WO2010054558A1 - 一种实现多媒体铃音业务安全机制的方法、设备及系统 - Google Patents

一种实现多媒体铃音业务安全机制的方法、设备及系统 Download PDF

Info

Publication number
WO2010054558A1
WO2010054558A1 PCT/CN2009/072900 CN2009072900W WO2010054558A1 WO 2010054558 A1 WO2010054558 A1 WO 2010054558A1 CN 2009072900 W CN2009072900 W CN 2009072900W WO 2010054558 A1 WO2010054558 A1 WO 2010054558A1
Authority
WO
WIPO (PCT)
Prior art keywords
signaling
message
header field
message body
processing
Prior art date
Application number
PCT/CN2009/072900
Other languages
English (en)
French (fr)
Inventor
郜文美
陈国乔
杨健
张惠萍
Original Assignee
华为终端有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为终端有限公司 filed Critical 华为终端有限公司
Priority to CN200980101231.9A priority Critical patent/CN102257784B/zh
Publication of WO2010054558A1 publication Critical patent/WO2010054558A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04MTELEPHONIC COMMUNICATION
    • H04M3/00Automatic or semi-automatic exchanges
    • H04M3/02Calling substations, e.g. by ringing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04MTELEPHONIC COMMUNICATION
    • H04M3/00Automatic or semi-automatic exchanges
    • H04M3/42Systems providing special services or facilities to subscribers
    • H04M3/42017Customized ring-back tones
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/10Architectures or entities
    • H04L65/1016IP multimedia subsystem [IMS]

