WO2014183526A1 - Identity recognition method, device and system - Google Patents

Identity recognition method, device and system Download PDF

Info

Publication number
WO2014183526A1
WO2014183526A1 PCT/CN2014/075513 CN2014075513W WO2014183526A1 WO 2014183526 A1 WO2014183526 A1 WO 2014183526A1 CN 2014075513 W CN2014075513 W CN 2014075513W WO 2014183526 A1 WO2014183526 A1 WO 2014183526A1
Authority
WO
WIPO (PCT)
Prior art keywords
application
identification information
terminal
terminal identification
application client
Prior art date
Application number
PCT/CN2014/075513
Other languages
French (fr)
Chinese (zh)
Inventor
夏潘斌
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2014183526A1 publication Critical patent/WO2014183526A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/44Program or device authentication

Definitions

  • the present invention relates to the field of communications, and in particular, to a method, device and system for identity recognition. Background technique
  • OpenID is a user-centric open, decentralized digital identity framework.
  • the framework is based on the OpenID service website.
  • the OpenID service website stores a certain The same password corresponding to multiple applications in the terminal device.
  • the user logs in to a website that supports OpenID, he only needs to input the OpenID username and password registered on the OpenID service website, and then the pre-login website will jump to the OpenID service website. After the password is verified by the OpenID service website, it directly returns to the pre-registered website and the login is successful.
  • an OAuth-based method the OAuth allows a user to have a third-party application access information stored by the user on a website without providing a username and password to a third-party application.
  • a third-party application accesses information stored on a website, it must first obtain authorization from the website, obtain an access license, and then exchange the access license for the access pass, and finally access the resource card of the website to present the access pass.
  • the information stored on the website In the above technical scenario, the user only needs to input the username and password of the resource server on the terminal device to achieve the purpose of logging in to the third-party application.
  • the embodiments of the present invention provide a method, an apparatus, and a system for identifying an identity, which are required to memorize a user name and a password when the user logs in to the application on the terminal device, and improve the security of the application on the user to log in to the terminal device.
  • a method for identifying an identity comprising:
  • the terminal middleware acquires the terminal identification information of the terminal device, where the terminal identification information at least includes the first terminal identification information;
  • the method is Also includes:
  • the first request message carries the first application name of the application client, according to the first possible implementation manner
  • the method further includes:
  • the step of opening the first terminal identification information to the application client is performed.
  • the first request message carries the first application name of the application client, according to the first possible implementation manner; After the receiving the first request message sent by the application client, the method further includes:
  • the application first invokes the first terminal identifier information, requesting the user right to open the first terminal identifier information to the application client;
  • the step of opening the first terminal identification information to the application client is performed.
  • the requesting, by the requesting user, the opening of the first terminal identifier information to the application client includes:
  • the method further includes:
  • the indication message that the authentication succeeds is sent to the application client, so that the application client opens the application of the application client according to the first terminal identifier information stored by the application client.
  • the method before the sending, sending the indication message that the authentication succeeds to the application client, the method further includes: Sending a pre-stored indication information of whether a login password is required to log in to the application client to the application client;
  • the indication message that the authentication succeeds is sent to the application client, so that the application client opens the application according to the first terminal identification information stored by the application client and the indication information of whether the login password is required. Client application.
  • the corresponding relationship between the saving the first application name and the first terminal identification information includes:
  • the opening the first terminal identifier information to the application client specifically includes: the encrypted first terminal identifier
  • the information is opened to the application client, so that the application client obtains and stores the encrypted first terminal identifier information, so that the first terminal identifier information stored by the application client is specifically an encrypted first terminal. Identification information.
  • determining, according to the first application name, whether the application is legal or not specifically includes: reading a local database Information
  • the local database information includes the first application name, determining that the application is legal; if the first application name is not included in the local database information, requesting the capability open platform/app store to obtain the first Application name
  • the terminal identifier information specifically includes:
  • the media access control MAC address of the terminal device is the media access control MAC address of the terminal device.
  • a method for identifying an identity comprising:
  • the application client receives an access request message, and the access request message requests to open an application of the application client;
  • the method further includes:
  • the first request message is sent to the terminal middleware, and the first request message requests to acquire the first terminal identifier information;
  • the first request message carries a first application name of the application client, so that the terminal middleware is configured according to the first application name, according to the first possible implementation manner. And determining whether the application is legal, and the first terminal identification information is opened to the application client when the application is legal.
  • the first request message carries the first application name of the application client, so that the terminal middleware is configured according to the first application name, according to the first possible implementation manner. Determining whether the application is legal, and when the application is legal, according to the first application Determining whether the application first invokes the first terminal identification information, and after determining that the application is the first time to invoke the first terminal identification information, requesting the user to authorize opening the first terminal identification information to the application client, After receiving the authorization response that the user returns to the application client to open the first terminal identifier information, the first terminal identifier information is opened to the application client.
  • the application for performing the login authentication according to the stored first terminal identifier information to open the application client includes:
  • the first application name and the stored first terminal identification information are authenticated; if the indication message of successful authentication sent by the terminal middleware is received, the application of the application client is opened.
  • the method further includes:
  • the application for opening the application client includes:
  • the application of the application client is opened according to the stored first terminal identifier information
  • the application of the application client is opened according to the stored first terminal identification information and the input login password.
  • the obtaining, by the third possible implementation manner to the fifth possible implementation manner, the acquiring the first terminal identifier information that is open by the terminal middleware specifically: acquiring the terminal middleware Encrypted first terminal identification information, wherein the encrypted first terminal identification information is generated by the terminal middleware according to the first application name and the first terminal identification information, using an advanced encryption standard AES ;
  • the storing the first terminal identifier information specifically includes:
  • the terminal identifier information specifically includes:
  • the international mobile subscriber identity of the SIM card in the terminal device IMSI is the international mobile subscriber identity of the SIM card in the terminal device IMSI;
  • the media access control MAC address of the terminal device is the media access control MAC address of the terminal device.
  • a terminal middleware in a third aspect, includes an acquiring unit and an opening unit;
  • the acquiring unit is configured to acquire terminal identification information of the terminal device, where the terminal identification information includes at least first terminal identification information;
  • the opening unit is configured to open the first terminal identification information to the application client, so that the application client obtains and stores the first terminal identification information, and after receiving the access request message, according to the The first terminal identification information is used for login authentication.
  • the terminal middleware further includes a receiving unit
  • the receiving unit is configured to: after the acquiring unit acquires the terminal identifier information of the terminal device, the open unit receives the first terminal identifier information to the application client, and receives the application client And sending the first request message, where the first request message requests to acquire the first terminal identifier information.
  • the terminal middleware further includes a determining unit and an executing unit, according to the first possible implementation manner;
  • the first request message carries a first application name of the application client
  • the determining unit is configured to determine, according to the first application name, whether the application is legal after the receiving unit receives the first request message sent by the application client;
  • the executing unit is further configured to: when the application is legal, perform the step of opening the first terminal identification information to an application client.
  • the terminal middleware further includes a determining unit, a requesting unit, a storage unit, and an executing unit, according to the first possible implementation manner;
  • the first request message carries a first application name of the application client
  • the determining unit is configured to determine, according to the first application name, whether the application is legal after the receiving unit receives the first request message sent by the application client;
  • the determining unit is further configured to: determine, according to the first application name, whether the application first invokes the first terminal identification information according to the first application name;
  • the requesting unit is configured to: if the application first invokes the first terminal identification information, request the user to authorize opening the first terminal identification information to the application client;
  • the receiving unit is further configured to receive a response to the user that opens the first terminal identification information to the application client.
  • the storage unit is configured to save a correspondence between the first application name and the first terminal identification information
  • the executing unit is configured to perform the step of opening the first terminal identification information to an application client.
  • the requesting unit requesting the user to authorize the opening of the first terminal identification information to the application client, specifically includes: sending an authentication short message, requesting the user to pass Entering the content of the authentication short message for authorization; or
  • the terminal middleware further includes an checking unit and a sending unit, according to the third possible implementation manner or the fourth possible implementation manner;
  • the receiving unit is further configured to receive a second request message that is sent by the application client to request authentication, where the second request message carries a first application name of the application client and a first terminal that is stored by the application client. Identification information;
  • the checking unit is configured to check whether a correspondence between the first application name and the first terminal identification information stored by the application client is stored;
  • the sending unit is further configured to: if stored, send an indication message that the authentication succeeds to the application client, so that the application client opens the application client according to the first terminal identifier information stored by the application client. application.
  • the sending unit is further configured to send, before the sending, sending the indication message that the authentication succeeds to the application client, the pre-stored indication information of whether the login password is required to log in to the application client;
  • the application client opens the application of the application client according to the first terminal identifier information stored by the application client, and specifically includes:
  • the indication message that the authentication succeeds is sent to the application client, so that the application client opens the application according to the first terminal identification information stored by the application client and the indication information of whether the login password is required. Client application.
  • the terminal middleware further includes a generating unit, according to the third possible implementation manner to the sixth possible implementation manner;
  • the generating unit configured to: after receiving, by the receiving unit, an authorization response that is opened by the user to open the first terminal identifier information to the application client, according to the first application name and the first terminal identifier information, Generating the encrypted first terminal identification information corresponding to the first application name by using the advanced encryption standard AES;
  • the storing, by the storage unit, the corresponding relationship between the first application name and the first terminal identification information includes:
  • the opening, by the open unit, the opening the first terminal identifier information to the application client specifically includes:
  • the determining, by the determining unit, whether the application is legal according to the first application name specifically includes:
  • the local database information includes the first application name, determining that the application is legal; if the first application name is not included in the local database information, requesting the capability open platform/app store to obtain the first Application name
  • the terminal identifier information specifically includes:
  • the media access control MAC address of the terminal device is the media access control MAC address of the terminal device.
  • the fourth aspect provides an application client, where the application client includes a receiving unit and a login authentication unit.
  • the receiving unit is configured to receive an access request message, where the access request message requests to open an application of the application client;
  • the login authentication unit is configured to perform login authentication according to the stored first terminal identifier information to open an application of the application client.
  • the application client further includes a determining unit, a sending unit, an obtaining unit, and a first storage unit;
  • the determining unit is configured to determine, after the receiving unit receives the access request message, whether to store the first terminal identification information of the terminal device;
  • the sending unit is configured to: if the first terminal identifier information of the terminal device is not stored, send a first request message to the terminal middleware, where the first request message requests to acquire the first terminal identifier information;
  • the acquiring unit is configured to acquire the first terminal identifier information that is open by the terminal middleware, and the first storage unit is configured to store the first terminal identifier information.
  • the first request message carries a first application name of the application client, so that the terminal middleware is configured according to the first application, according to the first possible implementation manner. And determining whether the application is legal, and the first terminal identification information is opened to the application client when the application is legal.
  • the first request message carries the first application name of the application client, so that the terminal middleware is configured according to the first application name, according to the first possible implementation manner. Determining whether the application is legal, and determining whether the application first invokes the first terminal identification information according to the first application name, and determining that the application is the first call to the first terminal After the information is identified, the user is requested to open the first terminal identification information to the application client, and after receiving the authorization response returned by the user to open the first terminal identification information to the application client, the first The terminal identification information is sent to the application client.
  • the login authentication unit performs login authentication according to the stored first terminal identifier information, to open the application of the application client, specifically, according to the fourth aspect to the third possible implementation manner.
  • the first application name and the stored first terminal identification information are authenticated; if the indication message of successful authentication sent by the terminal middleware is received, the application of the application client is opened.
  • the application client further includes a second storage unit according to the fourth possible implementation manner;
  • the receiving unit is further configured to receive, by the terminal middleware, indication information about whether a login password is required when logging in to the application;
  • the second storage unit is configured to store the indication information of whether the password is required to be logged in. If the indication message of the authentication success is sent by the terminal middleware, the application of the application client is specifically:
  • the application of the application client is opened according to the stored first terminal identifier information
  • the application of the application client is opened according to the stored first terminal identification information and the input login password.
  • the obtaining, by the acquiring unit, the first terminal identifier information that is open by the terminal middleware, according to the third possible implementation manner to the fifth possible implementation manner specifically includes:
  • the storing, by the storage unit, the first terminal identifier information specifically includes:
  • the terminal identifier information specifically includes:
  • the international mobile subscriber identity of the SIM card in the terminal device IMSI is the international mobile subscriber identity of the SIM card in the terminal device IMSI;
  • the media access control MAC address of the terminal device is the media access control MAC address of the terminal device.
  • a system for identifying an identity the system terminal terminal middleware and an application client;
  • the terminal middleware is configured to acquire terminal identification information of the terminal device, where the terminal identification information includes at least first terminal identification information;
  • the terminal middleware is further configured to: open the first terminal identification information to the application client, so that the application client obtains and stores the first terminal identification information;
  • the application client is configured to receive an access request message, where the access request message requests to open an application of the application client;
  • the application client is further configured to perform login authentication according to the stored first terminal identification information to open an application of the application client.
  • An embodiment of the present invention provides a method, an apparatus, and a system for identifying an identity, where the method includes acquiring, by a terminal middleware, terminal identification information of a terminal device, where the terminal identification information includes at least the first terminal identification information, The first terminal identifier information is opened to the application client. After receiving the access request message, the application client performs login authentication according to the stored first terminal identifier information to open the application of the application client.
  • the method for authenticating the first terminal identification information is used to solve the problem that the user needs to memorize the user name and password when logging in to the application on the terminal device.
  • the first terminal identification information is used as a unique identifier of the application that the user logs in to the terminal device, which improves the security of the application that the user logs in to the terminal device.
  • FIG. 1 is a schematic diagram of an identity recognition method according to an embodiment of the present invention
  • FIG. 3 is still another method for identity recognition according to an embodiment of the present invention.
  • FIG. 4 is still another method for identity recognition according to an embodiment of the present invention.
  • FIG. 5 is still another method for identity recognition according to an embodiment of the present invention.
  • FIG. 6 is a schematic diagram of an authorization interface according to an embodiment of the present invention.
  • FIG. 7 is still another method for identity recognition according to an embodiment of the present invention
  • FIG. 8 is still another method for identity recognition according to an embodiment of the present invention
  • FIG. 9 is a terminal middleware according to an embodiment of the present invention.
  • FIG. 10 is another terminal middleware according to an embodiment of the present invention.
  • FIG. 11 is still another terminal middleware according to an embodiment of the present invention.
  • FIG. 12 is still another terminal middleware according to an embodiment of the present invention.
  • FIG. 13 is still another terminal middleware according to an embodiment of the present invention.
  • FIG. 14 is still another terminal middleware according to an embodiment of the present invention.
  • FIG. 15 is an application client according to an embodiment of the present invention.
  • FIG. 16 is an application client according to an embodiment of the present invention.
  • FIG. 17 is an application client according to an embodiment of the present invention.
  • FIG. 18 is a terminal middleware according to an embodiment of the present invention.
  • FIG. 19 is another terminal middleware according to an embodiment of the present invention.
  • FIG. 20 is still another terminal middleware according to an embodiment of the present invention.
  • FIG. 21 is still another terminal middleware according to an embodiment of the present invention.
  • FIG. 22 is an identification system according to an embodiment of the present invention.
  • An embodiment of the present invention provides a method for identity identification, where the method is applied to a terminal middleware, as shown in FIG. 1 , the method includes:
  • terminal identification information of the terminal device where the terminal identification information includes at least first terminal identification information.
  • the terminal identifier information of the terminal device may be an IMSI (International Mobile Subscriber Identification Number) and/or a terminal design of a SIM (Subscriber Identity Module) card in the terminal device.
  • IMSI International Mobile Subscriber Identification Number
  • SIM Subscriber Identity Module
  • the IMEI International Mobile Equipment Identity
  • MAC Media Access Control address of the terminal device are not specifically limited in this embodiment of the present invention.
  • the terminal identifier information includes at least first terminal identifier information.
  • the terminal middleware may acquire multiple terminal identification information, and the “first” in the first terminal identification information does not have any special meaning, and only refers to the terminal identification information acquired by the terminal middleware. A terminal identification information.
  • the first terminal identifier information is opened to the application client, so that the application client obtains and stores the first terminal identifier information, and after receiving the access request message, according to the first terminal identifier information. Perform login authentication.
  • opening the first terminal identifier information to the application client may be determined by the configuration of the terminal device.
  • the configuration of the first terminal identification information in the following two scenarios:
  • the international mobile subscriber identity code IMSI can be configured as the first terminal identifier information.
  • the international mobile terminal identification code IMEI or the medium access control MAC address may be used as the first terminal identification information.
  • the terminal middleware may open the first terminal identification information to the application client according to the configuration of the terminal device, or the application client may determine when the user triggers the application client.
  • the first request message is sent to the terminal middleware, and the first terminal identifier information is requested to be obtained, so that the terminal middleware opens the first terminal identifier.
  • Information to the application client In this case, the terminal middleware may directly open the first terminal identification information to the application client; or the terminal middleware may determine whether the application is legal, and determine that the application is legal.
  • Opening the first terminal identification information to the application client; or the terminal middleware is configured to open the first terminal identification information to the application client after determining whether the application is legal, determining that the application is legal and authorized by the user end.
  • the embodiment of the present invention does not specifically limit this, and only describes that the terminal middleware opens the first terminal identification information to the application client after acquiring the terminal identification information.
  • the client so that the application client obtains and stores the first terminal identifier information, and after receiving the access request message, may perform login authentication according to the first terminal identifier information. Therefore, the security of the application that the user logs in to the terminal device is improved, and the problem that the user name and password need to be memorized when the user logs in to the application on the terminal device is avoided.
  • the embodiment of the present invention further provides a method for the identity identification, where the method is applied to an application client, as shown in FIG. 2, the method includes:
  • the application client receives an access request message, and the access request message requests to open an application of the application client.
  • the first terminal identifier information may be stored in the application client before receiving the access request message, or the application client may determine, after receiving the access request message, the first terminal identifier of the terminal device not stored. After the information is obtained, the first terminal identifier information is obtained from the terminal middleware, and then stored in the application client, which is not specifically limited in this embodiment of the present invention.
  • the terminal middleware may use the advanced encryption standard AES according to the first application name and the first terminal identification information of the application client. And generating the encrypted first terminal identifier information corresponding to the first application name, so the stored first terminal identifier information may be the encrypted first terminal identifier information, or may be the unencrypted first terminal identifier information.
  • the embodiment of the present invention does not specifically limit this, and only depends on actual conditions.
  • the application for performing the login authentication according to the stored first terminal identifier information to open the application client may include:
  • the application client may receive the indication information of whether the login password is required to log in to the application, and the method for opening the application of the application client may be determined according to the indication information, including:
  • the application of the application client is opened according to the stored first terminal identifier information
  • the application of the application client is opened according to the stored first terminal identification information and the input login password.
  • An embodiment of the present invention provides a method for identity identification, where the method includes: acquiring terminal identification information of a terminal device in a terminal middleware, where the terminal identification information includes at least first terminal identification information, and the first The terminal identifier information is opened to the application client. After receiving the access request message, the application client performs login authentication according to the stored first terminal identifier information to open the application of the application client.
  • the method for authenticating the first terminal identification information is used to solve the problem that the user needs to memorize the user name and password when the user logs in to the application on the terminal device.
  • An embodiment of the present invention provides a method for identity identification, where the method is based on a terminal middleware and an application client, where the application client does not store the first terminal identification information of the terminal device, as shown in FIG. 3
  • the method includes: after the terminal middleware acquires the terminal identifier information of the terminal device, the method includes:
  • the application client receives an access request message, where the access request message requests to open an application of the application client.
  • the application client receives an access request message, and the access request message requests to open an application of the application client. 302.
  • the application client determines whether to store the first terminal identifier information of the terminal device. Specifically, after the application client receives the access request message, it first determines whether the first terminal identifier information of the terminal device has been stored.
  • step 308 is performed;
  • the terminal middleware If the first terminal identifier information of the terminal device is not stored, send a first request message to the terminal middleware, where the first request message requests to acquire the first terminal identifier information.
  • the first request message requests to acquire the first terminal identification information.
  • the terminal middleware receives the first request message sent by the application client.
  • the terminal middleware opens the first terminal identification information to the application client.
  • the first request message is sent to the terminal middleware, and the triggering device is triggered.
  • the terminal middleware opens the first terminal identification information to the application client.
  • the application client After the first terminal identification information is requested by the application client, after the first terminal information is opened to the application client, the application client acquires the first terminal identification information, and receives After the request message is accessed, the login authentication is performed according to the first terminal identifier information, which prevents the terminal middleware from opening the problem that the terminal identifier information of the application client does not match the terminal identifier information required by the application client.
  • the application client acquires the first terminal identifier information that is open by the terminal middleware.
  • the application client stores the first terminal identifier information.
  • the application client stores the first terminal identifier information, so that the application client opens the application of the application client after performing login authentication according to the first terminal identifier information.
  • the terminal middleware may use the first application name and the first terminal identification information of the application client to use advanced Encrypting standard AES, generating the first application name corresponding The encrypted first terminal identifier information, so the stored first terminal identifier information may be the encrypted first terminal identifier information, or may be the unencrypted first terminal identifier information, which is not specifically described in this embodiment of the present invention. Limited, only based on actual conditions.
  • the application client performs login authentication according to the first terminal identifier information to open an application of the application client.
  • the application for performing the login authentication according to the stored first terminal identifier information to open the application client may include:
  • the first application name and the stored first terminal identification information are authenticated; if the indication message of successful authentication sent by the terminal middleware is received, the application of the application client is opened.
  • the application client may receive the indication information of the login password that is sent by the terminal middleware, and the method for opening the application of the application client may be determined according to the indication information, including:
  • the application of the application client is opened according to the stored first terminal identifier information
  • the application of the application client is opened according to the stored first terminal identification information and the input login password.
  • the embodiment of the present invention further provides a method for identity identification, where the method is based on the terminal middleware and the application client, to determine that the application is legal, the terminal device sends the first terminal identification information for description.
  • the method includes:
  • the application client receives an access request message, where the access request message requests to open an application of the application client. Specifically, after the user triggers the application client, the application client receives an access request message, and the access request message requests to open an application of the application client.
  • the application client determines whether to store the first terminal identifier information of the terminal device. Specifically, after the application client receives the access request message, it first determines whether the first terminal identification information of the terminal device has been stored.
  • the first terminal identifier information of the terminal device is not stored, send a first request message to the terminal middleware, and the first request message requests to acquire the first terminal identifier information, where the first The request message carries the first application name of the application client.
  • the first application name is obtained by registering on an application platform, where the first application name does not have any special
  • the meaning of the application only refers to the application name of the application client that currently receives the access request message.
  • the terminal middleware receives the first request message sent by the application client.
  • the terminal middleware determines, according to the first application name, whether the application is legal.
  • determining, according to the first application name, whether the application is legal or not may include:
  • the first application name is included in the local database information, determining that the application is legal; if the first application name is not included in the first database information, requesting the capability open platform/app store to obtain the first An application name;
  • the capability open platform/app store If the first application name sent by the capability open platform/app store is not received, it is determined that the application is illegal. It should be noted that if the application of the SP (Service Provider) / CP (Content Provider Content Provider) is registered in the capability open platform/app store, the application is legal. Therefore, if the first application name is not included in the first database information, and the capability open platform/app store requests to obtain the first application name, if the application is legal, the capability open platform/app store It should contain the unique identifying information assigned to the app when it is registered, ie the app name.
  • SP Service Provider
  • CP Content Provider
  • the application is determined to be legal; if the first application name sent by the capability open platform/app store is not received, the The application is not registered with the capability open platform/app store, and the application is determined to be illegal. No specific limitation.
