WO2012092711A1 - 配置无线局域网数字证书的方法和移动终端 - Google Patents

配置无线局域网数字证书的方法和移动终端 Download PDF

Info

Publication number
WO2012092711A1
WO2012092711A1 PCT/CN2011/070057 CN2011070057W WO2012092711A1 WO 2012092711 A1 WO2012092711 A1 WO 2012092711A1 CN 2011070057 W CN2011070057 W CN 2011070057W WO 2012092711 A1 WO2012092711 A1 WO 2012092711A1
Authority
WO
WIPO (PCT)
Prior art keywords
digital certificate
mobile terminal
local area
wireless local
sim card
Prior art date
Application number
PCT/CN2011/070057
Other languages
English (en)
French (fr)
Inventor
冯舒宇
马莉
马建勇
Original Assignee
宇龙计算机通信科技(深圳)有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 宇龙计算机通信科技(深圳)有限公司 filed Critical 宇龙计算机通信科技(深圳)有限公司
Priority to PCT/CN2011/070057 priority Critical patent/WO2012092711A1/zh
Publication of WO2012092711A1 publication Critical patent/WO2012092711A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security

Definitions

  • the present invention relates to the field of wireless local area network technologies, and in particular, to a method and a mobile terminal for configuring a wireless local area network digital certificate. Background of the invention
  • WLAN operators use WLAN digital certificates to authenticate and manage users.
  • the operator When the user applies for access to the wireless local area network, the operator writes the WLAN digital certificate to the customer identification module (SIMr) according to the user's application, and then provides the SIM card to the user for use, thereby satisfying the wireless local area network authentication.
  • SIMr customer identification module
  • WIPI WLAN Authentication and Privacy Infrastructure
  • the WLAN digital certificate is pre-written to the SIM card, when the user needs to replace the SIM card, the user needs to re-apply for a new SIM card written with the new WLAN digital certificate, or apply to the operator's business hall.
  • the WLAN digital certificate in the SIM card is written to the new SIM card.
  • the embodiment of the invention provides a method for configuring a wireless local area network digital certificate and a mobile terminal.
  • the wireless local area network digital certificate can be automatically written into the new SIM card.
  • the method for configuring a digital certificate for a wireless local area network includes: sending a change request message of a digital certificate of a wireless local area network to an operator when the first SIM card in the mobile terminal needs to be replaced with a second SIM card;
  • a mobile terminal provided by an embodiment of the present invention includes:
  • a sending module configured to send a change request message of the WLAN digital certificate to the operator when the first SIM card in the mobile terminal needs to be replaced with the second SIM card;
  • a receiving module configured to receive a change success message from the operator
  • a storage module configured to save a wireless local area network digital certificate
  • a writing module configured to write the wireless local area network digital certificate saved by the storage module to the second SIM card.
  • the mobile terminal when the first SIM card in the mobile terminal needs to be replaced with the second SIM card, the mobile terminal can automatically write the saved wireless local area network digital certificate to the second SIM card. Therefore, the user who uses the mobile terminal does not need to apply for a new WLAN digital certificate from the operator or apply to the business hall to use the original WLAN digital certificate. In this way, not only the WLAN digital certificate resources and operations are avoided. The waste of storage resources, but also greatly facilitates the use of users, saving users' time and reducing the management costs of operators. BRIEF DESCRIPTION OF THE DRAWINGS
  • 1 is a flow chart of a method for configuring a wireless local area network digital certificate in an embodiment of the present invention.
  • 2 is a flow chart showing a method of configuring a digital certificate for a wireless local area network in another embodiment of the present invention.
  • FIG. 3 is a flow chart showing a method of configuring a digital certificate for a wireless local area network in still another embodiment of the present invention.
  • FIG. 4 is a schematic diagram showing the structure of a mobile terminal in an embodiment of the present invention. Mode for carrying out the invention
  • the SIM card includes not only a SIM card conforming to the existing wireless local area network communication protocol, but also various SIM cards generated by the development of the wireless local area network technology, such as a global subscriber identity card (USIM). )Wait.
  • a WLAN digital certificate cartridge is hereinafter referred to as a digital certificate.
  • FIG. 1 is a flow chart of a method for configuring a wireless local area network digital certificate in an embodiment of the present invention. As shown in FIG. 1, the method includes the following steps.
  • Step 11 The mobile terminal reads the digital certificate from the first SIM card and saves the read digital certificate.
  • the first SIM card refers to the original SIM card in the mobile terminal.
  • the mobile terminal can read and write to the SIM card through the Attention (AT) command.
  • AT Attention
  • the read digital certificate can be saved in any storage module in the mobile terminal, such as mobile terminal Mobile storage media, such as memory or flash memory cards.
  • the storage module can be pre-assigned and update the stored digital certificate each time the digital certificate changes.
  • the mobile terminal can provide an option to back up the digital certificate so that the user using the mobile terminal can perform the operation of saving the digital certificate.
  • This step is only performed when the first SIM card is loaded in the mobile terminal, and then the mobile terminal saves the read digital certificate, and does not need to read the digital certificate in the first SIM card multiple times.
  • Step 12 When the first SIM card in the mobile terminal needs to be replaced with the second SIM card, the change request message of the digital certificate is sent to the operator.
  • the second SIM card refers to a new SIM card in the mobile terminal, and the first SIM card and the second SIM card are different.
  • the mobile terminal can send a change request message of the digital certificate to the operator through the first SIM card or the second SIM card.
  • the change request message of the digital certificate is sent through the first SIM card
  • the change request of the digital certificate includes the information of the second SIM card.
  • the change request may be sent by the wireless communication module of the mobile terminal via the telecommunication network, or the change request may be sent through the wireless local area network through the wireless Fidelity (WIFI) module of the mobile terminal.
  • WIFI wireless Fidelity
  • the mobile terminal may display an operation option of the change request message corresponding to the digital certificate, prompting the user to configure the digital certificate through the operation option.
  • the mobile terminal Upon receiving an instruction from the user to trigger the operational option, the mobile terminal transmits the change request message to the operator.