Definitions

  • the present invention relates to the field of communication technologies, and in particular, to a technology of a multimedia ring tone service.
  • the multimedia ring tone service specifically includes: a multimedia ring back tone, a multimedia ring tone, and a multimedia background sound.
  • Customized Alerting Tone (CAT): Also known as multimedia ring tones, that is, when the calling party dials the called party, the calling party enjoys the multimedia ring back tone before the called party picks up the call;
  • the multimedia ringing tone (Customized Ringing) Signal, CRS): Also known as multimedia color vibration, that is, when the calling party dials the called party, the called party enjoys the multimedia ringing tone before the called party picks up the phone.
  • CRS Customerized Ringing
  • multimedia color vibration also known as multimedia color vibration, that is, when the calling party dials the called party, the called party enjoys the multimedia ringing tone before the called party picks up the phone.
  • multimedia color lasers are called differently in major standards organizations.
  • CRS Cost Ratio Service
  • CRT Customerized Ringing Tone
  • CMRT Customized in OMA (Open Mobile Alliance)
  • CBT Customized Background Tone
  • multimedia color image that is, both the calling party and the called party can enjoy the multimedia background sound during the calling and called calls.
  • the multimedia ring tone service there are two types of implementations of the multimedia ring tone service: the CS domain solution and the IMS domain solution.
  • a circuit switched domain refers to all CN (Core Network) entities that can provide circuit domain class connectivity for user traffic and all entities that support related signals.
  • the CS domain is further divided into: a. Bridging scheme: The multimedia ring tone server not only acts as a ring tone playing device, but also acts as a bridge device, that is, participates in the entire call setup process, and is part of the voice path during the call. This solution takes up a large amount of E1 resources, and once the multimedia ring tone server fails, it will cause a call. Loss; b. Non-crossover scheme: When the calling party is called, the multimedia ring tone server plays the multimedia ring tone to the calling party (or called party). After the called user picks up the phone, the mobile switching center initiates the disconnection signaling, and the circuit between the multimedia ring tone server and the user is released, which saves circuit resources.
  • IMS IP Multimedia Subsystem
  • IMS is a standardized next-generation network architecture that enables telecom operators to offer mobile and fixed multimedia services.
  • the IMS uses a VoIP (Voice over Internet Protocol) application based on the 3GPP standard SIP (Session Initiation Protocol) application and is carried on the standard IP protocol.
  • VoIP Voice over Internet Protocol
  • SIP Session Initiation Protocol
  • IMS aims not only to provide new services, but to provide all the services that the Internet can provide now and in the future.
  • the IMS domain is further divided into: a. Early Session: Before the normal call session is established between the primary and the called, the early media (ie, the multimedia ring tone) is implemented by performing early media negotiation to establish an early session. Playback; b.
  • Multi Dialog Solution Before establishing a normal call session between the calling party and the called party, a second dialogue is established between the user equipment and the multimedia ring tone server to realize the playing of the multimedia ring tone. When the called party picks up the phone, the second conversation is terminated.
  • the embodiments of the present invention provide a method, a device, and a system for implementing a multimedia ring tone service security mechanism to implement a security mechanism of a multimedia ring tone service.
  • an embodiment of the present invention provides a method for implementing a security mechanism of a multimedia ring tone service, including:
  • Receiving signaling sent by the user equipment checking the message body and/or the message header of the signaling, processing the signaling, and transmitting the processed signaling.
  • the embodiment of the present invention further provides a device for implementing a multimedia ring tone service security mechanism, including: a receiving module, configured to receive signaling of the user equipment, and send a trigger signal to the processing module after receiving the signaling;
  • the processing module is configured to: when receiving the trigger signal sent by the receiving module, check the message body and/or the message header of the signaling, and process the signaling.
  • the embodiment of the present invention further provides a system for implementing a multimedia ring tone service security mechanism, including: a user equipment and the foregoing device for implementing a multimedia ring tone service security mechanism.
  • the method, device and system for implementing the multimedia ring tone service security mechanism provided by the embodiments of the present invention solve the problem that the security mechanism is lacking in the process of implementing the multimedia ring tone service.
  • Figure la is a process flowchart of the method in the first embodiment of the present invention.
  • Figure lb is a second processing flowchart of the method in the first embodiment of the present invention.
  • Embodiment 2 is a structural diagram of a networking of Embodiment 2 of the present invention.
  • Embodiment 3 is a flowchart of a method according to Embodiment 3 of the present invention.
  • Embodiment 4 is a structural diagram of networking of Embodiment 4 of the present invention.
  • Embodiment 5 is a flowchart of a method according to Embodiment 5 of the present invention.
  • FIG. 6 is a schematic diagram of a device according to Embodiment 6 of the present invention.
  • FIG. 7 is a schematic diagram of a device according to Embodiment 7 of the present invention.
  • Embodiment 8 is a schematic diagram of a system according to Embodiment 8 of the present invention.
  • FIG. 9 is a schematic diagram of a system according to Embodiment 9 of the present invention.
  • the first embodiment of the present invention provides a method for implementing a multimedia ring tone service security mechanism, including:
  • the inspection includes two optional aspects: Check the message body type of the message, delete all non-SDP (Session Description Protocol) type MIME (Multipurpose Internet Mail Extensions) message body; second, the message header of the signaling message Check to remove the Call-Info or Alert-Info header fields.
  • SDP Session Description Protocol
  • MIME Multipurpose Internet Mail Extensions
  • Step 101a Receive SIP signaling sent by the user equipment of the local network
  • Step 102a Determine whether the value of the Content-Type in the message header of the SIP signaling is "application/sdp"; if yes, proceed to step 106a without any processing ; if not, Going to the processing of the next step 103a;
  • Step 103a Determine whether the value of the Content-Type in the header of the SIP signaling is
  • step 106a If not, delete the message body, and then go to step 106a; if yes, the SIP signaling carries a plurality of message bodies, then proceeds to the loop processing of the next step 104a;
  • Step 104a Determine whether the value of Content-Type in the message body of the SIP signaling is "application/sdp": If not, delete the message body first, and then go to step 105a; if yes, go directly to Step 105a ;
  • Step 105a determining whether the SIP signaling has a next message body, if yes, jumping back to step 104a, continuing the loop determination process; if not, indicating that all message bodies have been checked, and proceeding to step 106a ;
  • Step 106a Send the SIP signaling to the next network entity (ie, the S-CSCF
  • I-CSCF Interrogating-Call Session Control Function
  • Step 101b Receive SIP signaling sent by the user equipment of the local network.
  • Step 102b determining whether the message header of the SIP signaling includes a Call-Info header field or Alert-Info header field: If yes, delete the Call-Info header field or the Alert-Info header field first, and then go to step 103b. If not, go directly to step 103b ;
  • Step 103b Send the SIP signaling to the next network entity (ie, S-CSCF or I-CSCF).
  • next network entity ie, S-CSCF or I-CSCF.
  • any one of the above two processing flows may be used or both of the foregoing processing flows may be used at the same time. If the two processing flows are used at the same time, the processing flow of the message body of the signaling message may be performed first, and then the processing flow of the message header of the signaling message may be performed; or the processing of the message header of the signaling message may be performed first. The process then performs a processing flow of the message body of the signaling message.
  • the main advantage of the solution proposed in this embodiment is that two check processing procedures for implementing the multimedia ring tone service security mechanism are provided.
  • the second embodiment of the present invention provides a network structure for a user equipment to implement a multimedia ring tone service, including:
  • the user equipment UE-A and the user equipment UE-B are both located in the IMS domain, and the user equipment UE-B customizes the multimedia color ring back tone service (CAT) for the user equipment UE-A;
  • CAT multimedia color ring back tone service
  • HSS A 201 Home Subscriber Server A, HSS A 201 is used to store related data of user equipment A, is an upgraded HLR (Home Location Register); HSS is XML (extensible Markup Language) , the extensible markup language) records the identity of the user equipment A, registration information, access parameters, and service trigger information;
  • HLR Home Location Register
  • HSS XML (extensible Markup Language) , the extensible markup language) records the identity of the user equipment A, registration information, access parameters, and service trigger information;
  • HSS B 202 Home Subscriber Server B, HSS B 202 is used to store related data of user equipment B, and is an upgraded HLR; HSS records the identity, registration information, and connection information of user equipment B in XML format. Incoming parameters and service trigger information, etc.
  • S-CSCF A 203 Serving Call Session Control Function A, S-CSCF A 203 is in the core control position in the IMS network, and is the key to IMS multi-process control; it is responsible for recording and controlling users. Process status of device A, performing session routing Function, and constantly interact with application services and billing functions, and perform value-added service triggering and service control according to rules;
