WO2013174185A1 - 实现虚拟sim卡的方法、系统及相关设备 - Google Patents

实现虚拟sim卡的方法、系统及相关设备 Download PDF

Info

Publication number
WO2013174185A1
WO2013174185A1 PCT/CN2013/074373 CN2013074373W WO2013174185A1 WO 2013174185 A1 WO2013174185 A1 WO 2013174185A1 CN 2013074373 W CN2013074373 W CN 2013074373W WO 2013174185 A1 WO2013174185 A1 WO 2013174185A1
Authority
WO
WIPO (PCT)
Prior art keywords
mobile terminal
cloud server
authentication
communication network
access
Prior art date
Application number
PCT/CN2013/074373
Other languages
English (en)
French (fr)
Inventor
安璐
徐旻尧
赖敏
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Priority to US14/402,772 priority Critical patent/US20150172922A1/en
Priority to EP13793480.8A priority patent/EP2854433B1/en
Publication of WO2013174185A1 publication Critical patent/WO2013174185A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0884Network architectures or network communication protocols for network security for authentication of entities by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/18Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
    • H04W8/183Processing at user equipment or user record carrier

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a method, system, and related device for implementing a virtual SIM card.
  • SIM Subscriber Identity Module
  • the authentication module is stored in the SIM card.
  • the mobile terminal performs network access or telecommunication service, the user identity is authenticated by the key and algorithm in the SIM card to complete the voice and voice.
  • the SIM card is installed in a separate card slot designed on the mobile terminal, and the connection with the card slot on the mobile terminal is a mechanical connector; further, the SIM card is specially made for different operators, and its production design and manufacture It can also be done by different vendors.
  • defects which may include: designing a SIM card slot on the mobile terminal, which increases the cost and thickens the mobile terminal, and the requirement for the high-end model to pursue a thin and light appearance will inevitably bring Fatal and bruised;
  • the mechanical connector between the SIM card and the card slot may also cause the card slot to be damaged, causing unnecessary loss to the user;
  • the SIM card stores a large amount of information of the user, but since different manufacturers can manufacture and manufacture the SIM card, it is possible to bring the opportunity for the criminal to clone the SIM card, causing loss to the user; after the user purchases the mobile terminal, if the user If you want to buy a SIM card, you must first decide which carrier you plan to enter the network, and then you can go to the designated outlet of the carrier to make a purchase. After you purchase the mobile terminal, you can take it home and choose the operator to enter the network. If the user wants to change the number, he must re-purchase the new SIM card, which is not only a troublesome thing for the user, but also a waste of resources.
  • the present invention aims to provide a method, system and phase for implementing a virtual SIM card.
  • the device is used to solve various defects caused by the physical SIM card existing in the existing card-separated mobile terminal.
  • the present invention provides a method for implementing a virtual SIM card, including: when a mobile terminal requests access to a communication network, connecting to a cloud server through a wireless network; and when the mobile terminal receives an authentication request sent by the communication network, Requesting the cloud server to perform an authentication calculation and feeding back the calculated authentication result to the mobile terminal; the mobile terminal sends the received authentication result to the communication network.
  • the method further includes: the communication network performs authentication according to the authentication result received from the mobile terminal, and the authentication passes, allowing the mobile terminal to access, otherwise the access to the communication network is not allowed.
  • the step of connecting to the cloud server by using the wireless network specifically includes: the cloud server verifies the legality of the mobile terminal, and performs normal connection after the verification is passed, otherwise the cloud server is not allowed to access.
  • the step of legality verification specifically includes: sending a new value obtained by the mobile terminal to the user name and password used for connecting to the preset connection cloud server according to a predetermined algorithm, and sending the new value to the cloud through the wireless network.
  • the cloud server uses the same predetermined algorithm to decrypt the received new value, and compares the decrypted user name and password with the user name and password corresponding to the mobile terminal pre-stored by the cloud server. The same is verified.
  • the step of performing the authentication calculation by the cloud server comprises: sending, by the mobile terminal, the random number to the cloud server, the cloud The server calculates the random number by using a pre-stored algorithm and a key for authentication, and obtains a corresponding response number, and feeds the response number to the mobile terminal.
  • the step of performing authentication by the communication network specifically includes: When the mobile terminal sends the response number to the communication network, the communication network compares the received response number with the pre-stored response number, and the same authentication passes, otherwise the access is not allowed; wherein, the pre-stored The number of responses corresponds to the random number in the authentication request.