  • the mobile terminal may verify the user after receiving the instruction for triggering the operation option from the user, and send the change message to the operator when the verification is passed, thereby improving the security of the digital certificate configuration and avoiding Others maliciously replace the user's SIM card.
  • the mobile terminal may update the saved digital certificate according to the information of the second SIM card, and When the change request is sent, it will be updated
  • the digital certificate is sent to the operator.
  • the information of the SIM card may include a customer identifier, such as a mobile phone number.
  • Step 13 Receive a change success message from the carrier.
  • the operator may first authenticate the user, accept the change request of the user after the authentication is passed, and send a change success message to the mobile terminal. If the user does not pass the authentication, the operator sends a change failure message to the mobile terminal.
  • the operator may correspond to the information of the second SIM card, such as the second SIM card.
  • the customer identification, etc. updates the backed up digital certificate, and sends the updated digital certificate to the mobile terminal when the change success message is sent.
  • the operator can obtain the customer identification by using a change request message sent by the mobile terminal. For example, the customer identifier carried in the change request message is directly obtained, or the client identifier that sends the change request message is determined as the client identifier corresponding to the second SIM card.
  • the operator does not need to update the backed up digital certificate, if the first SIM card and the second SIM card correspond to the same customer identity, the operator can only send the change success message to the mobile terminal.
  • step 12 the mobile terminal sends its updated digital certificate to the operator, the operator directly receives and saves the digital certificate updated by the mobile terminal.
  • the operator can send a change success message to the mobile terminal by means of a short message.
  • Step 14 Write the digital certificate saved in the mobile terminal to the second SIM card. After receiving the change success message, the mobile terminal writes the saved digital certificate to the second SIM card, thereby completing the configuration of the digital certificate.
  • the digital certificate saved by the mobile terminal may be the digital certificate read by the mobile terminal in step 11, the digital certificate updated by the mobile terminal in step 12, or the updated digital certificate received from the operator in step 13.
  • the mobile terminal can automatically write the saved wireless local area network digital certificate to the second SIM card, so the user using the mobile terminal does not need to apply for a new service to the operator.
  • the mobile terminal reads the digital certificate from the first SIM card in advance, and stores the digital certificate in the mobile terminal.
  • the second SIM card and the first SIM card respectively correspond to different mobile phone numbers.
  • the method includes the following steps.
  • Step 21 Display the operation options for the change request corresponding to the digital certificate.
  • the mobile terminal After the first SIM card in the mobile terminal is replaced with the second SIM card, the mobile terminal displays an operation option corresponding to the change request of the digital certificate. For example, after the mobile terminal detects the change of the SIM card, the mobile terminal may actively pop up a prompt box for displaying the operation option; or after the SIM card is replaced, the user searches for a preset operation option in the function menu of the mobile terminal, thereby making the mobile terminal This action option is displayed.
  • Step 22 Receive an instruction from the user using the mobile terminal to trigger the operation option.
  • the user can send an instruction to trigger the operation option to the mobile terminal by clicking the operation option displayed by the mobile terminal.
  • Step 23 Prompt the user to enter the verification information.
  • the mobile terminal After receiving the trigger command sent by the user, the mobile terminal prompts the user to input the verification information. Specifically, the mobile terminal can display a dialog box for the user to input the verification information.
  • the verification information may be the user's identity verification information.
  • the user's authentication information is a specific format information that the user notes in the operator's server when the user first applies for the digital certificate, such as a digital signature, a number, a letter, and the like.
  • the verification information may also be the user's authentication information and the information of the second SIM card.
  • the mobile terminal may prompt the user to input the authentication information and the information of the second SIM card, such as the customer identifier corresponding to the second SIM card, that is, the mobile phone number. In this way, the mobile terminal can obtain the information of the second SIM card, thereby transmitting a change request of the digital certificate carrying the information of the second SIM card when needed.
  • Step 24 Verify the user according to the verification information input by the user.
  • the mobile terminal After the user inputs the verification information according to the prompt of the mobile terminal, the mobile terminal authenticates the user according to the verification information input by the user.
  • the specific verification mode may be the verification mode existing in the art, and details are not described herein again.
  • the user is verified by performing steps 23 and 24, thereby improving the security of the digital certificate configuration.
  • steps 23 and 24 may not be performed, and the implementation of the present invention is not affected.
  • Step 25 When the verification is passed, a change request for the digital certificate is sent to the operator.
  • the mobile terminal can transmit the change request of the digital certificate to the operator through the telecommunication network or the wireless local area network.
  • Step 26 Receive the updated digital certificate of the operator when receiving the change success message from the operator.
  • the mobile terminal receives a change success message from the operator. Since the first SIM card and the second SIM card correspond to different mobile phone numbers, the operator modifies the content related to the mobile phone number in the digital certificate, and sends the modified digital certificate to the mobile terminal. Therefore, in this step, when receiving the change success message, the mobile terminal also receives the operator update. Digital certificate. If there is no content related to the mobile phone number in the digital certificate, in this step, the mobile terminal only receives the change success message.
  • the mobile terminal can receive the change success message and the updated digital certificate through a wireless local area network or a telecommunication network.
  • the second SIM card in the mobile terminal receives the updated digital certificate, and then the mobile terminal reads the updated digital certificate from the second SIM card.
  • Step 27 Update the digital certificate saved in the mobile terminal.