  • the terminal middleware opens the first terminal identification information to the application client.
  • the information is opened to the application client, which increases the security of accessing the application.
  • the application client acquires the first terminal identifier information that is open by the terminal middleware.
  • the application client stores the first terminal identifier information.
  • the application client stores the first terminal identifier information, so that the application client opens the application of the application client after performing login authentication according to the first terminal identifier information.
  • the terminal middleware may use the first application name and the first terminal identification information of the application client to use advanced
  • the encryption standard AES is configured to generate the encrypted first terminal identifier information corresponding to the first application name, so the stored first terminal identifier information may be the encrypted first terminal identifier information, or may be the first unencrypted information.
  • the terminal identification information is not specifically limited in this embodiment of the present invention, and is determined only according to actual conditions.
  • the application client performs login authentication according to the first terminal identifier information to open an application of the application client.
  • the application for performing the login authentication according to the stored first terminal identifier information to open the application client may include:
  • the first application name and the stored first terminal identification information are authenticated; if the indication message of successful authentication sent by the terminal middleware is received, the application of the application client is opened.
  • the application client may receive the indication information of whether the login password is required to be sent by the terminal middleware, and the method for opening the application of the application client may be determined according to the indication information, including:
  • the application of the application client is opened according to the stored first terminal identifier information
  • the application of the application client is opened according to the stored first terminal identification information and the input login password.
  • the embodiment of the present invention further provides a method for identity identification, where the method is based on the terminal middleware and the application client, and specifically, after determining that the application is legal and the user authorizes, the terminal device sends the first terminal.
  • the identification information is described. Specifically, as shown in FIG. 5, after the terminal middleware acquires terminal identification information of the terminal device, the method includes:
  • the application client receives an access request message, where the access request message requests to open an application of the application client.
  • the application client receives an access request message, and the access request message requests to open an application of the application client.
  • the application client determines whether to store the first terminal identifier information of the terminal device. Specifically, after the application client receives the access request message, it first determines whether the first terminal identifier information of the terminal device has been stored. If the application client has stored the first terminal identifier information of the terminal device, perform the step
  • the first terminal identifier information of the terminal device is not stored, send a first request message to the terminal middleware, and the first request message requests to acquire the first terminal identifier information, where the first The request message carries the first application name of the application client.
  • the first application name is obtained by registering on an application platform, where the first application name does not have any special
  • the meaning of the application only refers to the application name of the application client that currently receives the access request message.
  • the terminal middleware receives the first request message sent by the application client.
  • the terminal middleware determines, according to the first application name, whether the application is legal.
  • the method for the terminal middleware to determine whether the application is legal according to the first application name may refer to the description of step 405, which is not repeatedly described in the embodiment of the present invention.
  • the terminal middleware determines, according to the first application name, whether the application first invokes the first terminal identification information.
  • the terminal middleware may store the correspondence between the application name and the number of times the application corresponding to the terminal identifier information is called by the application name, so it may be determined, according to the first application name, whether the application first invokes the first terminal. Identification information.
  • step 507 If the application is to call the first terminal identification information for the first time, go to step 507;
  • step 511 is performed.
  • the terminal middleware If the application first invokes the first terminal identifier information, the terminal middleware requests the user to authorize opening the first terminal identifier information to the application client.
  • the terminal middleware requesting the user to authorize the opening of the first terminal identifier information to the application client may include:
  • the terminal middleware requests the user to authorize opening the first terminal to the application client.
  • the user performs the first terminal identification information right.
  • the terminal middleware can provide a 4 authorized interface as shown in FIG. 6, and the user can authorize the user information by setting the content of the authorization interface.
  • a service-level agreement can be provided to different types of application clients.
  • SLA service-level agreement
  • the user can authorize the password without login, and only the first terminal identifier is required. If the information is successfully authenticated, you can log in to the application, such as news and other tools.
  • the user can authorize the password input at login.
  • the first terminal identification information and password must be authenticated before logging in to the application. Similar to the bank's USB key and terminal identification information.
  • Account number the user needs to enter a password to log in correctly, such as bank/securities client, Alipay client, etc.
  • a password such as bank/securities client, Alipay client, etc.
  • the option of the login password is not necessarily included in the authorization interface.
  • the embodiment of the present invention only provides an illustration of the authorization interface, and the specific content of the authorization interface is not specifically limited. Authorization of terminal identification information.
  • the user returns a 4 authorized response that opens the first terminal identification information to the application client.
  • the terminal middleware opens the first terminal identification information to the application client. Specifically, in the embodiment of the present invention, when it is determined that the application is legal, and the user is authorized to send the first terminal identification information to the application client, the first terminal identification information is opened to the application client, The user's authorization further increases the security of the access application.
  • the application client acquires the first terminal identifier information that is open by the terminal middleware.
  • the application client stores the first terminal identifier information.
  • the application client stores the first terminal identifier information, so that the application client opens the application of the application client after performing login authentication according to the first terminal identifier information.
  • the terminal middleware after being authorized by the user, the terminal middleware also saves the following configuration information of the application client:
  • the application client performs login authentication according to the first terminal identifier information to open an application of the application client.
  • the application client stores the first terminal identification information, and the application client logs in according to the stored first terminal identification information.
  • the interaction between the terminal middleware and the application client is as shown in FIG. 7, and includes:
  • the application client sends a second request message requesting authentication to the terminal middleware, where the second request message carries a first application name of the application client and the stored first terminal identifier information.
  • the first application name of the application client and the stored first terminal identifier information carried by the second request message are used for login authentication.
  • the terminal middleware receives the second request message that is sent by the application client to request authentication.
  • the terminal middleware checks whether a correspondence between the first application name and the first terminal identifier information stored by the application client is stored.
  • the terminal middleware stores the first application name and the application client Corresponding relationship of the stored first terminal identification information, indicating that the authentication is successful, and performing step 704;
  • the terminal middleware does not store the correspondence between the first application name and the first terminal identification information stored by the application client, indicating that the authentication fails, the login fails.
  • the application client receives an indication message that the terminal middleware sends the authentication success.
  • the application client opens an application of the application client according to the stored first terminal identifier information.
  • the application client opens the application of the application client according to the stored first terminal identifier information.
  • the user is not required to memorize the username and password, and the security of the application on the user's login terminal device is improved.
  • the indication information of whether the login password is required when logging in to the application may be pre-configured in the terminal middleware.
  • the authorization interface shown in FIG. 6 may include an option of whether a login password is required to log in to the application, that is, whether the login password is required to log in to the application is pre-configured in the terminal middleware.
  • the method further includes: before the sending, sending the indication message that the authentication succeeds to the application client, the method further includes:
  • the terminal middleware sends a pre-stored indication information of whether the login password is required to log in to the application client to the application client;
  • the application client receives the indication information of whether the password is required to be logged in when the login is sent by the terminal middleware and stores the information.
  • the interaction between the terminal middleware and the application client is specifically as shown in FIG. 8, and includes: 801,
  • the application client sends a second request message for requesting authentication to the terminal middleware, where the second request message carries the first application name of the application client and the stored first terminal identification information.
  • the first application name of the application client and the stored first terminal identifier information carried by the second request message are used for login authentication.
  • the terminal middleware receives the second request message that is sent by the application client and requests authentication. -twenty one-
  • the terminal middleware checks whether a correspondence between the first application name and the first terminal identifier information stored by the application client is stored.
  • step 804 is performed;
  • the terminal middleware does not store the correspondence between the first application name and the first terminal identification information stored by the application client, indicating that the authentication fails, the login fails.
  • the application client stores indication information about whether a login password is required when logging in to the application, it may be determined at this time whether a login password is required.
  • the embodiment of the present invention provides a solution for different security levels to the user according to the stored indication information of whether the login password is required.
  • the user can log in without using a password.
  • Only the first terminal identification information can be successfully authenticated to log in to the application, such as news and other tools.
  • users can enter a password when logging in.
  • the first terminal identification information and password must be authenticated before they can log in to the application. Similar to the bank's USB key and terminal identification information as an account. Users need to enter a password to log in correctly, such as bank/securities client, Alipay client, etc.
  • the terminal middleware receives the response from the user that provides the terminal identification information to the application client, the terminal middleware further includes:
  • the terminal middleware generates the encrypted first terminal identification information corresponding to the first application name by using the advanced encryption standard AES according to the first application name and the first terminal identification information.
  • the opening the first terminal identifier information to the application client specifically includes: the encrypted first terminal identifier The information is open to the application client.
  • the application client obtains the encrypted first terminal identification information that is open by the terminal middleware
  • the storing, by the application client, the first terminal identifier information specifically includes:
  • the terminal middleware may use the first application name and the first terminal identification information of the application client to use advanced
  • the encryption standard AES generates the encrypted first terminal identification information corresponding to the first application name.
  • the application client stores the encrypted first terminal identification information, so that in the subsequent identity identification process, the application client and the terminal middleware communicate with each other through the encrypted first terminal identification information, thereby ensuring the terminal.
  • the first terminal identifier information in the terminal identifier information is opened to the application client by acquiring the terminal identifier information of the terminal device, so that the application client obtains and stores the first terminal identifier.
  • the information and after receiving the access request message, the technical solution for performing login authentication according to the first terminal identification information, which solves the problem that the user needs to memorize the user name and password when logging in to the application on the terminal device, and the first The terminal identification information is used as the unique identifier of the application that the user logs in to the terminal device, which improves the security of the application that the user logs in to the terminal device.
  • the embodiment of the present invention provides a terminal middleware 900.
  • the terminal middleware 900 includes an obtaining unit 901 and an opening unit 902.
  • the obtaining unit 901 is configured to acquire terminal identification information of the terminal device, where the terminal identifier information includes at least first terminal identifier information.
  • the opening unit 902 is configured to open the first terminal identification information to the application client, so that the application client obtains and stores the first terminal identification information, and receives the access request. After the message is obtained, login authentication is performed according to the first terminal identification information.
  • the terminal middleware 900 further includes a receiving unit 903.
  • the receiving unit 903 is configured to: after the acquiring unit 901 acquires the terminal identifier information of the terminal device, the opening unit 902 receives the first terminal identifier information before the application client is opened, and receives the The first request message sent by the client is requested, and the first request message requests to acquire the first terminal identifier information.
  • the terminal middleware 900 further includes a determining unit 904 and an executing unit 905.
  • the first request message carries a first application name of the application client.
  • the determining unit 904 is configured to determine, according to the first application name, whether the application is legal after the receiving unit 903 receives the first request message sent by the application client;
  • the executing unit 905 is further configured to: if the application is legal, perform the step of opening the first terminal identification information to an application client.
  • the terminal middleware 900 further includes a determining unit 904, a requesting unit 906, a storage unit 907, and an executing unit 905.
  • the first request message carries a first application name of the application client
  • the determining unit 904 is configured to determine, according to the first application name, whether the application is legal after the receiving unit 903 receives the first request message sent by the application client.
  • the determining unit 904 is further configured to: determine, according to the first application name, whether the application first invokes the first terminal identification information according to the first application name.
  • the requesting unit 906 is configured to request the user to open the first terminal identification information to the application client if the application first invokes the first terminal identification information.
  • the receiving unit 903 is configured to receive, by the user, a response to the application of the first terminal identifier information to the application client.
  • the storage unit 907 is configured to save a correspondence between the first application name and the first terminal identifier information.
  • the executing unit 905 is configured to perform the step of opening the first terminal identification information to an application client.
  • the requesting unit 906 requests the user to authorize the opening of the application to the application client.
  • the first terminal identification information specifically includes:
  • the terminal middleware further includes an checking unit 908 and a sending unit 909.
  • the receiving unit 903 is further configured to receive a second request message that is sent by the application client to request authentication, where the second request message carries a first application name of the application client and a first stored by the application client. Terminal identification information;
  • the checking unit 908 is configured to check whether a correspondence between the first application name and the first terminal identification information stored by the application client is stored.
  • the sending unit 909 is further configured to: if stored, send an indication message that the authentication succeeds to the application client, so that the application client opens the application client according to the first terminal identifier information stored by the application client. End application.
  • the sending unit 909 is further configured to send, before the sending, sending the indication message that the authentication succeeds to the application client, the pre-stored indication information of whether the login password is required to log in to the application to the Application client.
  • the sending unit 909 sends an indication message that the authentication succeeds to the application client, so that the application client opens the application of the application client according to the first terminal identifier information stored by the application client, including :
  • the indication message that the authentication succeeds is sent to the application client, so that the application client opens the application according to the first terminal identification information stored by the application client and the indication information of whether the login password is required. Client application.
  • the terminal middleware further includes a generating unit 910.
  • the generating unit 910 is configured to: after receiving, by the receiving unit 903, an authorization response that is opened by the user to open the first terminal identifier information to the application client, according to the first application name and the first terminal identifier
  • the information is generated by using the advanced encryption standard AES to generate the encrypted first terminal identification information corresponding to the first application name.
  • the storage unit 907 stores the correspondence between the first application name and the first terminal identification information.
  • the relationship specifically includes:
  • the identification information is specifically the encrypted first terminal identification information.
  • the determining unit 904 according to the first application name, determining whether the application is legal or not specifically includes:
  • the capability open platform/app store is requested to acquire the first application name.
  • the first application name is stored.
  • terminal identifier information specifically includes:
  • the media access control MAC address of the terminal device is the media access control MAC address of the terminal device.
  • the method for performing identity identification by using the terminal middleware can refer to the descriptions of the first embodiment and the second embodiment, and details are not described herein again.
  • the terminal middleware provided by the present invention includes an acquisition unit and an open unit.
  • the acquiring unit is configured to acquire terminal identification information of the terminal device, where the terminal identifier
  • the information includes at least the first terminal identification information
  • the open unit is configured to open the first terminal identification information to the application client, so that the application client obtains and stores the first terminal identification information, and
  • the terminal middleware provided by the embodiment of the present invention solves the problem that the user name and password need to be memorized when the user logs in to the application on the terminal device, and the user is improved at the same time. Log in to the security of the app on the terminal device.
  • the embodiment of the present invention provides an application client 1500.
  • the application client 1500 includes a receiving unit 1501 and a login authentication unit 1502.
  • the receiving unit 1501 is configured to receive an access request message, where the access request message requests to open an application of the application client.
  • the login authentication unit 1502 is configured to perform login authentication according to the stored first terminal identification information to open an application of the application client.
  • the first terminal identifier information may be stored in the application client before the receiving unit 1501 receives the access request message, or may be determined by the receiving unit 1501 not to store after receiving the access request message. After the first terminal identifier information of the terminal device is obtained, the first terminal identifier information is obtained from the terminal middleware, and then stored in the application client, which is not specifically limited in this embodiment of the present invention.
  • the application client further includes a determining unit 1503, a sending unit 1504, an obtaining unit 1505, and a first storage unit 1506.
  • the determining unit 1503 is configured to determine, after the receiving unit 1501 receives the access request message, whether to store the first terminal identification information of the terminal device.
  • the sending unit 1504 is configured to: if the first terminal identifier information of the terminal device is not stored, send a first request message to the terminal middleware, where the first request message requests to acquire the first terminal identifier information.
  • the obtaining unit 1505 is configured to acquire the first terminal identification information that is open by the terminal middleware.
  • the first storage unit 1505 is configured to store the first terminal identification information.
  • the first request message carries a first application name of the application client, so that The terminal middleware determines whether the application is legal according to the first application name, and the first terminal identification information is opened to the application client when the application is legal.
  • the first request message carries the first application name of the application client, so that the terminal middleware determines whether the application is legal according to the first application name, and the application is legal according to the
  • the first application name determines whether the application first invokes the first terminal identification information, and after determining that the application is the first time to invoke the first terminal identification information, requesting the user to authorize opening the first to the application client.
  • the terminal identification information is: after receiving the authorization response returned by the user to open the first terminal identification information to the application client, the first terminal identification information is opened to the application client.
  • the login authentication unit 1502 performs login authentication according to the stored first terminal identifier information, to open the application of the application client, specifically:
  • the application of the application client is opened.
  • the application client further includes a second storage unit 1507.
  • the receiving unit 1501 is further configured to receive, by the terminal middleware, indication information that a login password is required when logging in to the application.
  • the second storage unit 1507 is configured to store the indication information of whether the password is required to be used for the login. If the indication message that the authentication succeeds is sent by the terminal middleware, the application of the application client is specifically:
  • the application of the application client is opened according to the stored first terminal identifier information
  • the application of the application client is opened according to the stored first terminal identification information and the input login password.
  • the acquiring unit 1505 acquires a first terminal identification letter that is open by the terminal middleware.
  • the specific information includes:
  • the encrypted first terminal identifier information that is open to the terminal middleware, where the encrypted first terminal identifier information is that the terminal middleware is used according to the first application name and the first terminal identifier information. Generated by the advanced encryption standard AES.
  • the storing, by the first storage unit 1506, the first terminal identification information includes: storing the encrypted first terminal identification information, so that the stored first terminal identification information is specifically the encrypted first terminal identification information.
  • terminal identifier information specifically includes:
  • the international mobile subscriber identity of the SIM card in the terminal device IMSI is the international mobile subscriber identity of the SIM card in the terminal device IMSI;
  • the media access control MAC address of the terminal device is the media access control MAC address of the terminal device.
  • the method for performing the identification by the application client may refer to the descriptions of the first embodiment and the second embodiment, and details are not described herein again.
  • the application client provided by the embodiment of the present invention includes a receiving unit and a login authentication unit.
  • the receiving unit is configured to receive an access request message, where the access request message requests to open an application of the application client
  • the login authentication unit is configured to perform login authentication according to the stored first terminal identifier information, to open the The application application client.
  • the application client provided by the embodiment of the present invention solves the problem that the user needs to memorize the user name and password when logging in to the application on the terminal device, and improves the security of the application that the user logs in to the terminal device.
  • the embodiment of the present invention provides a terminal middleware 1800.
  • the terminal middleware includes a processor 1801.
  • the processor 1801 is configured to acquire terminal identifier information of the terminal device, where the terminal identifier information includes at least first terminal identifier information.
  • the processor 1801 is further configured to: open the first terminal identification information to the application client, so that the application client obtains and stores the first terminal identification information, and after receiving the access request message, according to the The first terminal identification information is used for login authentication.
  • the terminal middleware 1800 further includes an input interface 1802.
  • the input interface 1802 is configured to: after the processor 1801 acquires terminal identification information of the terminal device, Before the terminal identifier information is opened to the application client, the first request message sent by the application client is received, and the first request message requests to acquire the first terminal identifier information.
  • the first request message carries a first application name of the application client.
  • the processor 1801 is further configured to: after the input interface 1802 receives the first request message sent by the application client, determine, according to the first application name, whether the application is legal.
  • the processor 1801 is further configured to: when the application is legal, perform the step of opening the first terminal identification information to an application client.
  • the terminal middleware 1800 further includes a memory 1803.
  • the first request message carries a first application name of the application client.
  • the processor 1801 is further configured to: after the input interface 1802 receives the first request message sent by the application client, determine, according to the first application name, whether the application is legal.
  • the processor 1801 is further configured to determine, according to the first application name, whether the application first invokes the first terminal identification information according to the first application name.
  • the processor 1801 is further configured to: if the application first invokes the first terminal identifier information, request the user to authorize opening the first terminal identifier information to the application client.
  • the input interface 1802 is further configured to receive a response from the user that opens the first terminal identification information to the application client.
  • the memory 1803 is configured to save a correspondence between the first application name and the first terminal identification information.
  • the processor 1801 is configured to perform the step of opening the first terminal identification information to an application client.
  • the requesting, by the processor 1801, the user to open the first terminal identification information to the application client includes:
  • the terminal middleware 1800 further includes an output interface 1804.
  • the input interface 1802 is further configured to receive a second request message that is sent by the application client to request authentication, where the second request message carries a first application name of the application client and a first stored by the application client. Terminal identification information.
  • the processor 1801 is further configured to check whether a correspondence between the first application name and the first terminal identification information stored by the application client is stored.
  • the output interface 1804 is further configured to: if stored, send an indication message that the authentication succeeds to the application client, so that the application client opens the application client according to the first terminal identifier information stored by the application client. End application.
  • the output interface 1804 is further configured to send, before the sending, sending an indication message that the authentication succeeds to the application client, a pre-stored indication information of whether a login password is required to log in to the application, to the Application client.
  • the output interface 1804 sends an indication that the authentication succeeds to the application client, so that the application client opens the application of the application client according to the first terminal identifier information stored by the application client, including :
  • the indication message that the authentication succeeds is sent to the application client, so that the application client opens the application according to the first terminal identification information stored by the application client and the indication information of whether the login password is required. Client application.
  • the processor 1801 is further configured to: after receiving, by the input interface 1802, an authorization response returned by the user to open the first terminal identification information to the application client, according to the first application name and the The first terminal identification information is generated by using the advanced encryption standard AES to generate the encrypted first terminal identification information corresponding to the first application name.
  • the storing, by the memory 1803, the correspondence between the first application name and the first terminal identifier information specifically includes:
  • the opening, by the processor 1801, the first terminal identification information to the application client includes:
  • the stored first terminal identification information is specifically the encrypted first terminal identification information.
  • the determining, by the processor 1801, whether the application is legal according to the first application name specifically includes:
  • the local database information includes the first application name, determining that the application is legal; if the first application name is not included in the local database information, requesting the capability open platform/app store to obtain the first Application name
  • terminal identifier information specifically includes:
  • the media access control MAC address of the terminal device is the media access control MAC address of the terminal device.
  • the method for performing identity identification by using the terminal middleware can refer to the descriptions of the first embodiment and the second embodiment, and details are not described herein again.
  • the terminal middleware provided by the present invention includes a processor.
  • the processor is configured to obtain the terminal identifier information of the terminal device, where the terminal identifier information includes at least the first terminal identifier information, and the processor is further configured to: open the first terminal identifier information to the application client, so that The application client obtains and stores the first terminal identification information, and after receiving the access request message, performs login authentication according to the first terminal identification information.
  • the terminal middleware provided by the embodiment of the present invention solves the problem that the user needs to memorize the user name and the password when logging in to the application on the terminal device, and improves the security of the application of the user logging in to the terminal device.
  • Embodiment 6 The embodiment of the present invention provides an identity recognition system 2200. As shown in FIG. 22, the identity recognition system 2200 includes a terminal middleware 900 and an application client 1500.
  • the terminal middleware 900 is configured to acquire terminal identification information of the terminal device, where the terminal identification information includes at least first terminal identification information.
  • the terminal middleware 900 is further configured to open the first terminal identification information to the application client, so that the application client obtains and stores the first terminal identification information.
  • the application client 1500 is configured to receive an access request message, and perform login authentication according to the stored first terminal identification information to open an application of the application client.
  • the method for the identity identification system to perform the identity identification by the terminal middleware and the application client may refer to the descriptions of the first embodiment and the second embodiment, and details are not described herein again.
  • the terminal identifier information of the terminal device is obtained by the terminal middleware, and the first terminal identifier information in the terminal identifier information is opened to the application client, so that the application client obtains and stores the first a terminal identification information, and after receiving the access request message, performing a login authentication according to the first terminal identification information, which solves the problem that the user needs to memorize the user name and password when logging in to the application on the terminal device, and at the same time
  • the first terminal identifier information is used as the unique identifier of the application that the user logs in to the terminal device, which improves the security of the application that the user logs in to the terminal device.