  • S-CSCF B 204 Serving Call Session Control Function B, S-CSCF B 204 is in the core control position in the IMS network, and is the key to IMS multi-process control; it is responsible for recording and controlling users. Process status of device B, performing session routing, and continuously interacting with application services and accounting functions, and performing value-added service triggering and service control according to rules;
  • P-CSCF A 205 Proxy Call Session Control Function A, P-CSCF A 205 is the first contact point of user equipment A in the IMS network, and is mainly responsible for verifying requests, processing and sending responses;
  • P-CSCF B 206 Proxy Call Session Control Function B, P-CSCF B 206 is the first contact point of user equipment B in the IMS network, and is mainly responsible for verifying the request, processing and sending the response;
  • SGSN 207 Serving GPRS Support Node, which is a WCDMA (Packet Switch) domain function node, which mainly provides PS domain routing, mobility management, and session. Management, authentication, encryption and other functions;
  • WCDMA Packet Switch
  • SGSN 208 Server GPRS Support Node, which is a PS domain function node of the WCDMA core network, mainly provides functions of routing, mobility management, session management, authentication, encryption, etc. of the PS domain;
  • RNC 209 Radio Network Controller for controlling radio resources of the UTRAN (Universal Terrestrial Radio Access Network);
  • RNC 210 Radio Network Controller for controlling the radio resources of the UTRAN
  • NodeB 211 Base station of WCDMA system (ie, wireless transceiver), mainly completing Uu Processing of the interface physical layer protocol;
  • NodeB 212 a base station (ie, a wireless transceiver) of a WCDMA system, which mainly performs processing of a physical layer protocol of a Uu interface (an interface between a UE and a UTRAN);
  • UE-A 213 User Equipment A, where UE-A is the calling user equipment, used for wireless mobile communication;
  • UE-B 214 User Equipment B, where UE-B is the called user equipment, used for wireless mobile communication;
  • the AS is mainly used to provide CAT service logic and control the MRF to play media resources.
  • the MRF is a Multimedia Resource Function, and the MRF includes a Control Part (MRFC, Multimedia Resource Function Controller) and a processing unit of the user plane (MRFP). (Media Resource Function Processor), providing support for services related to bearers, such as multimedia resource play, video conference, user announcement, etc., capable of completing data media stream mixing, media stream distribution, bearer code conversion, and billing information Send, etc.
  • the network structure of the user equipment A and the user equipment B in the IMS network is provided in the embodiment, and after the user equipment UE-B customizes the multimedia color ring back tone service (CAT) for the user equipment UE-A, each network element is Hosted features.
  • CAT multimedia color ring back tone service
  • the third embodiment of the present invention provides a method for implementing a security mechanism for a multimedia session ring tone service.
  • the application scenario of the user equipment is that the user equipment UE-A and the user equipment UE-B are both located in the IMS domain.
  • User B has customized the multimedia ring back tone service (CAT) for user A, but the customized content is only one song, and does not include displaying its own vCard electronic business card; the network structure is the same as the corresponding description of the second embodiment of the present invention, No longer.
  • CAT multimedia ring back tone service
  • UE-A calls UE-B
  • UE-B illegally carries its own vCard electronic business card in the returned 18x temporary response message, and hopes that user A can see it; P-CSCF B arrives at the reception.
  • the message body type of the 18x message is checked. If the MIME message body containing the illegal electronic business card is detected, the MIME message body is deleted, and then sent, including The following steps:
  • Steps 301-306 the UE-A calls the UE-B, and sends an INVITE message, where the INVITE message carries the Offer SDP (Offer Session Description Protocol) of the UE-A, and the INVITE message finally Arriving at the UE-B;
  • the INVITE message carries the Offer SDP (Offer Session Description Protocol) of the UE-A, and the INVITE message finally Arriving at the UE-B;
  • Step 307 After receiving the INVITE message, the UE-B returns a 180 ringing message, and inserts a MIME message body in the message body of the 180 ringing message, and the MIME message body may include a piece of text or a vCard electronic business card, this example assumes that user B's vCard electronic business card is included, but this type of carrying is illegal;
  • Step 308 After receiving the 180 ringing message sent by the UE-B, the P-CSCF B triggers a check process of the message body, and checks whether the message body of the 180 ringing message includes a non-SDP type. The MIME message body, if the 180 ringing message is found to contain a non-SDP type MIME message body, delete the non-SDP type MIME message body; and then send the processed 180 ringing message to the S -CSCF B;
  • Steps 309 ⁇ 3013 the 180 ringing message continues to advance to the CAT AS, the CAT AS adds a CAT Offer SDP to the 180 ringing message, and the 180 ringing message finally reaches the UE-A; UE-A extracts the CAT Offer SDP therein for early media negotiation;
  • Steps 3014 ⁇ 3026 the UE-A returns a PRACK ( Provisional Response)
  • the message carries the CAT Answer SDP.
  • the CAT AS extracts it, completes the negotiation of the CRBT early media, and then plays the multimedia CRBT for the UE-A, and the PRACK finally reaches the UE-B;
  • UE-B returns a 200 OK message in response to the PRACK message to the UE-A;
  • Steps 3027 ⁇ 3040 user B picks up the phone, and sends a 200 OK message in response to the INVITE message. Giving the UE-A; the CAT AS stops playing the CRBT; the UE-A returns an ACK acknowledgement message. The calling party and the called user enter the normal call process.
  • the check of the signaling message body sent by the called user by P-CSCF B can be extended to: 180 Ringing message, 183 Session Progress message, 200 OK message in response to PRACK message, UPDATE message and response 200 OK of the INVITE message; that is, any message sent before the call of the calling party and the user (except the MESSAGE message) is checked;
  • the P-CSCF B checks the signaling sent by the called user before the calling party and the called party, including not only checking the message body, but also expanding to: Check whether the signaling header of the signaling includes
  • Call-Info header field or Alert-Info header field if yes, delete the Call-Info header field or Alert-Info header field.
  • the main advantage of the solution proposed in this embodiment is that when the user equipment is in the IMS network and the user B subscribes to the multimedia ring back tone service (CAT) for the user A, the signaling is added before the calling party and the called user make a normal call. If the header of the signaling is included in the message header of the Call-Info header field or the Alert-Info header field, the Call-Info header field or the Alert-Info header field is deleted; If the MIME message body of the non-SDP type is included, the MIME message body of the non-SDP type is deleted, which can solve the charging vulnerability problem caused by the user transmitting the end-to-end message before the call, and receive the dangerous code before the call or The security problem caused by the dangerous link, thus realizing the security mechanism of the multimedia ring tone service.
  • CAT multimedia ring back tone service
  • the fourth embodiment of the present invention provides a network structure for implementing a multimedia ring tone service by a user equipment, including:
  • the user equipment UE-A and the user equipment UE-B are both located in the IMS domain, and the user equipment UE-A customizes the multimedia color vibration service (CRS) for the user equipment UE-B;
  • CRS multimedia color vibration service
  • HSS A401 Home Subscriber Server A
  • HSS B Home Subscriber Server A
  • A401 is used to store related data of user equipment A, which is an upgraded HLR;
  • HSS is in XML The form records the identity of the user equipment A, registration information, access parameters, and service trigger information;
  • HSS B402 Home Subscriber Server B, HSS B402 is used to store related data of user equipment B, which is an upgraded HLR; HSS records the identity, registration information, and access parameters of user equipment B in XML format. And service trigger information, etc.; S-CSCF A403: Serving Call Session Control Function A (Serving Call Session Control)
  • S-CSCF A403 is in the core control position in the IMS network and is the key to IMS multi-process control; it is responsible for recording and controlling the status of user equipment A processes, performing session routing functions, and continuously applying services and accounting. Function interaction, value-added service triggering and service control according to rules;
  • S-CSCF B404 Service Call Session Control Function B (Serving Call Session Control)
  • S-CSCF B404 is in the core control position in the IMS network and is the key to IMS multi-process control; it is responsible for recording and controlling the status of user equipment B processes, performing session routing functions, and continuously applying services and accounting. Function interaction, value-added service triggering and service control according to rules;
  • P-CSCF A405 Proxy Call Session Control Function A (Proxy Call Session Control
  • P-CSCF A405 is the first contact point of user equipment A in the IMS network, and is mainly responsible for verifying requests, processing and sending responses;
  • P-CSCF B406 Proxy Call Session Control Function B, P-CSCF B406 is the first contact point of user equipment B in the IMS network, and is mainly responsible for verifying requests, processing and sending responses;
  • SGSN407 Serving GPRS Support Node, which is a PS domain function node of WCDMA core network, mainly provides functions such as route sending, mobility management, session management, authentication, and encryption in the PS domain;
  • SGSN408 Serving GPRS Support Node, which is a PS domain function node of the WCDMA core network, mainly provides functions such as route sending, mobility management, session management, authentication, and encryption of the PS domain;
  • RNC409 Radio Network Controller for controlling radio resources of UTRAN;