  • the mobile terminal After receiving the changed digital certificate of the operator, the mobile terminal updates its saved digital certificate, so that the digital certificate stored in the mobile terminal is consistent with the digital certificate backed up by the operator.
  • Step 28 Write the digital certificate saved in the mobile terminal to the second SIM card.
  • the digital certificate written to the second SIM card is the digital certificate updated by the mobile terminal in step 27.
  • the mobile terminal when the first SIM card in the mobile terminal is replaced with the second SIM card, the mobile terminal can automatically write the updated digital certificate of the operator to the second SIM card, so The user of the mobile terminal can complete the configuration of the digital certificate by the operation of the single ticket, which facilitates the use of the user, saves the user's time, and reduces the management cost of the operator.
  • FIG. 3 is a flow chart of a method of configuring a wireless local area network digital certificate in still another embodiment of the present invention. This embodiment is similar to the embodiment shown in FIG. 2, and the difference between the two is that, in this embodiment, the operator allows the mobile terminal to modify the digital certificate. As shown in FIG. 3, the method includes Next step.
  • Step 31 Display the operation options for the change request corresponding to the digital certificate.
  • Step 32 Receive an instruction from the user using the mobile terminal to trigger the operation option.
  • Step 33 Prompt the user to enter the verification information.
  • Step 34 Verify the user according to the verification information input by the user.
  • steps 31-34 are the same as steps 21-24 in the embodiment shown in Fig. 2 and will not be described in detail herein.
  • Step 35 When the verification is passed, update the digital certificate saved by the mobile terminal.
  • the mobile terminal modifies the digital certificate saved by the mobile terminal according to the rights developed by the operator for the mobile terminal.
  • the mobile terminal may modify the content related to the information in the digital certificate according to the information of the second SIM card.
  • Step 36 Send the digital certificate change request and the updated digital certificate to the operator.
  • the mobile terminal transmits the change request and the digital certificate updated by itself to the operator. Accordingly, in this embodiment, the operator directly updates the backed up digital certificate.
  • Step 37 When receiving the change success message from the operator, write the digital certificate saved in the mobile terminal to the second SIM card.
  • the digital certificate written to the second SIM card is the digital certificate updated by the mobile terminal in step 35.
  • the mobile terminal when the first SIM card in the mobile terminal is replaced with the second SIM card, the mobile terminal can automatically update the digital certificate, and after receiving the operator's change success message, the number is The certificate is written into the second SIM card. Therefore, the user who uses the mobile terminal can complete the configuration of the digital certificate by simply operating the device, thereby facilitating the use of the user, saving the user's time and reducing the operation of the operator. , further reducing the management costs of operations.
  • the embodiment of the invention further provides a mobile terminal capable of implementing the above method.
  • the mobile terminal includes a sending module, a receiving module, a storage module and a writing module.
  • the sending module is configured to: when the first SIM card in the mobile terminal needs to be replaced with the second SIM card, send a change request message of the digital certificate to the operator; the receiving module is configured to receive a change success message from the operator; The module is configured to save the digital certificate; the writing module is configured to write the digital certificate saved by the storage module to the second SIM card in the mobile terminal.
  • the mobile terminal further includes a reading module.
  • the reading module is configured to read a digital certificate from the first SIM card in advance, and the digital certificate saved by the storage module is a digital certificate read by the reading module.
  • the mobile terminal may first display an operation option corresponding to the change request message, and after receiving an instruction from the user to trigger the operation option, send the change request message to the operator.
  • the mobile terminal further includes an interaction module, configured to display an operation option corresponding to the operation, and receive an instruction sent by the user to trigger the operation selection.
  • the interaction module is further configured to prompt the user to input the verification information; and verify the user according to the verification information input by the user.
  • the sending module is specifically configured to send a change request of the digital certificate to the operator when the verification is passed, thereby improving the security of the digital certificate configuration, and preventing the malicious replacement of the user's SIM card by others.
  • the operator may first authenticate the user, accept the change request of the user after the authentication is passed, and send a change success message to the mobile terminal. If the user does not pass the authentication, the operator sends a change failure message to the mobile terminal. When the operator updates the backup digital certificate as needed, the operator sends the updated digital certificate to the mobile terminal.
  • the receiving module in the mobile terminal is further configured to: when receiving the change success message, receive the updated digital certificate sent by the operator, and the storage module is further configured to save the updated digital certificate. If the operator opens the modification right of the digital certificate to the mobile terminal, the mobile terminal can update the digital certificate stored by itself according to the need. At this time, the storage module in the mobile terminal is further used to update the digital certificate saved by itself, and the sending module is further configured to send the updated digital certificate when sending the change request message of the digital certificate to the operator.
  • the sending module of the mobile terminal may be a wireless communication module or
  • the WAFI module performs the transmission function through the telecommunication network and the wireless LAN respectively.
  • the mobile terminal when the first SIM card in the mobile terminal needs to be replaced with the second SIM card, the mobile terminal can automatically write the saved wireless local area network digital certificate to the second SIM card. Therefore, the user who uses the mobile terminal does not need to apply for a new WLAN digital certificate from the operator or apply to the business hall to use the original WLAN digital certificate. In this way, not only the waste of the digital localization certificate resources of the wireless local area network and the storage resources of the operator is avoided, but also the use of the user is greatly facilitated, the time of the user is saved, and the management cost of the operator is reduced.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)
  • Telephone Function (AREA)