  • the terminal middleware may be a software module on the terminal device;
  • the terminal middleware may also be an independent device having the function of the terminal middleware, that is, the terminal middleware can be connected with the terminal device, or can be built in the terminal device, for example, by means of card insertion or software integration, the present invention
  • the embodiment does not specifically limit this.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • Power Engineering (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Software Systems (AREA)
  • Computing Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Telephonic Communication Services (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Information Transfer Between Computers (AREA)
  • Telephone Function (AREA)

Abstract

An identity recognition method, device and system, which can solve the problem that a user name and a password are required to be remembered when a user logs in an application on a terminal device and improve the security for the user to log in the application on the terminal device at the same time. The method comprises: terminal middleware acquiring terminal identification information about a terminal device, wherein the terminal identification information at least contains first terminal identification information; and opening the first terminal identification information to an application client, so as to enable the application client to acquire and store the terminal identification information and perform a login authentication according to the first terminal identification information after receiving an access request message. The present invention is applicable to the field of communications.

Description

一种身份识别的方法、 装置和系统 技术领域  Method, device and system for identification
本发明涉及通信领域, 尤其涉及一种身份识别的方法、 装置和系统。 背景技术  The present invention relates to the field of communications, and in particular, to a method, device and system for identity recognition. Background technique
随着移动智能终端(智能手机、 Pad )的普及, 越来越多的 Web App (网 络应用程序)或者 Native App (本地应用程序)被安装在终端设备上。  With the popularity of mobile smart terminals (smart phones, pads), more and more Web App (network applications) or Native App (local applications) are installed on the terminal devices.
目前基本上所有需要用户登录认证的应用都是釆用用户名 +密码的方 式, 例如微信、 人人、 淘宝等, 但是每个应用都有相应的用户名和密码, 从 而导致用户需要记忆种类繁多的用户名和密码, 而且由于密码有可能被破 译、 窃取或者泄露, 因此安全性也得不到保证。  At present, basically all applications that require user login authentication are user name + password, such as WeChat, Renren, Taobao, etc., but each application has a corresponding username and password, resulting in a variety of memory users need to remember. The username and password, and because the password may be deciphered, stolen or compromised, security is not guaranteed.
现有技术中, 存在以下两种解决上述问题的方案:  In the prior art, there are two solutions to solve the above problems:
第一, OpenID ( Open Identity, 开放身份识别)业务: OpenID是一个以 用户为中心的开放的、分散的数字身份识别框架,该框架以 OpenID服务网站 为核心,所述 OpenID服务网站存储了某一终端设备中多个应用对应的同一密 码, 用户登录一个支持 OpenID的网站时, 只需输入在所述 OpenID服务网站 注册的 OpenID用户名和密码, 然后预登录的网站会跳转到所述 OpenID服务 网站,在所述 OpenID服务网站验证密码通过后, 直接回到预登录的网站并且 登陆成功。  First, OpenID (Open Identity) business: OpenID is a user-centric open, decentralized digital identity framework. The framework is based on the OpenID service website. The OpenID service website stores a certain The same password corresponding to multiple applications in the terminal device. When the user logs in to a website that supports OpenID, he only needs to input the OpenID username and password registered on the OpenID service website, and then the pre-login website will jump to the OpenID service website. After the password is verified by the OpenID service website, it directly returns to the pre-registered website and the login is successful.
第二, 一种基于 OAuth协议的方法, 所述 OAuth允许用户让第三方应用 访问该用户在某一网站上存储的信息, 而无需将用户名和密码提供给第三方 应用。 在第三方应用访问某一网站上存储的信息前, 它必须先从该网站获取 授权, 取得访问许可证, 然后用访问许可证换取访问通行证, 最后通过向该 网站的资源服务器出示访问通行证来访问该网站上存储的信息。在上述技术 场景下, 用户仅需要在终端设备上输入资源服务器的用户名和密码, 即可达 到登录第三方应用的目的。  Second, an OAuth-based method, the OAuth allows a user to have a third-party application access information stored by the user on a website without providing a username and password to a third-party application. Before a third-party application accesses information stored on a website, it must first obtain authorization from the website, obtain an access license, and then exchange the access license for the access pass, and finally access the resource card of the website to present the access pass. The information stored on the website. In the above technical scenario, the user only needs to input the username and password of the resource server on the terminal device to achieve the purpose of logging in to the third-party application.
上述两种方法虽然都可以减少用户记忆的用户名和密码的数量,但是用 户还是需要记忆一些用户名和密码, 而且第一种方法中, 相关应用和网站必 须遵循 OpenlD标准进行开发, 第二种方法中相关网站和应用遵循 OAuth2.0 的标准规范进行开发, 使得这两种方法的应用均存在一定的局限性, 并且 OAuth是一个授权协议而并非认证, 因此在安全性方面存在一些问题。。 发明内容 Although the above two methods can reduce the number of user names and passwords memorized by the user, the user still needs to memorize some user names and passwords, and in the first method, related applications and websites must It must be developed in accordance with the OpenlD standard. In the second method, related websites and applications follow the standard specification of OAuth2.0, which makes the application of these two methods have certain limitations, and OAuth is a license agreement and not authentication. Therefore, there are some problems in terms of security. . Summary of the invention
本发明的实施例提供一种身份识别的方法、 装置和系统, 以解决用户登 录终端设备上的应用时, 需要记忆用户名和密码的问题, 同时提高了用户登 录终端设备上的应用的安全性。  The embodiments of the present invention provide a method, an apparatus, and a system for identifying an identity, which are required to memorize a user name and a password when the user logs in to the application on the terminal device, and improve the security of the application on the user to log in to the terminal device.
为达到上述目的, 本发明的实施例釆用如下技术方案:  In order to achieve the above object, embodiments of the present invention use the following technical solutions:
第一方面, 提供一种身份识别的方法, 所述方法包括:  In a first aspect, a method for identifying an identity is provided, the method comprising:
终端中间件获取终端设备的终端标识信息, 其中, 所述终端标识信息至 少包含第一终端标识信息;  The terminal middleware acquires the terminal identification information of the terminal device, where the terminal identification information at least includes the first terminal identification information;
将所述第一终端标识信息开放给应用客户端, 以使得所述应用客户端获 取并存储所述第一终端标识信息, 并在接收访问请求消息后, 根据所述第一 终端标识信息进行登录认证。  Opening the first terminal identification information to the application client, so that the application client obtains and stores the first terminal identification information, and after receiving the access request message, logs in according to the first terminal identification information. Certification.
在第一种可能的实现方式中, 根据第一方面, 在所述终端中间件获取所 述终端设备的终端标识信息之后, 将所述第一终端标识信息开放给应用客户 端之前, 所述方法还包括:  According to the first aspect, after the terminal middleware acquires the terminal identification information of the terminal device, and after the first terminal identification information is opened to the application client, the method is Also includes:
接收所述应用客户端发送的第一请求消息, 所述第一请求消息请求获取 所述第一终端标识信息。  And receiving the first request message sent by the application client, where the first request message requests to acquire the first terminal identifier information.
在第二种可能的实现方式中, 根据第一种可能的实现方式, 所述第一请 求消息携带所述应用客户端的第一应用名;  In a second possible implementation, the first request message carries the first application name of the application client, according to the first possible implementation manner;
在所述接收所述应用客户端发送的第一请求消息之后, 所述方法还包 括:  After the receiving the first request message sent by the application client, the method further includes:
根据所述第一应用名, 判断所述应用是否合法;  Determining whether the application is legal according to the first application name;
若所述应用合法,执行将所述第一终端标识信息开放给应用客户端的步 骤。  If the application is legal, the step of opening the first terminal identification information to the application client is performed.
在第三种可能的实现方式中, 根据第一种可能的实现方式, 所述第一请 求消息携带所述应用客户端的第一应用名; 在所述接收所述应用客户端发送的第一请求消息之后, 所述方法还包 括: In a third possible implementation, the first request message carries the first application name of the application client, according to the first possible implementation manner; After the receiving the first request message sent by the application client, the method further includes:
根据所述第一应用名, 判断所述应用是否合法;  Determining whether the application is legal according to the first application name;
若所述应用合法,根据所述第一应用名判断所述应用是否首次调用所述 第一终端标识信息;  If the application is legal, determining, according to the first application name, whether the application first invokes the first terminal identification information;
若所述应用首次调用所述第一终端标识信息,请求用户 权向所述应用 客户端开放所述第一终端标识信息;  If the application first invokes the first terminal identifier information, requesting the user right to open the first terminal identifier information to the application client;
接收用户返回的向所述应用客户端开放所述第一终端标识信息的授权 向应;  Receiving, by the user, an authorization to open the first terminal identification information to the application client;
保存所述第一应用名和所述第一终端标识信息的对应关系;  Saving a correspondence between the first application name and the first terminal identifier information;
执行所述将所述第一终端标识信息开放给应用客户端的步骤。  The step of opening the first terminal identification information to the application client is performed.
在第四种可能的实现方式中, 根据第三种可能的实现方式, 所述请求用 户授权向所述应用客户端开放所述第一终端标识信息具体包括:  In a fourth possible implementation, the requesting, by the requesting user, the opening of the first terminal identifier information to the application client includes:
发送认证短信, 请求用户通过输入所述认证短信的内容进行授权; 或  Sending an authentication short message, requesting the user to authorize by inputting the content of the authentication short message; or
提供授权界面, 请求用户在授权界面进行授权。  Provide an authorization interface and request the user to authorize on the authorization interface.
在第五种可能的实现方式中, 根据第三种或第四种可能的实现方式, 所 述方法还包括:  In a fifth possible implementation manner, according to the third or fourth possible implementation manner, the method further includes:
接收所述应用客户端发送的请求认证的第二请求消息, 所述第二请求消 息携带所述应用客户端的第一应用名和所述应用客户端存储的第一终端标 识信息;  And receiving, by the application client, a second request message for requesting authentication, where the second request message carries a first application name of the application client and first terminal identification information stored by the application client;
检查是否存储所述第一应用名和所述应用客户端存储的第一终端标识 信息的对应关系;  Checking whether a correspondence between the first application name and the first terminal identification information stored by the application client is stored;
若存储, 发送认证成功的指示消息给所述应用客户端, 以使得所述应用 客户端根据所述应用客户端存储的第一终端标识信息打开所述应用客户端 的应用。  If the storage is sent, the indication message that the authentication succeeds is sent to the application client, so that the application client opens the application of the application client according to the first terminal identifier information stored by the application client.
在第六种可能的实现方式中, 根据第五种可能的实现方式, 在所述若存 储, 发送认证成功的指示消息给所述应用客户端前, 所述方法还包括: 发送预先存储的登录该应用时是否需要登录密码的指示信息给所述应 用客户端; In a sixth possible implementation, according to the fifth possible implementation, before the sending, sending the indication message that the authentication succeeds to the application client, the method further includes: Sending a pre-stored indication information of whether a login password is required to log in to the application client to the application client;
所述若存储, 发送认证成功的指示消息给所述应用客户端, 以使得所述 应用客户端根据所述应用客户端存储的第一终端标识信息打开所述应用客 户端的应用具体包括:  And the storing, sending the indication message that the authentication is successful to the application client, so that the application client opens the application of the application client according to the first terminal identifier information stored by the application client, specifically:
若存储, 发送认证成功的指示消息给所述应用客户端, 以使得所述应用 客户端根据所述应用客户端存储的第一终端标识信息和所述是否需要登录 密码的指示信息打开所述应用客户端的应用。  If the storage is sent, the indication message that the authentication succeeds is sent to the application client, so that the application client opens the application according to the first terminal identification information stored by the application client and the indication information of whether the login password is required. Client application.
在第七种可能的实现方式中,根据第三种可能的实现方式至第六种可能 的实现方式, 在所述接收用户返回的向所述应用客户端开放所述第一终端标 识信息的 4吏权响应后, 所述方法还包括:  In a seventh possible implementation manner, according to the third possible implementation manner to the sixth possible implementation manner, the receiving, by the receiving user, opening the first terminal identifier information to the application client After the response, the method further includes:
根据所述第一应用名和所述第一终端标识信息, 釆用高级加密标准 AES, 生成所述第一应用名对应的加密的第一终端标识信息;  And generating, according to the first application name and the first terminal identifier information, the encrypted first terminal identifier information corresponding to the first application name by using an advanced encryption standard AES;
所述保存所述第一应用名和所述第一终端标识信息的对应关系具体包 括:  The corresponding relationship between the saving the first application name and the first terminal identification information includes:
保存所述加密的第一终端标识信息和所述第一应用名的对应关系; 所述将所述第一终端标识信息开放给所述应用客户端具体包括: 将所述加密的第一终端标识信息开放给所述应用客户端, 以使得所述应 用客户端获取并存储所述加密的第一终端标识信息, 以使得所述应用客户端 存储的第一终端标识信息具体为加密的第一终端标识信息。  Saving the correspondence between the encrypted first terminal identifier information and the first application name; the opening the first terminal identifier information to the application client specifically includes: the encrypted first terminal identifier The information is opened to the application client, so that the application client obtains and stores the encrypted first terminal identifier information, so that the first terminal identifier information stored by the application client is specifically an encrypted first terminal. Identification information.
在第八种可能的实现方式中,根据第二种可能的实现方式至第七种可能 的实现方式, 所述根据所述第一应用名, 判断所述应用是否合法具体包括: 读取本地数据库信息;  In an eighth possible implementation manner, according to the second possible implementation manner to the seventh possible implementation manner, determining, according to the first application name, whether the application is legal or not specifically includes: reading a local database Information
判断所述本地数据库信息中是否包含所述第一应用名;  Determining whether the first application name is included in the local database information;
若所述本地数据库信息中包含所述第一应用名, 确定所述应用合法; 若所述本地数据库信息中未包含所述第一应用名,向能力开放平台 /应用 商店请求获取所述第一应用名;  If the local database information includes the first application name, determining that the application is legal; if the first application name is not included in the local database information, requesting the capability open platform/app store to obtain the first Application name
若接收到所述能力开放平台 /应用商店发送的所述第一应用名,确定所述 应用合法; 存储所述第一应用名; If the first application name sent by the capability open platform/app store is received, determining that the application is legal; Storing the first application name;
若未接收到所述能力开放平台 /应用商店发送的所述第一应用名,确定所 述应用不合法。  If the first application name sent by the capability open platform/app store is not received, it is determined that the application is illegal.
在第九种可能的实现方式中, 根据第一方面至第八种可能的实现方式, 所述终端标识信息具体包括:  In a ninth possible implementation, the terminal identifier information specifically includes:
终端设备中用户识别模块 SIM卡的国际移动用户识别码 IMSI;  User identification module in the terminal device, the international mobile subscriber identity of the SIM card IMSI;
和 /或  and / or
终端设备的国际移动终端识别码 IMEI;  International mobile terminal identification code of terminal equipment IMEI;
和 /或  and / or
终端设备的介质访问控制 MAC地址。  The media access control MAC address of the terminal device.
第二方面, 提供一种身份识别的方法, 所述方法包括:  In a second aspect, a method for identifying an identity is provided, the method comprising:
应用客户端接收访问请求消息, 所述访问请求消息请求打开所述应用客 户端的应用;  The application client receives an access request message, and the access request message requests to open an application of the application client;
根据存储的第一终端标识信息进行登录认证, 以打开所述应用客户端的 应用。  Performing login authentication according to the stored first terminal identification information to open the application of the application client.
在第一种可能的实现方式中, 根据第二方面, 在所述应用客户端接收访 问请求消息后, 所述方法还包括:  In a first possible implementation manner, after the application client receives the access request message, the method further includes:
判断是否存储所述终端设备的第一终端标识信息;  Determining whether to store the first terminal identification information of the terminal device;
若未存储所述终端设备的第一终端标识信息,发送第一请求消息给所述 终端中间件, 所述第一请求消息请求获取所述第一终端标识信息;  If the first terminal identifier information of the terminal device is not stored, the first request message is sent to the terminal middleware, and the first request message requests to acquire the first terminal identifier information;
获取终端中间件开放的所述第一终端标识信息;  Obtaining the first terminal identification information that is open by the terminal middleware;
存储所述第一终端标识信息。  And storing the first terminal identification information.
在第二种可能的实现方式中, 根据第一种可能的实现方式, 所述第一请 求消息携带所述应用客户端的第一应用名, 以使得所述终端中间件根据所述 第一应用名, 判断所述应用是否合法, 且所述应用合法时开放所述第一终端 标识信息给所述应用客户端。  In a second possible implementation manner, the first request message carries a first application name of the application client, so that the terminal middleware is configured according to the first application name, according to the first possible implementation manner. And determining whether the application is legal, and the first terminal identification information is opened to the application client when the application is legal.
在第三种可能的实现方式中, 根据第一种可能的实现方式, 所述第一请 求消息携带所述应用客户端的第一应用名, 以使得所述终端中间件根据所述 第一应用名, 判断所述应用是否合法, 且所述应用合法时根据所述第一应用 名判断所述应用是否首次调用所述第一终端标识信息,且在确定所述应用是 首次调用所述第一终端标识信息后,请求用户授权向应用客户端开放所述第 一终端标识信息,在接收到用户返回的向所述应用客户端开放所述第一终端 标识信息的授权响应后, 开放所述第一终端标识信息给所述应用客户端。 In a third possible implementation manner, the first request message carries the first application name of the application client, so that the terminal middleware is configured according to the first application name, according to the first possible implementation manner. Determining whether the application is legal, and when the application is legal, according to the first application Determining whether the application first invokes the first terminal identification information, and after determining that the application is the first time to invoke the first terminal identification information, requesting the user to authorize opening the first terminal identification information to the application client, After receiving the authorization response that the user returns to the application client to open the first terminal identifier information, the first terminal identifier information is opened to the application client.
在第四种可能的实现方式中, 根据第二方面至第三种可能的实现方式, 所述根据存储的第一终端标识信息进行登录认证, 以打开所述应用客户端的 应用具体包括:  In a fourth possible implementation, according to the second aspect to the third possible implementation, the application for performing the login authentication according to the stored first terminal identifier information to open the application client includes:
发送请求认证的第二请求消息给所述终端中间件, 所述第二请求消息携 带所述应用客户端的第一应用名和所述存储的第一终端标识信息, 以使得所 述终端中间件对所述第一应用名和所述存储的第一终端标识信息进行认证; 若接收所述终端中间件发送的认证成功的指示消息, 打开所述应用客户 端的应用。  Sending a second request message requesting authentication to the terminal middleware, where the second request message carries a first application name of the application client and the stored first terminal identification information, so that the terminal middleware is opposite The first application name and the stored first terminal identification information are authenticated; if the indication message of successful authentication sent by the terminal middleware is received, the application of the application client is opened.
在第五种可能的实现方式中, 根据第四种可能的实现方式, 所述方法还 包括:  In a fifth possible implementation manner, according to the fourth possible implementation manner, the method further includes:
接收所述终端中间件发送的登录该应用时是否需要登录密码的指示信 息并存储;  Receiving, by the terminal middleware, an indication information of whether a login password is required when logging in to the application, and storing the indication information;
所述若接收所述终端中间件发送的认证成功的指示消息,打开所述应用 客户端的应用具体包括:  If the receiving the indication message of the authentication success sent by the terminal middleware, the application for opening the application client includes:
若接收所述终端中间件发送的认证成功的指示消息,根据所述是否需要 登录密码的指示信息, 确定是否需要登录密码;  And receiving an indication message that the authentication succeeded by the terminal middleware, and determining whether a login password is required according to whether the indication information of the login password is required;
若不需要登录密码,根据所述存储的第一终端标识信息打开所述应用客 户端的应用;  If the login password is not required, the application of the application client is opened according to the stored first terminal identifier information;
若需要登录密码,根据所述存储的第一终端标识信息和输入的登录密码 打开所述应用客户端的应用。  If the login password is required, the application of the application client is opened according to the stored first terminal identification information and the input login password.
在第六种可能的实现方式中,根据第三种可能的实现方式至第五种可能 的实现方式, 所述获取终端中间件开放的第一终端标识信息具体包括: 获取所述终端中间件开放的加密的第一终端标识信息, 其中, 所述加密 的第一终端标识信息是所述终端中间件根据所述第一应用名和所述第一终 端标识信息, 釆用高级加密标准 AES所生成的; 所述存储所述第一终端标识信息具体包括: In a sixth possible implementation manner, the obtaining, by the third possible implementation manner to the fifth possible implementation manner, the acquiring the first terminal identifier information that is open by the terminal middleware, specifically: acquiring the terminal middleware Encrypted first terminal identification information, wherein the encrypted first terminal identification information is generated by the terminal middleware according to the first application name and the first terminal identification information, using an advanced encryption standard AES ; The storing the first terminal identifier information specifically includes:
存储所述加密的第一终端标识信息, 以使得所述存储的第一终端标识信 息具体为加密的第一终端标识信息。  And storing the encrypted first terminal identifier information, so that the stored first terminal identifier information is specifically the encrypted first terminal identifier information.
在第七种可能的实现方式中, 根据第二方面至第六种可能的实现方式, 所述终端标识信息具体包括:  In a seventh possible implementation manner, according to the second to sixth possible implementation manners, the terminal identifier information specifically includes:
终端设备中 SIM卡的国际移动用户识别码 IMSI;  The international mobile subscriber identity of the SIM card in the terminal device IMSI;
和 /或  and / or
终端设备的国际移动终端识别码 IMEI;  International mobile terminal identification code of terminal equipment IMEI;
和 /或  and / or
终端设备的介质访问控制 MAC地址。  The media access control MAC address of the terminal device.
第三方面, 提供了一种终端中间件, 所述终端中间件包含获取单元、 开 放单元;  In a third aspect, a terminal middleware is provided, where the terminal middleware includes an acquiring unit and an opening unit;
所述获取单元, 用于获取终端设备的终端标识信息, 其中, 所述终端标 识信息至少包含第一终端标识信息;  The acquiring unit is configured to acquire terminal identification information of the terminal device, where the terminal identification information includes at least first terminal identification information;
所述开放单元, 用于将所述第一终端标识信息开放给应用客户端, 以使 得所述应用客户端获取并存储所述第一终端标识信息, 并在接收访问请求消 息后, 根据所述第一终端标识信息进行登录认证。  The opening unit is configured to open the first terminal identification information to the application client, so that the application client obtains and stores the first terminal identification information, and after receiving the access request message, according to the The first terminal identification information is used for login authentication.
在第一种可能的实现方式中, 根据第三方面, 所述终端中间件还包含接 收单元;  In a first possible implementation manner, according to the third aspect, the terminal middleware further includes a receiving unit;
所述接收单元, 用于在所述获取单元获取所述终端设备的终端标识信息 后, 所述开放单元将所述第一终端标识信息开放给所述应用客户端之前, 接 收所述应用客户端发送的第一请求消息, 所述第一请求消息请求获取所述第 一终端标识信息。  The receiving unit is configured to: after the acquiring unit acquires the terminal identifier information of the terminal device, the open unit receives the first terminal identifier information to the application client, and receives the application client And sending the first request message, where the first request message requests to acquire the first terminal identifier information.
在第二种可能的实现方式中, 根据第一种可能的实现方式, 所述终端中 间件还包括判断单元、 执行单元;  In a second possible implementation manner, the terminal middleware further includes a determining unit and an executing unit, according to the first possible implementation manner;
所述第一请求消息携带所述应用客户端的第一应用名;  The first request message carries a first application name of the application client;
所述判断单元, 用于在所述接收单元接收所述应用客户端发送的第一请 求消息之后, 根据所述第一应用名, 判断所述应用是否合法; 所述执行单元, 还用于若所述应用合法, 执行将所述第一终端标识信息 开放给应用客户端的步骤。 The determining unit is configured to determine, according to the first application name, whether the application is legal after the receiving unit receives the first request message sent by the application client; The executing unit is further configured to: when the application is legal, perform the step of opening the first terminal identification information to an application client.