  • RNC410 Radio Network Controller for controlling the radio resources of the UTRAN
  • NodeB411 A base station (ie, a wireless transceiver) of a WCDMA system, which mainly performs processing of a physical layer protocol of the Uu interface;
  • NodeB412 The base station of the WCDMA system (ie, the wireless transceiver), which mainly completes the processing of the physical layer protocol of the Uu interface;
  • UE-A413 User Equipment A (User Equipment) A, where UE-A is the calling user equipment for wireless mobile communication;
  • UE-B414 User Equipment B (B, User Equipment B), where UE-B is the called user equipment, used for wireless mobile communication;
  • CRS AS/ MRF415 where CRS AS is a Customized Ringing Signal Application Server.
  • CRS AS is mainly used to provide CRS service logic and control MRF to play media resources.
  • MRF is a multimedia resource function (Multimedia Resource). Function), MRF includes control part (MRFC) and user plane processing part (MRFP), which provides support for bearer-related services, such as multimedia resource play, video conference, user announcement, etc., can complete data media stream mixing, media Distribution of streams, conversion of bearer codes, transmission of billing information, and the like.
  • MRFC multimedia resource function
  • MRFP user plane processing part
  • the network structure of the user equipment A and the user equipment B in the IMS network is provided in the embodiment, and the network elements are disclosed after the user equipment UE-A customizes the multimedia color vibration service (CRS) for the user equipment UE-B.
  • CRS multimedia color vibration service
  • the fifth embodiment of the present invention is a method for implementing a security mechanism for a multimedia session ring tone service.
  • the application scenario of the user equipment is that the user equipment UE-A and the user equipment UE-B are both located in the IMS domain.
  • User A has customized the multimedia color vibration service (CRS) for user B, but the customized content is only one song, and does not include displaying its own vCard electronic business card;
  • CRS multimedia color vibration service
  • Step 501 UE-A calls UE-B, and sends an INVITE message.
  • the message carries the UE-A Offer SDP and carries the MIME message body including the vCard electronic business card, but the manner of carrying the MIME message body is illegal;
  • Step 502 After receiving the INVITE message, the P-CSCF A triggers a check process of the message body, and checks whether the message body of the INVITE message includes a non-SDP type MIME message body, and if the INVITE message is detected.
  • the non-SDP type MIME message body is included, and the non-SDP type MIME message body is deleted, and then the processed INVITE message is sent to the S-CSCF A.
  • Steps 5014 ⁇ 5026 UE-A returns a PRACK message, and after the PRACK message arrives at the CRS AS, the CRS AS inserts a CRS Offer SDP in the message body, and then the message finally arrives at the UE-B; the UE-B returns In response to the 200 OK message of the PRACK, the 200 OK message in response to the PRACK carries the CRS Answer SDP, and when the 200 OK message responding to the PRACK arrives at the CRS AS, the CRS AS extracts the CRS Answer SDP and completes Negotiation of the early media, and then playing the multimedia color burst for the UE-B;
  • Steps 5027 ⁇ 5040 user B picks up the phone, sends a 200 OK message in response to the INVITE to the UE-A; the CRS AS stops playing the color burst; the UE-A returns an ACK acknowledgement message, and the primary called user enters the normal call process.
  • the check of the signaling message body sent by the calling user equipment by the P-CSCF A can be extended to: INVITE message, PRACK message, UPDATE message; that is, any message (except MESSAGE message) sent by the calling device before the call of the calling user device is checked;
  • the P-CSCF A checks the signaling sent by the calling user equipment before the calling party calls, including not only checking the message body of the signaling, but also extending to: checking the letter Whether the header of the command includes a Call-Info header field or an Alert-Info header field, and if so, the Call-Info header field or the Alert-Info header field is deleted.
  • the main advantage of the solution proposed in this embodiment is that when the user equipment is in the IMS network, and the user A subscribes to the multimedia color vibration service (CRS) for the user B, the letter is added before the calling party and the called user make a normal call.
  • the message header of the signaling includes a Call-Info header field or an Alert-Info header field
  • the Call-Info header field or the Alert-Info header field is deleted, and if the signaling is checked
  • the message body includes a non-SDP type MIME message body, and the non-SDP type MIME message body is deleted, which can solve the charging vulnerability problem caused by the user transmitting the end-to-end message before the call, and receive the call before the call.
  • the security problem caused by dangerous code or dangerous link thus realizing the security mechanism of multimedia ring tone service.
  • the sixth embodiment provided by the present invention is a device for implementing a security mechanism of a multimedia ring tone service, and includes the following modules:
  • the device 61 is configured to implement the function of the P-CSCF, and has the function of checking and processing the security of the signaling;
  • the receiving module 601 is configured to receive signaling of the user equipment, and send a trigger signal to the processing module 602 after receiving the signaling;
  • the processing module 602 is configured to process the signaling when receiving the trigger signal sent by the receiving module 601.
  • the main advantage of the solution proposed in this embodiment is that it provides a design method of a device for implementing a multimedia ring tone service security mechanism.
  • the seventh embodiment provided by the present invention is a device for implementing a multimedia ring tone service security mechanism, and includes the following modules: As shown in FIG. 7, the device 71 is configured to implement the function of the P-CSCF, and has the function of checking and processing the security of the signaling;
  • the receiving module 701 is configured to receive signaling of the user equipment, and send a trigger signal to the processing module 702 after receiving the signaling;
  • the check processing module 702 is configured to process the signaling when receiving the trigger signal sent by the receiving module 701.
  • the first processing sub-module 7001 is located inside the processing module 702, and is configured to: when receiving the trigger signal sent by the receiving module 701, check whether the message body of the signaling includes a non-SDP type MIME message body, if If yes, delete the MIME message body of the non-SDP type; or
  • the receiving module 701 When the trigger signal sent by the receiving module 701 is received, check whether the message header of the signaling includes a Call-Info header field or an Alert-Info header field, and if yes, delete the Call-Info Header field or Alert-Info header field;
  • the trigger signal sent by the receiving module 701 it is checked whether the message body of the signaling includes a MIME message body of a non-SDP type, and if yes, the MIME message body of the non-SDP type is deleted; Checking whether the message header of the signaling includes a Call-Info header field or an Alert-Info header field. If yes, deleting the Call-Info header field or the Alert-Info header field.
  • the second processing sub-module 7002 is configured to send the processed signal by the first processing sub-module 7001.
  • the main advantage of the solution proposed in this embodiment is that a detailed module design method of a device for implementing a multimedia ring tone service security mechanism is provided.
  • the eighth embodiment provided by the present invention is a system for implementing a security mechanism of a multimedia ring tone service, which includes the following:
  • the device 81 is configured to implement the function of the P-CSCF, and has the function of checking and processing the security of the signaling;
  • the receiving entity 801 is configured to receive signaling of the user equipment, and send a trigger signal to the processing entity 802 after receiving the signaling;
  • Processing entity 802 configured to process the signaling when a trigger signal sent by the receiving entity 801 is received.
  • the main advantage of the solution proposed in this embodiment is to provide a design method of a system for implementing a multimedia ring tone service security mechanism.
  • the ninth embodiment provided by the present invention is a system for implementing a multimedia ring tone service security mechanism, which includes the following:
  • the device 91 is configured to implement the function of the P-CSCF, and has the function of checking and processing the security of the signaling;
  • Receiving entity 901 signaling for receiving a user equipment, and sending a trigger signal to the processing entity 902 after receiving the signaling;
  • Processing entity 902 configured to process the signaling when receiving a trigger signal sent by the receiving entity 901.
  • the first processing sub-entity 9001 is located in the processing entity 902, and is configured to check whether the message body of the signaling includes a non-SDP type MIME message body when receiving the trigger signal sent by the receiving entity 901 If yes, deleting the non-SDP type MIME message body;
  • the receiving entity 901 For receiving the trigger signal sent by the receiving entity 901, checking whether the message header of the signaling includes a Call-Info header field or an Alert-Info header field, and if yes, deleting the Call-Info header Domain or Alert-Info header field;
  • the second processing sub-entity 9002 is located inside the processing entity 902, and is configured to send the processed signaling by the first processing sub-entity 9001.
  • the main advantage of the solution proposed in this embodiment is that a detailed module design method for a system for implementing a multimedia ring tone service security mechanism is provided.
  • the solution can be embodied in the form of a software product that can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.), including a number of instructions for causing a computer device (
  • a non-volatile storage medium which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.
  • the method described in various embodiments of the present invention may be a personal computer, a server, or a network device.