Description

配置无线局域网数字证书的方法和移动终端
技术领域
本发明涉及无线局域网技术领域, 尤其涉及一种配置无线局域网数 字证书的方法和移动终端。 发明背景
随着无线局域网技术的不断发展, 移动终端的使用越来越普及。 出 于安全性的考虑, 无线局域网的运营商采用无线局域网数字证书对用户 进行认证和管理。
在用户申请接入无线局域网时, 运营商根据用户的申请, 将无线局 域网数字证书写入客户识别模块( Subscriber Identity Module, SIM卡), 之后将该 SIM卡提供给用户使用,从而满足无线局域网鉴别和保密基础 结构 ( WLAN Authentication and Privacy Infrastructure, WIPI ) 的要求, 实现无线局域网的可运营、 可管理和安全性。
由于无线局域网数字证书是预先写入 SIM 卡的, 当用户需要更换 SIM 卡时, 用户需要重新申请写入了新的无线局域网数字证书的新的 SIM卡,或者到运营商的营业厅申请将原 SIM卡中的无线局域网数字证 书写入新的 SIM卡中。
但是, 如果用户每次更换 SIM卡都需要新的无线局域网数字证书, 由于原有的无线局域网数字证书无法再被使用, 但是运营商还需要对这 些无线局域网证书进行管理, 这样一来, 不仅造成大量无线局域网数字 证书的浪费, 还浪费了运营商的存储资源, 增加了运营商的管理成本。
另外,如果用户每次更换 SIM卡都到运营商的营业厅申请将原 SIM 卡中的无线局域网数字证书写入新的 SIM卡, 不仅过程比较繁瑣, 占用 用户较多的时间, 而且也增加了运营商对用户的管理成本。
可见, 当用户需要更换 SIM卡时, 现有的配置无线局域网数字证书 的方式无法满足用户和运营商的需要的。 发明内容
本发明实施例提供了一种配置无线局域网数字证书的方法及移动终 端, 当移动终端需要更换 SIM卡时, 能够自动将无线局域网数字证书写 入新的 SIM卡。
本发明实施例提供的一种配置无线局域网数字证书的方法包括: 当移动终端中的第一 SIM卡需要更换为第二 SIM卡时, 发送无线 局域网数字证书的变更请求消息给运营商;
接收来自所述运营商的变更成功消息; 本发明实施例提供的一种移动终端包括:
发送模块,用于当移动终端中的第一 SIM卡需要更换为第二 SIM卡 时, 发送无线局域网数字证书的变更请求消息给运营商;
接收模块, 用于接收来自所述运营商的变更成功消息;
存储模块, 用于保存无线局域网数字证书;
写模块, 用于将所述存储模块保存的所述无线局域网数字证书写入 所述第二 SIM卡。
可以看出, 根据本发明实施例提供的技术方案, 当移动终端中的第 一 SIM卡需要被更换为第二 SIM卡时, 移动终端能够自动将保存的无 线局域网数字证书写入第二 SIM卡, 因此, 使用该移动终端的用户无需 向运营商申请新无线局域网数字证书或者到营业厅申请使用原无线局 域网数字证书。 这样一来, 不仅避免了无线局域网数字证书资源和运营 商存储资源的浪费, 而且还极大地方便了用户的使用, 节省了用户的时 间, 降低了运营商的管理成本。 附图简要说明
图 1是本发明实施例中配置无线局域网数字证书的方法的流程图。 图 2是本发明另一实施例中配置无线局域网数字证书的方法的流程 图。
图 3是本发明又一实施例中配置无线局域网数字证书的方法的流程 图。
图 4是本发明实施例中移动终端结构的示意图。 实施本发明的方式
为了使本发明的目的、 技术方案和优点更清楚, 下面结合附图和具 体实施方式对本发明作进一步描述。
在本发明实施例中, SIM卡不仅包括符合现有无线局域网通信协议 的 SIM卡, 还包括随着无线局域网技术的发展产生的各种 SIM卡, 如 全球用户识别卡( Universal Subscriber Identity Module, USIM )等。另夕卜, 为了便于描述, 下面将无线局域网数字证书筒称为数字证书。
图 1是本发明实施例中配置无线局域网数字证书的方法的流程图。 如图 1所示, 该方法包括如下步骤。
步骤 11: 移动终端从第一 SIM卡中读取数字证书,并保存读取的数 字证书。
在本发明实施例中,第一 SIM卡指在移动终端中的原 SIM卡。移动 终端可以通过 Attention (AT)指令完成对 SIM卡的读写操作。
读取的数字证书可以保存在移动终端中任意的存储模块, 如移动终 端的移动存储介质, 如内存或者闪存卡中。 该存储模块可以预先指定, 并在每次数字证书变化时, 更新已存储的数字证书。
在实际应用中, 移动终端可以提供备份数字证书的选项, 以便使用 移动终端的用户能够执行保存数字证书的操作。
本步骤仅在移动终端中装入第一 SIM卡时执行,之后移动终端保存 读取的数字证书, 无需多次读取第一 SIM卡中的数字证书。
步骤 12: 当移动终端中的第一 SIM卡需要更换为第二 SIM卡时, 发送数字证书的变更请求消息给运营商。
在本发明实施例中, 第二 SIM卡指在移动终端中的新 SIM卡, 第 一 SIM卡和第二 SIM卡不同。
移动终端可以通过第一 SIM卡或第二 SIM卡发送数字证书的变更 请求消息给运营商。 当通过第一 SIM 卡发送数字证书的变更请求消息 时, 该数字证书的变更请求中包括第二 SIM卡的信息。
具体地, 该变更请求可以通过该移动终端的无线通信模块经电信网 发送,或者该变更请求可以通过该移动终端的无线相容性协议( Wireless Fidelity, WIFI )模块经无线局域网发送。
另外,移动终端可以显示对应数字证书的变更请求消息的操作选项, 提示用户通过该操作选项配置数字证书。 当接收到来自用户的触发该操 作选项的指令后, 移动终端发送该变更请求消息给运营商。