  • the present invention further provides a system for implementing a virtual SIM card, comprising: a mobile terminal and a cloud server, wherein the mobile terminal comprises: a cloud interface module and a sending module, and a cloud interface module, configured to, when requesting access to the communication network, Connecting to the cloud server through a wireless network; and after receiving the authentication request sent by the communication network, requesting the cloud server to perform an authentication calculation; the cloud server is configured to perform an authentication calculation and the calculated The weight result is fed back to the mobile terminal; and the sending module is configured to send the authentication result received by the mobile terminal to the communication network.
  • the mobile terminal comprises: a cloud interface module and a sending module, and a cloud interface module, configured to, when requesting access to the communication network, Connecting to the cloud server through a wireless network; and after receiving the authentication request sent by the communication network, requesting the cloud server to perform an authentication calculation; the cloud server is configured to perform an authentication calculation and the calculated The weight result is fed back to the mobile terminal; and the sending module is configured to send the authentication result
  • the system further includes: an authentication module disposed in the communication network, configured to perform authentication according to the authentication result received from the mobile terminal, and the authentication is passed to allow the mobile terminal to access, otherwise the system does not allow The mobile terminal accesses the communication network.
  • the present invention further provides a mobile terminal, comprising: a cloud interface module, configured to connect to a cloud server through a wireless network when requesting access to a communication network; and after receiving an authentication request sent by the communication network, requesting The cloud server performs authentication calculation and feeds back the authentication result.
  • the sending module is configured to send the authentication result received by the mobile terminal from the cloud server to the communication network.
  • the sending module is further configured to calculate, according to a predetermined algorithm, a pre-set username and password used by the mobile terminal to connect to the cloud server. A new value, and the new value is sent to the cloud server over the wireless network.
  • the invention further provides a cloud server, comprising: an authentication calculation module, configured to perform an authentication calculation according to a request of the mobile terminal; and a sending module, configured to feed back the calculated authentication result to the mobile terminal.
  • the cloud server further includes: a verification module, configured to verify the legality of the mobile terminal, and perform normal connection after the verification is passed, otherwise the mobile terminal is not allowed to access the cloud server.
  • the verification module is further configured to: when the cloud server receives the new value calculated by the mobile terminal for using the user name and password used for connecting the preset cloud server according to a predetermined algorithm, using the same The predetermined algorithm decrypts the received new value, compares the user name and password obtained by the decryption with the user name and password corresponding to the mobile terminal pre-stored by the cloud server, and the same is passed.
  • the beneficial effects of the present invention are as follows: The mobile terminal implementing the virtual SIM through the cloud service inherits the security of the physical SIM card, not only reduces the cost of producing and installing the SIM card slot, but also makes the mobile terminal thinner and lighter. More portable direction. Other features and advantages of the invention will be set forth in the description in the description which follows.
  • ⁇ RTI 1 is a schematic structural diagram of a method according to an embodiment of the present invention
  • FIG. 2 is a schematic structural diagram of a system according to an embodiment of the present invention
  • FIG. 3 is a schematic structural diagram of a mobile terminal according to an embodiment of the present invention
  • FIG. 1 is a schematic flowchart of a method according to an embodiment of the present invention, which may specifically include the following steps: Step 101: When a mobile terminal initiates a service, including a mobile terminal power on, registration, call setup attempt, location update, and Requesting access to the communication network for activation, deactivation, registration or deletion of supplementary services; Step 102: The mobile terminal connects to the cloud server through the wireless network. Specifically, a set of algorithms is designed in advance in the mobile terminal, and the predetermined algorithm is used to calculate the user name and password of the mobile terminal to obtain a new value.
  • Step 103 After the mobile terminal initiates an access request to the communication network, the communication network passes The control channel sends a random number to the mobile terminal.
  • Step 104 The mobile terminal sends an authentication request to the cloud server.
  • the mobile terminal may Send random numbers received from the communication network to the cloud
  • the cloud server calculates the random number by using a pre-stored algorithm and a key for authentication, and calculates a response number.
  • Step 105 The cloud server sends the authentication to the mobile terminal.
  • the cloud server sends the calculated response number to the mobile terminal.
  • Step 106 The mobile terminal sends an authentication result to the network, that is, the mobile terminal sends the response number fed back by the cloud server to the communication network.
  • Step 107 The communication network compares the received response number with the number of pre-stored responses (the number of responses corresponding to the random number in the previously sent authentication request), and if the comparison result is the same, the mobile terminal is allowed to access. Otherwise, it is an illegal customer, and the communication network refuses to serve the mobile terminal; this is because the wireless network sends to the mobile terminal and the mobile terminal actually receives the same random number, and uses the same key and the same algorithm. Therefore the resulting response number should be the same.