在第三种可能的实现方式中, 根据第一种可能的实现方式, 所述终端中 间件还包括判断单元、 请求单元、 存储单元、 执行单元;  In a third possible implementation manner, the terminal middleware further includes a determining unit, a requesting unit, a storage unit, and an executing unit, according to the first possible implementation manner;
所述第一请求消息携带所述应用客户端的第一应用名;  The first request message carries a first application name of the application client;
所述判断单元, 用于在所述接收单元接收所述应用客户端发送的第一请 求消息之后, 根据所述第一应用名, 判断所述应用是否合法;  The determining unit is configured to determine, according to the first application name, whether the application is legal after the receiving unit receives the first request message sent by the application client;
所述判断单元, 还用于若所述应用合法, 根据所述第一应用名判断所述 应用是否首次调用所述第一终端标识信息;  The determining unit is further configured to: determine, according to the first application name, whether the application first invokes the first terminal identification information according to the first application name;
所述请求单元, 用于若所述应用首次调用所述第一终端标识信息, 请求 用户授权向所述应用客户端开放所述第一终端标识信息;  The requesting unit is configured to: if the application first invokes the first terminal identification information, request the user to authorize opening the first terminal identification information to the application client;
所述接收单元,还用于接收用户返回的向所述应用客户端开放所述第一 终端标识信息的 4吏权响应;  The receiving unit is further configured to receive a response to the user that opens the first terminal identification information to the application client.
所述存储单元, 用于保存所述第一应用名和所述第一终端标识信息的对 应关系;  The storage unit is configured to save a correspondence between the first application name and the first terminal identification information;
所述执行单元, 用于执行所述将所述第一终端标识信息开放给应用客户 端的步骤。  The executing unit is configured to perform the step of opening the first terminal identification information to an application client.
在第四种可能的实现方式中, 根据第三种可能的实现方式, 所述请求单 元请求用户授权向所述应用客户端开放所述第一终端标识信息具体包括: 发送认证短信, 请求用户通过输入所述认证短信的内容进行授权; 或  In a fourth possible implementation, according to the third possible implementation, the requesting unit, requesting the user to authorize the opening of the first terminal identification information to the application client, specifically includes: sending an authentication short message, requesting the user to pass Entering the content of the authentication short message for authorization; or
提供授权界面, 请求用户在授权界面进行授权。  Provide an authorization interface and request the user to authorize on the authorization interface.
在第五种可能的实现方式中,根据第三种可能的实现方式或第四种可能 的实现方式, 所述终端中间件还包含检查单元、 发送单元;  In a fifth possible implementation manner, the terminal middleware further includes an checking unit and a sending unit, according to the third possible implementation manner or the fourth possible implementation manner;
所述接收单元,还用于接收所述应用客户端发送的请求认证的第二请求 消息, 所述第二请求消息携带所述应用客户端的第一应用名和所述应用客户 端存储的第一终端标识信息;  The receiving unit is further configured to receive a second request message that is sent by the application client to request authentication, where the second request message carries a first application name of the application client and a first terminal that is stored by the application client. Identification information;
所述检查单元, 用于检查是否存储所述第一应用名和所述应用客户端存 储的第一终端标识信息的对应关系; 所述发送单元, 还用于若存储, 发送认证成功的指示消息给所述应用客 户端, 以使得所述应用客户端根据所述应用客户端存储的第一终端标识信息 打开所述应用客户端的应用。 The checking unit is configured to check whether a correspondence between the first application name and the first terminal identification information stored by the application client is stored; The sending unit is further configured to: if stored, send an indication message that the authentication succeeds to the application client, so that the application client opens the application client according to the first terminal identifier information stored by the application client. application.
在第六种可能的实现方式中, 根据第五种可能的实现方式,  In a sixth possible implementation manner, according to the fifth possible implementation manner,
所述发送单元, 还用于在所述若存储, 发送认证成功的指示消息给所述 应用客户端前,发送预先存储的登录该应用时是否需要登录密码的指示信息 给所述应用客户端;  The sending unit is further configured to send, before the sending, sending the indication message that the authentication succeeds to the application client, the pre-stored indication information of whether the login password is required to log in to the application client;
若存储, 所述发送单元发送认证成功的指示消息给所述应用客户端, 以 使得所述应用客户端根据所述应用客户端存储的第一终端标识信息打开所 述应用客户端的应用具体包括:  If the storage unit sends the indication message that the authentication succeeds to the application client, the application client opens the application of the application client according to the first terminal identifier information stored by the application client, and specifically includes:
若存储, 发送认证成功的指示消息给所述应用客户端, 以使得所述应用 客户端根据所述应用客户端存储的第一终端标识信息和所述是否需要登录 密码的指示信息打开所述应用客户端的应用。  If the storage is sent, the indication message that the authentication succeeds is sent to the application client, so that the application client opens the application according to the first terminal identification information stored by the application client and the indication information of whether the login password is required. Client application.
在第七种可能的实现方式中,根据第三种可能的实现方式至第六种可能 的实现方式, 所述终端中间件还包含生成单元;  In a seventh possible implementation manner, the terminal middleware further includes a generating unit, according to the third possible implementation manner to the sixth possible implementation manner;
所述生成单元, 用于在所述接收单元接收用户返回的向所述应用客户端 开放所述第一终端标识信息的授权响应后,根据所述第一应用名和所述第一 终端标识信息, 釆用高级加密标准 AES, 生成所述第一应用名对应的加密的 第一终端标识信息;  The generating unit, configured to: after receiving, by the receiving unit, an authorization response that is opened by the user to open the first terminal identifier information to the application client, according to the first application name and the first terminal identifier information, Generating the encrypted first terminal identification information corresponding to the first application name by using the advanced encryption standard AES;
所述存储单元保存所述第一应用名和所述第一终端标识信息的对应关 系具体包括:  The storing, by the storage unit, the corresponding relationship between the first application name and the first terminal identification information includes:
保存所述加密的第一终端标识信息和所述第一应用名的对应关系; 所述开放单元将所述第一终端标识信息开放给所述应用客户端具体包 括:  And the corresponding relationship between the encrypted first terminal identifier information and the first application name is saved; the opening, by the open unit, the opening the first terminal identifier information to the application client, specifically includes:
将所述加密的第一终端标识信息开放给所述应用客户端, 以使得所述应 用客户端获取并存储所述加密的第一终端标识信息, 以使得所述应用客户端 存储的第一终端标识信息具体为加密的第一终端标识信息。 在第八种可能的实现方式中,根据第二种可能的实现方式至第七种可能 的实现方式, 所述判断单元根据所述第一应用名, 判断所述应用是否合法具 体包括: Opening the encrypted first terminal identifier information to the application client, so that the application client obtains and stores the encrypted first terminal identifier information, so that the first terminal stored by the application client is used. The identification information is specifically the encrypted first terminal identification information. In an eighth possible implementation manner, according to the second possible implementation manner to the seventh possible implementation manner, the determining, by the determining unit, whether the application is legal according to the first application name, specifically includes:
读取本地数据库信息;  Read local database information;
判断所述本地数据库信息中是否包含所述第一应用名;  Determining whether the first application name is included in the local database information;
若所述本地数据库信息中包含所述第一应用名, 确定所述应用合法; 若所述本地数据库信息中未包含所述第一应用名,向能力开放平台 /应用 商店请求获取所述第一应用名;  If the local database information includes the first application name, determining that the application is legal; if the first application name is not included in the local database information, requesting the capability open platform/app store to obtain the first Application name
若接收到所述能力开放平台 /应用商店发送的所述第一应用名,确定所述 应用合法;  If the first application name sent by the capability open platform/app store is received, determining that the application is legal;
存储所述第一应用名;  Storing the first application name;
若未接收到所述能力开放平台 /应用商店发送的所述第一应用名,确定所 述应用不合法。  If the first application name sent by the capability open platform/app store is not received, it is determined that the application is illegal.
在第九种可能的实现方式中, 根据第三方面至第八种可能的实现方式, 所述终端标识信息具体包括:  In a ninth possible implementation manner, according to the third aspect to the eighth possible implementation, the terminal identifier information specifically includes:
终端设备中用户识别模块 SIM卡的国际移动用户识别码 IMSI;  User identification module in the terminal device, the international mobile subscriber identity of the SIM card IMSI;
和 /或  and / or
终端设备的国际移动终端识别码 IMEI;  International mobile terminal identification code of terminal equipment IMEI;
和 /或  and / or
终端设备的介质访问控制 MAC地址。  The media access control MAC address of the terminal device.
第四方面, 提供一种应用客户端, 所述应用客户端包含接收单元、 登录 认证单元;  The fourth aspect provides an application client, where the application client includes a receiving unit and a login authentication unit.
所述接收单元, 用于接收访问请求消息, 所述访问请求消息请求打开所 述应用客户端的应用;  The receiving unit is configured to receive an access request message, where the access request message requests to open an application of the application client;
所述登录认证单元, 用于根据存储的第一终端标识信息进行登录认证, 以打开所述应用客户端的应用。  The login authentication unit is configured to perform login authentication according to the stored first terminal identifier information to open an application of the application client.
在第一种可能的实现方式中, 根据第四方面, 所述应用客户端还包含判 断单元、 发送单元、 获取单元、 第一存储单元; 所述判断单元, 用于在所述接收单元接收访问请求消息后, 判断是否存 储终端设备的第一终端标识信息; In a first possible implementation manner, according to the fourth aspect, the application client further includes a determining unit, a sending unit, an obtaining unit, and a first storage unit; The determining unit is configured to determine, after the receiving unit receives the access request message, whether to store the first terminal identification information of the terminal device;
所述发送单元, 用于若未存储所述终端设备的第一终端标识信息, 发送 第一请求消息给所述终端中间件, 所述第一请求消息请求获取所述第一终端 标识信息;  The sending unit is configured to: if the first terminal identifier information of the terminal device is not stored, send a first request message to the terminal middleware, where the first request message requests to acquire the first terminal identifier information;
所述获取单元, 用于获取终端中间件开放的所述第一终端标识信息; 所述第一存储单元, 用于存储所述第一终端标识信息。  The acquiring unit is configured to acquire the first terminal identifier information that is open by the terminal middleware, and the first storage unit is configured to store the first terminal identifier information.
在第二种可能的实现方式中, 根据第一种可能的实现方式中, 所述第一 请求消息携带所述应用客户端的第一应用名, 以使得所述终端中间件根据所 述第一应用名, 判断所述应用是否合法, 且所述应用合法时开放所述第一终 端标识信息给所述应用客户端。  In a second possible implementation manner, the first request message carries a first application name of the application client, so that the terminal middleware is configured according to the first application, according to the first possible implementation manner. And determining whether the application is legal, and the first terminal identification information is opened to the application client when the application is legal.
在第三种可能的实现方式中, 根据第一种可能的实现方式, 所述第一请 求消息携带所述应用客户端的第一应用名, 以使得所述终端中间件根据所述 第一应用名, 判断所述应用是否合法, 且所述应用合法时根据所述第一应用 名判断所述应用是否首次调用所述第一终端标识信息,且在确定所述应用是 首次调用所述第一终端标识信息后,请求用户授权向应用客户端开放所述第 一终端标识信息,在接收到用户返回的向所述应用客户端开放所述第一终端 标识信息的授权响应后, 开放所述第一终端标识信息给所述应用客户端。  In a third possible implementation manner, the first request message carries the first application name of the application client, so that the terminal middleware is configured according to the first application name, according to the first possible implementation manner. Determining whether the application is legal, and determining whether the application first invokes the first terminal identification information according to the first application name, and determining that the application is the first call to the first terminal After the information is identified, the user is requested to open the first terminal identification information to the application client, and after receiving the authorization response returned by the user to open the first terminal identification information to the application client, the first The terminal identification information is sent to the application client.
在第四种可能的实现方式中, 根据第四方面至第三种可能的实现方式, 所述登录认证单元根据存储的第一终端标识信息进行登录认证, 以打开所述 应用客户端的应用具体包括:  In a fourth possible implementation manner, the login authentication unit performs login authentication according to the stored first terminal identifier information, to open the application of the application client, specifically, according to the fourth aspect to the third possible implementation manner. :
发送请求认证的第二请求消息给所述终端中间件, 所述第二请求消息携 带所述应用客户端的第一应用名和所述存储的第一终端标识信息, 以使得所 述终端中间件对所述第一应用名和所述存储的第一终端标识信息进行认证; 若接收所述终端中间件发送的认证成功的指示消息, 打开所述应用客户 端的应用。  Sending a second request message requesting authentication to the terminal middleware, where the second request message carries a first application name of the application client and the stored first terminal identification information, so that the terminal middleware is opposite The first application name and the stored first terminal identification information are authenticated; if the indication message of successful authentication sent by the terminal middleware is received, the application of the application client is opened.
在第五种可能的实现方式中, 根据第四种可能的实现方式, 所述应用客 户端还包含第二存储单元; 所述接收单元,还用于接收所述终端中间件发送的登录该应用时是否需 要登录密码的指示信息; In a fifth possible implementation, the application client further includes a second storage unit according to the fourth possible implementation manner; The receiving unit is further configured to receive, by the terminal middleware, indication information about whether a login password is required when logging in to the application;
所述第二存储单元, 用于存储所述是否需要登录密码的指示信息; 所述若接收所述终端中间件发送的认证成功的指示消息,打开所述应用 客户端的应用具体包括:  The second storage unit is configured to store the indication information of whether the password is required to be logged in. If the indication message of the authentication success is sent by the terminal middleware, the application of the application client is specifically:
若接收所述终端中间件发送的认证成功的指示消息,根据所述是否需要 登录密码的指示信息, 确定是否需要登录密码;  And receiving an indication message that the authentication succeeded by the terminal middleware, and determining whether a login password is required according to whether the indication information of the login password is required;
若不需要登录密码,根据所述存储的第一终端标识信息打开所述应用客 户端的应用;  If the login password is not required, the application of the application client is opened according to the stored first terminal identifier information;
若需要登录密码,根据所述存储的第一终端标识信息和输入的登录密码 打开所述应用客户端的应用。  If the login password is required, the application of the application client is opened according to the stored first terminal identification information and the input login password.
在第六种可能的实现方式中,根据第三种可能的实现方式至第五种可能 的实现方式, 所述获取单元获取终端中间件开放的第一终端标识信息具体包 括:  In a sixth possible implementation manner, the obtaining, by the acquiring unit, the first terminal identifier information that is open by the terminal middleware, according to the third possible implementation manner to the fifth possible implementation manner, specifically includes:
获取所述终端中间件开放的加密的第一终端标识信息, 其中, 所述加密 的第一终端标识信息是所述终端中间件根据所述第一应用名和所述第一终 端标识信息, 釆用高级加密标准 AES所生成的;  Acquiring the encrypted first terminal identifier information that is open to the terminal middleware, where the encrypted first terminal identifier information is that the terminal middleware is used according to the first application name and the first terminal identifier information. Generated by the advanced encryption standard AES;
所述存储单元存储所述第一终端标识信息具体包括:  The storing, by the storage unit, the first terminal identifier information specifically includes:
存储所述加密的第一终端标识信息, 以使得所述存储的第一终端标识信 息具体为加密的第一终端标识信息。  And storing the encrypted first terminal identifier information, so that the stored first terminal identifier information is specifically the encrypted first terminal identifier information.
在第七种可能的实现方式中, 根据第四方面至第六种可能的实现方式, 所述终端标识信息具体包括:  In a seventh possible implementation manner, according to the fourth to sixth possible implementation manners, the terminal identifier information specifically includes:
终端设备中 SIM卡的国际移动用户识别码 IMSI;  The international mobile subscriber identity of the SIM card in the terminal device IMSI;
和 /或  and / or
终端设备的国际移动终端识别码 IMEI;  International mobile terminal identification code of terminal equipment IMEI;
和 /或  and / or
终端设备的介质访问控制 MAC地址。  The media access control MAC address of the terminal device.
第五方面, 提供一种身份识别的系统, 所述身份识别的系统包终端中间 件和应用客户端; 所述终端中间件, 用于获取终端设备的终端标识信息, 其中, 所述终端 标识信息至少包含第一终端标识信息; In a fifth aspect, a system for identifying an identity, the system terminal terminal middleware and an application client; The terminal middleware is configured to acquire terminal identification information of the terminal device, where the terminal identification information includes at least first terminal identification information;
所述终端中间件, 还用于将所述第一终端标识信息开放给应用客户端, 以使得所述应用客户端获取并存储所述第一终端标识信息;  The terminal middleware is further configured to: open the first terminal identification information to the application client, so that the application client obtains and stores the first terminal identification information;
所述应用客户端, 用于接收访问请求消息, 所述访问请求消息请求打开 所述应用客户端的应用;  The application client is configured to receive an access request message, where the access request message requests to open an application of the application client;
所述应用客户端, 还用于根据存储的第一终端标识信息进行登录认证, 以打开所述应用客户端的应用。  The application client is further configured to perform login authentication according to the stored first terminal identification information to open an application of the application client.
本发明实施例提供一种身份识别的方法、 装置和系统, 所述方法包括在 终端中间件获取终端设备的终端标识信息, 其中, 所述终端标识信息至少包 含第一终端标识信息后, 将所述第一终端标识信息开放给应用客户端; 应用 客户端在接收访问请求消息后, 根据存储的第一终端标识信息进行登录认 证, 以打开所述应用客户端的应用。  An embodiment of the present invention provides a method, an apparatus, and a system for identifying an identity, where the method includes acquiring, by a terminal middleware, terminal identification information of a terminal device, where the terminal identification information includes at least the first terminal identification information, The first terminal identifier information is opened to the application client. After receiving the access request message, the application client performs login authentication according to the stored first terminal identifier information to open the application of the application client.
基于上述实施例的描述, 通过在登录终端设备的应用时, 釆用第一终端 标识信息进行身份认证的方法, 解决了用户登录终端设备上的应用时, 需要 记忆用户名和密码的问题, 同时将所述第一终端标识信息作为用户登录终端 设备上的应用的唯一标识, 提升了用户登录终端设备上的应用的安全性。 附图说明  Based on the description of the foregoing embodiment, when the application of the terminal device is logged in, the method for authenticating the first terminal identification information is used to solve the problem that the user needs to memorize the user name and password when logging in to the application on the terminal device. The first terminal identification information is used as a unique identifier of the application that the user logs in to the terminal device, which improves the security of the application that the user logs in to the terminal device. DRAWINGS
为了更清楚地说明本发明实施例或现有技术中的技术方案, 下面将对实 施例或现有技术描述中所需要使用的附图作简单地介绍, 显而易见地, 下面 描述中的附图仅仅是本发明的一些实施例, 对于本领域普通技术人员来讲, 在不付出创造性劳动性的前提下, 还可以根据这些附图获得其他的附图。  In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings used in the embodiments or the description of the prior art will be briefly described below. Obviously, the drawings in the following description are only It is a certain embodiment of the present invention, and other drawings can be obtained from those skilled in the art without any inventive labor.
图 1为本发明实施例提供的一种身份识别的方法;  FIG. 1 is a schematic diagram of an identity recognition method according to an embodiment of the present invention;
图 2为本发明实施例提供的另一种身份识别的方法;  2 is another method for identity recognition according to an embodiment of the present invention;
图 3为本发明实施例提供的又一种身份识别的方法;  FIG. 3 is still another method for identity recognition according to an embodiment of the present invention;
图 4为本发明实施例提供的又一种身份识别的方法;  FIG. 4 is still another method for identity recognition according to an embodiment of the present invention;
图 5为本发明实施例提供的又一种身份识别的方法;  FIG. 5 is still another method for identity recognition according to an embodiment of the present invention;
图 6为本发明实施例提供的一种授权界面示意图;  FIG. 6 is a schematic diagram of an authorization interface according to an embodiment of the present invention;
图 7为本发明实施例提供的又一种身份识别的方法; 图 8为本发明实施例提供的又一种身份识别的方法; FIG. 7 is still another method for identity recognition according to an embodiment of the present invention; FIG. 8 is still another method for identity recognition according to an embodiment of the present invention;
图 9为本发明实施例提供的一种终端中间件;  FIG. 9 is a terminal middleware according to an embodiment of the present invention;
图 10为本发明实施例提供的另一种终端中间件;  FIG. 10 is another terminal middleware according to an embodiment of the present invention;
图 11为本发明实施例提供的又一种终端中间件;  FIG. 11 is still another terminal middleware according to an embodiment of the present invention;
图 12为本发明实施例提供的又一种终端中间件;  FIG. 12 is still another terminal middleware according to an embodiment of the present invention;
图 13为本发明实施例提供的又一种终端中间件;  FIG. 13 is still another terminal middleware according to an embodiment of the present invention;
图 14为本发明实施例提供的又一种终端中间件;  FIG. 14 is still another terminal middleware according to an embodiment of the present invention;
图 15为本发明实施例提供的一种应用客户端;  FIG. 15 is an application client according to an embodiment of the present invention;
图 16为本发明实施例提供的一种应用客户端;  FIG. 16 is an application client according to an embodiment of the present invention;
图 17为本发明实施例提供的一种应用客户端;  FIG. 17 is an application client according to an embodiment of the present invention;
图 18为本发明实施例提供的一种终端中间件;  FIG. 18 is a terminal middleware according to an embodiment of the present invention;
图 19为本发明实施例提供的另一种终端中间件;  FIG. 19 is another terminal middleware according to an embodiment of the present invention;
图 20为本发明实施例提供的又一种终端中间件;  FIG. 20 is still another terminal middleware according to an embodiment of the present invention;
图 21为本发明实施例提供的又一种终端中间件;  FIG. 21 is still another terminal middleware according to an embodiment of the present invention;
图 22为本发明实施例提供的一种身份识别系统。  FIG. 22 is an identification system according to an embodiment of the present invention.
具体实施方式 detailed description
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行 清楚、 完整地描述, 显然, 所描述的实施例仅仅是本发明一部分实施例, 而 不是全部的实施例。 基于本发明中的实施例, 本领域普通技术人员在没有作 出创造性劳动前提下所获得的所有其他实施例, 都属于本发明保护的范围。  The technical solutions in the embodiments of the present invention are clearly and completely described in the following with reference to the accompanying drawings in the embodiments of the present invention. It is obvious that the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments. All other embodiments obtained by a person of ordinary skill in the art based on the embodiments of the present invention without creative efforts are within the scope of the present invention.
实施例一、  Embodiment 1
本发明实施例提供一种身份识别的方法, 所述方法应用于终端中间件, 具体如图 1所示, 所述方法包括:  An embodiment of the present invention provides a method for identity identification, where the method is applied to a terminal middleware, as shown in FIG. 1 , the method includes:
101、 获取终端设备的终端标识信息, 其中, 所述终端标识信息至少包 含第一终端标识信息。  101. Obtain terminal identification information of the terminal device, where the terminal identification information includes at least first terminal identification information.
具体的, 所述终端设备的终端标识信息可以为终端设备中 SIM(Subscriber Identity Module , 客户识别模块)卡的 IMSI ( International Mobile Subscriberldentification Number, 国际移动用户识别码 )和 /或终端设 备的 IMEI ( International Mobile Equipment Identity, 国际移动终端识别码 ) 和 /或终端设备的 MAC ( Media Access Control, 介质访问控制)地址, 本发 明实施例对此不作具体限定。 Specifically, the terminal identifier information of the terminal device may be an IMSI (International Mobile Subscriber Identification Number) and/or a terminal design of a SIM (Subscriber Identity Module) card in the terminal device. The IMEI (International Mobile Equipment Identity) and/or the MAC (Media Access Control) address of the terminal device are not specifically limited in this embodiment of the present invention.
