端;服務端根據個人識別碼查找相應的服務清單並回傳給行動通訊裝置,服務清單紀錄多筆服務項目;從服務清單中任選其中之一的服務項目,並透過服務端將安裝要求導向至雲端計算機裝置,藉以下載服務項目至行動通訊裝置,並安裝該項服務項目至行動裝置中;當行動通訊裝置運行所安裝的服務項目時,行動通訊裝置透過個人識別碼對所安裝的服務項目進行權限驗證;相反的,被安裝的服務與可透過行動通訊裝置上的識別單元所提供使用者識別資訊確認識別單元的合法性(完成雙向驗證);若所安裝的服務項目通過權限驗證,則行動通訊裝置運行服務項目;若所安裝的服務項目未通過權限驗證,則停止運行服務項目。In addition to the foregoing data transmission method, the present invention further provides a data transmission system for a mobile communication device, which includes: a server, at least one cloud computer device, and a mobile communication device. The server is configured to store a service list with multiple service items and a first verification program; the mobile communication device further includes an identification unit; the identification unit stores the personal identification code, the navigation information and the second verification program; and the mobile communication device access identification unit Personal identification code and guiding information; the mobile communication device is connected to the server according to the guiding information and the personal identification code; the server searches for the corresponding service list according to the personal identification code and returns it to the mobile communication device, and the service list records a plurality of service items; Select one of the service items from the service list, and direct the installation requirements to the cloud computing device through the server, thereby downloading the service item to the mobile communication device, and installing the service item into the mobile device; when the mobile communication device When the installed service item is run, the mobile communication device authenticates the installed service item through the personal identification number; on the contrary, the installed service and the user identification information provided by the identification unit on the mobile communication device confirm the identification. Unit legitimacy (complete two-way verification); The installation of services through rights verification, the mobile communication device running a service project; if the installed services are not verified by the authority, then stop running services.

本發明提供一種行動通訊裝置的資料傳輸方法及其系統,使得行動通訊裝置可以透過本發明的服務端取得不同種類的雲端計算機裝置的服務清單。行動通訊裝置在透過服務端導向至不同種類的雲端計算機裝置。如此一來,可以提供行動通訊裝置更加安全的下載環境,也可以在運行下載服務項目時進一步的驗證服務項目是否對於行動通訊裝置是否合法,藉以加強整體的運作安全性。The invention provides a data transmission method and a system for a mobile communication device, so that the mobile communication device can obtain a service list of different kinds of cloud computer devices through the server of the present invention. The mobile communication device is directed to different types of cloud computing devices through the server. In this way, it is possible to provide a more secure download environment for the mobile communication device, and further verify whether the service item is legal for the mobile communication device when running the download service project, thereby enhancing the overall operational security.

有關本發明的特徵與實作,茲配合圖式作最佳實施例詳細說明如下。The features and implementations of the present invention are described in detail below with reference to the drawings.

請參考「第1A圖」所示,其係為本發明之架構示意圖。本發明的資料傳輸系統包括行動通訊裝置110、服務端210與至少一雲端計算機裝置310。服務端210、雲端計算機裝置310與行動通訊裝置110間可以透過電信傳輸(例如:無線應用協定(Wireless Application Protocol,WAP)、IMT-2000(3rd-generation,俗稱第三代通訊傳輸技術,3G)、高速下行封包接入技術(High Speed Downlink Packet Access,簡稱HSDPA)、第四代無線通訊系統(fourth-generation,4G)或超寬頻服務(Ultra Wideband,UWB))或網際網路傳輸(例如:IEEE 802.11x系列或乙太網路)。Please refer to "Figure 1A" for a schematic diagram of the architecture of the present invention. The data transmission system of the present invention includes a mobile communication device 110, a server 210, and at least one cloud computer device 310. The server 210, the cloud computing device 310, and the mobile communication device 110 can transmit through telecommunications (for example, Wireless Application Protocol (WAP), IMT-2000 (3rd-generation, commonly known as third-generation communication transmission technology, 3G) High Speed Downlink Packet Access (HSDPA), fourth-generation (4G) or Ultra Wideband (UWB) or Internet transmission (eg: IEEE 802.11x series or Ethernet).

服務端210儲存具有多筆服務項目315的服務清單211與第一驗證程式212。每一雲端計算機裝置310儲存各其所屬的服務項目315。更進一步而言,可以針對不同的社群(例如:網路交友社群、攝影社群或其他同好社群)提供不同的服務項目。本發明所述的服務項目315除了可以是應用程式外,也可以是各種的網路服務。舉例來說,服務項目315若為應用程式時,則服務項目315可以為遊戲程式、文書編輯程式、多媒體播放程式或影像編輯程式等;若服務項目315為網路服務時,則可以將文件編輯服務、行事曆服務、電子郵件服務或網路相本服務等服務以獨立的應用程式分別導向相應的服務提供處。而本發明除了可以應用在各自獨立的服務端210與雲端計算機裝置310外,也可以將雲端計算機裝置310結合至服務端210之中。The server 210 stores a service list 211 having a plurality of service items 315 and a first verification program 212. Each cloud computing device 310 stores a service item 315 to which it belongs. Further, different services can be offered to different communities (for example, online dating communities, photography communities, or other like communities). The service item 315 of the present invention may be a variety of network services in addition to an application. For example, if the service item 315 is an application, the service item 315 can be a game program, a document editing program, a multimedia player or an image editing program, etc.; if the service item 315 is a network service, the file can be edited. Services such as services, calendar services, email services, or web-based services are directed to the respective service providers by separate applications. In addition to the present invention, the cloud computing device 310 can be incorporated into the server 210 in addition to the separate server 210 and the cloud computing device 310.