  • FIG. 2 As shown in FIG. 2, FIG.
  • FIG. 2 is a schematic structural diagram of a system according to an embodiment of the present invention, which may specifically include: a mobile terminal and a cloud server, where the mobile terminal includes: a cloud interface module and a sending module, and a cloud interface module, configured to When requesting access to the communication network, the cloud server is connected through the wireless network; and after receiving the authentication request sent by the communication network, requesting the cloud server to perform authentication calculation; the cloud server is set to perform authentication The weight calculation calculates and returns the calculated authentication result to the mobile terminal; and the sending module is configured to send the authentication result received by the mobile terminal to the communication network.
  • the mobile terminal includes: a cloud interface module and a sending module, and a cloud interface module, configured to When requesting access to the communication network, the cloud server is connected through the wireless network; and after receiving the authentication request sent by the communication network, requesting the cloud server to perform authentication calculation; the cloud server is set to perform authentication The weight calculation calculates and returns the calculated authentication result to the mobile terminal; and the sending module is configured to send the authentication result received by
  • the system may further include: an authentication module disposed in the communication network, configured to perform authentication according to an authentication result received from the mobile terminal, and authenticate the passage to allow the mobile terminal Access, otherwise the mobile terminal is not allowed to access the communication network.
  • an authentication module disposed in the communication network, configured to perform authentication according to an authentication result received from the mobile terminal, and authenticate the passage to allow the mobile terminal Access, otherwise the mobile terminal is not allowed to access the communication network.
  • FIG. 3 is a schematic structural diagram of a mobile terminal according to an embodiment of the present invention, which may specifically include: a cloud interface module, configured to connect to a cloud server through a wireless network when requesting access to a communication network; and receive After the authentication request sent by the communication network, requesting the cloud server to perform an authentication calculation and feeding back an authentication result; the sending module is configured to send the authentication result received by the mobile terminal from the cloud server to the The communication network.
  • the sending module further needs to calculate a new value for the preset user name and password used by the mobile terminal to connect to the cloud server according to a predetermined algorithm, and This new value is sent to the cloud server over the wireless network.
  • FIG. 4 FIG.
  • FIG. 4 is a schematic structural diagram of a cloud server according to an embodiment of the present invention, which may further include: an authentication calculation module, configured to perform an authentication calculation according to a request of a mobile terminal; and a sending module configured to calculate The authentication result is fed back to the mobile terminal.
  • the cloud server may further include: a verification module, configured to verify the legality of the mobile terminal, and perform normal connection after the verification is passed, otherwise the mobile terminal is not allowed to access the cloud server. Specifically, when the cloud server receives the new value calculated by the mobile terminal for using the user name and password used for connecting the preset cloud server according to a predetermined algorithm, the verification module adopts the same predetermined algorithm pair.
  • the embodiments of the present invention provide a method, a system, and a related device for implementing a virtual SIM card.
  • the mobile terminal that implements the virtual SIM through the cloud service has the following features: 1.
  • the mobile terminal is a terminal, and the SIM card slot is not designed, and the SIM card is not inserted; thus, since the mobile terminal does not design the SIM card slot, the cost is reduced, and the terminal is reduced to a lighter and thinner design, and The user can select the operator to access the network from the Internet, and does not need to go to the operator's branch to purchase the SIM card.
  • the authentication module is stored in the cloud server, and the authentication operation is performed on the cloud server. That is, when the voice or data service is performed, after the service is initiated, the cloud server is connected through the wireless network and the user name and password are used. When the name and password are sent to the cloud server, the encryption algorithm is used to ensure the security of the user.
  • the communication network requests authentication from the mobile terminal, the mobile terminal sends the authentication request data to the cloud server, and requests the authentication result to move. The terminal then sends the authentication result data to the communication network to complete the authentication process.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Databases & Information Systems (AREA)
  • Telephonic Communication Services (AREA)
  • Telephone Function (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明公开了一种实现虚拟SIM卡的方法、系统及相关设备,其中方法包括:当移动终端请求接入通信网络时,通过无线网络连接云服务端;当该移动终端接收到该通信网络发来的鉴权请求后,请求该云服务端进行鉴权计算并将计算得到的鉴权结果反馈给该移动终端;该移动终端将接收到的鉴权结果发送给该通信网络;本发明通过云服务实现虚拟SIM的移动终端,在继承了实体SIM卡安全性的基础上,不仅降低生产安装SIM卡卡槽的成本,也可使移动终端向更轻薄,更便携方向迈进。