其中, 所述终端标识信息至少包含第一终端标识信息。  The terminal identifier information includes at least first terminal identifier information.
需要说明的是, 终端中间件可能获取多个终端标识信息, 所述第一终端 标识信息中的 "第一" 不具有任何特殊的含义, 仅指代终端中间件获取的终 端标识信息中的其中一个终端标识信息。  It should be noted that the terminal middleware may acquire multiple terminal identification information, and the “first” in the first terminal identification information does not have any special meaning, and only refers to the terminal identification information acquired by the terminal middleware. A terminal identification information.
102、 将所述第一终端标识信息开放给应用客户端, 以使得所述应用客 户端获取并存储所述第一终端标识信息, 并在接收访问请求消息后, 根据所 述第一终端标识信息进行登录认证。  102. The first terminal identifier information is opened to the application client, so that the application client obtains and stores the first terminal identifier information, and after receiving the access request message, according to the first terminal identifier information. Perform login authentication.
具体的,将所述第一终端标识信息开放给应用客户端可能是由终端设备 的配置决定。 例如, 下述两个场景下第一终端标识信息的配置:  Specifically, opening the first terminal identifier information to the application client may be determined by the configuration of the terminal device. For example, the configuration of the first terminal identification information in the following two scenarios:
场景一,用户在不同终端设备使用同一张 SIM卡,则可以配置国际移动 用户识别码 IMSI作为第一终端标识信息。  In scenario 1, if the user uses the same SIM card on different terminal devices, the international mobile subscriber identity code IMSI can be configured as the first terminal identifier information.
场景二、  Scene 2,
用户换 SIM卡而不换终端设备, 或者是无 SIM卡的终端设备(例如 iPad ), 则可以釆用国际移动终端识别码 IMEI或者介质访问控制 MAC地址 作为第一终端标识信息。  If the user changes the SIM card without changing the terminal device, or a terminal device without a SIM card (for example, iPad), the international mobile terminal identification code IMEI or the medium access control MAC address may be used as the first terminal identification information.
当然, 所述终端中间件在获取终端标识信息后, 除了根据终端设备的配 置将所述第一终端标识信息开放给应用客户端,也可能在用户触发应用客户 端时, 所述应用客户端判断未存储所述终端设备的第一终端标识信息后, 发 送第一请求消息给所述终端中间件, 请求获取所述第一终端标识信息, 以使 得所述终端中间件开放所述第一终端标识信息给所述应用客户端。 此种情况 下, 所述终端中间件可能直接将所述第一终端标识信息开放给所述应用客户 端; 也可能是所述终端中间件判断所述应用是否合法, 确定所述应用合法后 才开放所述第一终端标识信息给应用客户端; 或者是所述终端中间件在判断 所述应用是否合法, 确定所述应用合法且得到用户授权后才开放所述第一终 端标识信息给应用客户端。 本发明实施例对此不作具体限定, 仅说明所述终 端中间件在获取终端标识信息后,还将所述第一终端标识信息开放给应用客 户端, 这样应用客户端将获取并存储所述第一终端标识信息, 在接收访问请 求消息后, 可以根据所述第一终端标识信息进行登录认证。 因此提高了用户 登录终端设备上的应用的安全性, 同时避免了用户登录终端设备上的应用 时, 需要记忆用户名和密码的问题。 Of course, after obtaining the terminal identification information, the terminal middleware may open the first terminal identification information to the application client according to the configuration of the terminal device, or the application client may determine when the user triggers the application client. After the first terminal identifier information of the terminal device is not stored, the first request message is sent to the terminal middleware, and the first terminal identifier information is requested to be obtained, so that the terminal middleware opens the first terminal identifier. Information to the application client. In this case, the terminal middleware may directly open the first terminal identification information to the application client; or the terminal middleware may determine whether the application is legal, and determine that the application is legal. Opening the first terminal identification information to the application client; or the terminal middleware is configured to open the first terminal identification information to the application client after determining whether the application is legal, determining that the application is legal and authorized by the user end. The embodiment of the present invention does not specifically limit this, and only describes that the terminal middleware opens the first terminal identification information to the application client after acquiring the terminal identification information. The client, so that the application client obtains and stores the first terminal identifier information, and after receiving the access request message, may perform login authentication according to the first terminal identifier information. Therefore, the security of the application that the user logs in to the terminal device is improved, and the problem that the user name and password need to be memorized when the user logs in to the application on the terminal device is avoided.
本发明实施例还提供一种身份识别的方法, 所述方法应用于应用客户 端, 具体如图 2所示, 所述方法包括:  The embodiment of the present invention further provides a method for the identity identification, where the method is applied to an application client, as shown in FIG. 2, the method includes:
201、 接收访问请求消息, 所述访问请求消息请求打开所述应用客户端 的应用。  201. Receive an access request message, where the access request message requests to open an application of the application client.
具体的,当用户触发应用客户端后,所述应用客户端接收访问请求消息, 所述访问请求消息请求打开所述应用客户端的应用。  Specifically, after the user triggers the application client, the application client receives an access request message, and the access request message requests to open an application of the application client.
202、 根据存储的第一终端标识信息进行登录认证, 以打开所述应用客 户端的应用。  202. Perform login authentication according to the stored first terminal identifier information to open an application of the application client.
具体的, 所述第一终端标识信息可能是在接收访问请求消息前已经存储 在所述应用客户端, 也可能是应用客户端在接收访问请求消息后, 判断未存 储终端设备的第一终端标识信息后,从终端中间件中获取所述第一终端标识 信息后, 存储到所述应用客户端, 本发明实施例对此不作具体限定。  Specifically, the first terminal identifier information may be stored in the application client before receiving the access request message, or the application client may determine, after receiving the access request message, the first terminal identifier of the terminal device not stored. After the information is obtained, the first terminal identifier information is obtained from the terminal middleware, and then stored in the application client, which is not specifically limited in this embodiment of the present invention.
考虑到终端设备可能有多个应用客户端, 为了区分每个应用客户端对应 不同的终端标识信息, 终端中间件可以根据应用客户端的第一应用名和第一 终端标识信息, 釆用高级加密标准 AES, 生成所述第一应用名对应的加密的 第一终端标识信息, 所以所述存储的第一终端标识信息可以是加密后的第一 终端标识信息, 也可以是未加密的第一终端标识信息, 本发明实施例对此不 作具体限定, 仅依据实际情况而定。  Considering that the terminal device may have multiple application clients, in order to distinguish the different terminal identification information corresponding to each application client, the terminal middleware may use the advanced encryption standard AES according to the first application name and the first terminal identification information of the application client. And generating the encrypted first terminal identifier information corresponding to the first application name, so the stored first terminal identifier information may be the encrypted first terminal identifier information, or may be the unencrypted first terminal identifier information. The embodiment of the present invention does not specifically limit this, and only depends on actual conditions.
所述根据存储的第一终端标识信息进行登录认证, 以打开所述应用客户 端的应用具体可以包括:  The application for performing the login authentication according to the stored first terminal identifier information to open the application client may include:
发送请求认证的第二请求消息给所述终端中间件, 所述第二请求消息携 带所述应用客户端的第一应用名和所述存储的第一终端标识信息, 以使得所 述终端中间件对所述第一应用名和所述存储的第一终端标识信息进行认证; 若接收所述终端中间件发送的认证成功的指示消息, 打开所述应用客户 端的应用。 具体的, 所述应用客户端可能接收终端中间件发送的登录该应用时是否 需要登录密码的指示信息, 所述打开所述应用客户端的应用的方法可以依据 所述指示信息决定, 包括: Sending a second request message requesting authentication to the terminal middleware, where the second request message carries a first application name of the application client and the stored first terminal identification information, so that the terminal middleware is opposite The first application name and the stored first terminal identification information are authenticated; if the indication message of successful authentication sent by the terminal middleware is received, the application of the application client is opened. Specifically, the application client may receive the indication information of whether the login password is required to log in to the application, and the method for opening the application of the application client may be determined according to the indication information, including:
根据所述指示信息, 确定是否需要登录密码;  Determining whether a login password is required according to the indication information;
若不需要登录密码,根据所述存储的第一终端标识信息打开所述应用客 户端的应用;  If the login password is not required, the application of the application client is opened according to the stored first terminal identifier information;
若需要登录密码,根据所述存储的第一终端标识信息和输入的登录密码 打开所述应用客户端的应用。  If the login password is required, the application of the application client is opened according to the stored first terminal identification information and the input login password.
当然, 上述仅是示例性的给出一种打开所述应用客户端的应用的方法, 还可能存储其它打开所述应用客户端的应用的方法, 本发明实施例对此不作 具体限定。  Of course, the foregoing is merely illustrative of a method for opening an application of the application client, and may also store other methods for opening an application of the application client, which is not specifically limited in the embodiment of the present invention.
本发明实施例提供一种身份识别的方法, 所述方法包括: 在终端中间件 获取终端设备的终端标识信息, 其中, 所述终端标识信息至少包含第一终端 标识信息后, 将所述第一终端标识信息开放给应用客户端; 应用客户端在接 收访问请求消息后, 根据存储的第一终端标识信息进行登录认证, 以打开所 述应用客户端的应用。  An embodiment of the present invention provides a method for identity identification, where the method includes: acquiring terminal identification information of a terminal device in a terminal middleware, where the terminal identification information includes at least first terminal identification information, and the first The terminal identifier information is opened to the application client. After receiving the access request message, the application client performs login authentication according to the stored first terminal identifier information to open the application of the application client.
基于上述实施例的描述, 通过在登录终端设备的应用时, 釆用第一终端 标识信息进行身份认证的方法, 解决了用户登录终端设备上的应用时, 需要 记忆用户名和密码的问题, 同时提高了用户登录终端设备上的应用的安全 性。  Based on the description of the foregoing embodiment, when the application of the terminal device is logged in, the method for authenticating the first terminal identification information is used to solve the problem that the user needs to memorize the user name and password when the user logs in to the application on the terminal device. The security of the application that the user logs in to the terminal device.
实施例二、  Embodiment 2
本发明实施例提供一种身份识别的方法, 所述方法基于终端中间件和应 用客户端, 以所述应用客户端未存储终端设备的第一终端标识信息时的情况 进行说明, 具体如图 3所示, 在所述终端中间件获取终端设备的终端标识信 息后, 所述方法包括:  An embodiment of the present invention provides a method for identity identification, where the method is based on a terminal middleware and an application client, where the application client does not store the first terminal identification information of the terminal device, as shown in FIG. 3 The method includes: after the terminal middleware acquires the terminal identifier information of the terminal device, the method includes:
301、 应用客户端接收访问请求消息, 所述访问请求消息请求打开所述 应用客户端的应用。  301. The application client receives an access request message, where the access request message requests to open an application of the application client.
具体的,当用户触发应用客户端后,所述应用客户端接收访问请求消息, 所述访问请求消息请求打开所述应用客户端的应用。 302、 应用客户端判断是否存储所述终端设备的第一终端标识信息。 具体的, 当所述应用客户端接收访问请求消息后, 首先判断是否已经存 储所述终端设备的第一终端标识信息。 Specifically, after the user triggers the application client, the application client receives an access request message, and the access request message requests to open an application of the application client. 302. The application client determines whether to store the first terminal identifier information of the terminal device. Specifically, after the application client receives the access request message, it first determines whether the first terminal identifier information of the terminal device has been stored.
若所述应用客户端已存储所述终端设备的第一终端标识信息,执行步骤 308;  If the application client has stored the first terminal identification information of the terminal device, step 308 is performed;
若所述应用客户端未存储所述终端设备的第一终端标识信息,执行步骤 If the application client does not store the first terminal identifier information of the terminal device, perform the step
303。 303.
303、 若未存储所述终端设备的第一终端标识信息, 发送第一请求消息 给所述终端中间件, 所述第一请求消息请求获取所述第一终端标识信息。  303. If the first terminal identifier information of the terminal device is not stored, send a first request message to the terminal middleware, where the first request message requests to acquire the first terminal identifier information.
具体的, 所述第一请求消息请求获取所述第一终端标识信息。  Specifically, the first request message requests to acquire the first terminal identification information.
304、 终端中间件接收所述应用客户端发送的所述第一请求消息。  304. The terminal middleware receives the first request message sent by the application client.
305、 终端中间件将所述第一终端标识信息开放给应用客户端。  305. The terminal middleware opens the first terminal identification information to the application client.
具体的, 考虑到终端设备上应用客户端的多样性, 当某一应用客户端接 收访问请求消息, 判断未存储终端设备的终端标识信息时, 向所述终端中间 件发送第一请求消息,触发所述终端中间件将所述第一终端标识信息开放给 所述应用客户端。  Specifically, in consideration of the diversity of the application client on the terminal device, when an application client receives the access request message and determines that the terminal identifier information of the terminal device is not stored, the first request message is sent to the terminal middleware, and the triggering device is triggered. The terminal middleware opens the first terminal identification information to the application client.
因为所述第一终端标识信息是所述应用客户端所请求的, 因此将所述第 一终端信息开放给应用客户端后, 所述应用客户端获取所述第一终端标识信 息, 并在接收访问请求消息后, 根据所述第一终端标识信息进行登录认证, 防止了终端中间件开放给应用客户端的终端标识信息与所述应用客户端所 需的终端标识信息不匹配的问题。  After the first terminal identification information is requested by the application client, after the first terminal information is opened to the application client, the application client acquires the first terminal identification information, and receives After the request message is accessed, the login authentication is performed according to the first terminal identifier information, which prevents the terminal middleware from opening the problem that the terminal identifier information of the application client does not match the terminal identifier information required by the application client.
306、 应用客户端获取终端中间件开放的所述第一终端标识信息。  306. The application client acquires the first terminal identifier information that is open by the terminal middleware.
307、 应用客户端存储所述第一终端标识信息。  307. The application client stores the first terminal identifier information.
具体的, 所述应用客户端存储所述第一终端标识信息, 以使得所述应用 客户端在根据所述第一终端标识信息进行登录认证后,打开所述应用客户端 的应用。  Specifically, the application client stores the first terminal identifier information, so that the application client opens the application of the application client after performing login authentication according to the first terminal identifier information.
具体的, 考虑到终端设备可能有多个应用客户端, 为了区分每个应用客 户端对应不同的终端标识信息, 终端中间件可以根据应用客户端的第一应用 名和第一终端标识信息, 釆用高级加密标准 AES, 生成所述第一应用名对应 的加密的第一终端标识信息, 所以所述存储的第一终端标识信息可以是加密 后的第一终端标识信息, 也可以是未加密的第一终端标识信息, 本发明实施 例对此不作具体限定, 仅依据实际情况而定。 Specifically, in consideration of the fact that the terminal device may have multiple application clients, in order to distinguish different application terminal identification information, the terminal middleware may use the first application name and the first terminal identification information of the application client to use advanced Encrypting standard AES, generating the first application name corresponding The encrypted first terminal identifier information, so the stored first terminal identifier information may be the encrypted first terminal identifier information, or may be the unencrypted first terminal identifier information, which is not specifically described in this embodiment of the present invention. Limited, only based on actual conditions.
308、 应用客户端根据所述第一终端标识信息进行登录认证, 以打开所 述应用客户端的应用。  308. The application client performs login authentication according to the first terminal identifier information to open an application of the application client.
具体的, 所述根据存储的第一终端标识信息进行登录认证, 以打开所述 应用客户端的应用具体可以包括:  Specifically, the application for performing the login authentication according to the stored first terminal identifier information to open the application client may include:
发送请求认证的第二请求消息给所述终端中间件, 所述第二请求消息携 带所述应用客户端的第一应用名和所述存储的第一终端标识信息, 以使得所 述终端中间件对所述第一应用名和所述存储的第一终端标识信息进行认证; 若接收所述终端中间件发送的认证成功的指示消息, 打开所述应用客户 端的应用。  Sending a second request message requesting authentication to the terminal middleware, where the second request message carries a first application name of the application client and the stored first terminal identification information, so that the terminal middleware is opposite The first application name and the stored first terminal identification information are authenticated; if the indication message of successful authentication sent by the terminal middleware is received, the application of the application client is opened.
具体的, 所述应用客户端可能接收终端中间件发送的登录该应用时的是 否需要登录密码的指示信息, 所述打开所述应用客户端的应用的方法可以依 据所述指示信息决定, 包括:  Specifically, the application client may receive the indication information of the login password that is sent by the terminal middleware, and the method for opening the application of the application client may be determined according to the indication information, including:
根据所述指示信息, 确定是否需要登录密码;  Determining whether a login password is required according to the indication information;
若不需要登录密码,根据所述存储的第一终端标识信息打开所述应用客 户端的应用;  If the login password is not required, the application of the application client is opened according to the stored first terminal identifier information;
若需要登录密码,根据所述存储的第一终端标识信息和输入的登录密码 打开所述应用客户端的应用。  If the login password is required, the application of the application client is opened according to the stored first terminal identification information and the input login password.
当然, 上述仅是示例性的给出一种打开所述应用客户端的应用的方法, 还可能存储其它打开所述应用客户端的应用的方法, 本发明实施例对此不作 具体限定。  Of course, the foregoing is merely illustrative of a method for opening an application of the application client, and may also store other methods for opening an application of the application client, which is not specifically limited in the embodiment of the present invention.
进一步的, 本发明实施例还提供一种身份识别的方法, 所述方法基于终 端中间件和应用客户端, 以判断所述应用合法后, 终端设备才发送所述第一 终端标识信息进行说明, 具体如图 4所示, 在所述终端中间件获取终端设备 的终端标识信息后, 所述方法包括:  Further, the embodiment of the present invention further provides a method for identity identification, where the method is based on the terminal middleware and the application client, to determine that the application is legal, the terminal device sends the first terminal identification information for description. Specifically, as shown in FIG. 4, after the terminal middleware acquires the terminal identifier information of the terminal device, the method includes:
401、 应用客户端接收访问请求消息, 所述访问请求消息请求打开所述 应用客户端的应用。 具体的,当用户触发应用客户端后,所述应用客户端接收访问请求消息, 所述访问请求消息请求打开所述应用客户端的应用。 401. The application client receives an access request message, where the access request message requests to open an application of the application client. Specifically, after the user triggers the application client, the application client receives an access request message, and the access request message requests to open an application of the application client.
402、 应用客户端判断是否存储所述终端设备的第一终端标识信息。 具体的, 当所述应用客户端接收访问请求消息后, 首先判断是否已经存 储所述终端设备的第一终端标识信息。  402. The application client determines whether to store the first terminal identifier information of the terminal device. Specifically, after the application client receives the access request message, it first determines whether the first terminal identification information of the terminal device has been stored.
若所述应用客户端已存储所述终端设备的第一终端标识信息,执行步骤 If the application client has stored the first terminal identifier information of the terminal device, perform the step
409; 409;
若所述应用客户端未存储所述终端设备的第一终端标识信息,执行步骤 If the application client does not store the first terminal identifier information of the terminal device, perform the step
403。 403.
403、 若未存储所述终端设备的第一终端标识信息, 发送第一请求消息 给所述终端中间件, 所述第一请求消息请求获取所述第一终端标识信息, 其 中, 所述第一请求消息携带所述应用客户端的第一应用名。  403. If the first terminal identifier information of the terminal device is not stored, send a first request message to the terminal middleware, and the first request message requests to acquire the first terminal identifier information, where the first The request message carries the first application name of the application client.
具体的, 所述应用客户端在加载在终端设备上时, 会首先在某一应用平 台进行注册, 获取第一应用名, 其中, 所述第一应用名中的 "第一" 不具有 任何特殊的含义, 仅指代当前接收访问请求消息的应用客户端的应用名。  Specifically, when the application client is loaded on the terminal device, the first application name is obtained by registering on an application platform, where the first application name does not have any special The meaning of the application only refers to the application name of the application client that currently receives the access request message.
404、 终端中间件接收所述应用客户端发送的所述第一请求消息。  404. The terminal middleware receives the first request message sent by the application client.
405、 终端中间件根据所述第一应用名, 判断所述应用是否合法。  405. The terminal middleware determines, according to the first application name, whether the application is legal.
具体的, 所述根据所述第一应用名, 判断所述应用是否合法具体可以包 括:  Specifically, determining, according to the first application name, whether the application is legal or not may include:
读取本次数据库信息;  Read this database information;
判断所述本地数据库信息中是否包含所述第一应用名;  Determining whether the first application name is included in the local database information;
若所述本地数据库信息中包含所述第一应用名, 确定所述应用合法; 若所述第一数据库信息中未包含所述第一应用名,向能力开放平台 /应用 商店请求获取所述第一应用名;  If the first application name is included in the local database information, determining that the application is legal; if the first application name is not included in the first database information, requesting the capability open platform/app store to obtain the first An application name;
若接收到所述能力开放平台 /应用商店发送的所述第一应用名,确定所述 应用合法;  If the first application name sent by the capability open platform/app store is received, determining that the application is legal;
存储所述第一应用名;  Storing the first application name;
若未接收到所述能力开放平台 /应用商店发送的所述第一应用名,确定所 述应用不合法。 需要说明的是, 如果 SP ( Service Provider, 应用提供商) /CP(Content Provider内容提供商)的应用在能力开放平台 /应用商店进行注册,说明该应用 是合法的。 所以若所述第一数据库信息中未包含所述第一应用名, 向能力开 放平台 /应用商店请求获取所述第一应用名时,若该应用是合法的,则能力开 放平台 /应用商店中应包含该应用注册时,分配给该应用的唯一标识信息, 即 应用名。 If the first application name sent by the capability open platform/app store is not received, it is determined that the application is illegal. It should be noted that if the application of the SP (Service Provider) / CP (Content Provider Content Provider) is registered in the capability open platform/app store, the application is legal. Therefore, if the first application name is not included in the first database information, and the capability open platform/app store requests to obtain the first application name, if the application is legal, the capability open platform/app store It should contain the unique identifying information assigned to the app when it is registered, ie the app name.
因此若接收到所述能力开放平台 /应用商店发送的所述第一应用名,确定 所述应用合法;若未接收到所述能力开放平台 /应用商店发送的所述第一应用 名,说明该应用并未在所述能力开放平台 /应用商店进行注册,确定所述应用 不合法。 不作具体限定。  Therefore, if the first application name sent by the capability open platform/app store is received, the application is determined to be legal; if the first application name sent by the capability open platform/app store is not received, the The application is not registered with the capability open platform/app store, and the application is determined to be illegal. No specific limitation.
406、 若所述应用合法, 终端中间件将所述第一终端标识信息开放给应 用客户端。 信息开放给所述应用客户端, 增加了访问应用的安全性。  406. If the application is legal, the terminal middleware opens the first terminal identification information to the application client. The information is opened to the application client, which increases the security of accessing the application.
407、 应用客户端获取终端中间件开放的所述第一终端标识信息。  407. The application client acquires the first terminal identifier information that is open by the terminal middleware.
408、 应用客户端存储所述第一终端标识信息。  408. The application client stores the first terminal identifier information.
具体的, 所述应用客户端存储所述第一终端标识信息, 以使得所述应用 客户端在根据所述第一终端标识信息进行登录认证后,打开所述应用客户端 的应用。  Specifically, the application client stores the first terminal identifier information, so that the application client opens the application of the application client after performing login authentication according to the first terminal identifier information.