行動通訊裝置110包括儲存單元111、處理單元112與識別單元113。行動通訊裝置110的種類可以是行動電話、平板電腦、掌上型計算機或桌上型計算機。儲存單元111儲存所下載的服務項目315與相應服務項目315的認證資訊,請參考「第1B圖」。在本發明中不限定行動通訊裝置110所使用的作業系統,例如作業系統可能是蘋果(Apple)電腦的iOS作業系統、Google所推出的Android作業系統或微軟公司所推出的視窗作業系統(Windows OS)等。The mobile communication device 110 includes a storage unit 111, a processing unit 112, and an identification unit 113. The type of mobile communication device 110 can be a mobile phone, a tablet, a palmtop computer, or a desktop computer. The storage unit 111 stores the authentication information of the downloaded service item 315 and the corresponding service item 315. Please refer to "1B". The operating system used by the mobile communication device 110 is not limited in the present invention. For example, the operating system may be an iOS operating system of an Apple computer, an Android operating system launched by Google, or a Windows operating system (Windows OS) introduced by Microsoft Corporation. )Wait.

在識別單元113中更包括用戶識別模組114(Subscriber Identity Model,SIM)與用戶識別模組貼片115。在此將用戶識別模組貼片115與用戶識別模組114間的側面定義為第一側面,而相對的另一側面定義為第二側面。用戶識別模組貼片115的兩側面分別設置多組接腳。第一側面的接腳分別對應至用戶識別模組114的金屬接點,第二側面的接腳則對應至行動通訊裝置110的接腳。當用戶識別模組貼片115貼合於用戶識別模組114上,行動通訊裝置110可以透過用戶識別模組貼片115讀取用戶識別模組114中的資料與用戶識別模組貼片115中的資料。在用戶識別模組貼片115儲存個人辨識碼116(Personal Identify Number,PIN)、導向資訊117與第二驗證程式118。行動通訊裝置110透過個人辨識碼116、導向資訊117與第二驗證程式118將連線至服務端210,並取得對應的服務清單211(其運作將於後文詳述)。The identification unit 113 further includes a Subscriber Identity Model (SIM) and a user identification module patch 115. Here, the side between the user identification module patch 115 and the user identification module 114 is defined as a first side, and the opposite side is defined as a second side. A plurality of sets of pins are respectively disposed on both sides of the user identification module patch 115. The pins of the first side correspond to the metal contacts of the user identification module 114, and the pins of the second side correspond to the pins of the mobile communication device 110. When the user identification module patch 115 is attached to the user identification module 114, the mobile communication device 110 can read the data in the user identification module 114 and the user identification module patch 115 through the user identification module patch 115. data of. The user identification module patch 115 stores a personal identification number 116 (PIN), a navigation information 117, and a second verification program 118. The mobile communication device 110 connects to the server 210 via the personal identification code 116, the navigation information 117, and the second verification program 118, and obtains a corresponding service list 211 (the operation of which will be described later in detail).

為能清楚解說本發明之運作流程,還請配合考「第2圖」所示,其係包括以下步驟:步驟S210:行動通訊裝置執行識別單元的導引程式,由行動通訊裝置存取識別單元中的個人辨識碼與導向資訊;步驟S230:行動通訊裝置根據導向資訊與個人識別碼連接至服務端;步驟S240:服務端根據個人識別碼查找相應的服務清單並回傳給行動通訊裝置;步驟S250:從服務清單中任選其中之一服務項目,並透過服務端將安裝要求導向至雲端計算機裝置,用以下載服務項目至行動通訊裝置並進行安裝;步驟S260:當行動通訊裝置運行所安裝的服務項目時,行動通訊裝置透過個人識別碼對所安裝的服務項目進行權限驗證;步驟S270:若所安裝的服務項目通過權限驗證,則行動通訊裝置運行服務項目;以及步驟S280:若所安裝的服務項目未通過權限驗證,則停止運行服務項目。In order to clearly explain the operation flow of the present invention, please also refer to the "Fig. 2", which includes the following steps: Step S210: The mobile communication device executes the guidance program of the identification unit, and the mobile communication device accesses the identification unit. The personal identification code and the guiding information in the step; step S230: the mobile communication device is connected to the server according to the guiding information and the personal identification code; step S240: the server searches for the corresponding service list according to the personal identification code and returns the information to the mobile communication device; S250: Select one of the service items from the service list, and direct the installation request to the cloud computer device through the server to download the service item to the mobile communication device and install the device; Step S260: When the mobile communication device is installed and installed The service communication device performs the authority verification on the installed service item through the personal identification code; step S270: if the installed service item passes the authority verification, the mobile communication device runs the service item; and step S280: if installed If the service project does not pass the permission verification, the service project is stopped.

首先,行動通訊裝置110會執行導引程式,透過導引程式存取識別單元113中的個人辨識碼116與導向資訊117。其中,導引程式可以從網路下載的應用程式(Application)外,也可以被儲存在用戶識別模組貼片115之中使得行動通訊裝置110可以直接執行該導引程式,或是已經內建在行動通訊裝置110的記憶體中,請參考「第3A圖」所示,其係為本發明的導引程式之示意圖。以Android或iOS為例,使用者可以從原本廠商所提供的軟體下載處下載該導引程式。或者,在行動通訊裝置110啟動(Booting)後且行動通訊裝置110檢測到其中並未安裝前導程序,則行動通訊裝置110從用戶識別模組貼片115中讀取出該導引程式並安裝之。First, the mobile communication device 110 executes a navigation program to access the personal identification code 116 and the navigation information 117 in the identification unit 113 through the navigation program. The guide program can be downloaded from the Internet application or can be stored in the user identification module patch 115 so that the mobile communication device 110 can directly execute the guide program, or is already built in. In the memory of the mobile communication device 110, please refer to "FIG. 3A", which is a schematic diagram of the navigation program of the present invention. For example, in Android or iOS, the user can download the boot program from the software download provided by the original manufacturer. Alternatively, after the mobile communication device 110 is booted and the mobile communication device 110 detects that the preamble is not installed, the mobile communication device 110 reads the boot program from the user identification module tile 115 and installs the boot program. .