Description

实现虚拟 SIM卡的方法、 系统及相关设备 技术领域 本发明涉及通信技术领域, 尤其涉及一种实现虚拟 SIM卡的方法、 系统及相关设 备。 背景技术 市场上使用 SIM (用户身份识别模块) 卡的移动终端分为两种, 一种是机卡一体 式; 另一种是机卡分离式。 对于机卡分离式的移动终端, 鉴权模块保存在 SIM卡中, 移动终端进行网络接入 或电信业务时, 通过 SIM卡中的密钥和算法与运营商网络进行用户身份鉴别, 完成语 音和数据业务; 并且 SIM卡安装在移动终端上设计的单独卡槽内, 与移动终端上卡槽 的连接为机械接插件; 再有, SIM卡是为不同运营商专门制作的, 其生产设计与制造 也可以由不同厂商完成。 对于上述技术方案, 存在的缺陷比较多, 具体可以包括: 在移动终端上设计 SIM卡卡槽, 会增加成本, 而且使移动终端变厚, 对于高端机 型追求轻薄外观的要求, 必然会带来致命硬伤;
SIM卡与卡槽之间的机械接插件, 也有可能会发生卡槽损坏的现象, 给用户带来 不必要的损失;
SIM卡中保存有用户大量信息, 但由于不同的生产厂商可以生产制造 SIM卡, 则 有可能给不法分子带来克隆 SIM卡的机会, 给用户带来损失; 用户在购买移动终端后, 如果用户想购买 SIM卡, 必须先决定自己计划在哪个运 营商入网, 才能去该运营商的指定网点进行购买; 而无法在购买移动终端后, 就可以 拿回家自己在网上选择运营商进行入网,如果用户想更换号码,必须重新购买新的 SIM 卡, 不仅对用户而言是件麻烦的事情, 在资源上也是一种浪费。 发明内容 鉴于上述的分析, 本发明旨在提供一种虚拟 SIM卡的实现方法、 系统及相 关设备, 用以解决现有机卡分离式的移动终端中所存在的由物理 SIM卡带来的多 种缺陷。 本发明提供了一种实现虚拟 SIM卡的方法, 包括: 当移动终端请求接入通信网络时, 通过无线网络连接云服务端; 当该移动终端接收到该通信网络发来的鉴权请求后, 请求该云服务端进行鉴权计 算并将计算得到的鉴权结果反馈给该移动终端; 该移动终端将接收到的鉴权结果发送给该通信网络。 优选地, 上述方法还包括: 该通信网络根据从该移动终端接收到的鉴权结果进行鉴权, 鉴权通过, 允许该移 动终端接入, 否则不允许接入该通信网络。 优选地, 通过无线网络连接云服务端的步骤具体包括: 该云服务端对该移动终端的合法性进行验证, 验证通过后进行正常连接, 否则不 允许接入该云服务端。 优选地, 合法性验证的步骤具体包括: 当该移动终端将其根据预定算法对预设置的连接云服务端时用的用户名及密码进 行计算得到的一个新值, 通过无线网络发送到该云服务端时, 该云服务端采用同样的 预定算法对接收到的新值进行解密, 根据解密得到的用户名及密码与该云服务端预先 存储的该移动终端对应的用户名及密码进行比较, 相同则验证通过。 优选地, 当该通信网络发来的鉴权请求中包含有随机数时, 通过该云服务端进行 鉴权计算的步骤具体包括: 该移动终端将该随机数发送给该云服务端, 该云服务端采用预先存储的鉴权用的 算法以及密钥对该随机数进行计算, 得到相应的响应数, 并将该响应数反馈给该移动 终端。 优选地, 该通信网络进行鉴权的步骤具体包括: 当该移动终端将该响应数发送给该通信网络时, 该通信网络将接收到的响应数与 其预先存储的响应数进行比较, 相同则鉴权通过, 否则不允许接入; 其中, 预先存储 的响应数与鉴权请求中的随机数对应。 本发明还提供了一种实现虚拟 SIM卡的系统,包括:移动终端和云服务端,其中, 移动终端包括: 云接口模块和发送模块, 云接口模块, 设置为在请求接入通信网络时, 通过无线网络连接该云服务端; 并 在接收到该通信网络发来的鉴权请求后, 请求该云服务端进行鉴权计算; 云服务端, 设置为进行鉴权计算并将计算得到的鉴权结果反馈给该移动终端; 发送模块, 设置为将该移动终端接收到的鉴权结果发送给该通信网络。 优选地, 该系统还包括: 设置于该通信网络中的鉴权模块, 设置为根据从该移动 终端接收到的鉴权结果进行鉴权, 鉴权通过, 允许该移动终端接入, 否则不允许该移 动终端接入该通信网络。 本发明又提供了一种移动终端, 包括: 云接口模块, 设置为在请求接入通信网络时, 通过无线网络连接云服务端; 并在 接收到该通信网络发来的鉴权请求后,请求该云服务端进行鉴权计算并反馈鉴权结果; 发送模块, 设置为将该移动终端将从该云服务端接收到的鉴权结果发送给该通信 网络。 优选地, 当该云服务端对该移动终端进行合法性验证时,所述发送模块还设置为, 根据预定算法对预设置的该移动终端连接云服务端时用的用户名及密码进行计算得到 一个新值, 并将该新值通过无线网络发送到该云服务端。 本发明又提供了一种云服务端, 包括: 鉴权计算模块, 设置为根据移动终端的请求进行鉴权计算; 发送模块, 设置为将计算得到的鉴权结果反馈给该移动终端。 优选地, 该云服务端还包括: 验证模块, 设置为对该移动终端的合法性进行验证, 验证通过后进行正常连接, 否则不允许该移动终端接入该云服务端。 优选地, 所述验证模块还设置为, 当该云服务端接收到该移动终端根据预定算法 对预设置的连接云服务端时用的用户名及密码进行计算得到的新值时, 采用同样的预 定算法对接收到的新值进行解密, 根据解密得到的用户名及密码与云服务端预先存储 的该移动终端对应的用户名及密码进行比较, 相同则验证通过。 本发明有益效果如下: 本发明通过云服务实现虚拟 SIM的移动终端,在继承了实体 SIM卡安全性的基础 上, 不仅降低生产安装 SIM卡卡槽的成本, 也可使移动终端向更轻薄, 更便携方向迈 进。 本发明的其他特征和优点将在随后的说明书中阐述, 并且, 部分的从说明书中变 得显而易见, 或者通过实施本发明而了解。 本发明的目的和其他优点可通过在所写的 说明书、 权利要求书、 以及附图中所特别指出的结构来实现和获得。 