具体的, 考虑到终端设备可能有多个应用客户端, 为了区分每个应用客 户端对应不同的终端标识信息, 终端中间件可以根据应用客户端的第一应用 名和第一终端标识信息, 釆用高级加密标准 AES, 生成所述第一应用名对应 的加密的第一终端标识信息, 所以所述存储的第一终端标识信息可以是加密 后的第一终端标识信息, 也可以是未加密的第一终端标识信息, 本发明实施 例对此不作具体限定, 仅依据实际情况而定。  Specifically, in consideration of the fact that the terminal device may have multiple application clients, in order to distinguish different application terminal identification information, the terminal middleware may use the first application name and the first terminal identification information of the application client to use advanced The encryption standard AES is configured to generate the encrypted first terminal identifier information corresponding to the first application name, so the stored first terminal identifier information may be the encrypted first terminal identifier information, or may be the first unencrypted information. The terminal identification information is not specifically limited in this embodiment of the present invention, and is determined only according to actual conditions.
409、 应用客户端根据所述第一终端标识信息进行登录认证, 以打开所 述应用客户端的应用。 具体的, 所述根据存储的第一终端标识信息进行登录认证, 以打开所述 应用客户端的应用具体可以包括: 409. The application client performs login authentication according to the first terminal identifier information to open an application of the application client. Specifically, the application for performing the login authentication according to the stored first terminal identifier information to open the application client may include:
发送请求认证的第二请求消息给所述终端中间件, 所述第二请求消息携 带所述应用客户端的第一应用名和所述存储的第一终端标识信息, 以使得所 述终端中间件对所述第一应用名和所述存储的第一终端标识信息进行认证; 若接收所述终端中间件发送的认证成功的指示消息, 打开所述应用客户 端的应用。  Sending a second request message requesting authentication to the terminal middleware, where the second request message carries a first application name of the application client and the stored first terminal identification information, so that the terminal middleware is opposite The first application name and the stored first terminal identification information are authenticated; if the indication message of successful authentication sent by the terminal middleware is received, the application of the application client is opened.
具体的, 所述应用客户端可能接收终端中间件发送的是否需要登录密码 的指示信息, 所述打开所述应用客户端的应用的方法可以依据所述指示信息 决定, 包括:  Specifically, the application client may receive the indication information of whether the login password is required to be sent by the terminal middleware, and the method for opening the application of the application client may be determined according to the indication information, including:
根据所述指示信息, 确定是否需要登录密码;  Determining whether a login password is required according to the indication information;
若不需要登录密码,根据所述存储的第一终端标识信息打开所述应用客 户端的应用;  If the login password is not required, the application of the application client is opened according to the stored first terminal identifier information;
若需要登录密码,根据所述存储的第一终端标识信息和输入的登录密码 打开所述应用客户端的应用。  If the login password is required, the application of the application client is opened according to the stored first terminal identification information and the input login password.
当然, 上述仅是示例性的给出一种打开所述应用客户端的应用的方法, 还可能存储其它打开所述应用客户端的应用的方法, 本发明实施例对此不作 具体限定。  Of course, the foregoing is merely illustrative of a method for opening an application of the application client, and may also store other methods for opening an application of the application client, which is not specifically limited in the embodiment of the present invention.
可选的, 本发明实施例还提供一种身份识别的方法, 所述方法基于终端 中间件和应用客户端, 具体以判断所述应用合法且用户授权后, 终端设备才 发送所述第一终端标识信息进行说明, 具体如图 5所示, 在所述终端中间件 获取终端设备的终端标识信息后, 所述方法包括:  Optionally, the embodiment of the present invention further provides a method for identity identification, where the method is based on the terminal middleware and the application client, and specifically, after determining that the application is legal and the user authorizes, the terminal device sends the first terminal. The identification information is described. Specifically, as shown in FIG. 5, after the terminal middleware acquires terminal identification information of the terminal device, the method includes:
501、 应用客户端接收访问请求消息, 所述访问请求消息请求打开所述 应用客户端的应用。  501. The application client receives an access request message, where the access request message requests to open an application of the application client.
具体的,当用户触发应用客户端后,所述应用客户端接收访问请求消息, 所述访问请求消息请求打开所述应用客户端的应用。  Specifically, after the user triggers the application client, the application client receives an access request message, and the access request message requests to open an application of the application client.
502、 应用客户端判断是否存储所述终端设备的第一终端标识信息。 具体的, 当所述应用客户端接收访问请求消息后, 首先判断是否已经存 储所述终端设备的第一终端标识信息。 若所述应用客户端已存储所述终端设备的第一终端标识信息,执行步骤502. The application client determines whether to store the first terminal identifier information of the terminal device. Specifically, after the application client receives the access request message, it first determines whether the first terminal identifier information of the terminal device has been stored. If the application client has stored the first terminal identifier information of the terminal device, perform the step
514; 514;
若所述应用客户端未存储所述终端设备的第一终端标识信息,执行步骤 If the application client does not store the first terminal identifier information of the terminal device, perform the step
503。 503.
503、 若未存储所述终端设备的第一终端标识信息, 发送第一请求消息 给所述终端中间件, 所述第一请求消息请求获取所述第一终端标识信息, 其 中, 所述第一请求消息携带所述应用客户端的第一应用名。  503. If the first terminal identifier information of the terminal device is not stored, send a first request message to the terminal middleware, and the first request message requests to acquire the first terminal identifier information, where the first The request message carries the first application name of the application client.
具体的, 所述应用客户端在加载在终端设备上时, 会首先在某一应用平 台进行注册, 获取第一应用名, 其中, 所述第一应用名中的 "第一" 不具有 任何特殊的含义, 仅指代当前接收访问请求消息的应用客户端的应用名。  Specifically, when the application client is loaded on the terminal device, the first application name is obtained by registering on an application platform, where the first application name does not have any special The meaning of the application only refers to the application name of the application client that currently receives the access request message.
504、 终端中间件接收所述应用客户端发送的所述第一请求消息。  504. The terminal middleware receives the first request message sent by the application client.
505、 终端中间件根据所述第一应用名, 判断所述应用是否合法。  505. The terminal middleware determines, according to the first application name, whether the application is legal.
具体的, 所述终端中间件根据所述第一应用名, 判断所述应用是否合法 的方法可参考步骤 405的描述, 本发明实施例对此不再赘述。  Specifically, the method for the terminal middleware to determine whether the application is legal according to the first application name may refer to the description of step 405, which is not repeatedly described in the embodiment of the present invention.
506、 若所述应用合法, 终端中间件根据所述第一应用名判断所述应用 是否首次调用所述第一终端标识信息。  506. If the application is legal, the terminal middleware determines, according to the first application name, whether the application first invokes the first terminal identification information.
具体的, 终端中间件中可能存储了应用名与该应用名对应的应用调用终 端标识信息的次数的对应关系,故可以根据所述第一应用名判断所述应用是 否首次调用所述第一终端标识信息。  Specifically, the terminal middleware may store the correspondence between the application name and the number of times the application corresponding to the terminal identifier information is called by the application name, so it may be determined, according to the first application name, whether the application first invokes the first terminal. Identification information.
若所述应用是首次调用所述第一终端标识信息, 执行步骤 507;  If the application is to call the first terminal identification information for the first time, go to step 507;
若所述应用不是首次调用所述第一终端标识信息, 执行步骤 511。  If the application does not invoke the first terminal identification information for the first time, step 511 is performed.
507、 若所述应用首次调用所述第一终端标识信息, 终端中间件请求用 户授权向所述应用客户端开放所述第一终端标识信息。  507. If the application first invokes the first terminal identifier information, the terminal middleware requests the user to authorize opening the first terminal identifier information to the application client.
具体的, 所述终端中间件请求用户授权向所述应用客户端开放所述第一 终端标识信息具体可以包括:  Specifically, the terminal middleware requesting the user to authorize the opening of the first terminal identifier information to the application client may include:
发送认证短信, 请求应用通过输入所述认证短信的内容进行授权; 或  Sending an authentication short message, requesting the application to authorize by inputting the content of the authentication short message; or
提供授权界面, 请求应用在授权界面进行授权。  Provide an authorization interface and request the application to authorize on the authorization interface.
当然, 所述终端中间件请求用户授权向所述应用客户端开放所述第一终 端标识信息的方法可能有多种, 本发明实施例对此不作具体限定。 Of course, the terminal middleware requests the user to authorize opening the first terminal to the application client. There may be a plurality of methods for identifying information at the end, which is not specifically limited in the embodiment of the present invention.
508、 用户进行第一终端标识信息 权。  508. The user performs the first terminal identification information right.
具体的, 终端中间件可以提供如图 6所示的 4受权界面, 用户可以通过设 置授权界面的内容进行用户信息的授权。  Specifically, the terminal middleware can provide a 4 authorized interface as shown in FIG. 6, and the user can authorize the user information by setting the content of the authorization interface.
需要说明的是, 为了向不同安全级别的应用提供差异化服务, 可以向不 同类型的应用客户端提供分级服务 SLA ( Service-Level Agreement, 服务等 级协议)。 例如可以通过设置授权界面的内容, 使得授权界面上包含用户登 录时是否需要登录密码的选项, 对于安全性不高的应用客户端, 用户可以授 权在登录时不需要密码, 仅需第一终端标识信息认证成功即可登录应用, 例 如新闻等工具。 对于少部分安全性要求非常高的应用客户端, 用户可以授权 在登录时输入密码, 需第一终端标识信息和密码同时认证成功后才可登录应 用, 类似银行的 USB 密钥, 终端标识信息作为账号, 用户需要输入密码才 能正确登录, 例如银行 /证券客户端、 支付宝客户端等。 当然, 是否需要登录 密码的选项不一定包含在授权界面上, 本发明实施例仅是给出一种授权界面 的图示, 对授权界面的具体内容不作具体限定, 仅要求授权界面至少支持第 一终端标识信息的授权。  It should be noted that in order to provide differentiated services to applications of different security levels, a service-level agreement (SLA) can be provided to different types of application clients. For example, you can set the content of the authorization interface so that the authorization interface contains the option of whether the user needs to log in to the password when logging in. For an application client with low security, the user can authorize the password without login, and only the first terminal identifier is required. If the information is successfully authenticated, you can log in to the application, such as news and other tools. For a small number of application clients with very high security requirements, the user can authorize the password input at login. The first terminal identification information and password must be authenticated before logging in to the application. Similar to the bank's USB key and terminal identification information. Account number, the user needs to enter a password to log in correctly, such as bank/securities client, Alipay client, etc. Certainly, the option of the login password is not necessarily included in the authorization interface. The embodiment of the present invention only provides an illustration of the authorization interface, and the specific content of the authorization interface is not specifically limited. Authorization of terminal identification information.
另一方面, 对于某些应用客户端, 如果用户有多个账号而需要更换登陆 账号信息, 可以在终端中间件 "我的授权设置" 里面取消应用名和终端标识 信息的绑定, 在下次应用客户端调用接口时重新进行授权, 从而应用客户端 也将更新到新的账号。  On the other hand, for some application clients, if the user has multiple accounts and need to change the login account information, you can unbind the application name and terminal identification information in the terminal middleware "My authorization settings", and apply the client next time. When the interface is called, the authorization is re-authorized, so that the application client will also update to the new account.
当然, 要解决用户有多个账号而需要更换登陆账号信息的问题, 除了设 置授权界面, 还可以通过其它的方法实现, 例如在应用客户端提供的登录界 面上, 把终端标识信息和新的账号进行关联绑定。 本发明实施例对此不作具 体限定。  Of course, to solve the problem that the user has multiple accounts and need to change the login account information, in addition to setting the authorization interface, it can also be implemented by other methods, for example, on the login interface provided by the application client, the terminal identification information and the new account. Make association bindings. This embodiment of the present invention does not specifically limit this.
509、 用户返回向所述应用客户端开放所述第一终端标识信息的 4受权响 应。  509. The user returns a 4 authorized response that opens the first terminal identification information to the application client.
510、 接收用户返回的向所述应用客户端开放所述第一终端标识信息的 授权响应。  510. Receive an authorization response returned by the user to open the first terminal identifier information to the application client.
511、 终端中间件将所述第一终端标识信息开放给应用客户端。 具体的, 本发明实施例中在判断所述应用合法, 并且用户授权向应用客 户端发送第一终端标识信息时, 才将所述第一终端标识信息开放给所述应用 客户端, 由于经过了用户的授权, 进一步增加了访问应用的安全性。 511. The terminal middleware opens the first terminal identification information to the application client. Specifically, in the embodiment of the present invention, when it is determined that the application is legal, and the user is authorized to send the first terminal identification information to the application client, the first terminal identification information is opened to the application client, The user's authorization further increases the security of the access application.
512、 应用客户端获取终端中间件开放的所述第一终端标识信息。  512. The application client acquires the first terminal identifier information that is open by the terminal middleware.
513、 应用客户端存储所述第一终端标识信息。  513. The application client stores the first terminal identifier information.
具体的, 所述应用客户端存储所述第一终端标识信息, 以使得所述应用 客户端在根据所述第一终端标识信息进行登录认证后,打开所述应用客户端 的应用。  Specifically, the application client stores the first terminal identifier information, so that the application client opens the application of the application client after performing login authentication according to the first terminal identifier information.
具体的, 在经过用户授权后, 终端中间件还将保存该应用客户端如下配 置信息:  Specifically, after being authorized by the user, the terminal middleware also saves the following configuration information of the application client:
Figure imgf000026_0001
Figure imgf000026_0001
514、 应用客户端根据所述第一终端标识信息进行登录认证, 以打开所 述应用客户端的应用。  514. The application client performs login authentication according to the first terminal identifier information to open an application of the application client.
进一步的, 当用户授权终端中间件向应用客户端开放第一终端标识信息 后, 所述应用客户端存储所述第一终端标识信息, 所述应用客户端根据存储 的第一终端标识信息进行登录认证时, 所述终端中间件与所述应用客户端之 间的交互如图 7所示, 包括:  Further, after the user authorization terminal middleware opens the first terminal identification information to the application client, the application client stores the first terminal identification information, and the application client logs in according to the stored first terminal identification information. During authentication, the interaction between the terminal middleware and the application client is as shown in FIG. 7, and includes:
701、 所述应用客户端发送请求认证的第二请求消息给所述终端中间件, 所述第二请求消息携带所述应用客户端的第一应用名和所述存储的第一终 端标识信息。  701. The application client sends a second request message requesting authentication to the terminal middleware, where the second request message carries a first application name of the application client and the stored first terminal identifier information.
具体的, 所述第二请求消息携带的所述应用客户端的第一应用名和所述 存储的第一终端标识信息用于登录认证。  Specifically, the first application name of the application client and the stored first terminal identifier information carried by the second request message are used for login authentication.
702、终端中间件接收所述应用客户端发送的请求认证的第二请求消息。  702. The terminal middleware receives the second request message that is sent by the application client to request authentication.
703、 终端中间件检查是否存储所述第一应用名和所述应用客户端存储 的第一终端标识信息的对应关系。  703. The terminal middleware checks whether a correspondence between the first application name and the first terminal identifier information stored by the application client is stored.
具体的, 若所述终端中间件存储了所述第一应用名和所述应用客户端存 储的第一终端标识信息的对应关系, 说明认证成功, 执行步骤 704; Specifically, if the terminal middleware stores the first application name and the application client Corresponding relationship of the stored first terminal identification information, indicating that the authentication is successful, and performing step 704;
若所述终端中间件未存储所述第一应用名和所述应用客户端存储的第 一终端标识信息的对应关系, 说明认证未通过, 则登录失败。  If the terminal middleware does not store the correspondence between the first application name and the first terminal identification information stored by the application client, indicating that the authentication fails, the login fails.
704、 若存储, 发送认证成功的指示消息给所述应用客户端。  704. If stored, send an indication message that the authentication succeeds to the application client.
705、 应用客户端接收所述终端中间件发送的认证成功的指示消息。 705. The application client receives an indication message that the terminal middleware sends the authentication success.
706、 应用客户端根据所述存储的第一终端标识信息打开所述应用客户 端的应用。 706. The application client opens an application of the application client according to the stored first terminal identifier information.
具体的, 在认证成功后, 所述应用客户端根据所述存储的第一终端标识 信息打开所述应用客户端的应用。 不需要用户记忆用户名和密码, 同时提高 了用户登录终端设备上的应用的安全性。  Specifically, after the authentication succeeds, the application client opens the application of the application client according to the stored first terminal identifier information. The user is not required to memorize the username and password, and the security of the application on the user's login terminal device is improved.
进一步的,登录该应用时是否需要登录密码的指示信息可能预先配置在 所述终端中间件中。  Further, the indication information of whether the login password is required when logging in to the application may be pre-configured in the terminal middleware.
具体的, 在如图 6所示的授权界面中, 可以包含登录该应用时是否需要 登录密码的选项, 即登录该应用时是否需要登录密码的指示信息预先配置在 所述终端中间件中。  Specifically, the authorization interface shown in FIG. 6 may include an option of whether a login password is required to log in to the application, that is, whether the login password is required to log in to the application is pre-configured in the terminal middleware.
在所述若存储, 发送认证成功的指示消息给所述应用客户端前, 所述方 法还包括:  The method further includes: before the sending, sending the indication message that the authentication succeeds to the application client, the method further includes:
终端中间件发送预先存储的登录该应用时是否需要登录密码的指示信 息给所述应用客户端;  The terminal middleware sends a pre-stored indication information of whether the login password is required to log in to the application client to the application client;
应用客户端接收所述终端中间件发送的所述登录该应用时是否需要登 录密码的指示信息并存储。  The application client receives the indication information of whether the password is required to be logged in when the login is sent by the terminal middleware and stores the information.
这种情况下, 所述应用客户端根据存储的第一终端标识信息进行登录认 证时,所述终端中间件与所述应用客户端之间的交互具体如图 8所示,包括: 801、 所述应用客户端发送请求认证的第二请求消息给所述终端中间件, 所述第二请求消息携带所述应用客户端的第一应用名和所述存储的第一终 端标识信息。  In this case, when the application client performs login authentication according to the stored first terminal identification information, the interaction between the terminal middleware and the application client is specifically as shown in FIG. 8, and includes: 801, The application client sends a second request message for requesting authentication to the terminal middleware, where the second request message carries the first application name of the application client and the stored first terminal identification information.
具体的, 所述第二请求消息携带的所述应用客户端的第一应用名和所述 存储的第一终端标识信息用于登录认证。  Specifically, the first application name of the application client and the stored first terminal identifier information carried by the second request message are used for login authentication.
802、终端中间件接收所述应用客户端发送的请求认证的第二请求消息。 -21-802. The terminal middleware receives the second request message that is sent by the application client and requests authentication. -twenty one-
803、 终端中间件检查是否存储所述第一应用名和所述应用客户端存储 的第一终端标识信息的对应关系。 803. The terminal middleware checks whether a correspondence between the first application name and the first terminal identifier information stored by the application client is stored.
具体的, 若所述终端中间件存储了所述第一应用名和所述应用客户端存 储的第一终端标识信息的对应关系, 说明认证成功, 执行步骤 804;  Specifically, if the terminal middleware stores the correspondence between the first application name and the first terminal identification information stored by the application client, indicating that the authentication is successful, step 804 is performed;
若所述终端中间件未存储所述第一应用名和所述应用客户端存储的第 一终端标识信息的对应关系, 说明认证未通过, 则登录失败。  If the terminal middleware does not store the correspondence between the first application name and the first terminal identification information stored by the application client, indicating that the authentication fails, the login fails.
804、 若存储, 发送认证成功的指示消息给所述应用客户端。  804. If stored, send an indication message that the authentication succeeds to the application client.
805、 接收所述终端中间件发送的认证成功的指示消息。  805. Receive an indication message that the terminal middleware sends the authentication success.
806、 根据存储的登录该应用时是否需要登录密码的指示信息, 确定是 否需要登录密码。  806. Determine, according to the stored indication information that the login password is required to log in to the application, whether the login password is required.
具体的, 因为所述应用客户端存储了登录该应用时是否需要登录密码的 指示信息, 故此时可以首先确定是否需要登录密码。  Specifically, because the application client stores indication information about whether a login password is required when logging in to the application, it may be determined at this time whether a login password is required.
807、 若不需要登录密码, 根据所述存储的第一终端标识信息打开所述 应用客户端的应用。  807. If the login password is not required, open the application of the application client according to the stored first terminal identifier information.
808、 若需要登录密码, 根据所述存储的第一终端标识信息和输入的登 录密码打开所述应用客户端的应用。  808. If a login password is required, open the application of the application client according to the stored first terminal identification information and the input login password.
具体的, 本发明实施例根据存储的是否需要登录密码的指示信息, 向用 户提供了不同安全级别的解决方案。 对于安全性不高的应用客户端, 用户可 以在登录时不需要密码, 仅需第一终端标识信息认证成功即可登录应用, 例 如新闻等工具。 对于少部分安全性要求非常高的应用客户端, 用户可以在登 录时输入密码, 需第一终端标识信息和密码同时认证成功后才可登录应用, 类似银行的 USB 密钥, 终端标识信息作为账号, 用户需要输入密码才能正 确登录, 例如银行 /证券客户端、 支付宝客户端等。 通过上述方法, 满足了用 户多样化的需求。  Specifically, the embodiment of the present invention provides a solution for different security levels to the user according to the stored indication information of whether the login password is required. For an application client with low security, the user can log in without using a password. Only the first terminal identification information can be successfully authenticated to log in to the application, such as news and other tools. For a small number of application clients with very high security requirements, users can enter a password when logging in. The first terminal identification information and password must be authenticated before they can log in to the application. Similar to the bank's USB key and terminal identification information as an account. Users need to enter a password to log in correctly, such as bank/securities client, Alipay client, etc. Through the above methods, the diversified needs of users are met.
进一步的,在所述终端中间件接收用户返回的向所述应用客户端提供所 述终端标识信息的 4吏权响应后, 还包括:  Further, after the terminal middleware receives the response from the user that provides the terminal identification information to the application client, the terminal middleware further includes:
终端中间件根据所述第一应用名和所述第一终端标识信息, 釆用高级加 密标准 AES, 生成所述第一应用名对应的加密的第一终端标识信息。  The terminal middleware generates the encrypted first terminal identification information corresponding to the first application name by using the advanced encryption standard AES according to the first application name and the first terminal identification information.
所述保存所述第一应用名和所述第一终端标识信息的对应关系具体包 括: And storing the corresponding relationship between the first application name and the first terminal identifier information Includes:
保存所述加密的第一终端标识信息和所述第一应用名的对应关系; 所述将所述第一终端标识信息开放给所述应用客户端具体包括: 将所述加密的第一终端标识信息开放给所述应用客户端。  Saving the correspondence between the encrypted first terminal identifier information and the first application name; the opening the first terminal identifier information to the application client specifically includes: the encrypted first terminal identifier The information is open to the application client.
对应的,应用客户端获取所述终端中间件开放的加密的第一终端标识信 息;  Correspondingly, the application client obtains the encrypted first terminal identification information that is open by the terminal middleware;
所述应用客户端存储所述第一终端标识信息具体包括:  The storing, by the application client, the first terminal identifier information specifically includes:
存储所述加密的第一终端标识信息。  And storing the encrypted first terminal identification information.