Landscapes

  • Engineering & Computer Science (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Telephonic Communication Services (AREA)

Description

一种实现多媒体铃音业务安全机制的方法、 设备及系统
本申请要求于 2008 年 11 月 13 日提交中国专利局、 申请号为 200810217418.2、 发明名称为 "一种实现多媒体铃音业务安全机制的方法、 设备及系统" 的中国专利申请的优先权, 其全部内容通过引用结合在本申请 中。
技术领域
本发明涉及通信技术领域, 尤其涉及多媒体铃音业务的技术。
目前, 多媒体铃音业务具体包括: 多媒体回铃音、 多媒体振铃音、 多媒 体背景音。 多媒体回铃音 (Customized Alerting Tone, CAT) : 又称为多媒 体彩铃, 即主叫拨打被叫时, 在被叫摘机接听之前, 主叫欣赏到多媒体回铃 音; 多媒体振铃音 (Customized Ringing Signal, CRS ) : 又称为多媒体彩 振, 即主叫拨打被叫时, 在被叫摘机接听之前, 被叫欣赏到多媒体振铃音。 目前多媒体彩振在各大标准组织中的叫法不同, 3GPP中称为 CRS, ITU-T 中称为 CRT (Customized Ringing Tone) , OMA ( Open Mobile Alliance, 开放移动联盟) 中称为 CMRT (Customized Multimedia Ringing Tone) ; 多 媒体背景音 (Customized Background Tone, CBT) : 又称为多媒体彩像, 即主叫和被叫通话过程中, 主被叫双方都能欣赏到多媒体背景音。
在 3G 网络中, 多媒体铃音业务的实现方案有两类: CS域方案、 IMS 域方案。
(1) CS域 (Circuit Switched Domain, 电路交换域) 方案:
电路交换域指所有的可以为用户流量提供电路域类连接的 CN ( Core Network, 核心网) 实体和所有的支持相关信号的实体。 CS域中具体又分 为: a.跨接方案: 多媒体铃音服务器不仅作为铃音播放设备, 同时兼作桥接 设备, 即参与整个呼叫建立过程, 并且在通话过程中作为话路的一部分。 这 种方案对 E1 资源占用大, 且多媒体铃音服务器一旦出现故障, 会造成呼 损; b.非跨接方案: 当主叫呼叫被叫时, 多媒体铃音服务器为主叫方 (或被 叫方) 播放多媒体铃音。 当被叫用户摘机后, 由移动交换中心发起拆线信 令, 多媒体铃音服务器与用户之间的电路随即释放, 该方案节省了电路资 源。
(2) IMS (IP Multimedia Subsystem, IP多媒体子系统) 域方案:
IMS是一种标准化的下一代网络架构, 使电信运营商提供移动和固定多 媒体业务成为可能。 IMS 使用基于 3GPP标准化 SIP ( Session Initiation Protocol, 会话初始协议) 应用的 VoIP (Voice over Internet Protocol, IP电 话) 应用, 承载在标准 IP协议上。 IMS 目的不仅是提供新的服务, 而是现 有及将来因特网所能提供的所有服务。 IMS域中具体又分为: a.早期会话 (Early Session) 方案: 在主被叫之间建立正常通话会话之前, 通过进行早 期媒体协商以建立早期会话, 来实现早期媒体 (即多媒体铃音) 的播放; b. 多对话 (Multi Dialog) 方案: 在主被叫之间建立正常通话会话之前, 用户 设备与多媒体铃音服务器之间建立第二个对话, 实现多媒体铃音的播放。 当 被叫摘机时, 终止第二个对话。
在实现本发明过程中, 发明人发现现有技术中至少存在如下问题: 多媒 体铃音业务的现有实现方案缺少安全机制。
发明内容
有鉴于此, 本发明实施例提供一种实现多媒体铃音业务安全机制的方 法、 设备及系统以实现多媒体铃音业务的安全机制。
为解决上述技术问题, 本发明实施例提供一种实现多媒体铃音业务安全 机制的方法, 包括:
接收用户设备发送的信令, 检查所述信令的消息体和 /或消息头, 处理 所述信令, 发送上述处理后的信令。
相应地, 本发明实施例还提供一种实现多媒体铃音业务安全机制的设 备, 包括: 接收模块: 用于接收用户设备的信令, 当接收到所述信令后向处理模块 发送触发信号;
处理模块: 用于当接收到所述接收模块发送的触发信号时, 检查所述信 令的消息体和 /或消息头, 处理所述信令。
相应地, 本发明实施例还提供一种实现多媒体铃音业务安全机制的系 统, 包括: 用户设备和上述实现多媒体铃音业务安全机制的设备。
本发明实施例提供的实现多媒体铃音业务安全机制的方法、 设备及系统 解决了多媒体铃音业务实现过程中安全机制缺乏的问题。
附图说明
图 la为本发明实施例一中的方法的处理流程图之一;
图 lb为本发明实施例一中的方法的处理流程图之二;
图 2为本发明实施例二的组网结构图;
图 3为本发明实施例三的方法流程图;
图 4为本发明实施例四的组网结构图;
图 5为本发明实施例五的方法流程图;
图 6为本发明实施例六的设备示意图;
图 7为本发明实施例七的设备示意图;
图 8为本发明实施例八的系统示意图;
图 9为本发明实施例九的系统示意图。
具体实施方式
为使本发明的目的、 技术方案及优点更加清楚明白, 以下参照附图并举 九个实施例, 对本发明进一步详细说明。
本发明提供的第一实施例是一种实现多媒体铃音业务安全机制的方法, 包括:
在通话建立之前, 对本侧网络中的用户设备发来的信令消息进行检查
(除 MESSAGE消息之外) 。 检查包括可选的两方面: 一是对所述信令消 息的消息体类型进行检查, 删除所有的非 SDP ( session description protocol, 会话描述协议) 类型的 MIME ( Multipurpose Internet Mail Extensions , 通用网际邮件扩展) 消息体; 二是对所述信令消息的消息头进 行检查, 删除 Call-Info或 Alert-Info头域。
检查所述信令消息的消息体的处理流程如图 1 a所示, 具体步骤如下: 步骤 101a、 接收来自本侧网络用户设备发送的 SIP信令;
步骤 102a、 判断所述 SIP信令的消息头中的 Content-Type (内容类型) 的值是否为" application/sdp" ; 如果是, 则不做任何处理, 直接转入步骤 106a; 如果不是, 则进入下一步骤 103a的处理;
步骤 103a、 判断所述 SIP信令的消息头中的 Content-Type的值是否为
"multipart/mixed" : 如果不是, 则删除该消息体, 然后转至步骤 106a; 如 果是, 说明所述 SIP信令携带了多个消息体, 则进入下一步骤 104a的循环 处理;
步骤 104a、 判断所述 SIP信令的消息体中的 Content-Type的值是否为 "application/sdp " : 如果不是, 则先删除该消息体, 然后转至步骤 105a; 如果是, 则直接转至步骤 105a;
步骤 105a、 判断所述 SIP信令是否还有下一个消息体, 如果有, 则跳 回步骤 104a, 继续循环判断过程; 如果不是, 则说明已经检查完了所有的 消息体, 转至步骤 106a;
步骤 106a、 将所述 SIP信令发送给下一个网络实体 (即 S-CSCF
(Serving Call Session Control Function, 服务呼叫会话控制功能) 或 I-CSCF ( Interrogating-Call Session Control Function, 询问服务呼叫会话控制功 能) ) 。
检查所述信令消息的消息头的处理流程如图 l b所示, 具体步骤如下: 歩骤 101b、 接收来自本侧网络用户设备发送的 SIP信令;
歩骤 102b、 判断所述 SIP信令的消息头中是否包含 Call-Info头域或 Alert-Info头域: 如果有, 则先将所述 Call-Info头域或 Alert-Info头域删除, 然后转至步骤 103b, 如果没有, 则直接转至步骤 103b;
步骤 103b、 将所述 SIP信令发送给下一个网络实体 (即 S-CSCF或 I- CSCF) 。
在实现多媒体铃音业务安全机制的方法中可采用上述两种处理流程中的 任意一种或者同时采用上述两种处理流程。 如果同时采用两种处理流程, 可 以先进行所述信令消息的消息体的处理流程, 然后进行所述信令消息的消息 头的处理流程; 或者先进行所述信令消息的消息头的处理流程, 然后进行所 述信令消息的消息体的处理流程。
本实施例当中所提出的方案的主要优点在于提供了两种实现多媒体铃音 业务安全机制的检査处理流程。
本发明提供的第二实施例是用户设备实现多媒体铃音业务的网络结构, 包括:
如图 2所示, 用户设备 UE-A和用户设备 UE-B均位于 IMS域中, 用户 设备 UE-B为用户设备 UE-A定制了多媒体彩铃业务 (CAT) ;
HSS A 201 , 归属用户服务器 A (Home Subscriber Server A) , HSS A 201用于存储用户设备 A的相关数据, 是一个升级的 HLR (Home Location Register, 归属位置寄存器) ; HSS以 XML (extensible Markup Language, 可扩展的标记语言) 形式记录了用户设备 A的身份、 注册信息、 接入参数 和服务触发信息等;
HSS B 202, 归属用户服务器 B (Home Subscriber Server B ) , HSS B 202用于存储用户设备 B的相关数据, 是一个升级的 HLR; HSS以 XML形 式记录了用户设备 B的身份、 注册信息、 接入参数和服务触发信息等;
S-CSCF A 203: 服务呼叫会话控制功能 A(Serving Call Session Control Function A),S-CSCF A 203在 IMS网络中处于核心控制地位, 是 IMS多进程 控制的关键所在;其负责记录并控制用户设备 A的进程状态, 执行会话路由 功能, 并不断与应用服务和计费功能进行交互, 根据规则进行增值业务触发 与业务控制;
S-CSCF B 204: 服务呼叫会话控制功能 B(Serving Call Session Control Function B),S-CSCF B 204在 IMS网络中处于核心控制地位, 是 IMS多进程 控制的关键所在;其负责记录并控制用户设备 B 的进程状态, 执行会话路由 功能, 并不断与应用服务和计费功能进行交互, 根据规则进行增值业务触发 与业务控制;