进一步地, 移动终端可以在接收到来自用户的触发该操作选项的指 令后, 对用户进行验证, 当验证通过时, 才将该变更消息发送给运营商, 从而提高数字证书配置的安全性, 避免他人恶意更换用户的 SIM卡。
另外, 如果数字证书中包括与 SIM卡的信息相关的内容, 并且运营 商向移动终端开放了数字证书的修改权限, 则移动终端可以根据第二 SIM卡的信息, 更新保存的数字证书, 并在发送该变更请求时, 将更新 的数字证书发送给运营商。 其中, SIM卡的信息可以包括客户标识, 如 手机号码等。
步骤 13: 接收来自运营商的变更成功消息。
收到移动终端的变更请求后, 运营商可以先对用户进行认证, 当认 证通过后接受用户的变更请求, 并发送变更成功消息给移动终端。 如果 用户没有通过认证, 则运营商发送变更失败消息给移动终端。
其中, 运营商对用户进行认证的方式由运营商自行设置, 在此不作 详细说明。
当需要根据 SIM 卡的信息更新网络侧存储的数字证书时, 如第一 SIM卡和第二 SIM卡对应的客户标识不同时,运营商可以根据第二 SIM 卡的信息, 如第二 SIM卡对应的客户标识等, 更新备份的数字证书, 并 在发送变更成功消息时发送更新的数字证书的给移动终端。 在本发明实 施例中, 运营商可以通过移动终端发送的变更请求消息获取该客户标 识。 例如, 直接获取变更请求消息中携带的该客户标识, 或者将发送该 变更请求消息的客户标识确定为第二 SIM卡对应的客户标识。
如果运营商不需要更新备份的数字证书,如第一 SIM卡和第二 SIM 卡对应的客户标识相同时, 运营商可以仅发送变更成功消息给移动终 端。
如果在步骤 12中, 移动终端将自身更新的数字证书发送给运营商, 则运营商直接接收并保存移动终端更新的数字证书。
在实际应用中, 运营商可以通过短信的形式将变更成功消息发送给 移动终端。
步骤 14: 将在移动终端中保存的数字证书写入该第二 SIM卡。 接收到变更成功消息后, 移动终端将保存的数字证书写入该第二 SIM卡, 从而完成对数字证书的配置。 在本步骤中,移动终端保存的数字证书可以是在步骤 11中移动终端 读取的数字证书, 在步骤 12 中移动终端更新的数字证书, 或者在步骤 13中从运营商接收的更新的数字证书。
当移动终端中的第一 SIM卡被更换为第二 SIM卡时,移动终端能够 自动将保存的无线局域网数字证书写入第二 SIM卡, 因此, 使用该移动 终端的用户无需向运营商申请新无线局域网数字证书或者到营业厅申 请使用原无线局域网数字证书。 这样一来, 不仅避免了无线局域网数字 证书资源和运营商存储资源的浪费, 而且还极大地方便了用户的使用, 节省了用户的时间, 降低了运营商的管理成本。
图 2是本发明另一实施例中配置数字证书的方法的流程图。 在本实 施例中, 移动终端预先从第一 SIM卡中读取了数字证书, 并将该数字证 书存储在移动终端中, 另外, 第二 SIM卡与第一 SIM卡分别对应不同 的手机号码。 如图 2所示, 该方法包括以下步骤。
步骤 21: 显示对应数字证书的变更请求的操作选项。
当移动终端中的第一 SIM卡更换为第二 SIM卡后,移动终端显示对 应数字证书的变更请求的操作选项。 例如, 当移动终端检测到 SIM卡变 化后, 可以主动弹出显示该操作选项的提示框; 或者用户在更换 SIM卡 后, 在移动终端的功能菜单中查找预先设置的该操作选项, 从而使移动 终端显示该操作选项。
步骤 22: 接收来自使用该移动终端的用户的触发该操作选项的指 令。
用户可以通过点击移动终端显示的该操作选项, 发送触发该操作选 项的指令给该移动终端。
步骤 23: 提示该用户输入验证信息。
接收到用户发送的触发指令后, 移动终端提示用户输入验证信息。 具体地, 移动终端可以显示对话框, 供用户输入验证信息。
在本实施例中, 验证信息可以是用户的身份验证信息。 其中, 用户 的身份验证信息是该用户在初次申请数字证书时, 用户在运营商服务器 中备注的特定格式的信息, 如数字签名, 数字, 字母等格式的密码。
另夕卜,验证信息还可以是用户的身份验证信息和第二 SIM卡的信息。 此时,移动终端可以依次提示用户分别输入身份验证信息和第二 SIM卡 的信息, 如第二 SIM卡对应的客户标识, 即手机号码等。 这样一来, 移 动终端可以获取第二 SIM卡的信息,从而在需要时发送携带有第二 SIM 卡的信息的数字证书的变更请求。
步骤 24: 根据该用户输入的验证信息, 对该用户进行验证。
用户根据移动终端的提示输入验证信息后, 移动终端根据用户输入 的验证信息对该用户进行验证。 具体的验证方式可以采用本领域已有的 验证方式, 在此不再赘述。
在本实施例中, 通过执行步骤 23和 24, 对用户进行了验证, 从而 提高了数字证书配置的安全性。 在实际应用中, 也可以不执行步骤 23 和 24, 并不影响本发明的实施。
步骤 25: 当验证通过时, 发送数字证书的变更请求给运营商。
在本实施例中, 移动终端可以通过电信网或者无线局域网将数字证 书的变更请求发送给运营商。
步骤 26: 在接收来自运营商的变更成功消息时, 接收该运营商更新 后的数字证书。
在本步骤中, 移动终端接收来自运营商的变更成功消息。 由于第一 SIM卡和第二 SIM卡对应不同的手机号码,运营商会修改数字证书中与 手机号码相关的内容, 并将修改后的数字证书发送给移动终端。 因此, 在本步骤中, 移动终端在接收变更成功消息时, 还接收到运营商更新后 的数字证书。 如果数字证书中没有与手机号码相关的内容, 则在本步骤 中, 移动终端只接收到变更成功消息。
其中, 移动终端可以通过无线局域网或电信网接收该变更成功消息 和更新后的数字证书。