接著,導引程式會從用戶識別模組貼片115讀取導向資訊117,並根據導向資訊117連線至服務端210。服務端210在接收到行動通訊裝置110的登入要求時,服務端210再根據個人辨識碼116查找是否有相符的服務清單211。如前文所述,每一個雲端計算機裝置310係提供給不同種類的使用者相應的服務項目315。因此服務端210會根據個人辨識碼116確認該名使用者所屬的雲端計算機,並將服務清單211回覆給行動通訊裝置110。Then, the guiding program reads the guiding information 117 from the user identification module tile 115, and connects to the server 210 according to the guiding information 117. When the server 210 receives the login request of the mobile communication device 110, the server 210 searches for the matching service list 211 according to the personal identification code 116. As mentioned above, each cloud computing device 310 provides a corresponding service item 315 to a different type of user. Therefore, the server 210 confirms the cloud computer to which the user belongs according to the personal identification code 116, and returns the service list 211 to the mobile communication device 110.

舉例來說,用戶識別模組貼片115A、用戶識別模組貼片115B與用戶識別模組貼片115C係由不同的雲端服務廠商(分別為雲端α、雲端β與雲端γ)所提供。雲端α所提供的服務清單211係包括:服務項目α001~服務項目α009;雲端β所提供的服務清單211係包括:服務項目β001~服務項目β012;雲端γ所提供的服務清單211係包括:服務項目γ001~服務項目γ007,請參考「第3A圖」。當使用者的行動通訊裝置110安裝用戶識別模組貼片115A時,用戶識別模組貼片115A會根據所記錄的導向資訊117連線至雲端α,並從服務端210取得具有服務項目α001~服務項目α009的服務清單a。同理,如果使用者安裝裝用戶識別模組貼片115B時,則會取得具有服務項目β001~服務項目β0012的服務清單b。For example, the user identification module patch 115A, the user identification module patch 115B, and the user identification module patch 115C are provided by different cloud service providers (cloud α, cloud β, and cloud γ, respectively). The service list 211 provided by the cloud α includes: a service item α001 to a service item α009; a service list 211 provided by the cloud β includes: a service item β001 to a service item β012; and a service list 211 provided by the cloud γ includes: a service For item γ001 to service item γ007, please refer to "3A". When the user's mobile communication device 110 is installed with the user identification module patch 115A, the user identification module patch 115A is connected to the cloud α according to the recorded navigation information 117, and obtains the service item α001 from the server 210. Service list a of service item α009. Similarly, if the user installs the user identification module patch 115B, the service list b having the service item β001 to the service item β0012 is obtained.

在行動通訊裝置110連線到服務端210的過程中,為能確認用戶識別模組貼片115之所屬雲端,因此服務端210會根據導向資訊與個人識別碼執行第一驗證程式212。其中,第一驗證程式212的種類可以是但不限定為RSA加密、數據加密標准(Data Encryption Standard,DES)、高級加密標准(Advanced Encryption Standard,AES)等非對稱加密演算法,也可以是對稱加密演算法。以RSA的簽章為例,行動通訊裝置110會將用戶識別模組貼片115A中的個人辨識碼116透過其所屬的私有金鑰(private key)進行簽章處理,並產生相應的密文,將此一密文定義為簽章資訊。接著,行動通訊裝置110將簽章資訊傳送給服務端210。服務端210利用公開金鑰(public key)對簽章資訊驗證,取得簽章資訊所包含的個人識別碼。服務端210根據個人識別碼查找其所屬的雲端後,再將該雲端的服務清單211回覆至行動通訊裝置110,請參考「第3B圖」,在「第3B圖」中係以用戶識別模組貼片115A與相應的服務清單a為例。In the process of connecting the mobile communication device 110 to the server 210, in order to confirm the cloud to which the user identification module tile 115 belongs, the server 210 executes the first verification program 212 according to the navigation information and the personal identification code. The type of the first verification program 212 may be, but not limited to, an asymmetric encryption algorithm such as RSA encryption, Data Encryption Standard (DES), Advanced Encryption Standard (AES), or may be symmetric. Encryption algorithm. Taking the RSA signature as an example, the mobile communication device 110 will perform the signature processing on the personal identification code 116 in the user identification module patch 115A through the private key to which it belongs, and generate the corresponding ciphertext. Define this ciphertext as signature information. Next, the mobile communication device 110 transmits the signature information to the server 210. The server 210 verifies the signature information by using a public key, and obtains the personal identification code included in the signature information. The server 210 searches for the cloud to which it belongs according to the personal identification code, and then returns the service list 211 of the cloud to the mobile communication device 110. Please refer to "3B" and the user identification module in "3B". The patch 115A and the corresponding service list a are taken as an example.

當行動通訊裝置110下載服務清單211後,使用者可以從行動通訊裝置110的螢幕上觀看服務清單211所載的內容。承接前文的服務清單a為例,在行動通訊裝置110的螢幕上會依序列出服務項目α001~服務項目α009,藉以提供使用者選擇,請參考「第3C圖」。當使用者從服務清單211中任選其中之一服務項目315,行動通訊裝置110會向服務端210發送安裝要求。接著,服務端210將安裝要求導向至雲端計算機裝置310。After the mobile communication device 110 downloads the service list 211, the user can view the content contained in the service list 211 from the screen of the mobile communication device 110. Taking the service list a of the foregoing example as an example, the service item α001 to the service item α009 are sequentially displayed on the screen of the mobile communication device 110, so as to provide user selection, please refer to "3C". When the user selects one of the service items 315 from the service list 211, the mobile communication device 110 sends an installation request to the server 210. The server 210 then directs the installation requirements to the cloud computing device 310.