附图说明 图 1为本发明实施例所述方法的流程示意图; 图 2本发明实施例所述系统的结构示意图; 图 3为本发明实施例所述移动终端的结构示意图; 以及 图 4为本发明实施例所述云服务端的结构示意图。 具体实施方式 下面结合附图来具体描述本发明的优选实施例, 其中, 附图构成本申请一部分, 并与本发明的实施例一起用于阐释本发明的原理。 为了清楚和简化目的, 当其可能使 本发明的主题模糊不清时, 将省略本文所描述的器件中已知功能和结构的详细具体说 明。 首先结合附图 1对本发明实施例所述方法进行详细说明。 如图 1所示, 图 1为本发明实施例所述方法的流程示意图, 具体可以包括如下步 骤: 步骤 101 : 移动终端发起业务时, 包括移动终端开机、 登记、 呼叫建立尝试、 位 置更新以及在补充业务的激活、 去活、 登记或删除等, 请求接入通信网络; 步骤 102: 移动终端通过无线网络连接到云服务端; 具体的说就是, 预先在移动 终端中设计一套算法, 采用该预定算法对该移动终端的用户名和密码进行计算得到一 个新值, 通过无线网络连接到云服务端时, 同时附带计算得到的这个新值; 在云服务 端中, 用同样的预定算法进行解密后, 核对移动终端的身份是否为合法用户, 即将解 密得到的用户名和密码与云服务端之前存储的与该移动终端对应的用户名和密码进行 比较, 如果相同, 则正常连接, 否则不允许接入; 步骤 103 : 在移动终端向通信网络发起接入请求后, 通信网络会通过控制信道给 移动终端发送一个随机数; 步骤 104: 移动终端向云服务端发送鉴权请求; 具体的说就是, 由于移动终端已 经在步骤 102后与云服务端取得连接, 因此本步骤中移动终端可以将从通信网络收到 的随机数发送给云服务端, 云服务端收到随机数后, 采用预先存储的鉴权用的算法以 及密钥对该随机数进行计算, 计算得出一个响应数; 步骤 105 : 云服务端向移动终端发送鉴权结果, 即云服务端将计算得到的响应数 发送给移动终端; 步骤 106: 移动终端向网络发送鉴权结果, 即移动终端将云服务端反馈的响应数 发送给通信网络。 步骤 107: 通信网络将收到响应数与其中预先存储的响应数 (该响应数与之前发 送的鉴权请求中的随机数对应) 进行比较, 比较的结果如果相同, 就允许移动终端接 入, 否则为非法客户, 通信网络拒绝为此移动终端服务; 这是因为, 无线网络发给移 动终端的和移动终端实际接收到的应该是同一随机数, 并且使用的是同样的密钥和同 一算法, 因此结果响应数应该是相同的。 接下来, 结合附图 2对本发明实施例所述系统进行详细说明。 如图 2所示, 图 2为本发明实施例所述系统的结构示意图, 具体可以包括: 移动终端和云服务端, 其中, 移动终端包括: 云接口模块和发送模块, 云接口模块, 设置为在请求接入通信网络时, 通过无线网络连接该云服务端; 并 在接收到该通信网络发来的鉴权请求后, 请求该云服务端进行鉴权计算; 云服务端, 设置为进行鉴权计算并将计算得到的鉴权结果反馈给该移动终端; 发送模块, 设置为将该移动终端接收到的鉴权结果发送给该通信网络。 作为本发明的优先实施例, 该系统还可以包括: 设置于该通信网络中的鉴权模块, 设置为根据从该移动终端接收到的鉴权结果进行鉴权, 鉴权通过, 允许该移动终端接 入, 否则不允许该移动终端接入该通信网络。 对于移动终端以及云服务端的具体实现, 以下将结合附图 3和附图 4予以详细说 明。 如图 3所示, 图 3为本发明实施例所述移动终端的结构示意图, 具体可以包括: 云接口模块, 设置为在请求接入通信网络时, 通过无线网络连接云服务端; 并在 接收到该通信网络发来的鉴权请求后,请求该云服务端进行鉴权计算并反馈鉴权结果; 发送模块, 设置为将该移动终端将从该云服务端接收到的鉴权结果发送给该通信 网络。 当该云服务端对该移动终端进行合法性验证时, 该发送模块还需要根据预定算法 对预设置的该移动终端连接云服务端时用的用户名及密码进行计算得到一个新值, 并 将该新值通过无线网络发送到该云服务端。 如图 4所示, 图 4为本发明实施例所述云服务端的结构示意图, 具体可以包括: 鉴权计算模块, 设置为根据移动终端的请求进行鉴权计算; 发送模块, 设置为将计算得到的鉴权结果反馈给该移动终端。 作为本发明的优先实施例, 该云服务端还可以包括: 验证模块, 设置为对该移动终端的合法性进行验证, 验证通过后进行正常连接, 否则不允许该移动终端接入该云服务端; 具体的说就是, 当该云服务端接收到该移动 终端根据预定算法对预设置的连接云服务端时用的用户名及密码进行计算得到的新值 时, 验证模块采用同样的预定算法对接收到的新值进行解密, 根据解密得到的用户名 及密码与云服务端预先存储的该移动终端对应的用户名及密码进行比较, 相同则验证 通过。 综上所述, 本发明实施例提供了一种实现虚拟 SIM卡的方法、 系统及相关设备, 通过云服务实现虚拟 SIM的移动终端, 具有以下特点: 1、 移动终端为痩终端, 不设计 SIM卡卡槽, 不用插入 SIM卡; 这样由于移动终 端不设计 SIM卡卡槽, 就会减少成本, 对终端向更轻更薄设计减少了诸多阻碍, 而且 用户可以自己从网上选择运营商入网, 不用单独去运营商营业网点购买 SIM卡。
2、鉴权模块保存在云服务端中, 鉴权操作在云服务端上进行, 即在进行语音或数 据业务时, 发起业务后, 先通过无线网络, 利用用户名和密码连接云服务端, 用户名 和密码发送给云服务端时, 采用加密算法, 保证用户的安全性, 待通信网络向移动终 端要求鉴权时, 移动终端再将鉴权请求数据发给云服务端, 同时请求鉴权结果, 移动 终端再将鉴权结果数据发给通信网络, 完成鉴权过程。 以上所述,仅为本发明较佳的具体实施方式,但本发明的保护范围并不局限于此, 任何熟悉本技术领域的技术人员在本发明揭露的技术范围内, 可轻易想到的变化或替 换, 都应涵盖在本发明的保护范围之内。 因此, 本发明的保护范围应该以权利要求书 的保护范围为准。