当移动终端通过电信网接收变更成功消息和更新后的数字证书时, 移动终端中的第二 SIM卡接收更新后的数字证书,之后移动终端从第二 SIM卡中读取更新后的数字证书。
步骤 27: 更新在移动终端中保存的数字证书。
接收到运营商的变更后的数字证书后, 移动终端更新自身保存的数 字证书, 从而使移动终端中保存的数字证书与运营商备份的数字证书一 致。
步骤 28: 将在移动终端中保存的数字证书写入第二 SIM卡。
在本步骤中, 写入第二 SIM卡的数字证书是在步骤 27中移动终端 更新后的数字证书。
另外, 如果移动终端中的第二 SIM卡已经在步骤 26中接收了更新 第二 SIM卡。
可以看出, 根据本实施例, 当移动终端中的第一 SIM卡被更换为第 二 SIM 卡时, 移动终端能够自动将运营商更新后的数字证书写入第二 SIM卡, 因此, 使用该移动终端的用户只要通过筒单的操作, 就能够完 成数字证书的配置, 便了用户的使用, 节省了用户的时间, 同时降低了 运营商的管理成本。
图 3是本发明又一实施例中配置无线局域网数字证书的方法的流程 图。 本实施例与图 2所示实施例类似, 两者的区别在于, 在本实施例中, 运营商允许移动终端对数字证书进行修改。 如图 3所示, 该方法包括以 下步骤。
步骤 31 : 显示对应数字证书的变更请求的操作选项。
步骤 32: 接收来自使用该移动终端的用户的触发该操作选项的指 令。
步骤 33: 提示该用户输入验证信息。
步骤 34: 根据该用户输入的验证信息, 对该用户进行验证。
上述步骤 31-34与图 2所示实施例中的步骤 21-24相同, 在此不作 详细描述。
步骤 35: 当验证通过时, 更新移动终端保存的数字证书。
在本步骤中, 移动终端根据运营商为移动终端开发的权限, 对自身 保存的数字证书进行修改。例如,移动终端可以根据第二 SIM卡的信息, 对数字证书中与该信息相关的内容进行修改。
步骤 36: 发送数字证书的变更请求和更新的数字证书给运营商。 在本实施中, 移动终端将变更请求和自身更新的数字证书发送给运 营商。 相应地, 在本实施例中, 运营商直接更新备份的数字证书。
步骤 37: 在接收来自运营商的变更成功消息时, 将在移动终端中保 存的数字证书写入第二 SIM卡。
在本步骤中, 写入第二 SIM卡的数字证书是在步骤 35中移动终端 更新后的数字证书。
可以看出, 根据本实施例, 当移动终端中的第一 SIM卡被更换为第 二 SIM卡时, 移动终端能够自动更新数字证书, 并在接收到运营商的变 更成功消息后, 将该数字证书写入第二 SIM卡, 因此, 使用该移动终端 的用户只要通过筒单的操作, 就能够完成数字证书的配置, 便了用户的 使用, 节省了用户的时间, 同时减少了运营商的操作, 进一步降低了运 营的管理成本。 本发明实施例还提供了一种能够实现上述方法的移动终端。
图 4是本发明实施例中移动终端结构的示意图。 如图 4所示, 该移 动终端包括发送模块, 接收模块, 存储模块和写模块。
其中, 发送模块用于当移动终端中的第一 SIM 卡需要更换为第二 SIM卡时, 发送数字证书的变更请求消息给运营商; 接收模块用于接收 来自该运营商的变更成功消息; 存储模块, 用于保存数字证书; 写模块 用于将该存储模块保存的数字证书写入所述移动终端中的第二 SIM卡。
在本发明实施例中, 移动终端还包括读模块。 该读模块用于预先从 第一 SIM卡中读取数字证书,该存储模块保存的数字证书是该读模块读 取的数字证书。
在本发明实施例中, 移动终端可以先显示对应该变更请求消息的操 作选项, 当接收到来自用户的触发该操作选项的指令后, 发送该变更请 求消息给运营商。 此时该移动终端还包括交互模块, 用于显示对应该操 作选项, 并接收该用户发送的触发该操作选择的指令。
进一步地, 交互模块还用于提示用户输入验证信息; 根据该用户输 入的验证信息, 对该用户进行验证。 此时, 该发送模块具体用于当所述 验证通过时, 发送数字证书的变更请求给运营商, 从而提高数字证书配 置的安全性, 避免他人恶意更换用户的 SIM卡。
收到移动终端的变更请求后, 运营商可以先对用户进行认证, 当认 证通过后接受用户的变更请求, 并发送变更成功消息给移动终端。 如果 用户没有通过认证, 则运营商发送变更失败消息给移动终端。 当运营商 根据需要更新了备份数字证书时, 该运营商发送更新的数字证书的给移 动终端。此时,该移动终端中的接收模块还用于在接收变更成功消息时, 接收该运营商发送的更新后的数字证书, 该存储模块还用于保存该更新 的数字证书。 如果运营商向移动终端开放了数字证书的修改权限, 该移动终端可 以根据需要更新自身存储的数字证书。 此时, 移动终端中的存储模块还 用于更新自身保存的数字证书, 发送模块还用于在发送数字证书的变更 请求消息给运营商时, 发送更新的数字证书。
在本实施例中, 移动终端的发送模块可以是无线通信模块或者
WAFI模块, 分别通过电信网和无线局域网完成发送功能。
可以看出, 根据本发明实施例提供的移动终端, 当移动终端中的第 一 SIM卡需要被更换为第二 SIM卡时, 移动终端能够自动将保存的无 线局域网数字证书写入第二 SIM卡, 因此, 使用该移动终端的用户无需 向运营商申请新无线局域网数字证书或者到营业厅申请使用原无线局 域网数字证书。 这样一来, 不仅避免了无线局域网数字证书资源和运营 商存储资源的浪费, 而且还极大地方便了用户的使用, 节省了用户的时 间, 降低了运营商的管理成本。
以上所述仅为本发明的较佳实施例而已, 并不用以限制本发明, 凡 在本发明的精神和原则之内, 所作的任何修改、 等同替换、 改进等, 均 应包含在本发明的保护范围之内。