P-CSCF A 205: 代理呼叫会话控制功能 A(Proxy Call Session Control Function A), P-CSCF A 205是 IMS网络中用户设备 A的第一个接触点, 主 要负责验证请求, 处理和发送响应;
P-CSCF B 206: 代理呼叫会话控制功能 B(Proxy Call Session Control Function B), P-CSCF B 206是 IMS网络中用户设备 B的第一个接触点, 主 要负责验证请求, 处理和发送响应;
SGSN 207: 服务器 GPRS支持节点 (Serving GPRS Support Node) , 是 WCDMA ( Wideband Code Division Multiple Access ) 核心网 PS ( Packet Switch, 分组交换) 域功能节点, 主要提供 PS域的路由发送、 移动性管 理、 会话管理、 鉴权、 加密等功能;
SGSN 208: 服务器 GPRS支持节点 (Serving GPRS Support Node) , 是 WCDMA核心网 PS域功能节点, 主要提供 PS域的路由发送、 移动性管 理、 会话管理、 鉴权、 加密等功能;
RNC 209: 无线网络控制器 (Radio Network Controller ) , 用于控制 UTRAN ( Universal Terrestrial Radio Access Network , 全球陆地无线接入 网) 的无线资源;
RNC 210: 无线网络控制器 (Radio Network Controller ) , 用于控制 UTRAN的无线资源;
NodeB 211: WCDMA系统的基站 (即无线收发信机) , 主要完成 Uu 接口物理层协议的处理;
NodeB 212: WCDMA系统的基站 (即无线收发信机) , 主要完成 Uu 接口 (UE和 UTRAN之间的接口) 物理层协议的处理;
UE-A 213: 用户设备 A (User Equipment A) , 此处 UE-A为主叫用户 设备, 用于无线移动通信;
UE-B 214: 用户设备 B (User Equipment B) , 此处 UE-B为被叫用户 设备, 用于无线移动通信;
CAT AS/ MRF 215, 其中 CAT AS 是多媒体彩铃应用服务器 (Customized Alerting Tone Application Server) , AS是 IMS网络中为用户 提供 IM增值业务的服务器, 可以位于用户归属网, 也可以由第三方提供; CAT AS主要用于提供 CAT业务逻辑, 并控制 MRF进行媒体资源的播放; 而 MRF是多媒体资源功能 (Multimedia Resource Function) , MRF包括控 制部分 (MRFC, Multimedia Resource Function Controller) 和用户平面的处 理部分 (MRFP, Media Resource Function Processor) , 对与承载相关的业 务提供支持, 如多媒体资源播放、 视频会议、 用户公告等, 能够完成数据媒 体流的混合、 媒体流的分发、 承载代码的转换、 计费信息的发送等。
本实施例当中提供了用户设备 A与用户设备 B处于 IMS网络中的网络 结构示意图, 揭示了当用户设备 UE-B为用户设备 UE-A定制了多媒体彩铃 业务 (CAT) 后, 各个网元所承载的功能。
本发明提供的第三实施例是一种实现多媒体会话铃音业务安全机制的方 法, 如图 3所示, 首先用户设备的应用场景为用户设备 UE-A和用户设备 UE-B 均位于 IMS 域中, 用户 B 为用户 A 定制了多媒体彩铃业务 (CAT) , 但是定制内容仅为一首歌曲, 并没有包括显示自己的 vCard电子 名片; 网络结构与本发明实施例二的相应描述相同, 在此不再赘述。
当 UE-A呼叫 UE-B时, UE-B在返回的 18x临时应答消息中非法携带 了自己的 vCard电子名片, 并希望用户 A能够看到; P-CSCF B在接收到来 自 UE-B的 18x消息后, 会对所述 18x消息的消息体类型进行检查, 若检查 出包含有非法的包含电子名片的 MIME消息体, 则删除该 MIME消息体 后, 再进行发送, 包括如下步骤:
歩骤 301-306, UE-A呼叫 UE-B , 发送 INVITE消息, 所述 INVITE消 息中携带了 UE-A的 Offer SDP (Offer Session Description Protocol, 请求类 型的会话描述协议) , 所述 INVITE消息最终到达所述 UE-B;
步骤 307、 所述 UE-B收到所述 INVITE消息后, 返回 180振铃消息, 并且在所述 180振铃消息的消息体中插入了 MIME消息体, 该 MIME消息 体可以包含一段文字或一个 vCard电子名片, 本例中假设包含了用户 B 的 vCard电子名片, 但是这种携带方式是非法的;
步骤 308、 P-CSCF B收到所述 UE-B发来的所述 180振铃消息后, 触发 对其消息体的检查流程, 检查所述 180振铃消息的消息体中是否包含非 SDP类型的 MIME消息体, 若发现所述 180振铃消息中包含了非 SDP类型 的 MIME消息体, 则删除所述非 SDP类型的 MIME消息体; 然后将处理之 后的所述 180振铃消息发送给 S-CSCF B;
歩骤 309~3013、 所述 180振铃消息继续前进, 到达 CAT AS , 所述 CAT AS在所述 180振铃消息中添加 CAT Offer SDP, 所述 180振铃消息最 终到达 UE-A; 所述 UE-A提取其中的所述 CAT Offer SDP, 进行早期媒体 的协商;
步骤 3014~3026、 所述 UE-A 返回 PRACK ( Provisional Response
ACKnowledgement , 临时响应的确认消息) 消息, 消息中携带了 CAT Answer SDP。 所述 CAT AS接收到所述 CAT Answer SDP之后, 将其提取 出来, 完成了彩铃早期媒体的协商, 然后为所述 UE-A播放多媒体彩铃, 所 述 PRACK最终到达所述 UE-B; 所述 UE-B返回响应 PRACK消息的 200 OK消息给所述 UE-A;
歩骤 3027~3040、 用户 B摘机, 发送响应 INVITE消息的 200 OK消息 给所述 UE-A; 所述 CAT AS停止播放彩铃; UE-A返回 ACK确认消息。 主 被叫用户进入正常通话过程。
方案扩展:
(1) P-CSCF B对被叫用户发来的信令消息体的检查可以扩展至: 180 Ringing消息、 183 Session Progress (会话进行中) 消息、 响应 PRACK消息 的 200 OK消息、 UPDATE消息以及响应 INVITE消息的 200 OK; 即对主 被叫用户通话之前所发送的任何消息 (除 MESSAGE消息外) 均进行检 查;
(2) P-CSCF B在主被叫通话之前对被叫用户所发信令进行的检查, 不仅 包括对消息体的检查, 还可以扩展至: 检查所述信令的消息头是否包含
Call-Info头域或 Alert-Info头域, 如果是, 则将所述 Call-Info头域或 Alert- Info头域删除。
本实施例当中所提出的方案的主要优点是在用户设备处于 IMS 网络, 用户 B为用户 A订制了多媒体彩铃业务 (CAT) 情况下, 在主被叫用户正 常通话之前, 增加了对信令的检查流程, 若检查出信令的消息头中包含 Call-Info头域或 Alert-Info头域, 则删除所述 Call-Info头域或 Alert-Info头 域; 若检查出信令的消息体中包含非 SDP类型的 MIME消息体, 则删除所 述非 SDP类型的 MIME消息体, 可解决用户在通话之前传递端到端消息而 造成的计费漏洞问题, 以及在通话之前接收到危险代码或危险链接而造成的 安全性问题, 从而实现了多媒体铃音业务的安全机制。
本发明提供的第四实施例是用户设备实现多媒体铃音业务的网络结构, 包括:
如图 4所示, 用户设备 UE-A和用户设备 UE-B均位于 IMS域中, 用户 设备 UE-A为用户设备 UE-B定制了多媒体彩振业务 (CRS ) ;
HSS A401 , 归属用户服务器 A (Home Subscriber Server ) A, HSS
A401用于存储用户设备 A的相关数据, 是一个升级的 HLR; HSS以 XML 形式记录了用户设备 A的身份、 注册信息、 接入参数和服务触发信息等;
HSS B402 , 归属用户服务器 B ( Home Subscriber Server ) B, HSS B402用于存储用户设备 B的相关数据, 是一个升级的 HLR; HSS以 XML 形式记录了用户设备 B的身份、 注册信息、 接入参数和服务触发信息等; S-CSCF A403: 服务呼叫会话控制功能 A(Serving Call Session Control
Function)A,S-CSCF A403在 IMS网络中处于核心控制地位, 是 IMS多进程 控制的关键所在;其负责记录并控制用户设备 A进程状态, 执行会话路由功 能, 并不断与应用服务和计费功能进行交互, 根据规则进行增值业务触发与 业务控制;
S-CSCF B404: 服务呼叫会话控制功能 B(Serving Call Session Control
Function)B,S-CSCF B404在 IMS网络中处于核心控制地位, 是 IMS多进程 控制的关键所在;其负责记录并控制用户设备 B进程状态, 执行会话路由功 能, 并不断与应用服务和计费功能进行交互, 根据规则进行增值业务触发与 业务控制;
P-CSCF A405 : 代理呼叫会话控制功能 A(Proxy Call Session Control
Function) A, P-CSCF A405是 IMS网络中用户设备 A的第一个接触点, 主 要负责验证请求, 处理和发送响应;
P-CSCF B406 : 代理呼叫会话控制功能 B(Proxy Call Session Control Function)B, P-CSCF B406是 IMS网络中用户设备 B的第一个接触点, 主要 负责验证请求, 处理和发送响应;
SGSN407: 服务器 GPRS支持节点 (Serving GPRS Support Node) , 是 WCDMA核心网 PS域功能节点, 主要提供 PS域的路由发送、 移动性管 理、 会话管理、 鉴权、 加密等功能;