Claims

权 利 要 求 书 、 一种实现虚拟 SIM卡的方法, 包括: 当移动终端请求接入通信网络时, 通过无线网络连接到云服务端; 当该移动终端接收到该通信网络发来的鉴权请求后, 请求该云服务端进行 鉴权计算并将计算得到的鉴权结果反馈给该移动终端;
该移动终端将接收到的鉴权结果发送给该通信网络。 、 根据权利要求 1所述的方法, 其中, 还包括:
该通信网络根据从该移动终端接收到的鉴权结果进行鉴权,如果鉴权通过, 允许该移动终端接入, 否则不允许接入该通信网络。 、 根据权利要求 1或 2所述的方法, 其中, 通过无线网络连接到云服务端的步骤 具体包括:
该云服务端对该移动终端的合法性进行验证, 验证通过后进行正常连接, 否则不允许接入该云服务端。 、 根据权利要求 3所述的方法, 其中, 合法性验证的步骤具体包括:
当该移动终端将其根据预定算法对预设置的连接云服务端时用的用户名及 密码进行计算得到的一个新值, 通过无线网络发送到该云服务端时, 该云服务 端采用同样的预定算法对接收到的新值进行解密, 根据解密得到的用户名及密 码与该云服务端预先存储的该移动终端对应的用户名及密码进行比较, 相同则 验证通过。 、 根据权利要求 2所述的方法, 其中, 当该通信网络发来的鉴权请求中包含有随 机数时, 通过该云服务端进行鉴权计算的步骤具体包括:
该移动终端将该随机数发送给该云服务端, 该云服务端采用预先存储的鉴 权用的算法以及密钥对该随机数进行计算, 得到相应的响应数, 并将该响应数 反馈给该移动终端。 、 根据权利要求 5所述的方法, 其中, 该通信网络进行鉴权的步骤具体包括: 当该移动终端将该响应数发送给该通信网络时, 该通信网络将接收到的响 应数与其预先存储的响应数进行比较, 相同则鉴权通过, 否则不允许接入; 其 中, 预先存储的响应数与鉴权请求中的随机数对应。 、 一种实现虚拟 SIM卡的系统, 包括: 移动终端和云服务端, 其中, 移动终端包 括: 云接口模块和发送模块,
云接口模块, 设置为在请求接入通信网络时, 通过无线网络连接到该云服 务端; 并在接收到该通信网络发来的鉴权请求后, 请求该云服务端进行鉴权计 算;
云服务端, 设置为进行鉴权计算并将计算得到的鉴权结果反馈给该移动终
W;
发送模块, 设置为将该移动终端接收到的鉴权结果发送给该通信网络。 、 根据权利要求 7所述的系统, 其中, 该系统还包括: 设置于该通信网络中的鉴 权模块, 设置为根据从该移动终端接收到的鉴权结果进行鉴权, 鉴权通过, 允 许该移动终端接入, 否则不允许该移动终端接入该通信网络。 种移动终端, 包括:
云接口模块, 设置为在请求接入通信网络时, 通过无线网络连接到云服务 端; 并在接收到该通信网络发来的鉴权请求后, 请求该云服务端进行鉴权计算 并反馈鉴权结果;
发送模块, 设置为将该移动终端将从该云服务端接收到的鉴权结果发送给 该通信网络。 0、 根据权利要求 9所述的移动终端, 其中, 当该云服务端对该移动终端进行合法 性验证时, 所述发送模块设置为, 根据预定算法对预设置的该移动终端连接云 服务端时用的用户名及密码进行计算得到一个新值, 并将该新值通过无线网络 发送到该云服务端。 1 种云服务端, 包括:
鉴权计算模块, 设置为根据移动终端的请求进行鉴权计算;
发送模块, 设置为将计算得到的鉴权结果反馈给该移动终端。 根据权利要求 11所述的云服务端, 其中, 该云服务端还包括: 验证模块, 设置为对该移动终端的合法性进行验证, 验证通过后进行正常 连接, 否则不允许该移动终端接入该云服务端。 根据权利要求 12所述的云服务端, 其中, 所述验证模块还设置为, 当该云服务 端接收到该移动终端根据预定算法对预设置的连接云服务端时用的用户名及密 码进行计算得到的新值时, 采用同样的预定算法对接收到的新值进行解密, 根 据解密得到的用户名及密码与云服务端预先存储的该移动终端对应的用户名及 密码进行比较, 相同则验证通过。
PCT/CN2013/074373 2012-05-22 2013-04-18 实现虚拟sim卡的方法、系统及相关设备 WO2013174185A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
US14/402,772 US20150172922A1 (en) 2012-05-22 2013-04-18 Method, system and relevant device for realizing virtual sim card
EP13793480.8A EP2854433B1 (en) 2012-05-22 2013-04-18 Method, system and related device for realizing virtual sim card

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201210159453.X 2012-05-22
CN201210159453.XA CN103428696B (zh) 2012-05-22 2012-05-22 实现虚拟sim卡的方法、系统及相关设备

Publications (1)

Publication Number Publication Date
WO2013174185A1 true WO2013174185A1 (zh) 2013-11-28

Family

ID=49623084

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/074373 WO2013174185A1 (zh) 2012-05-22 2013-04-18 实现虚拟sim卡的方法、系统及相关设备

Country Status (4)

Country Link
US (1) US20150172922A1 (zh)
EP (1) EP2854433B1 (zh)
CN (1) CN103428696B (zh)
WO (1) WO2013174185A1 (zh)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104902475A (zh) * 2015-04-24 2015-09-09 梁融凌 一种远端sim卡转接装置及其鉴权方法
CN105873018A (zh) * 2016-05-31 2016-08-17 宇龙计算机通信科技(深圳)有限公司 一种虚拟sim卡信息存储方法及系统
WO2017028872A1 (en) 2015-08-17 2017-02-23 Giesecke & Devrient Gmbh A cloud-based method and system for enhancing endurance of euicc by organizing non-volatile memory updates
EP3177054A4 (en) * 2014-07-28 2018-03-14 Baicells Technologies Co. Ltd. Method and device for terminal authentication for use in mobile communication system
JP2018513462A (ja) * 2015-03-06 2018-05-24 クアルコム,インコーポレイテッド 既存の資格証明を使用したセルラーネットワークに対するスポンサー付き接続性