具体的, 考虑到终端设备可能有多个应用客户端, 为了区分每个应用客 户端对应不同的终端标识信息, 终端中间件可以根据应用客户端的第一应用 名和第一终端标识信息, 釆用高级加密标准 AES, 生成所述第一应用名对应 的加密的第一终端标识信息。 另外, 所述应用客户端存储所述加密的第一终 端标识信息, 使得后续的身份识别过程中, 应用客户端和终端中间件之间通 过加密后的第一终端标识信息进行通讯,保证了终端设备的物理信息以及用 户的个人信息的安全性。  Specifically, in consideration of the fact that the terminal device may have multiple application clients, in order to distinguish different application terminal identification information, the terminal middleware may use the first application name and the first terminal identification information of the application client to use advanced The encryption standard AES generates the encrypted first terminal identification information corresponding to the first application name. In addition, the application client stores the encrypted first terminal identification information, so that in the subsequent identity identification process, the application client and the terminal middleware communicate with each other through the encrypted first terminal identification information, thereby ensuring the terminal. The physical information of the device and the security of the user's personal information.
基于上述实施例的描述, 通过获取终端设备的终端标识信息, 将所述终 端标识信息中的第一终端标识信息开放给应用客户端,使得所述应用客户端 获取并存储所述第一终端标识信息, 并在接收访问请求消息后, 根据所述第 一终端标识信息进行登录认证的技术方案,解决了用户登录终端设备上的应 用时, 需要记忆用户名和密码的问题, 同时将所述第一终端标识信息作为用 户登录终端设备上的应用的唯一标识,提升了用户登录终端设备上的应用的 安全性。  Based on the description of the foregoing embodiment, the first terminal identifier information in the terminal identifier information is opened to the application client by acquiring the terminal identifier information of the terminal device, so that the application client obtains and stores the first terminal identifier. The information, and after receiving the access request message, the technical solution for performing login authentication according to the first terminal identification information, which solves the problem that the user needs to memorize the user name and password when logging in to the application on the terminal device, and the first The terminal identification information is used as the unique identifier of the application that the user logs in to the terminal device, which improves the security of the application that the user logs in to the terminal device.
实施例三、  Embodiment 3
本发明实施例提供一种终端中间件 900, 具体如图 9所示, 所述终端中 间件 900包括获取单元 901、 开放单元 902。  The embodiment of the present invention provides a terminal middleware 900. Specifically, as shown in FIG. 9, the terminal middleware 900 includes an obtaining unit 901 and an opening unit 902.
所述获取单元 901, 用于获取终端设备的终端标识信息, 其中, 所述终 端标识信息至少包含第一终端标识信息。  The obtaining unit 901 is configured to acquire terminal identification information of the terminal device, where the terminal identifier information includes at least first terminal identifier information.
所述开放单元 902, 用于将所述第一终端标识信息开放给应用客户端, 以使得所述应用客户端获取并存储所述第一终端标识信息, 并在接收访问请 求消息后, 根据所述第一终端标识信息进行登录认证。 The opening unit 902 is configured to open the first terminal identification information to the application client, so that the application client obtains and stores the first terminal identification information, and receives the access request. After the message is obtained, login authentication is performed according to the first terminal identification information.
进一步的, 如图 10所示, 所述终端中间件 900还包含接收单元 903。 所述接收单元 903, 用于在所述获取单元 901获取所述终端设备的终端 标识信息后, 所述开放单元 902将所述第一终端标识信息开放给所述应用客 户端之前, 接收所述应用客户端发送的第一请求消息, 所述第一请求消息请 求获取所述第一终端标识信息。  Further, as shown in FIG. 10, the terminal middleware 900 further includes a receiving unit 903. The receiving unit 903 is configured to: after the acquiring unit 901 acquires the terminal identifier information of the terminal device, the opening unit 902 receives the first terminal identifier information before the application client is opened, and receives the The first request message sent by the client is requested, and the first request message requests to acquire the first terminal identifier information.
进一步的, 如图 11所示, 所述终端中间件 900还包括判断单元 904、执 行单元 905。  Further, as shown in FIG. 11, the terminal middleware 900 further includes a determining unit 904 and an executing unit 905.
所述第一请求消息携带所述应用客户端的第一应用名。  The first request message carries a first application name of the application client.
所述判断单元 904, 用于在所述接收单元 903接收所述应用客户端发送 的第一请求消息后, 根据所述第一应用名, 判断所述应用是否合法;  The determining unit 904 is configured to determine, according to the first application name, whether the application is legal after the receiving unit 903 receives the first request message sent by the application client;
所述执行单元 905, 还用于若所述应用合法, 执行将所述第一终端标识 信息开放给应用客户端的步骤。  The executing unit 905 is further configured to: if the application is legal, perform the step of opening the first terminal identification information to an application client.
可选的, 如图 12所示, 所述终端中间件 900还包括判断单元 904、 请求 单元 906、 存储单元 907、 执行单元 905。  Optionally, as shown in FIG. 12, the terminal middleware 900 further includes a determining unit 904, a requesting unit 906, a storage unit 907, and an executing unit 905.
所述第一请求消息携带所述应用客户端的第一应用名;  The first request message carries a first application name of the application client;
所述判断单元 904, 用于在所述接收单元 903接收所述应用客户端发送 的第一请求消息之后, 根据所述第一应用名, 判断所述应用是否合法。  The determining unit 904 is configured to determine, according to the first application name, whether the application is legal after the receiving unit 903 receives the first request message sent by the application client.
所述判断单元 904, 还用于若所述应用合法, 根据所述第一应用名判断 所述应用是否首次调用所述第一终端标识信息。  The determining unit 904 is further configured to: determine, according to the first application name, whether the application first invokes the first terminal identification information according to the first application name.
所述请求单元 906, 用于若所述应用首次调用所述第一终端标识信息, 请求用户授权向所述应用客户端开放所述第一终端标识信息。  The requesting unit 906 is configured to request the user to open the first terminal identification information to the application client if the application first invokes the first terminal identification information.
所述接收单元 903, 用于接收用户返回的向所述应用客户端开放所述第 一终端标识信息的 4吏权响应;  The receiving unit 903 is configured to receive, by the user, a response to the application of the first terminal identifier information to the application client.
所述存储单元 907, 用于保存所述第一应用名和所述第一终端标识信息 的对应关系;  The storage unit 907 is configured to save a correspondence between the first application name and the first terminal identifier information.
所述执行单元 905, 用于执行所述将所述第一终端标识信息开放给应用 客户端的步骤。  The executing unit 905 is configured to perform the step of opening the first terminal identification information to an application client.
进一步的, 所述请求单元 906请求用户授权向所述应用客户端开放所述 第一终端标识信息具体包括: Further, the requesting unit 906 requests the user to authorize the opening of the application to the application client. The first terminal identification information specifically includes:
发送认证短信, 请求用户通过输入所述认证短信的内容进行授权; 或  Sending an authentication short message, requesting the user to authorize by inputting the content of the authentication short message; or
提供授权界面, 请求用户在授权界面进行授权。  Provide an authorization interface and request the user to authorize on the authorization interface.
进一步的, 如图 13所示, 所述终端中间件还包含检查单元 908、发送单 元 909。  Further, as shown in FIG. 13, the terminal middleware further includes an checking unit 908 and a sending unit 909.
所述接收单元 903, 还用于接收所述应用客户端发送的请求认证的第二 请求消息, 所述第二请求消息携带所述应用客户端的第一应用名和所述应用 客户端存储的第一终端标识信息;  The receiving unit 903 is further configured to receive a second request message that is sent by the application client to request authentication, where the second request message carries a first application name of the application client and a first stored by the application client. Terminal identification information;
所述检查单元 908, 用于检查是否存储所述第一应用名和所述应用客户 端存储的第一终端标识信息的对应关系;  The checking unit 908 is configured to check whether a correspondence between the first application name and the first terminal identification information stored by the application client is stored.
所述发送单元 909, 还用于若存储, 发送认证成功的指示消息给所述应 用客户端, 以使得所述应用客户端根据所述应用客户端存储的第一终端标识 信息打开所述应用客户端的应用。  The sending unit 909 is further configured to: if stored, send an indication message that the authentication succeeds to the application client, so that the application client opens the application client according to the first terminal identifier information stored by the application client. End application.
进一步的, 所述发送单元 909, 还用于在所述若存储, 发送认证成功的 指示消息给所述应用客户端前,发送预先存储的登录该应用时是否需要登录 密码的指示信息给所述应用客户端。  Further, the sending unit 909 is further configured to send, before the sending, sending the indication message that the authentication succeeds to the application client, the pre-stored indication information of whether the login password is required to log in to the application to the Application client.
若存储,所述发送单元 909发送认证成功的指示消息给所述应用客户端, 以使得所述应用客户端根据所述应用客户端存储的第一终端标识信息打开 所述应用客户端的应用具体包括:  If the information is sent, the sending unit 909 sends an indication message that the authentication succeeds to the application client, so that the application client opens the application of the application client according to the first terminal identifier information stored by the application client, including :
若存储, 发送认证成功的指示消息给所述应用客户端, 以使得所述应用 客户端根据所述应用客户端存储的第一终端标识信息和所述是否需要登录 密码的指示信息打开所述应用客户端的应用。  If the storage is sent, the indication message that the authentication succeeds is sent to the application client, so that the application client opens the application according to the first terminal identification information stored by the application client and the indication information of whether the login password is required. Client application.
进一步的, 如图 14所示, 所述终端中间件还包含生成单元 910。  Further, as shown in FIG. 14, the terminal middleware further includes a generating unit 910.
所述生成单元 910, 用于在所述接收单元 903接收用户返回的向所述应 用客户端开放所述第一终端标识信息的授权响应后,根据所述第一应用名和 所述第一终端标识信息, 釆用高级加密标准 AES, 生成所述第一应用名对应 的加密的第一终端标识信息。  The generating unit 910 is configured to: after receiving, by the receiving unit 903, an authorization response that is opened by the user to open the first terminal identifier information to the application client, according to the first application name and the first terminal identifier The information is generated by using the advanced encryption standard AES to generate the encrypted first terminal identification information corresponding to the first application name.
所述存储单元 907保存所述第一应用名和所述第一终端标识信息的对应 关系具体包括: The storage unit 907 stores the correspondence between the first application name and the first terminal identification information. The relationship specifically includes:
保存所述加密的第一终端标识信息和所述第一应用名的对应关系; 所述开放单元 902将所述第一终端标识信息开放给所述应用客户端具体 包括:  And the corresponding relationship between the first terminal identifier information and the first application name is saved; the opening, the 902, the opening, the 902, the
将所述加密的第一终端标识信息开放给所述应用客户端, 以使得所述应 用客户端获取并存储所述加密的第一终端标识信息, 以使得所述应用客户端 存储的第一终端标识信息具体为加密的第一终端标识信息。  Opening the encrypted first terminal identifier information to the application client, so that the application client obtains and stores the encrypted first terminal identifier information, so that the first terminal stored by the application client is used. The identification information is specifically the encrypted first terminal identification information.
进一步的, 所述判断单元 904根据所述第一应用名, 判断所述应用是否 合法具体包括:  Further, the determining unit 904, according to the first application name, determining whether the application is legal or not specifically includes:
读取本地数据库信息。  Read local database information.
判断所述本地数据库信息中是否包含所述第一应用名。  Determining whether the first application name is included in the local database information.
若所述本地数据库信息中包含所述第一应用名, 确定所述应用合法。 若所述本地数据库信息中未包含所述第一应用名,向能力开放平台 /应用 商店请求获取所述第一应用名。  If the first application name is included in the local database information, it is determined that the application is legal. If the first application name is not included in the local database information, the capability open platform/app store is requested to acquire the first application name.
若接收到所述能力开放平台 /应用商店发送的所述第一应用名,确定所述 应用合法。  If the first application name sent by the capability open platform/app store is received, it is determined that the application is legal.
存储所述第一应用名。  The first application name is stored.
若未接收到所述能力开放平台 /应用商店发送的所述第一应用名,确定所 述应用不合法。  If the first application name sent by the capability open platform/app store is not received, it is determined that the application is illegal.
进一步的, 所述终端标识信息具体包括:  Further, the terminal identifier information specifically includes:
终端设备中用户识别模块 SIM卡的国际移动用户识别码 IMSI;  User identification module in the terminal device, the international mobile subscriber identity of the SIM card IMSI;
和 /或  and / or
终端设备的国际移动终端识别码 IMEI;  International mobile terminal identification code of terminal equipment IMEI;
和 /或  and / or
终端设备的介质访问控制 MAC地址。  The media access control MAC address of the terminal device.
具体的,通过所述终端中间件进行身份识别的方法可参考实施例一和实 施例二的描述, 本发明实施例对此不再赘述。  Specifically, the method for performing identity identification by using the terminal middleware can refer to the descriptions of the first embodiment and the second embodiment, and details are not described herein again.
基于上述实施例的描述, 本发明提供的终端中间件包括获取单元、 开放 单元。 所述获取单元用于获取终端设备的终端标识信息, 其中, 所述终端标 识信息至少包含第一终端标识信息, 所述开放单元用于将所述第一终端标识 信息开放给应用客户端, 以使得所述应用客户端获取并存储所述第一终端标 识信息, 并在接收访问请求消息后, 根据所述第一终端标识信息进行登录认 证, 本发明实施例提供的终端中间件解决了用户登录终端设备上的应用时, 需要记忆用户名和密码的问题, 同时提高了用户登录终端设备上的应用的安 全性。 Based on the description of the above embodiments, the terminal middleware provided by the present invention includes an acquisition unit and an open unit. The acquiring unit is configured to acquire terminal identification information of the terminal device, where the terminal identifier The information includes at least the first terminal identification information, where the open unit is configured to open the first terminal identification information to the application client, so that the application client obtains and stores the first terminal identification information, and After receiving the access request message, performing login authentication according to the first terminal identifier information, the terminal middleware provided by the embodiment of the present invention solves the problem that the user name and password need to be memorized when the user logs in to the application on the terminal device, and the user is improved at the same time. Log in to the security of the app on the terminal device.
实施例四、  Embodiment 4
本发明实施例提供一种应用客户端 1500, 具体如图 15所示, 所述应用 客户端 1500包括接收单元 1501、 登录认证单元 1502。  The embodiment of the present invention provides an application client 1500. Specifically, as shown in FIG. 15, the application client 1500 includes a receiving unit 1501 and a login authentication unit 1502.
所述接收单元 1501,用于接收访问请求消息, 所述访问请求消息请求打 开所述应用客户端的应用。  The receiving unit 1501 is configured to receive an access request message, where the access request message requests to open an application of the application client.
所述登录认证单元 1502,用于根据存储的第一终端标识信息进行登录认 证, 以打开所述应用客户端的应用。  The login authentication unit 1502 is configured to perform login authentication according to the stored first terminal identification information to open an application of the application client.
具体的, 所述第一终端标识信息可能是在所述接收单元 1501接收访问 请求消息前已经存储在所述应用客户端, 也可能是所述接收单元 1501在接 收访问请求消息后, 判断未存储终端设备的第一终端标识信息后, 从终端中 间件中获取所述第一终端标识信息后, 存储到所述应用客户端, 本发明实施 例对此不作具体限定。  Specifically, the first terminal identifier information may be stored in the application client before the receiving unit 1501 receives the access request message, or may be determined by the receiving unit 1501 not to store after receiving the access request message. After the first terminal identifier information of the terminal device is obtained, the first terminal identifier information is obtained from the terminal middleware, and then stored in the application client, which is not specifically limited in this embodiment of the present invention.
进一步的, 如图 16所示, 所述应用客户端还包含判断单元 1503、 发送 单元 1504、 获取单元 1505、 第一存储单元 1506。  Further, as shown in FIG. 16, the application client further includes a determining unit 1503, a sending unit 1504, an obtaining unit 1505, and a first storage unit 1506.
所述判断单元 1503, 用于在所述接收单元 1501接收访问请求消息后, 判断是否存储终端设备的第一终端标识信息。  The determining unit 1503 is configured to determine, after the receiving unit 1501 receives the access request message, whether to store the first terminal identification information of the terminal device.
所述发送单元 1504, 用于若未存储所述终端设备的第一终端标识信息, 发送第一请求消息给所述终端中间件, 所述第一请求消息请求获取所述第一 终端标识信息。  The sending unit 1504 is configured to: if the first terminal identifier information of the terminal device is not stored, send a first request message to the terminal middleware, where the first request message requests to acquire the first terminal identifier information.
所述获取单元 1505, 用于获取终端中间件开放的所述第一终端标识信 息。  The obtaining unit 1505 is configured to acquire the first terminal identification information that is open by the terminal middleware.
所述第一存储单元 1505, 用于存储所述第一终端标识信息。  The first storage unit 1505 is configured to store the first terminal identification information.
进一步的, 所述第一请求消息携带所述应用客户端的第一应用名, 以使 得所述终端中间件根据所述第一应用名, 判断所述应用是否合法, 且所述应 用合法时开放所述第一终端标识信息给所述应用客户端。 Further, the first request message carries a first application name of the application client, so that The terminal middleware determines whether the application is legal according to the first application name, and the first terminal identification information is opened to the application client when the application is legal.
可选的, 所述第一请求消息携带所述应用客户端的第一应用名, 以使得 所述终端中间件根据所述第一应用名, 判断所述应用是否合法, 且所述应用 合法时根据所述第一应用名判断所述应用是否首次调用所述第一终端标识 信息, 且在确定所述应用是首次调用所述第一终端标识信息后, 请求用户授 权向应用客户端开放所述第一终端标识信息, 在接收到用户返回的向所述应 用客户端开放所述第一终端标识信息的授权响应后, 开放所述第一终端标识 信息给所述应用客户端。  Optionally, the first request message carries the first application name of the application client, so that the terminal middleware determines whether the application is legal according to the first application name, and the application is legal according to the The first application name determines whether the application first invokes the first terminal identification information, and after determining that the application is the first time to invoke the first terminal identification information, requesting the user to authorize opening the first to the application client. The terminal identification information is: after receiving the authorization response returned by the user to open the first terminal identification information to the application client, the first terminal identification information is opened to the application client.
进一步的, 所述登录认证单元 1502根据存储的第一终端标识信息进行 登录认证, 以打开所述应用客户端的应用具体包括:  Further, the login authentication unit 1502 performs login authentication according to the stored first terminal identifier information, to open the application of the application client, specifically:
发送请求认证的第二请求消息给所述终端中间件, 所述第二请求消息携 带所述应用客户端的第一应用名和所述存储的第一终端标识信息, 以使得所 述终端中间件对所述第一应用名和所述存储的第一终端标识信息进行认证。  Sending a second request message requesting authentication to the terminal middleware, where the second request message carries a first application name of the application client and the stored first terminal identification information, so that the terminal middleware is opposite The first application name and the stored first terminal identification information are authenticated.
若接收所述终端中间件发送的认证成功的指示消息, 打开所述应用客户 端的应用。  If the indication message of successful authentication sent by the terminal middleware is received, the application of the application client is opened.
进一步的, 如图 17所示, 所述应用客户端还包含第二存储单元 1507。 所述接收单元 1501,还用于接收所述终端中间件发送的登录该应用时是 否需要登录密码的指示信息。  Further, as shown in FIG. 17, the application client further includes a second storage unit 1507. The receiving unit 1501 is further configured to receive, by the terminal middleware, indication information that a login password is required when logging in to the application.
所述第二存储单元 1507, 用于存储所述是否需要登录密码的指示信息; 所述若接收所述终端中间件发送的认证成功的指示消息,打开所述应用 客户端的应用具体包括:  The second storage unit 1507 is configured to store the indication information of whether the password is required to be used for the login. If the indication message that the authentication succeeds is sent by the terminal middleware, the application of the application client is specifically:
若接收所述终端中间件发送的认证成功的指示消息,根据所述是否需要 登录密码的指示信息, 确定是否需要登录密码;  And receiving an indication message that the authentication succeeded by the terminal middleware, and determining whether a login password is required according to whether the indication information of the login password is required;
若不需要登录密码,根据所述存储的第一终端标识信息打开所述应用客 户端的应用;  If the login password is not required, the application of the application client is opened according to the stored first terminal identifier information;
若需要登录密码,根据所述存储的第一终端标识信息和输入的登录密码 打开所述应用客户端的应用。  If the login password is required, the application of the application client is opened according to the stored first terminal identification information and the input login password.
进一步的, 所述获取单元 1505获取终端中间件开放的第一终端标识信 息具体包括: Further, the acquiring unit 1505 acquires a first terminal identification letter that is open by the terminal middleware. The specific information includes:
获取所述终端中间件开放的加密的第一终端标识信息, 其中, 所述加密 的第一终端标识信息是所述终端中间件根据所述第一应用名和所述第一终 端标识信息, 釆用高级加密标准 AES所生成的。  Acquiring the encrypted first terminal identifier information that is open to the terminal middleware, where the encrypted first terminal identifier information is that the terminal middleware is used according to the first application name and the first terminal identifier information. Generated by the advanced encryption standard AES.
所述第一存储单元 1506存储所述第一终端标识信息具体包括: 存储所述加密的第一终端标识信息, 以使得所述存储的第一终端标识信 息具体为加密的第一终端标识信息。  The storing, by the first storage unit 1506, the first terminal identification information includes: storing the encrypted first terminal identification information, so that the stored first terminal identification information is specifically the encrypted first terminal identification information.
进一步的, 所述终端标识信息具体包括:  Further, the terminal identifier information specifically includes:
终端设备中 SIM卡的国际移动用户识别码 IMSI;  The international mobile subscriber identity of the SIM card in the terminal device IMSI;
和 /或  and / or
终端设备的国际移动终端识别码 IMEI;  International mobile terminal identification code of terminal equipment IMEI;
和 /或  and / or
终端设备的介质访问控制 MAC地址。  The media access control MAC address of the terminal device.
具体的,通过所述应用客户端进行身份识别的方法可参考实施例一和实 施例二的描述, 本发明实施例在此不再赘述。  For example, the method for performing the identification by the application client may refer to the descriptions of the first embodiment and the second embodiment, and details are not described herein again.
基于上述实施例的描述, 本发明实施例提供的应用客户端包括接收单 元、 登录认证单元。 其中, 所述接收单元用于接收访问请求消息, 所述访问 请求消息请求打开所述应用客户端的应用; 所述登录认证单元, 用于根据存 储的第一终端标识信息进行登录认证, 以打开所述应用客户端的应用。 本发 明实施例提供的应用客户端解决了用户登录终端设备上的应用时, 需要记忆 用户名和密码的问题, 同时提高了用户登录终端设备上的应用的安全性。  Based on the description of the foregoing embodiment, the application client provided by the embodiment of the present invention includes a receiving unit and a login authentication unit. The receiving unit is configured to receive an access request message, where the access request message requests to open an application of the application client, and the login authentication unit is configured to perform login authentication according to the stored first terminal identifier information, to open the The application application client. The application client provided by the embodiment of the present invention solves the problem that the user needs to memorize the user name and password when logging in to the application on the terminal device, and improves the security of the application that the user logs in to the terminal device.
实施例五、  Embodiment 5
本发明实施例提供一种终端中间件 1800, 具体如图 18所示, 所述终端 中间件包括处理器 1801。  The embodiment of the present invention provides a terminal middleware 1800. Specifically, as shown in FIG. 18, the terminal middleware includes a processor 1801.
所述处理器 1801, 用于获取终端设备的终端标识信息, 其中, 所述终端 标识信息至少包含第一终端标识信息。  The processor 1801 is configured to acquire terminal identifier information of the terminal device, where the terminal identifier information includes at least first terminal identifier information.