雲端計算機裝置310在傳送服務項目315的過程中,為能確定行動通訊裝置110與所下載的服務項目315是呈現一對一的對應關係。在本發明所述的一對一之對應關係所指的是每一服務項目315僅能對應一台行動通訊裝置110。換言之,當使用者將行動通訊裝置110A上的服務項目315複製到行動通訊裝置110B時,行動通訊裝置110B則無法通過服務項目315的各項驗證,進而禁止服務項目315的安裝/運行。因此雲端計算機裝置310會將認證資訊(license)加入服務項目315中。而認證資訊的生成方式也可以是但不限定為RSA加密、DES、AES等非對稱加密演算法,也可以是對稱加密演算法。In the process of transmitting the service item 315, the cloud computing device 310 presents a one-to-one correspondence between the mobile communication device 110 and the downloaded service item 315. The one-to-one correspondence in the present invention means that each service item 315 can only correspond to one mobile communication device 110. In other words, when the user copies the service item 315 on the mobile communication device 110A to the mobile communication device 110B, the mobile communication device 110B cannot pass the verification of the service item 315, thereby prohibiting the installation/operation of the service item 315. Therefore, the cloud computing device 310 adds the authentication information (license) to the service item 315. The authentication information may be generated by, but not limited to, an asymmetric encryption algorithm such as RSA encryption, DES, or AES, or a symmetric encryption algorithm.

在產生認證資訊的過程中,也可以另外加入一次性密碼(one time password)、亂數產生或時間戳記(time stamp)。以Android作業系統為例,當使用者欲進行下載服務項目315前,行動通訊裝置110會透過Android作業系統呼叫其密碼輸入視窗,用以提供使用者輸入其個人辨識碼116,請參考「第3D圖」所示。在傳輸所輸入的個人識別碼時,行動通訊裝置110會加入上述的其他數據(或者加入來自於服務端210所提供的數據),並進行相關的加密處理。除了透過Android作業系統呼叫輸入視窗外,也可以透過標準開發套件(Standard Development Kit,SDK)創建新的輸入視窗。這樣的作法可以避免Android作業系統的內部缺失,使得非法使用者透過遠端遙控(remote)的方式監聽使用者所輸入的資料。透過SDK的客製化輸入視窗使得所輸入的數值在應用程式間的傳遞過程無法透過作業系統直接被獲取,進而提高非法使用者入侵的門檻。In the process of generating the authentication information, a one-time password, a random number generation, or a time stamp may be added. Taking the Android operating system as an example, before the user wants to download the service item 315, the mobile communication device 110 calls its password input window through the Android operating system to provide the user with the personal identification code 116. Please refer to "3D". Figure". When transmitting the entered personal identification number, the mobile communication device 110 will add the above-mentioned other data (or join the data supplied from the server 210) and perform related encryption processing. In addition to calling the input window through the Android operating system, a new input window can also be created through the Standard Development Kit (SDK). This method can avoid the internal missing of the Android operating system, so that the illegal user can remotely monitor the data input by the user. Through the custom input window of the SDK, the transfer of the entered values between applications can not be directly obtained through the operating system, thereby increasing the threshold of illegal user intrusion.

除此之外,在本發明的行動通訊裝置110也可以將下載的服務項目315以下述方式寫入用戶識別模組貼片115或用戶識別模組114之中,藉以增強本案的服務項目315之驗證強度。在現有的行動通訊裝置中110均由作業系統再透過所安裝的應用程式對底層的用戶識別模組114(或用戶識別模組貼片115)進行目的資料夾的存取,其中目的資料夾可以是但不限定為通訊錄或簡訊匣。In addition, the mobile communication device 110 of the present invention can also write the downloaded service item 315 into the user identification module patch 115 or the user identification module 114 in the following manner, thereby enhancing the service item 315 of the present case. Verify the strength. In the existing mobile communication device 110, the operating system and the installed application program access the underlying user identification module 114 (or the user identification module patch 115) to the destination folder, wherein the destination folder can be accessed. Yes, but not limited to contacts or newsletters.

就一般的文字簡訊(或多媒體簡訊(Multimedia Messaging Service,MMS))的標頭都是利用固定數值作為識別。行動通訊裝置110在下載服務項目315時,行動通訊裝置110會將服務項目315寫入通訊錄或簡訊匣之中,並對通訊錄或簡訊匣的對應標頭進行改寫。舉例來說,服務項目315欲儲存至簡訊匣時,可以將服務項目315切分成符合簡訊的最大長度的多組資料區塊。並將每一個切分後的資料區塊的標頭寫入特定的數值,例如在標頭前2bytes寫入FFFFh。所以當行動通訊裝置110在讀取簡訊匣中的資料時,行動通訊裝置110只要發現該封簡訊的標頭資料為FFFFh,則代表該簡訊並非是文字資料而是服務項目315,請參考「第3E圖」所示。當標頭為簡訊預設值時,則行動通訊裝置110將從用戶識別模組114讀取相應的簡訊,請參考「第3F圖」所示。The headers of general text messages (or Multimedia Messaging Service (MMS)) are identified by fixed values. When the mobile communication device 110 downloads the service item 315, the mobile communication device 110 writes the service item 315 into the address book or the short message box, and rewrites the corresponding header of the address book or the text message frame. For example, when the service item 315 is to be stored in the short message, the service item 315 can be divided into a plurality of sets of data blocks that meet the maximum length of the short message. The header of each sliced data block is written to a specific value, for example, FFFFh is written 2 bytes before the header. Therefore, when the mobile communication device 110 reads the data in the short message, the mobile communication device 110 only needs to find that the header information of the short message is FFFFh, and the mobile communication device is not the text data but the service item 315. Figure 3E shows. When the header is the default value of the short message, the mobile communication device 110 will read the corresponding short message from the user identification module 114. Please refer to the "3F".