Families Citing this family (27)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103906030A (zh) * 2014-04-29 2014-07-02 陈硕 基于云端服务器的远程接入蜂窝移动网络系统及处理方法
CN104010307A (zh) * 2014-06-04 2014-08-27 张才尤 一种利用互联网实现远程usim卡的鉴权方法
CN104378752B (zh) * 2014-06-30 2019-04-02 天津泰岳小漫科技有限公司 一种网络漫游系统及网络漫游方法
CN104469766A (zh) * 2014-07-28 2015-03-25 北京佰才邦技术有限公司 用于移动通信系统中的终端认证方法和装置
CN104185171B (zh) * 2014-08-29 2017-09-29 广东欧珀移动通信有限公司 一种虚拟sim卡实现的方法与装置
CN104159214B (zh) * 2014-08-29 2019-11-05 高新兴物联科技有限公司 虚拟sim卡的管理方法、系统和装置
CN104469771B (zh) * 2014-12-12 2018-04-17 深圳市宜联畅游技术有限公司 接入蜂窝移动网络系统的数据传输方法及相关设备
CN105813072B (zh) * 2014-12-29 2019-10-18 中国移动通信集团公司 一种终端鉴权方法、系统及云端服务器
CN105813070B (zh) * 2014-12-29 2019-08-30 中国移动通信集团公司 一种车载终端通过移动终端进行通信的方法及装置
CN106304277B (zh) 2015-05-12 2020-12-04 中兴通讯股份有限公司 一种实现网络接入的方法和终端
CN104902463B (zh) * 2015-05-22 2020-01-07 努比亚技术有限公司 移动终端及其虚拟卡终端的多卡管理方法和服务器
CN105263140A (zh) * 2015-07-10 2016-01-20 苏州蜗牛数字科技股份有限公司 一种实现sim卡远程鉴权的系统与方法
CN106375995A (zh) * 2015-07-22 2017-02-01 深圳市中兴微电子技术有限公司 一种信息处理方法、系统及车载通信装置
CN105611485A (zh) * 2015-07-27 2016-05-25 宇龙计算机通信科技(深圳)有限公司 虚拟sim卡的共享方法、共享装置和共享系统
CN106454820A (zh) * 2015-08-12 2017-02-22 深圳富泰宏精密工业有限公司 实现云端身份认证的网络系统、方法及移动设备
CN105338516A (zh) * 2015-09-23 2016-02-17 宇龙计算机通信科技(深圳)有限公司 一种移动通信网络接入方法及装置
US10798570B2 (en) 2015-09-25 2020-10-06 Gunagdong Oppo Mobile Telecommunications Corp. Ltd. Terminal authentication method and device
CN105188049B (zh) * 2015-09-30 2017-12-12 宇龙计算机通信科技(深圳)有限公司 一种虚拟sim卡服务授权方法、终端、服务器以及系统
CN105554738A (zh) * 2015-12-09 2016-05-04 惠州Tcl移动通信有限公司 虚拟sim卡的多终端映射系统、方法及终端设备
CN105578452A (zh) * 2015-12-31 2016-05-11 集怡嘉数码科技(深圳)有限公司 一种虚拟卡的实现方法、装置和移动终端
CN106131814A (zh) * 2016-06-15 2016-11-16 天翼电信终端有限公司 一种使用虚拟sim卡的方法及终端
US10536436B1 (en) 2016-06-24 2020-01-14 Amazon Technologies, Inc. Client authentication utilizing shared secrets to encrypt one-time passwords
CN106162606A (zh) * 2016-07-26 2016-11-23 努比亚技术有限公司 一种网络切换方法和移动终端
WO2018219490A1 (en) 2017-06-02 2018-12-06 Giesecke+Devrient Mobile Security Gmbh Method for preparing instructions to be executed by a subscriber identity module, subscriber identity module and service providing system
CN107257555A (zh) * 2017-07-26 2017-10-17 北京小米移动软件有限公司 网络接入方法及装置
CN108769978A (zh) * 2018-04-13 2018-11-06 深圳市优克联新技术有限公司 Sim卡管理服务器、绑定装置、管理方法、绑定方法及系统
CN112511654B (zh) * 2021-02-04 2022-02-22 上海途鸽数据科技有限公司 云通信终端的联网处理与控制方法、终端及平台

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102118447A (zh) * 2011-03-16 2011-07-06 宇龙计算机通信科技(深圳)有限公司 资源管理的方法及移动终端
US20110269423A1 (en) * 2010-05-03 2011-11-03 Schell Stephan V Wireless network authentication apparatus and methods
CN102307349A (zh) * 2011-08-16 2012-01-04 宇龙计算机通信科技(深圳)有限公司 无线网络的接入方法、终端和服务器
CN102571792A (zh) * 2012-01-06 2012-07-11 西安润基投资控股有限公司 智能移动无线终端访问云服务器的身份认证方法
CN102752269A (zh) * 2011-04-21 2012-10-24 中国移动通信集团广东有限公司 基于云计算的身份认证的方法、系统及云端服务器