SGSN408: 服务器 GPRS支持节点 (Serving GPRS Support Node) , 是 WCDMA核心网 PS域功能节点, 主要提供 PS域的路由发送、 移动性管 理、 会话管理、 鉴权、 加密等功能; RNC409: 无线网络控制器 (Radio Network Controller ) , 用于控制 UTRAN的无线资源;
RNC410 : 无线网络控制器 ( Radio Network Controller ) , 用于控制 UTRAN的无线资源;
NodeB411 : WCDMA系统的基站 (即无线收发信机) , 主要完成 Uu 接口物理层协议的处理;
NodeB412: WCDMA系统的基站 (即无线收发信机) , 主要完成 Uu 接口物理层协议的处理;
UE-A413 : 用户设备 A (User Equipment) A, 此处 UE-A为主叫用户设 备, 用于无线移动通信;
UE-B414: 用户设备 B (User Equipment) B, 此处 UE-B为被叫用户设 备, 用于无线移动通信;
CRS AS/ MRF415, 其中 CRS AS 是多媒体彩振应用服务器 ( Customized Ringing Signal Application Server) , CRS AS主要用于提供 CRS业务逻辑, 并控制 MRF进行媒体资源的播放; 而 MRF是多媒体资源 功能 (Multimedia Resource Function) , MRF包括控制部分 (MRFC) 和用 户平面的处理部分 (MRFP) , 对与承载相关的业务提供支持, 如多媒体资 源播放、 视频会议、 用户公告等, 能够完成数据媒体流的混合、 媒体流的分 发、 承载代码的转换、 计费信息的发送等。
本实施例当中提供了用户设备 A与用户设备 B处于 IMS网络中的网络 结构示意图, 揭示了当用户设备 UE-A为用户设备 UE-B定制了多媒体彩振 业务 (CRS) 后, 各个网元所承载的功能。
本发明提供的第五实施例是一种实现多媒体会话铃音业务安全机制的方 法, 如图 5所示, 首先用户设备的应用场景为用户设备 UE-A和用户设备 UE-B均位于 IMS域中, 用户 A为用户 B定制了多媒体彩振业务 (CRS) , 但是定制内容仅为一首歌曲, 并没有包括显示自己的 vCard电子名片; 网络 结构与本发明实施例四的相应描述相同, 在此不再赘述。
当 UE-A呼叫 UE-B时, UE-A在发送的 INVITE呼叫请求消息中非法携 带了自己的 vCard电子名片, P-CSCF A在接收到来自 UE-A的 INVITE消 息后, 会对消息体的类型进行检查, 若检查出包含有非法的包含电子名片的 MIME消息体, 则删除该 MIME消息体后, 再进行发送, 包括如下步骤: 步骤 501、 UE-A呼叫 UE-B, 发送 INVITE消息, 消息中携带了 UE- A Offer SDP, 并且携带了包含 vCard电子名片的 MIME消息体, 但是这种携 带 MIME消息体的方式是非法的;
步骤 502、 P-CSCF A收到 INVITE消息后, 触发对其消息体的检査流 程, 检查所述 INVITE消息的消息体中是否包含非 SDP类型的 MIME消息 体, 若检査出所述 INVITE消息中包含了非 SDP类型的 MIME消息体, 则 删除所述非 SDP类型的 MIME消息体, 然后将处理后的所述 INVITE消息 发送给 S-CSCF A。
步骤 503~5013、 所述 INVITE消息继续前进, 最终到达 UE-B; UE-B 返回 180 Ringing消息;
歩骤 5014~5026、 UE-A返回 PRACK消息, 所述 PRACK消息到达 CRS AS后, 所述 CRS AS在消息体中插入 CRS Offer SDP, 然后该消息最 终到达 UE-B; 所述 UE-B返回响应 PRACK的 200 OK消息, 所述响应 PRACK的 200 OK消息中携带了 CRS Answer SDP, 当所述响应 PRACK的 200 OK消息到达所述 CRS AS时, 所述 CRS AS将 CRS Answer SDP提取出 来, 完成了早期媒体的协商, 然后为所述 UE-B播放多媒体彩振;
步骤 5027~5040、 用户 B摘机, 发送响应 INVITE的 200 OK消息给 UE-A; 所述 CRS AS停止播放彩振; 所述 UE-A返回 ACK确认消息, 主被 叫用户进入正常通话过程。
方案扩展:
(1) P-CSCF A对主叫用户设备发来的信令消息体的检查可以扩展至: INVITE消息、 PRACK消息、 UPDATE消息; 即对主被叫用户设备通话之 前所述主叫设备所发送的任何消息 (MESSAGE消息除外) 均进行检查;
(2) P-CSCF A在主被叫通话之前对所述主叫用户设备所发送信令进行的 检查, 不仅包括对所述信令的消息体的检查, 还可以扩展至: 检查所述信令 的消息头是否包含 Call-Info头域或 Alert-Info头域, 如果是, 则将所述 Call- Info头域或 Alert-Info头域删除。
本实施例当中所提出的方案的主要优点是在用户设备处于 IMS 网络, 用户 A为用户 B订制了多媒体彩振业务 (CRS) 情况下, 在主被叫用户正 常通话之前, 增加了对信令的检查流程, 若检査出信令的消息头中包含 Call-Info头域或 Alert-Info头域, 则删除所述 Call-Info头域或 Alert-Info头 域, 若检査出信令的消息体中包含非 SDP类型的 MIME消息体, 则删除所 述非 SDP类型的 MIME消息体, 可解决用户在通话之前传递端到端消息而 造成的计费漏洞问题, 以及在通话之前接收到危险代码或危险链接而造成的 安全性问题, 从而实现了多媒体铃音业务的安全机制。
本发明提供的第六实施例是一种实现多媒体铃音业务安全机制的设备, 包括如下模块:
如图 6所示, 设备 61用于实现 P-CSCF的功能, 且具有对信令的安全 性进行检查处理功能;
接收模块 601 : 用于接收用户设备的信令, 当接收到所述信令后向处理 模块 602发送触发信号;
处理模块 602: 用于当接收到所述接收模块 601发送的触发信号时, 处 理所述信令。
本实施例当中所提出的方案的主要优点在于提供了一种实现多媒体铃音 业务安全机制的设备的设计方式。
本发明提供的第七实施例是一种实现多媒体铃音业务安全机制的设备, 包括如下模块: 如图 7所示, 设备 71用于实现 P-CSCF的功能, 且具有对信令的安全 性进行检查处理功能;
接收模块 701 : 用于接收用户设备的信令, 当接收到所述信令后向处理 模块 702发送触发信号;
检查处理模块 702: 用于当接收到所述接收模块 701发送的触发信号 时, 处理所述信令。
第一处理子模块 7001 : 其位于处理模块 702 的内部, 用于当接收到所 述接收模块 701 发送的触发信号时, 检查所述信令的消息体是否包含非 SDP类型的 MIME消息体, 若为是, 则删除所述非 SDP类型的 MIME消息 体; 或者,
用于当接收到所述接收模块 701发送的触发信号时, 检査所述信令的消 息头是否包含 Call-Info头域或 Alert-Info头域, 若为是, 则删除所述 Call- Info头域或 Alert-Info头域;
或者,
用于当接收到所述接收模块 701发送的触发信号时, 检查所述信令的消 息体是否包含非 SDP类型的 MIME消息体, 若为是, 则删除所述非 SDP类 型的 MIME消息体; 检查所述信令的消息头是否包含 Call-Info头域或 Alert- Info头域, 若为是, 则删除所述 Call-Info头域或 Alert-Info头域。
第二处理子模块 7002: 用于发送所述第一处理子模块 7001处理后的信 令。
本实施例当中所提出的方案的主要优点在于提供了一种实现多媒体铃音 业务安全机制的设备的详细模块设计方式。
本发明提供的第八实施例是一种实现多媒体铃音业务安全机制的系统, 包括如下:
如图 8所示, 设备 81用于实现 P-CSCF的功能, 且具有对信令的安全 性进行检查处理功能; 接收实体 801 : 用于接收用户设备的信令, 当接收到所述信令后向处理 实体 802发送触发信号;
处理实体 802: 用于当接收到所述接收实体 801发送的触发信号时, 处 理所述信令。
本实施例当中所提出的方案的主要优点在于提供一种实现多媒体铃音业 务安全机制的系统的设计方式。
本发明提供的第九实施例是一种实现多媒体铃音业务安全机制的系统, 包括如下:
如图 9所示, 设备 91用于实现 P-CSCF的功能, 且具有对信令的安全 性进行检查处理功能;
接收实体 901 : 用于接收用户设备的信令, 当接收到所述信令后向处理 实体 902发送触发信号;
处理实体 902: 用于当接收到所述接收实体 901发送的触发信号时, 处 理所述信令。
第一处理子实体 9001 : 其位于所述处理实体 902的内部, 用于当接收 到所述接收实体 901发送的触发信号时, 检查所述信令的消息体是否包含非 SDP类型的 MIME消息体, 若为是, 则删除所述非 SDP类型的 MIME消息 体;
或者,
用于当接收到所述接收实体 901发送的触发信号时, 检查所述信令的消 息头是否包含 Call-Info头域或 Alert-Info头域, 若为是, 则删除所述 Call- Info头域或 Alert-Info头域;
或者,
用于当接收到所述接收实体 901发送的触发信号时, 检查所述信令的消 息体是否包含非 SDP类型的 MIME消息体, 若为是, 则删除所述非 SDP类 型的 MIME消息体; 检查所述信令的消息头是否包含 Call-Info头域或 Alert- Info头域, 若为是, 则删除所述 Call-Info头域或 Alert-Info头域。
第二处理子实体 9002: 其位于所述处理实体 902的内部, 用于发送所 述第一处理子实体 9001处理后的信令。
本实施例当中所提出的方案的主要优点在于提供了一种实现多媒体铃音 业务安全机制的系统的详细模块设计方式。
通过以上的实施方式的描述, 本领域的技术人员可以清楚地了解到本发 明可以通过硬件实现, 也可以可借助软件加必要的通用硬件平台的方式来实 现, 基于这样的理解, 本发明的技术方案可以以软件产品的形式体现出来, 该软件产品可以存储在一个非易失性存储介质 (可以是 CD-ROM, U盘, 移动硬盘等) 中, 包括若干指令用以使得一台计算机设备 (可以是个人计算 机, 服务器, 或者网络设备等) 执行本发明各个实施例所述的方法。
以上所述, 仅为本发明较佳的具体实施方式, 但本发明的保护范围并不 局限于此, 任何熟悉本技术领域的技术人员在本发明揭露的技术范围内, 可 轻易想到的变化或替换, 都应涵盖在本发明的保护范围之内。 因此, 本发明 的保护范围应该以权利要求的保护范围为准。