Claims

权利要求书
1、 一种配置无线局域网数字证书的方法, 其特征在于, 包括: 当移动终端中的第一 SIM卡需要更换为第二 SIM卡时, 发送无线 局域网数字证书的变更请求消息给运营商;
接收来自所述运营商的变更成功消息;
2、根据权利要求 1所述的方法, 其特征在于, 所述无线局域网数字 证书保存在所述移动终端的移动存储介质中。
3、 根据权利要求 1所述的方法, 其特征在于, 所述第一 SIM卡和 第二 SIM卡对应的客户标识相同或者不同。
4、 根据权利要求 1所述的方法, 其特征在于, 还包括:
从所述第一 SIM卡中读取对应所述第一 SIM卡的无线局域网数字 证书;
在所述移动终端中保存所述读取的无线局域网数字证书。
5、 根据权利要求 1所述的方法, 其特征在于, 还包括:
提示所述用户输入验证信息;
根据所述用户输入的验证信息, 对所述用户进行验证;
所述发送无线局域网数字证书的变更请求消息给运营商包括: 当所述验证通过时, 发送所述无线局域网数字证书的变更请求给所 述运营商。
6、根据权利要求 5所述的方法, 其特征在于, 所述验证信息包括所 述用户的身份验证信息, 或者包括所述用户的身份验证信息和所述第二 SIM卡的信息。
7、 根据权利要求 1所述的方法, 其特征在于, 还包括: 在接收所述变更成功消息时, 接收所述运营商更新后的无线局域网 数字证书;
保存所述更新后的无线局域网数字证书。
8、 根据权利要求 1所述的方法, 其特征在于, 还包括:
更新所述保存的无线局域网数字证书;
在发送所述无线局域网数字证书的变更请求消息给所述运营商时, 发送所述更新的无线局域网数字证书。
9、根据权利要求 8所述的方法, 其特征在于, 所述更新所述保存的 无线局域网数字证书包括:
根据所述第二 SIM卡的信息,更新所述保存的无线局域网数字证书。
10、 根据权利要求 1所述的方法, 其特征在于, 所述发送无线局域 网数字证书的变更请求消息给运营商包括:
通过电信网发送所述无线局域网数字证书的变更请求消息给所述运 营商; 或者 述运营商。
11、 根据权利要求 1所述的方法, 其特征在于, 所述接收来自所述 运营商的变更成功消息包括:
通过无线局域网接收所述变更成功消息; 或者通过电信网接收所述 变更成功消息。
12、 一种移动终端, 其特征在于, 包括:
发送模块,用于当移动终端中的第一 SIM卡需要更换为第二 SIM卡 时, 发送无线局域网数字证书的变更请求消息给运营商;
接收模块, 用于接收来自所述运营商的变更成功消息;
存储模块, 用于保存无线局域网数字证书; 写模块, 用于将所述存储模块保存的所述无线局域网数字证书写入 所述第二 SIM卡。
13、根据权利要求 12所述的移动终端, 其特征在于, 所述存储模块 包括所述移动终端的移动存储介质。
14、 根据权利要求 12所述的移动终端, 其特征在于, 还包括: 读模块, 用于从所述第一 SIM卡中读取对应所述第一 SIM卡的无 线局域网数字证书;
所述存储模块用于保存所述读模块读取的无线局域网数字证书。
15、 根据权利要求 12所述的移动终端, 其特征在于, 还包括: 交互模块, 用于显示对应所述无线局域网数字证书的变更请求的操 作选项; 接收使用所述移动终端的用户发送的触发所述操作选择的指 令。
16、根据权利要求 15所述的移动终端, 其特征在于, 所述交互模块 还用于提示所述用户输入验证信息; 根据所述用户输入的验证信息, 对 所述用户进行验证; 所述发送模块具体用于当所述验证通过时, 发送所 述无线局域网数字证书的变更请求给所述运营商。
17、 根据权利要求 12所述的移动终端, 其特征在于,
所述接收模块还用于在接收所述变更成功消息时, 接收所述运营商 更新后的无线局域网数字证书;
18、 根据权利要求 12所述的移动终端, 其特征在于,
所述存储模块还用于更新所述保存的无线局域网数字证书; 息给所述运营商时, 发送所述更新的无线局域网数字证书。
19、 根据权利要求 12所述的移动终端, 其特征在于, 所述发送模 块包括无线通信模块或者 WAFI模块。
20、 根据权利要求 12所述的移动终端, 其特征在于, 所述接收模 块包括无线通信模块或者 WAFI模块。
PCT/CN2011/070057 2011-01-06 2011-01-06 配置无线局域网数字证书的方法和移动终端 WO2012092711A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/CN2011/070057 WO2012092711A1 (zh) 2011-01-06 2011-01-06 配置无线局域网数字证书的方法和移动终端