在完成服務項目315中加入認證資訊後,雲端計算機裝置310會將服務項目315傳送至行動通訊裝置110。接著,行動通訊裝置110會進行安裝服務項目315的處理,請同時配合「第4A圖」所示,其係包括下列步驟:步驟S410:行動通訊裝置從所下載的服務項目中取得認證資訊;步驟S420:行動通訊裝置對個人辨識碼執行驗證處理,產生待驗證資訊;步驟S430:由行動通訊裝置比對認證資訊與待驗證資訊是否一致;步驟S440:當認證資訊與待驗證資訊不一致時,則行動通訊裝置停止進行安裝服務項目;以及步驟S450:當認證資訊與待驗證資訊一致時,則行動通訊裝置將服務項目所相應的認證資料註冊至儲存單元中。After the authentication information is added to the completion service item 315, the cloud computing device 310 transmits the service item 315 to the mobile communication device 110. Next, the mobile communication device 110 performs the processing of the installation service item 315. Please also cooperate with the "FIG. 4A", which includes the following steps: Step S410: The mobile communication device obtains the authentication information from the downloaded service item; S420: the mobile communication device performs verification processing on the personal identification code to generate information to be verified; step S430: whether the mobile communication device compares the authentication information with the information to be verified; and step S440: when the authentication information is inconsistent with the information to be verified, The mobile communication device stops the installation service item; and step S450: when the authentication information is consistent with the information to be verified, the mobile communication device registers the authentication data corresponding to the service item into the storage unit.

如同前文所述,為能行動通訊裝置110確定與服務項目315間的唯一對應關係,因此導引程式下載服務項目315完成後,導引程式會對服務項目315進行驗證。導引程式從所下載的服務項目315中取得認證資訊。於此同時,行動通訊裝置110對個人辨識碼116另進行驗證處理,產生另一組的待驗證資訊。As described above, the mobile communication device 110 determines a unique correspondence with the service item 315. Therefore, after the navigation program download service item 315 is completed, the guidance program verifies the service item 315. The vector program obtains the authentication information from the downloaded service item 315. At the same time, the mobile communication device 110 performs another verification process on the personal identification code 116 to generate another set of information to be verified.

接著,導引程式會比對認證資訊與待驗證資訊是否一致。由於認證資料與待驗證資訊是由相同的處理演算法(例如:單向雜湊、RSA、DES、MD5、SHA或AES)所產生。例如:行動通訊裝置可以在傳送已經過驗證處理的待驗證資料之前/後再加入特定長度的時間戳記。服務端210可根據所加入的時間戳記從正確的位置起讀出正確的待驗證資料。Then, the pilot program compares the authentication information with the information to be verified. Since the authentication data and the information to be verified are generated by the same processing algorithm (for example, one-way hash, RSA, DES, MD5, SHA or AES). For example, the mobile communication device may add a time stamp of a specific length before/after transmitting the data to be verified that has been verified. The server 210 can read the correct data to be verified from the correct location according to the added time stamp.

因此,相同的輸入資料經過前述的加密後會產生相同的結果。所以當兩者一致時,則代表待驗證資訊與認證資訊都是由被認可的對方(分別為行動通訊裝置110與雲端計算機裝置310)所形成。當確認待驗證資訊與認證資訊後,導引程式將服務項目315所相應的認證資料(或待驗證資訊)註冊至儲存單元111中,並在行動通訊裝置110的螢幕上顯示所安裝的服務項目315,請同時參考「第4B圖」與「第4C圖」。Therefore, the same input data will produce the same result after the aforementioned encryption. Therefore, when the two are consistent, the information to be verified and the authentication information are formed by the recognized counterparts (the mobile communication device 110 and the cloud computing device 310, respectively). After confirming the information to be verified and the authentication information, the guiding program registers the authentication data (or the information to be verified) corresponding to the service item 315 into the storage unit 111, and displays the installed service item on the screen of the mobile communication device 110. 315, please refer to "4B" and "4C" at the same time.

當使用者欲執行前述下載的服務項目315時,導引程式會再次驗證行動通訊裝置110是否合法。請參考「第5圖」所示,其係為本發明的服務項目315驗證行動通訊裝置110之步驟流程圖。驗證行動通訊裝置110包括以下步驟:步驟S510:行動通訊裝置從服務資料庫中取得認證資料;步驟S520:行動通訊裝置從識別單元中取得個人辨識碼;步驟S530:比對認證資料與個人識別碼是否一致;步驟S540:若認證資料與個人識別碼一致,則行動通訊裝置執行服務項目;以及步驟S550:若認證資料與個人識別碼不一致,則行動通訊裝置不執行服務項目。When the user wants to execute the previously downloaded service item 315, the pilot program will again verify that the mobile communication device 110 is legitimate. Please refer to FIG. 5, which is a flow chart of the steps of verifying the mobile communication device 110 for the service item 315 of the present invention. The verification mobile communication device 110 includes the following steps: Step S510: The mobile communication device obtains the authentication data from the service database; Step S520: The mobile communication device acquires the personal identification code from the identification unit; Step S530: Align the authentication data with the personal identification code Whether it is consistent; step S540: if the authentication data is consistent with the personal identification number, the mobile communication device executes the service item; and step S550: if the authentication data does not coincide with the personal identification number, the mobile communication device does not execute the service item.

當使用者欲執行該項服務項目315時,行動通訊裝置110會要求使用者鍵入個人辨識碼116。行動通訊裝置110同時會從服務資料庫中取得對應該服務項目315的認證資料。接著,行動通訊裝置110會根據個人辨識碼116進行對應於前述的驗證處理,並將生成的待驗證資訊與認證資料進行比對。若經過驗證處理後的個人識別碼與認證資訊一致,則代表該服務項目315是由行動通訊裝置110所下載且使用者為合法使用者,因此行動通訊裝置110可以執行該項服務項目315。反之,行動通訊裝置110將無法執行該服務項目315。When the user wants to execute the service item 315, the mobile communication device 110 asks the user to enter the personal identification code 116. The mobile communication device 110 also obtains the authentication material corresponding to the service item 315 from the service database. Next, the mobile communication device 110 performs the verification processing corresponding to the foregoing according to the personal identification code 116, and compares the generated information to be verified with the authentication data. If the verified personal identification code is consistent with the authentication information, the service item 315 is downloaded by the mobile communication device 110 and the user is a legitimate user, so the mobile communication device 110 can execute the service item 315. Conversely, the mobile communication device 110 will not be able to execute the service item 315.