Claims

权利要求书
1、 一种实现多媒体铃音业务安全机制的方法, 其特征在于, 包括: 接收用户设备发送的信令;
检查所述信令的消息体和 /或消息头, 处理所述信令;
发送处理后的信令。
2、 如权利要求 1所述的方法, 其特征在于, 所述信令包括:
在通话建立之前, 本侧网络的用户设备发送的信令。
3、 如权利要求 2所述的方法, 其特征在于, 所述信令为:
SIP信令、 INVITE消息、 PRACK消息、 UPDATE消息、 180 Ringing 消息、 183 Session Progress 消息、 响应 PRACK消息的 200 OK消息、 UPDATE消息或响应 INVITE消息的 200 OK消息。
4、 如权利要求 1或 2所述的方法, 其特征在于, 所述处理所述信令包 括:
如果所述信令的消息体包含非 SDP类型的 MIME消息体, 则删除所述 非 SDP类型的 MIME消息体。
5、 如权利要求 4所述的方法, 其特征在于,
如果所述信令携带了多个消息体, 则分别判断每一个消息体是否包括非 SDP类型的 MIME消息体。
6、 如权利要求 1或 2所述的方法, 所述处理所述信令包括:
如果所述信令的消息头包含 Call-Info头域或 Alert-Info头域, 则删除所 述 Call-Info头域或 Alert-Info头域。
7、 一种实现多媒体铃音业务安全机制的设备, 其特征在于, 所述设备 包括:
接收模块: 用于接收用户设备的信令, 当接收到所述信令后向处理模块 发送触发信号;
处理模块: 用于当接收到所述接收模块发送的触发信号时, 检查所述信 令的消息体和 /或消息头, 处理所述信令。
8、 如权利要求 7所述的设备, 其特征在于, 所述处理模块包括: 第一处理子模块: 用于当接收到所述接收模块发送的触发信号时, 检查 所述信令的消息体是否包含非 SDP类型的 MIME消息体, 若为是, 则删除 所述非 SDP类型的 MIME消息体;
第二处理子模块: 用于发送所述第一处理子模块处理后的信令。
9、 如权利要求 7所述的设备, 其特征在于, 所述处理模块包括: 第一处理子模块: 用于当接收到所述接收模块发送的触发信号时, 检查 所述信令的消息头是否包含 Call-Info头域或 Alert-Info头域, 若为是, 则删 除所述 Call-Info头域或 Alert-Info头域;
第二处理子模块: 用于发送所述第一处理子模块处理后的信令。
10、 如权利要求 7所述的设备, 其特征在于, 所述处理模块包括: 第一处理子模块: 用于当接收到所述接收模块发送的触发信号时, 检查 所述信令的消息体是否包含非 SDP类型的 MIME消息体, 若为是, 则删除 所述非 SDP类型的 MIME消息体, 检查所述信令的消息头是否包含 Call- Info头域或 Alert-Info头域, 若为是, 则删除所述 Call-Info头域或 Alert-Info 头域;
第二处理子模块: 用于发送所述第一处理子模块处理后的信令。
11、 一种实现多媒体铃音业务安全机制的系统, 其特征在于, 所述系统 包括: 用户设备和权利要求 7至 10任一项所述的实现多媒体铃音业务安全 机制的设备。
PCT/CN2009/072900 2008-11-13 2009-07-24 一种实现多媒体铃音业务安全机制的方法、设备及系统 WO2010054558A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN200980101231.9A CN102257784B (zh) 2008-11-13 2009-07-24 一种实现多媒体铃音业务安全机制的方法、设备及系统

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN200810217418.2 2008-11-13
CN200810217418 2008-11-13

Publications (1)

Publication Number Publication Date
WO2010054558A1 true WO2010054558A1 (zh) 2010-05-20

Family

ID=42169622

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/072900 WO2010054558A1 (zh) 2008-11-13 2009-07-24 一种实现多媒体铃音业务安全机制的方法、设备及系统

Country Status (2)

Country Link
CN (1) CN102257784B (zh)
WO (1) WO2010054558A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2020192435A1 (zh) * 2019-03-28 2020-10-01 华为技术有限公司 一种播放多媒体彩振、彩铃的方法、应用服务器
WO2022032574A1 (en) * 2020-08-13 2022-02-17 Qualcomm Incorporated User equipment signaling of customize ringing signal capability

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1889560A (zh) * 2005-08-03 2007-01-03 华为技术有限公司 网际协议多媒体子系统中面向用户的网络拓扑隐藏方法
CN1968280A (zh) * 2006-11-23 2007-05-23 华为技术有限公司 对非法头域进行检测和过滤的系统和方法
US20080037498A1 (en) * 2006-08-10 2008-02-14 Motorola, Inc. Optimized tunneling methods in a network
CN101217698A (zh) * 2008-01-10 2008-07-09 中兴通讯股份有限公司 一种实现彩铃和/或彩像业务的方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1889560A (zh) * 2005-08-03 2007-01-03 华为技术有限公司 网际协议多媒体子系统中面向用户的网络拓扑隐藏方法
US20080037498A1 (en) * 2006-08-10 2008-02-14 Motorola, Inc. Optimized tunneling methods in a network
CN1968280A (zh) * 2006-11-23 2007-05-23 华为技术有限公司 对非法头域进行检测和过滤的系统和方法
CN101217698A (zh) * 2008-01-10 2008-07-09 中兴通讯股份有限公司 一种实现彩铃和/或彩像业务的方法

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2020192435A1 (zh) * 2019-03-28 2020-10-01 华为技术有限公司 一种播放多媒体彩振、彩铃的方法、应用服务器
US11849067B2 (en) 2019-03-28 2023-12-19 Huawei Technologies Co., Ltd. Method for playing multimedia customized ringing signal and customized alerting tone, and application server
WO2022032574A1 (en) * 2020-08-13 2022-02-17 Qualcomm Incorporated User equipment signaling of customize ringing signal capability

Also Published As

Publication number Publication date
CN102257784B (zh) 2016-04-06
CN102257784A (zh) 2011-11-23

Similar Documents

Publication Publication Date Title
US8213418B2 (en) Providing packet-based multimedia services via a circuit breaker
US8155084B2 (en) User equipment, call continuity application server, and network handover method
US8832792B2 (en) Limiting services based on location
EP2107714B1 (en) Method and apparatus for implementing a multimedia ring back tone service and multimedia caller identification service
US8553869B2 (en) Method for implementing RBT interworking, media gateway control function device, and application server
US20060034195A1 (en) SIP message extension for push to watch service
JP5255123B2 (ja) 通信ネットワークにおいてセッションを確立する方法
WO2006064347A1 (en) Method and system to the instant transfer of multimedia files between mobile radio users within the scope of combinational services
US20100284267A1 (en) Call set-up in a communication network
US20120213346A1 (en) Method, server and terminal device for playing multimedia ring tone during call
US20100254372A1 (en) System and method for enhancing ims centralized services
JP5551786B2 (ja) 会話期間中にマルチメディア呼出し音を再生する方法、サーバおよび端末デバイス
CN102394989A (zh) 在通话期间播放多媒体铃音的方法、服务器及终端设备
CN102006371B (zh) 一种实现多媒体彩振业务的方法及设备
ES2289586T3 (es) Metodo y dispositivo para servicio pulsar para hablar.
WO2011023041A1 (zh) 一种指示终端媒体类型的呼叫方法及系统
WO2010054558A1 (zh) 一种实现多媒体铃音业务安全机制的方法、设备及系统
EP2723053B1 (en) Transfer inquiry method, application server, service terminal, and system
RU2395918C2 (ru) Предоставление служб, основанных на пакетах, через доступ с коммутацией каналов
CN101448202B (zh) 一种彩铃彩像业务更新媒体的方法

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 200980101231.9

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09825733

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 09825733

Country of ref document: EP

Kind code of ref document: A1