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2011/070057 WO2012092711A1 (zh) 2011-01-06 2011-01-06 配置无线局域网数字证书的方法和移动终端

Publications (1)

Publication Number Publication Date
WO2012092711A1 true WO2012092711A1 (zh) 2012-07-12

Family

ID=46457181

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2011/070057 WO2012092711A1 (zh) 2011-01-06 2011-01-06 配置无线局域网数字证书的方法和移动终端

Country Status (1)

Country Link
WO (1) WO2012092711A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104469739A (zh) * 2014-12-31 2015-03-25 北京大唐智能卡技术有限公司 一种写卡方法和客户端设备
CN110022552A (zh) * 2018-01-08 2019-07-16 中国移动通信有限公司研究院 用户身份识别模块数据写入方法、设备、平台及存储介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030228866A1 (en) * 2002-05-24 2003-12-11 Farhad Pezeshki Mobile terminal system
CN101212291A (zh) * 2006-12-28 2008-07-02 中国移动通信集团公司 数字证书分发方法及服务器
CN101350985A (zh) * 2007-07-18 2009-01-21 中兴通讯股份有限公司 一种备份sim卡信息的方法、移动终端及系统
CN101621803A (zh) * 2009-08-11 2010-01-06 中兴通讯股份有限公司 无线局域网鉴别和保密基础结构证书的管理方法及装置
CN101800984A (zh) * 2010-01-14 2010-08-11 宇龙计算机通信科技(深圳)有限公司 获取wapi证书的方法、服务器端及wapi认证系统

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030228866A1 (en) * 2002-05-24 2003-12-11 Farhad Pezeshki Mobile terminal system
CN101212291A (zh) * 2006-12-28 2008-07-02 中国移动通信集团公司 数字证书分发方法及服务器
CN101350985A (zh) * 2007-07-18 2009-01-21 中兴通讯股份有限公司 一种备份sim卡信息的方法、移动终端及系统
CN101621803A (zh) * 2009-08-11 2010-01-06 中兴通讯股份有限公司 无线局域网鉴别和保密基础结构证书的管理方法及装置
CN101800984A (zh) * 2010-01-14 2010-08-11 宇龙计算机通信科技(深圳)有限公司 获取wapi证书的方法、服务器端及wapi认证系统

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104469739A (zh) * 2014-12-31 2015-03-25 北京大唐智能卡技术有限公司 一种写卡方法和客户端设备
CN104469739B (zh) * 2014-12-31 2019-01-11 北京大唐智能卡技术有限公司 一种写卡方法和客户端设备
CN110022552A (zh) * 2018-01-08 2019-07-16 中国移动通信有限公司研究院 用户身份识别模块数据写入方法、设备、平台及存储介质

Similar Documents

Publication Publication Date Title
US10985926B2 (en) Managing embedded universal integrated circuit card (eUICC) provisioning with multiple certificate issuers (CIs)
US9917698B2 (en) Management of certificates for mobile devices
US10574465B2 (en) Electronic subscriber identity module (eSIM) eligibility checking
WO2018076711A1 (zh) 一种简档下载方法及设备
US10141966B2 (en) Update of a trusted name list
CA2721890C (en) Method of securely transferring services between mobile devices
WO2021098140A1 (zh) 区块链网络部署方法、电子装置及计算机可读存储介质
US11533160B2 (en) Embedded universal integrated circuit card (eUICC) profile content management
CN103716795B (zh) 一种无线网络安全接入方法、装置和系统
CN101232372B (zh) 认证方法、认证系统和认证装置
TW201909614A (zh) 入網認證方法、裝置及系統
CN109842862A (zh) 在车辆中建立安全短程无线通信连接
US20110154041A1 (en) Method to securely transfer user encryption keys and services between mobile devices
CN106060303A (zh) 通信装置及其控制方法
WO2014048130A1 (zh) 保持客户识别模块卡待机的方法和终端设备
WO2018000834A1 (zh) 一种wifi热点信息修改方法及装置
US20190007835A1 (en) Profile installation based on privilege level
US20190036727A1 (en) System And Method For Coupling A Digital Appliance To A Monitoring Service
WO2018233726A1 (zh) 网络切片的认证方法及相应装置、系统和介质
CN103248655A (zh) 名片信息更新的方法和装置
EP3541106A1 (en) Methods and apparatus for euicc certificate management
WO2010127545A1 (zh) 一种用户证书的管理及使用方法及移动终端
WO2012092711A1 (zh) 配置无线局域网数字证书的方法和移动终端
JP5388088B2 (ja) 通信端末装置、管理装置、通信方法、管理方法及びコンピュータプログラム。
WO2012139463A1 (zh) 终端设备的初始化方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11855123

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 11855123

Country of ref document: EP

Kind code of ref document: A1