在使用者鍵入個人辨識碼116時,可以透過行動通訊裝置110所採用的作業系統創建輸入視窗,也可以透過SDK創建客製化的輸入視窗,請參考「第3D圖」所示。這樣的作法可以避免行動通訊裝置110的作業系統之內部缺失,使得非法使用者透過遠端遙控的方式取得使用者所輸入的資料。透過SDK的客製化輸入視窗使得所輸入的數值在應用程式間的傳遞過程無法透過作業系統直接被獲取,提高非法使用者入侵的門檻。When the user types the personal identification code 116, the input window can be created through the operating system used by the mobile communication device 110, or a customized input window can be created through the SDK. Please refer to the "3D". Such a method can avoid the internal missing of the operating system of the mobile communication device 110, so that the illegal user can obtain the data input by the user through remote remote control. Through the customized input window of the SDK, the input value between the applications can not be directly obtained through the operating system, which increases the threshold of illegal user intrusion.

本發明提供一種行動通訊裝置110的資料傳輸方法及其系統,行動通訊裝置110可以確認用戶身份並透過用戶分類向服務端210取得不同種類的雲端計算機裝置310的服務清單211。The present invention provides a data transmission method and system for the mobile communication device 110. The mobile communication device 110 can confirm the identity of the user and obtain the service list 211 of the different types of cloud computing devices 310 from the server 210 through the user classification.

此外,本發明的行動通訊裝置110係透過用戶識別模組貼片114對用戶識別模組115進行存取,所以行動通訊裝置110不需透過JSR177(或者是應用程式)才能對用戶識別模組115進行資料的交換。行動通訊裝置110在透過服務端210導向至不同種類的雲端計算機裝置310。如此一來,可以提供行動通訊裝置110更加安全的下載環境,也可以在運行下載服務項目315時進一步的驗證服務項目315是否對於行動通訊裝置110是否合法,藉以加強整體的運作安全性。In addition, the mobile communication device 110 of the present invention accesses the user identification module 115 through the user identification module tile 114. Therefore, the mobile communication device 110 does not need to pass the JSR 177 (or an application) to identify the user identification module 115. Exchange of information. The mobile communication device 110 is directed through the server 210 to different types of cloud computing devices 310. In this way, it is possible to provide a more secure download environment for the mobile communication device 110, and further verify whether the service item 315 is legal for the mobile communication device 110 when the download service item 315 is run, thereby enhancing overall operational security.

雖然本發明以前述之較佳實施例揭露如上,然其並非用以限定本發明,任何熟習相像技藝者,在不脫離本發明之精神和範圍內,當可作些許之更動與潤飾,因此本發明之專利保護範圍須視本說明書所附之申請專利範圍所界定者為準。While the present invention has been described above in terms of the preferred embodiments thereof, it is not intended to limit the invention, and the invention may be modified and modified without departing from the spirit and scope of the invention. The patent protection scope of the invention is subject to the definition of the scope of the patent application attached to the specification.

110...行動通訊裝置110. . . Mobile communication device

111...儲存單元111. . . Storage unit

112...處理單元112. . . Processing unit

113...識別單元113. . . Identification unit

114...用戶識別模組貼片114. . . User identification module patch

115...用戶識別模組115. . . User identification module

115A...用戶識別模組貼片115A. . . User identification module patch

115B...用戶識別模組貼片115B. . . User identification module patch

115C...用戶識別模組貼片115C. . . User identification module patch

116...個人辨識碼116. . . Personal identification code

117...導向資訊117. . . Guided information

118...第二驗證程式118. . . Second verification program

210...服務端210. . . Server

211...服務清單211. . . Service list

212...第一驗證程式212. . . First verification program

310...雲端計算機裝置310. . . Cloud computer device

311...雲端α311. . . Cloud alpha

312...雲端β312. . . Cloud beta

313...雲端γ313. . . Cloud γ

315...服務項目315. . . service items

第1A圖係為本發明之架構示意圖。Figure 1A is a schematic diagram of the architecture of the present invention.

第1B圖係為本發明之行動通訊裝置的服務項目之外觀示意圖。FIG. 1B is a schematic diagram showing the appearance of a service item of the mobile communication device of the present invention.

第2圖係為本發明之運作流程圖。Figure 2 is a flow chart of the operation of the present invention.

第3A圖係為本發明的導引程式之示意圖。Figure 3A is a schematic diagram of the pilot program of the present invention.

第3B圖係為本發明之選擇服務清單之示意圖。Figure 3B is a schematic diagram of a list of selected services for the present invention.

第3C圖係為本發明之顯示服務清單之示意圖。Figure 3C is a schematic diagram of a display service list of the present invention.

第3D圖係為本發明之密碼輸入之架構示意圖。The 3D diagram is a schematic diagram of the architecture of the password input of the present invention.

第3E圖係為本發明之寫入用戶識別模組之操作示意圖。Figure 3E is a schematic diagram of the operation of the write user identification module of the present invention.

第3F圖係為本發明之讀取用戶識別模組之操作示意圖。The 3F figure is a schematic diagram of the operation of the read user identification module of the present invention.

第4A圖係為本發明行動通訊裝置安裝服務項目之運作流程圖。Figure 4A is a flow chart showing the operation of the mobile communication device installation service project of the present invention.

第4B圖係為本發明之安裝服務項目前之介面示意圖。Figure 4B is a schematic diagram of the interface before the installation service project of the present invention.

第4C圖係為本發明之安裝服務項目後之介面示意圖。Figure 4C is a schematic diagram of the interface after the installation service project of the present invention.

第5圖係為本發明的服務項目驗證行動通訊裝置之步驟流程圖。Figure 5 is a flow chart showing the steps of the service item verification mobile communication device of the present invention.