Family Cites Families (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7489918B2 (en) * 2003-05-09 2009-02-10 Intel Corporation System and method for transferring wireless network access passwords
US6628934B2 (en) * 2001-07-12 2003-09-30 Earthlink, Inc. Systems and methods for automatically provisioning wireless services on a wireless device
JP2004342088A (ja) * 2003-04-21 2004-12-02 Sony Corp 端末機器認証システム、端末機器、第1の振り分けサーバ、振り分けシステム、サービスサーバ、第2の振り分けサーバ、端末機器方法、第1の振り分け方法、振り分け方法、サービス提供方法、サービスサーバ方法、第1の振り分け方法、第2の振り分け方法、端末機器プログラム、第1の振り分けプログラム、振り分けプログラム、サービスサーバプログラム、第2の振り分けプログラム、及び記憶媒体
GB0420409D0 (en) * 2004-09-14 2004-10-20 Waterleaf Ltd Online commercial transaction system and method of operation thereof
US8112790B2 (en) * 2005-06-30 2012-02-07 Alcatel Lucent Methods and apparatus for authenticating a remote service to another service on behalf of a user
US8200736B2 (en) * 2007-12-24 2012-06-12 Qualcomm Incorporated Virtual SIM card for mobile handsets
CN101222711B (zh) * 2008-02-02 2010-11-10 代邦(江西)制卡有限公司 支持虚拟sim卡的移动通讯网络系统及其认证方法
WO2009102247A1 (en) * 2008-02-15 2009-08-20 Telefonaktiebolaget Lm Ericsson (Publ) Application specific master key selection in evolved networks
US8881235B2 (en) * 2008-12-15 2014-11-04 Koninklijke Kpn N.V. Service-based authentication to a network
EP2211497A1 (fr) * 2009-01-26 2010-07-28 Gemalto SA Procédé d'établissement de communication sécurisée sans partage d'information préalable
CN102098317B (zh) * 2011-03-22 2013-12-18 浙江中控技术股份有限公司 一种应用于云系统的数据传输方法及系统

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20110269423A1 (en) * 2010-05-03 2011-11-03 Schell Stephan V Wireless network authentication apparatus and methods
CN102118447A (zh) * 2011-03-16 2011-07-06 宇龙计算机通信科技(深圳)有限公司 资源管理的方法及移动终端
CN102752269A (zh) * 2011-04-21 2012-10-24 中国移动通信集团广东有限公司 基于云计算的身份认证的方法、系统及云端服务器
CN102307349A (zh) * 2011-08-16 2012-01-04 宇龙计算机通信科技(深圳)有限公司 无线网络的接入方法、终端和服务器
CN102571792A (zh) * 2012-01-06 2012-07-11 西安润基投资控股有限公司 智能移动无线终端访问云服务器的身份认证方法

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3177054A4 (en) * 2014-07-28 2018-03-14 Baicells Technologies Co. Ltd. Method and device for terminal authentication for use in mobile communication system
US10045213B2 (en) 2014-07-28 2018-08-07 Baicells Technologies Co. Ltd Method and apparatus for authenticating terminal in mobile communications system
JP2018513462A (ja) * 2015-03-06 2018-05-24 クアルコム,インコーポレイテッド 既存の資格証明を使用したセルラーネットワークに対するスポンサー付き接続性
CN104902475A (zh) * 2015-04-24 2015-09-09 梁融凌 一种远端sim卡转接装置及其鉴权方法
CN104902475B (zh) * 2015-04-24 2020-06-02 梁融凌 一种远端sim卡转接装置及其鉴权方法
WO2017028872A1 (en) 2015-08-17 2017-02-23 Giesecke & Devrient Gmbh A cloud-based method and system for enhancing endurance of euicc by organizing non-volatile memory updates
CN105873018A (zh) * 2016-05-31 2016-08-17 宇龙计算机通信科技(深圳)有限公司 一种虚拟sim卡信息存储方法及系统

Also Published As

Publication number Publication date
CN103428696B (zh) 2017-04-19
US20150172922A1 (en) 2015-06-18
EP2854433A4 (en) 2015-06-03
EP2854433A1 (en) 2015-04-01
CN103428696A (zh) 2013-12-04
EP2854433B1 (en) 2018-10-31

Similar Documents

Publication Publication Date Title
WO2013174185A1 (zh) 实现虚拟sim卡的方法、系统及相关设备
EP2255507B1 (en) A system and method for securely issuing subscription credentials to communication devices
CN107079007B (zh) 用于基于证书的认证的方法、装置和计算机可读介质
CN103477666B (zh) 连接移动设备,连接至互联网的车辆以及云服务
JP5922166B2 (ja) アクセス制御クライアントの記憶及び演算に関する方法及び装置
US20170374551A1 (en) Method for connecting network access device to wireless network access point, network access device, and application server
US8516133B2 (en) Method and system for mobile device credentialing
EP1869820B1 (en) System and method for achieving machine authentication without maintaining additional credentials
CN108471610B (zh) 蓝牙连接控制系统
US20100177663A1 (en) Method and Apparatus for Enabling Connectivity in a Communication Network
KR20180053371A (ko) 신원 인증 방법 및 장치
WO2018014760A1 (zh) 图形码信息提供、获取方法、装置及终端
WO2014180198A1 (zh) 终端接入方法、系统、设备和计算机存储介质
WO2011017924A1 (zh) 无线局域网的认证方法、系统、服务器和终端
JP2018517367A (ja) サービスプロバイダ証明書管理
US9444815B2 (en) Method and system for accessing a service
WO2019056971A1 (zh) 一种鉴权方法及设备
CN106790080A (zh) 业务系统和电子凭证系统之间的网络安全通信方法与装置
KR20210006329A (ko) 원격 생체 식별
EP3997851B1 (en) Method, first device, first server, second server and system for accessing a private key
WO2017219976A1 (zh) 一种登录云服务器的方法及装置
WO2011029297A1 (zh) 向机器到机器设备提供机器通信身份模块的系统及方法
WO2012068801A1 (zh) 移动终端的认证方法及移动终端
CN107426724B (zh) 智能家电接入无线网络的方法及系统及终端及认证服务器
JP5650252B2 (ja) 権限発行システム、権限発行サーバ、及び権限発行方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13793480

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 14402772

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 2013793480

Country of ref document: EP