Claims (11)

一種行動通訊裝置的資料傳輸方法,包括以下步驟:該行動通訊裝置透過一識別單元取得一導向資訊與一個人識別碼,用以連線至對應的一服務端;該服務端根據該個人識別碼查找相應的一服務清單,該服務清單紀錄有一雲端計算機裝置的多個服務項目;該行動通訊裝置選擇至少一該服務項目,利用該服務端將一安裝要求導向至該雲端計算機裝置,將該服務項目下載至該行動通訊裝置並進行安裝;該行動通訊裝置執行該服務項目時,利用該個人識別碼對所安裝的該服務項目進行權限驗證;若所安裝的該服務項目通過權限驗證,則該行動通訊裝置運行該服務項目;以及若所安裝的該服務項目未通過權限驗證,則停止運行該服務項目。A data transmission method for a mobile communication device includes the following steps: the mobile communication device obtains a navigation information and a personal identification code through a recognition unit for connecting to a corresponding server; the server searches for the personal identification code according to the personal identification code Corresponding service list, the service list records a plurality of service items of the cloud computer device; the mobile communication device selects at least one service item, and uses the server to direct an installation request to the cloud computer device, and the service item is Downloading and installing the mobile communication device; when the mobile communication device executes the service item, using the personal identification code to perform permission verification on the installed service item; if the installed service item passes the authority verification, the action The communication device runs the service item; and if the installed service item does not pass the authority verification, the service item is stopped. 如請求項1所述之行動通訊裝置的資料傳輸方法,在該行動通訊裝置存取該識別單元之步驟中更包括:該行動通訊裝置執行一導引程式;以及由該導引程式從該識別單元存取該個人辨識碼與該導向資訊。The data transmission method of the mobile communication device according to claim 1, wherein the step of accessing the identification unit by the mobile communication device further comprises: the mobile communication device executing a guidance program; and the identification program is used by the guidance program The unit accesses the personal identification code and the navigation information. 如請求項1所述之行動通訊裝置的資料傳輸方法,該識別單元更包括一用戶識別模組貼片與一用戶識別模組,該用戶識別模組貼片電性連接於該用戶識別模組,該用戶識別模組貼片儲存該個人辨識碼與該導向資訊。The data transmission method of the mobile communication device according to claim 1, wherein the identification unit further comprises a user identification module patch and a user identification module, wherein the user identification module patch is electrically connected to the user identification module. The user identification module tile stores the personal identification code and the navigation information. 如請求項3所述之行動通訊裝置的資料傳輸方法,在下載該服務項目至該行動通訊裝置之步驟中更包括:該雲端計算機裝置將一認證資訊加入該服務項目中;以及由該雲端計算機裝置將已加入該認證資訊的該服務項目傳送至該行動通訊裝置。The data transmission method of the mobile communication device according to claim 3, wherein the step of downloading the service item to the mobile communication device further comprises: the cloud computer device adding an authentication information to the service item; and the cloud computer The device transmits the service item that has joined the authentication information to the mobile communication device. 如請求項3所述之行動通訊裝置的資料傳輸方法,在安裝該服務項目至該行動通訊裝置之步驟中更包括:該行動通訊裝置從所下載的該服務項目中取得一認證資訊;該行動通訊裝置對該個人辨識碼進行一驗證處理,產生一待驗證資訊;由該行動通訊裝置比對該認證資訊與該待驗證資訊是否一致;以及當該認證資訊與該待驗證資訊一致時,則該行動通訊裝置將該服務項目所相應的該待驗證資訊註冊至一儲存單元中。The data transmission method of the mobile communication device according to claim 3, wherein the step of installing the service item to the mobile communication device further comprises: the mobile communication device obtaining an authentication information from the downloaded service item; the action The communication device performs a verification process on the personal identification code to generate a to-be-verified information; the mobile communication device compares the authentication information with the to-be-verified information; and when the authentication information is consistent with the to-be-verified information, The mobile communication device registers the information to be verified corresponding to the service item in a storage unit. 如請求項3所述之行動通訊裝置的資料傳輸方法,在運行所安裝的該服務項目的權限驗證之步驟中更包括:該行動通訊裝置從一服務資料庫中取得一認證資料;該行動通訊裝置從該識別單元中取得該個人辨識碼;比對該認證資料與該個人識別碼是否一致;若該認證資料與該個人識別碼一致,則該行動通訊裝置執行該服務項目;以及若該認證資料與該個人識別碼不一致,則該行動通訊裝置不執行該服務項目。The method for transmitting data of the mobile communication device according to claim 3, wherein the step of running the installed authority verification of the service item further comprises: the mobile communication device obtaining an authentication data from a service database; the mobile communication The device obtains the personal identification code from the identification unit; whether the authentication data is consistent with the personal identification code; if the authentication data is consistent with the personal identification number, the mobile communication device executes the service item; and if the authentication If the data does not match the personal identification number, the mobile communication device does not execute the service item. 一種行動通訊裝置的資料傳輸系統,行動通訊裝置連接至服務端時,由服務端提供行動電話所屬的服務項目的清單,行動通訊裝置於下載服務項目時與執行服務項目時進行服務項目的驗證,該資料傳輸系統包括:至少一雲端計算機裝置,每一該雲端計算機裝置儲存多筆服務項目;一服務端,用以儲存具有多筆該服務項目的一服務清單與一第一驗證程式,該服務端根據該第一驗證程式之結果將行動通訊裝置導向至相應的該雲端計算機裝置;以及一行動通訊裝置,其係更包括一識別單元,該識別單元儲存一個人辨識碼、一導向資訊與一第二驗證程式;其中,該行動通訊裝置根據該個人識別碼與該導向資訊連結至相應的該服務端,該服務端根據該個人識別碼執行該第一驗證程式用以查找相應的該服務清單,該服務端將該服務清單回應給該行動通訊裝置;該行動通訊裝置從該服務清單中選擇任一該服務項目,透過該服務端下載所選的該服務項目至該行動通訊裝置進行安裝,並登錄該服務項目的一認證資訊;當該行動通訊裝置執行該服務項目時,該行動通訊裝置運行該第二驗證程式,該行動通訊裝置比對該認證資訊與該個人辨識碼是否一致;當該認證資訊與該個人辨識碼一致時,則運行該服務項目。A data transmission system for a mobile communication device, wherein when the mobile communication device is connected to the server, the server provides a list of service items to which the mobile phone belongs, and the mobile communication device performs verification of the service item when the service item is downloaded and when the service item is executed. The data transmission system includes: at least one cloud computing device, each of the cloud computing devices storing a plurality of service items; and a server for storing a service list having a plurality of the service items and a first verification program, the service Transmitting the mobile communication device to the corresponding cloud computing device according to the result of the first verification program; and a mobile communication device further comprising an identification unit, the identification unit storing a personal identification code, a guiding information and a first a verification program, wherein the mobile communication device is connected to the corresponding server according to the personal identification code and the navigation information, and the server executes the first verification program according to the personal identification code to search for the corresponding service list. The server responds to the mobile communication device with the service list; The mobile communication device selects any one of the service items from the service list, downloads the selected service item to the mobile communication device through the server for installation, and logs in an authentication information of the service item; when the mobile communication device performs In the service item, the mobile communication device runs the second verification program, and the mobile communication device compares the authentication information with the personal identification code; when the authentication information is consistent with the personal identification code, the service item is run . 如請求項7所述之行動通訊裝置的資料傳輸系統,該識別單元更包括一用戶識別模組貼片與一用戶識別模組,該用戶識別模組貼片電性連接於該用戶識別模組,該用戶識別模組貼片儲存該個人辨識碼與該導向資訊。The data transmission system of the mobile communication device of claim 7, wherein the identification unit further comprises a user identification module patch and a user identification module, wherein the user identification module patch is electrically connected to the user identification module. The user identification module tile stores the personal identification code and the navigation information. 如請求項8所述之行動通訊裝置的資料傳輸系統,該行動通訊裝置下載所選的該服務項目中更包括:該服務項目透過該用戶識別模組貼片對該服務項目新增一附加資訊,再將具有該附加資訊的該服務項目寫入該用戶識別模組的一目的資料夾中。The data transmission system of the mobile communication device according to claim 8, wherein the mobile communication device downloads the selected service item further comprises: the service item adds an additional information to the service item through the user identification module patch And the service item with the additional information is written into a destination folder of the user identification module. 如請求項9所述之行動通訊裝置的資料傳輸系統,該目的資料夾係為一簡訊資料夾或一通訊錄資料夾。The data transmission system of the mobile communication device according to claim 9, wherein the destination folder is a short message folder or an address book folder. 如請求項9所述之行動通訊裝置的資料傳輸系統,該行動通訊裝置運行該服務項目時,該行動通訊裝置從該用戶識別模組的該目的資料夾中讀取具有一附加資訊的該服務項目,該行動通訊裝置透過該用戶識別模組解析出該服務項目。The data transmission system of the mobile communication device according to claim 9, wherein when the mobile communication device runs the service item, the mobile communication device reads the service having an additional information from the destination folder of the user identification module. The item, the mobile communication device parses the service item through the user identification module.
TW100111903A 2011-04-06 2011-04-06 A method of the data transmission of the mobile phone and the system therefore TWI441534B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW100111903A TWI441534B (en) 2011-04-06 2011-04-06 A method of the data transmission of the mobile phone and the system therefore

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW100111903A TWI441534B (en) 2011-04-06 2011-04-06 A method of the data transmission of the mobile phone and the system therefore

Publications (2)

Publication Number Publication Date
TW201242391A TW201242391A (en) 2012-10-16
TWI441534B true TWI441534B (en) 2014-06-11

Family

ID=47600295

Family Applications (1)

Application Number Title Priority Date Filing Date
TW100111903A TWI441534B (en) 2011-04-06 2011-04-06 A method of the data transmission of the mobile phone and the system therefore

Country Status (1)

Country Link
TW (1) TWI441534B (en)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI499932B (en) 2013-07-17 2015-09-11 Ind Tech Res Inst Method for application management, corresponding system, and user device
TWI799286B (en) * 2022-06-07 2023-04-11 英屬開曼群島商現代財富控股有限公司 Random number generation system for threshold signature scheme and method thereof

Also Published As

Publication number Publication date
TW201242391A (en) 2012-10-16

Similar Documents

Publication Publication Date Title
US11323260B2 (en) Method and device for identity verification
CN110036613B (en) System and method for providing identity authentication for decentralized applications
US11921839B2 (en) Multiple device credential sharing
US9867043B2 (en) Secure device service enrollment
EP2875463B1 (en) Method and system for browser identity
US9830459B2 (en) Privacy protection for mobile devices
EP3195558B1 (en) Efficient and reliable attestation
WO2018152519A1 (en) Performance of distributed system functions using a trusted execution environment
US20210092115A1 (en) Custom authorization of network connected devices using signed credentials
US20140161258A1 (en) Authentication server, mobile terminal and method for issuing radio frequency card key using authentication server and mobile terminal
TR201810238T4 (en) The appropriate authentication method and apparatus for the user using a mobile authentication application.
CN107528830B (en) Account login method, system and storage medium
US9600671B2 (en) Systems and methods for account recovery using a platform attestation credential
US10045212B2 (en) Method and apparatus for providing provably secure user input/output
CA3122376A1 (en) Systems and methods for securing login access
US11445374B2 (en) Systems and methods for authenticating a subscriber identity module swap
CN110717128B (en) Method, device, terminal and storage medium for processing in-application webpage
TWI441534B (en) A method of the data transmission of the mobile phone and the system therefore
CN114448722B (en) Cross-browser login method and device, computer equipment and storage medium
CN108574658B (en) Application login method and device
CN113297559B (en) Single sign-on method and device, computer equipment and storage medium
CN111931222B (en) Application data encryption method, device, terminal and storage medium
CN110457959B (en) Information transmission method and device based on Trust application
CN113127844A (en) Variable access method, device, system, equipment and medium
CN102739721B (en) The data transmission method of mobile communication device and system thereof

Legal Events

Date Code Title Description
MM4A Annulment or lapse of patent due to non-payment of fees