所述处理器 1801, 还用于将所述第一终端标识信息开放给应用客户端, 以使得所述应用客户端获取并存储所述第一终端标识信息, 并在接收访问请 求消息后, 根据所述第一终端标识信息进行登录认证。 进一步的, 如图 19所示, 所述终端中间件 1800还包括输入接口 1802; 所述输入接口 1802, 用于在所述处理器 1801获取所述终端设备的终端 标识信息后, 将所述第一终端标识信息开放给所述应用客户端之前, 接收所 述应用客户端发送的第一请求消息, 所述第一请求消息请求获取所述第一终 端标识信息。 The processor 1801 is further configured to: open the first terminal identification information to the application client, so that the application client obtains and stores the first terminal identification information, and after receiving the access request message, according to the The first terminal identification information is used for login authentication. Further, as shown in FIG. 19, the terminal middleware 1800 further includes an input interface 1802. The input interface 1802 is configured to: after the processor 1801 acquires terminal identification information of the terminal device, Before the terminal identifier information is opened to the application client, the first request message sent by the application client is received, and the first request message requests to acquire the first terminal identifier information.
进一步的, 所述第一请求消息携带所述应用客户端的第一应用名。  Further, the first request message carries a first application name of the application client.
所述处理器 1801, 还用于在所述输入接口 1802接收所述应用客户端发 送的第一请求消息之后, 根据所述第一应用名, 判断所述应用是否合法。  The processor 1801 is further configured to: after the input interface 1802 receives the first request message sent by the application client, determine, according to the first application name, whether the application is legal.
所述处理器 1801,还用于若所述应用合法,执行将所述第一终端标识信 息开放给应用客户端的步骤。  The processor 1801 is further configured to: when the application is legal, perform the step of opening the first terminal identification information to an application client.
可选的, 如图 20所示, 所述终端中间件 1800还包括存储器 1803。 所述第一请求消息携带所述应用客户端的第一应用名。  Optionally, as shown in FIG. 20, the terminal middleware 1800 further includes a memory 1803. The first request message carries a first application name of the application client.
所述处理器 1801, 还用于在所述输入接口 1802接收所述应用客户端发 送的第一请求消息之后, 根据所述第一应用名, 判断所述应用是否合法。  The processor 1801 is further configured to: after the input interface 1802 receives the first request message sent by the application client, determine, according to the first application name, whether the application is legal.
所述处理器 1801,还用于若所述应用合法,根据所述第一应用名判断所 述应用是否首次调用所述第一终端标识信息。  The processor 1801 is further configured to determine, according to the first application name, whether the application first invokes the first terminal identification information according to the first application name.
所述处理器 1801, 还用于若所述应用首次调用所述第一终端标识信息, 请求用户授权向所述应用客户端开放所述第一终端标识信息。  The processor 1801 is further configured to: if the application first invokes the first terminal identifier information, request the user to authorize opening the first terminal identifier information to the application client.
所述输入接口 1802,还用于接收用户返回的向所述应用客户端开放所述 第一终端标识信息的 4吏权响应。  The input interface 1802 is further configured to receive a response from the user that opens the first terminal identification information to the application client.
所述存储器 1803,用于保存所述第一应用名和所述第一终端标识信息的 对应关系。  The memory 1803 is configured to save a correspondence between the first application name and the first terminal identification information.
所述处理器 1801,用于执行所述将所述第一终端标识信息开放给应用客 户端的步骤。  The processor 1801 is configured to perform the step of opening the first terminal identification information to an application client.
进一步的, 所述处理器 1801请求用户授权向所述应用客户端开放所述 第一终端标识信息具体包括:  Further, the requesting, by the processor 1801, the user to open the first terminal identification information to the application client includes:
发送认证短信, 请求用户通过输入所述认证短信的内容进行授权; 或  Sending an authentication short message, requesting the user to authorize by inputting the content of the authentication short message; or
提供授权界面, 请求用户在授权界面进行授权。 进一步的, 如图 21所示, 所述终端中间件 1800还包括输出接口 1804。 所述输入接口 1802,还用于接收所述应用客户端发送的请求认证的第二 请求消息, 所述第二请求消息携带所述应用客户端的第一应用名和所述应用 客户端存储的第一终端标识信息。 Provide an authorization interface and request the user to authorize on the authorization interface. Further, as shown in FIG. 21, the terminal middleware 1800 further includes an output interface 1804. The input interface 1802 is further configured to receive a second request message that is sent by the application client to request authentication, where the second request message carries a first application name of the application client and a first stored by the application client. Terminal identification information.
所述处理器 1801,还用于检查是否存储所述第一应用名和所述应用客户 端存储的第一终端标识信息的对应关系。  The processor 1801 is further configured to check whether a correspondence between the first application name and the first terminal identification information stored by the application client is stored.
所述输出接口 1804,还用于若存储,发送认证成功的指示消息给所述应 用客户端, 以使得所述应用客户端根据所述应用客户端存储的第一终端标识 信息打开所述应用客户端的应用。  The output interface 1804 is further configured to: if stored, send an indication message that the authentication succeeds to the application client, so that the application client opens the application client according to the first terminal identifier information stored by the application client. End application.
进一步的, 所述输出接口 1804, 还用于在所述若存储, 发送认证成功的 指示消息给所述应用客户端前,发送预先存储的登录该应用时是否需要登录 密码的指示信息给所述应用客户端。  Further, the output interface 1804 is further configured to send, before the sending, sending an indication message that the authentication succeeds to the application client, a pre-stored indication information of whether a login password is required to log in to the application, to the Application client.
若存储, 所述输出接口 1804发送认证成功的指示消息给所述应用客户 端, 以使得所述应用客户端根据所述应用客户端存储的第一终端标识信息打 开所述应用客户端的应用具体包括:  If the storage interface is sent, the output interface 1804 sends an indication that the authentication succeeds to the application client, so that the application client opens the application of the application client according to the first terminal identifier information stored by the application client, including :
若存储, 发送认证成功的指示消息给所述应用客户端, 以使得所述应用 客户端根据所述应用客户端存储的第一终端标识信息和所述是否需要登录 密码的指示信息打开所述应用客户端的应用。  If the storage is sent, the indication message that the authentication succeeds is sent to the application client, so that the application client opens the application according to the first terminal identification information stored by the application client and the indication information of whether the login password is required. Client application.
进一步的, 所述处理器 1801, 还用于在所述输入接口 1802接收用户返 回的向所述应用客户端开放所述第一终端标识信息的授权响应后,根据所述 第一应用名和所述第一终端标识信息, 釆用高级加密标准 AES, 生成所述第 一应用名对应的加密的第一终端标识信息。  Further, the processor 1801 is further configured to: after receiving, by the input interface 1802, an authorization response returned by the user to open the first terminal identification information to the application client, according to the first application name and the The first terminal identification information is generated by using the advanced encryption standard AES to generate the encrypted first terminal identification information corresponding to the first application name.
所述存储器 1803保存所述第一应用名和所述第一终端标识信息的对应 关系具体包括:  The storing, by the memory 1803, the correspondence between the first application name and the first terminal identifier information specifically includes:
保存所述加密的第一终端标识信息和所述第一应用名的对应关系。  And storing a correspondence between the encrypted first terminal identification information and the first application name.
所述处理器 1801将所述第一终端标识信息开放给所述应用客户端具体 包括:  The opening, by the processor 1801, the first terminal identification information to the application client includes:
将所述加密的第一终端标识信息开放给所述应用客户端, 以使得所述应 用客户端获取并存储所述加密的第一终端标识信息, 以使得所述应用客户端 存储的第一终端标识信息具体为加密的第一终端标识信息。 Opening the encrypted first terminal identifier information to the application client, so that the application client obtains and stores the encrypted first terminal identifier information, so that the application client The stored first terminal identification information is specifically the encrypted first terminal identification information.
进一步的, 所述处理器 1801根据所述第一应用名, 判断所述应用是否 合法具体包括:  Further, the determining, by the processor 1801, whether the application is legal according to the first application name specifically includes:
读取本地数据库信息;  Read local database information;
判断所述本地数据库信息中是否包含所述第一应用名;  Determining whether the first application name is included in the local database information;
若所述本地数据库信息中包含所述第一应用名, 确定所述应用合法; 若所述本地数据库信息中未包含所述第一应用名,向能力开放平台 /应用 商店请求获取所述第一应用名;  If the local database information includes the first application name, determining that the application is legal; if the first application name is not included in the local database information, requesting the capability open platform/app store to obtain the first Application name
若接收到所述能力开放平台 /应用商店发送的所述第一应用名,确定所述 应用合法;  If the first application name sent by the capability open platform/app store is received, determining that the application is legal;
存储所述第一应用名;  Storing the first application name;
若未接收到所述能力开放平台 /应用商店发送的所述第一应用名,确定所 述应用不合法。  If the first application name sent by the capability open platform/app store is not received, it is determined that the application is illegal.
进一步的, 所述终端标识信息具体包括:  Further, the terminal identifier information specifically includes:
终端设备中用户识别模块 SIM卡的国际移动用户识别码 IMSI;  User identification module in the terminal device, the international mobile subscriber identity of the SIM card IMSI;
和 /或  and / or
终端设备的国际移动终端识别码 IMEI;  International mobile terminal identification code of terminal equipment IMEI;
和 /或  and / or
终端设备的介质访问控制 MAC地址。  The media access control MAC address of the terminal device.
具体的,通过所述终端中间件进行身份识别的方法可参考实施例一和实 施例二的描述, 本发明实施例对此不再赘述。  Specifically, the method for performing identity identification by using the terminal middleware can refer to the descriptions of the first embodiment and the second embodiment, and details are not described herein again.
基于上述实施例的描述, 本发明提供的终端中间件包括处理器。 所述处 理器用于获取终端设备的终端标识信息, 其中, 所述终端标识信息至少包含 第一终端标识信息, 所述处理器还用于将所述第一终端标识信息开放给应用 客户端, 使得所述应用客户端获取并存储所述第一终端标识信息, 并在接收 访问请求消息后, 根据所述第一终端标识信息进行登录认证。 本发明实施例 提供的终端中间件解决了用户登录终端设备上的应用时, 需要记忆用户名和 密码的问题, 同时提高了用户登录终端设备上的应用的安全性。  Based on the description of the above embodiments, the terminal middleware provided by the present invention includes a processor. The processor is configured to obtain the terminal identifier information of the terminal device, where the terminal identifier information includes at least the first terminal identifier information, and the processor is further configured to: open the first terminal identifier information to the application client, so that The application client obtains and stores the first terminal identification information, and after receiving the access request message, performs login authentication according to the first terminal identification information. The terminal middleware provided by the embodiment of the present invention solves the problem that the user needs to memorize the user name and the password when logging in to the application on the terminal device, and improves the security of the application of the user logging in to the terminal device.
实施例六、 本发明实施例提供一种身份识别的系统 2200, 具体如图 22所示, 所述 身份识别的系统 2200包括终端中间件 900和应用客户端 1500。 Embodiment 6 The embodiment of the present invention provides an identity recognition system 2200. As shown in FIG. 22, the identity recognition system 2200 includes a terminal middleware 900 and an application client 1500.
所述终端中间件 900, 用于获取终端设备的终端标识信息, 其中, 所述 终端标识信息至少包含第一终端标识信息。  The terminal middleware 900 is configured to acquire terminal identification information of the terminal device, where the terminal identification information includes at least first terminal identification information.
所述终端中间件 900, 还用于将所述第一终端标识信息开放给应用客户 端, 以使得所述应用客户端获取并存储所述第一终端标识信息。  The terminal middleware 900 is further configured to open the first terminal identification information to the application client, so that the application client obtains and stores the first terminal identification information.
所述应用客户端 1500,用于接收访问请求消息,并根据存储的第一终端 标识信息进行登录认证, 以打开所述应用客户端的应用。  The application client 1500 is configured to receive an access request message, and perform login authentication according to the stored first terminal identification information to open an application of the application client.
具体的, 所述身份识别的系统通过所述终端中间件和所述应用客户端 进行身份识别的方法可参考实施例一和实施例二的描述, 本发明实施例对此 不再赘述。  Specifically, the method for the identity identification system to perform the identity identification by the terminal middleware and the application client may refer to the descriptions of the first embodiment and the second embodiment, and details are not described herein again.
基于上述实施例的描述, 通过终端中间件获取终端设备的终端标识信 息, 将所述终端标识信息中的第一终端标识信息开放给应用客户端, 使得所 述应用客户端获取并存储所述第一终端标识信息, 并在接收访问请求消息 后, 根据所述第一终端标识信息进行登录认证的技术方案, 解决了用户登录 终端设备上的应用时, 需要记忆用户名和密码的问题, 同时将所述第一终端 标识信息作为用户登录终端设备上的应用的唯一标识,提升了用户登录终端 设备上的应用的安全性。  The terminal identifier information of the terminal device is obtained by the terminal middleware, and the first terminal identifier information in the terminal identifier information is opened to the application client, so that the application client obtains and stores the first a terminal identification information, and after receiving the access request message, performing a login authentication according to the first terminal identification information, which solves the problem that the user needs to memorize the user name and password when logging in to the application on the terminal device, and at the same time The first terminal identifier information is used as the unique identifier of the application that the user logs in to the terminal device, which improves the security of the application that the user logs in to the terminal device.
需要说明的是, 在实际应用中, 本发明实施例中, 应当理解的是, 在一 种实现方式下, 所述终端中间件可以为终端设备上的一个软件模块; 在另一 种实现方式下, 所述终端中间件也可以是具有终端中间件功能的独立的装 置, 即终端中间件能与终端设备进行对接, 也可以内置于终端设备上, 例如 通过插卡或软件集成的方式, 本发明实施例对此不作具体限定。  It should be noted that, in an actual implementation, in the embodiment of the present invention, it should be understood that, in an implementation manner, the terminal middleware may be a software module on the terminal device; The terminal middleware may also be an independent device having the function of the terminal middleware, that is, the terminal middleware can be connected with the terminal device, or can be built in the terminal device, for example, by means of card insertion or software integration, the present invention The embodiment does not specifically limit this.
以上所述, 仅为本发明的具体实施方式, 但本发明的保护范围并不局限 于此, 任何熟悉本技术领域的技术人员在本发明揭露的技术范围内, 可轻易 想到变化或替换, 都应涵盖在本发明的保护范围之内。 因此, 本发明的保护 范围应所述以权利要求的保护范围为准。  The above is only the specific embodiment of the present invention, but the scope of the present invention is not limited thereto, and any person skilled in the art can easily think of changes or substitutions within the technical scope of the present invention. It should be covered by the scope of the present invention. Therefore, the scope of the invention should be determined by the scope of the claims.

Claims

权 利 要 求 Rights request
1、 一种身份识别的方法, 其特征在于, 所述方法包括: 1. An identity recognition method, characterized in that the method includes:
终端中间件获取终端设备的终端标识信息, 其中, 所述终端标识信息至 少包含第一终端标识信息; The terminal middleware obtains terminal identification information of the terminal device, wherein the terminal identification information at least includes first terminal identification information;
将所述第一终端标识信息开放给应用客户端, 以使得所述应用客户端获 取并存储所述第一终端标识信息, 并在接收访问请求消息后, 根据所述第一 终端标识信息进行登录认证。 Open the first terminal identification information to the application client, so that the application client obtains and stores the first terminal identification information, and after receiving the access request message, logs in according to the first terminal identification information Certification.
2、 根据权利要求 1 所述的方法, 其特征在于, 在所述终端中间件获取 终端设备的终端标识信息之后,将所述第一终端标识信息开放给应用客户端 之前, 所述方法还包括: 2. The method according to claim 1, characterized in that, after the terminal middleware obtains the terminal identification information of the terminal device and before opening the first terminal identification information to the application client, the method further includes: :
接收所述应用客户端发送的第一请求消息, 所述第一请求消息请求获取 所述第一终端标识信息。 Receive a first request message sent by the application client, where the first request message requests acquisition of the first terminal identification information.
3、 根据权利要求 2所述的方法, 其特征在于, 所述第一请求消息携带 所述应用客户端的第一应用名; 3. The method according to claim 2, characterized in that the first request message carries the first application name of the application client;
在所述接收所述应用客户端发送的第一请求消息之后, 所述方法还包 括: After receiving the first request message sent by the application client, the method further includes:
根据所述第一应用名, 判断所述应用是否合法; According to the first application name, determine whether the application is legal;
若所述应用合法,执行将所述第一终端标识信息开放给应用客户端的步 骤。 If the application is legal, perform the step of opening the first terminal identification information to the application client.
4、 根据权利要求 2所述的方法, 其特征在于, 所述第一请求消息携带 所述应用客户端的第一应用名; 4. The method according to claim 2, characterized in that the first request message carries the first application name of the application client;
在所述接收所述应用客户端发送的第一请求消息之后, 所述方法还包 括: After receiving the first request message sent by the application client, the method further includes:
根据所述第一应用名, 判断所述应用是否合法; According to the first application name, determine whether the application is legal;
若所述应用合法,根据所述第一应用名判断所述应用是否首次调用所述 第一终端标识信息; If the application is legal, determine whether the application calls the first terminal identification information for the first time based on the first application name;
若所述应用首次调用所述第一终端标识信息,请求用户 权向所述应用 客户端开放所述第一终端标识信息; If the application calls the first terminal identification information for the first time, request the user's right to open the first terminal identification information to the application client;
接收用户返回的向所述应用客户端开放所述第一终端标识信息的授权 向应; Receive authorization returned by the user to open the first terminal identification information to the application client respond to;
保存所述第一应用名和所述第一终端标识信息的对应关系; Save the corresponding relationship between the first application name and the first terminal identification information;
执行所述将所述第一终端标识信息开放给应用客户端的步骤。 Execute the step of opening the first terminal identification information to an application client.
5、 根据权利要求 4所述的方法, 其特征在于, 所述请求用户授权向所 述应用客户端开放所述第一终端标识信息具体包括: 5. The method according to claim 4, wherein the requesting the user to authorize opening the first terminal identification information to the application client specifically includes:
发送认证短信, 请求用户通过输入所述认证短信的内容进行授权; 或 Send an authentication text message and request the user to authorize by entering the content of the authentication text message; or
提供授权界面, 请求用户在授权界面进行授权。 Provide an authorization interface and request users to authorize on the authorization interface.
6、 根据权利要求 4或 5所述的方法, 其特征在于, 所述方法还包括: 接收所述应用客户端发送的请求认证的第二请求消息, 所述第二请求消 息携带所述应用客户端的第一应用名和所述应用客户端存储的第一终端标 识信息; 6. The method according to claim 4 or 5, characterized in that, the method further includes: receiving a second request message requesting authentication sent by the application client, the second request message carrying the application client The first application name of the client and the first terminal identification information stored by the application client;
检查是否存储所述第一应用名和所述应用客户端存储的第一终端标识 信息的对应关系; Check whether the corresponding relationship between the first application name and the first terminal identification information stored by the application client is stored;
若存储, 发送认证成功的指示消息给所述应用客户端, 以使得所述应用 客户端根据所述应用客户端存储的第一终端标识信息打开所述应用客户端 的应用。 If stored, send an authentication success indication message to the application client, so that the application client opens the application of the application client according to the first terminal identification information stored in the application client.
7、 根据权利要求 6所述的方法, 其特征在于, 在所述若存储, 发送认 证成功的指示消息给所述应用客户端前, 所述方法还包括: 7. The method according to claim 6, characterized in that, before storing and sending an authentication success indication message to the application client, the method further includes:
发送预先存储的登录该应用时是否需要登录密码的指示信息给所述应 用客户端; Send pre-stored indication information to the application client indicating whether a login password is required when logging in to the application;
所述若存储, 发送认证成功的指示消息给所述应用客户端, 以使得所述 应用客户端根据所述应用客户端存储的第一终端标识信息打开所述应用客 户端的应用具体包括: If stored, sending an authentication success indication message to the application client, so that the application client opens the application of the application client according to the first terminal identification information stored in the application client specifically includes:
若存储, 发送认证成功的指示消息给所述应用客户端, 以使得所述应用 客户端根据所述应用客户端存储的第一终端标识信息和所述是否需要登录 密码的指示信息打开所述应用客户端的应用。 If stored, send an authentication success indication message to the application client, so that the application client opens the application according to the first terminal identification information stored by the application client and the indication information of whether a login password is required. Client application.
8、 根据权利要求 4-7 任一项所述的方法, 其特征在于, 在所述接收用 户返回的向所述应用客户端开放所述第一终端标识信息的授权响应后, 所述 方法还包括: 8. The method according to any one of claims 4 to 7, characterized in that, after receiving the authorization response returned by the user to open the first terminal identification information to the application client, the Methods also include:
根据所述第一应用名和所述第一终端标识信息, 釆用高级加密标准 AES, 生成所述第一应用名对应的加密的第一终端标识信息; According to the first application name and the first terminal identification information, use the Advanced Encryption Standard AES to generate encrypted first terminal identification information corresponding to the first application name;
所述保存所述第一应用名和所述第一终端标识信息的对应关系具体包 括: The storing of the corresponding relationship between the first application name and the first terminal identification information specifically includes:
保存所述加密的第一终端标识信息和所述第一应用名的对应关系; 所述将所述第一终端标识信息开放给所述应用客户端具体包括: 将所述加密的第一终端标识信息开放给所述应用客户端, 以使得所述应 用客户端获取并存储所述加密的第一终端标识信息, 以使得所述应用客户端 存储的第一终端标识信息具体为加密的第一终端标识信息。 Saving the corresponding relationship between the encrypted first terminal identification information and the first application name; The opening of the first terminal identification information to the application client specifically includes: The information is opened to the application client, so that the application client obtains and stores the encrypted first terminal identification information, so that the first terminal identification information stored by the application client is specifically the encrypted first terminal. Identification information.
9、 根据权利要求 3-8任一项所述的方法, 其特征在于, 所述根据所述 第一应用名, 判断所述应用是否合法具体包括: 9. The method according to any one of claims 3 to 8, characterized in that, judging whether the application is legal based on the first application name specifically includes:
读取本地数据库信息; Read local database information;
判断所述本地数据库信息中是否包含所述第一应用名; Determine whether the local database information contains the first application name;
若所述本地数据库信息中包含所述第一应用名, 确定所述应用合法; 若所述本地数据库信息中未包含所述第一应用名,向能力开放平台 /应用 商店请求获取所述第一应用名; If the local database information contains the first application name, determine that the application is legal; if the local database information does not contain the first application name, request the capability opening platform/application store to obtain the first application name. application name;
若接收到所述能力开放平台 /应用商店发送的所述第一应用名,确定所述 应用合法; If the first application name sent by the capability opening platform/application store is received, determine that the application is legal;
存储所述第一应用名; Store the first application name;
若未接收到所述能力开放平台 /应用商店发送的所述第一应用名,确定所 述应用不合法。 If the first application name sent by the capability opening platform/application store is not received, it is determined that the application is illegal.
10、 根据权利要求 1-9任一项所述的方法, 其特征在于, 所述终端标识 信息具体包括: 10. The method according to any one of claims 1 to 9, characterized in that the terminal identification information specifically includes:
终端设备中用户识别模块 SIM卡的国际移动用户识别码 IMSI; The International Mobile Subscriber Identity IMSI of the SIM card of the subscriber identification module in the terminal device;
和 /或 and / or
终端设备的国际移动终端识别码 IMEI; The International Mobile Terminal Identity IMEI of the terminal device;
和 /或 and / or
终端设备的介质访问控制 MAC地址。 The media access control MAC address of the end device.
11、 一种身份识别的方法, 其特征在于, 所述方法包括: 应用客户端接收访问请求消息, 所述访问请求消息请求打开所述应用客 户端的应用; 11. An identity recognition method, characterized in that the method includes: the application client receives an access request message, and the access request message requests to open an application of the application client;
根据存储的第一终端标识信息进行登录认证, 以打开所述应用客户端的 应用。 Login authentication is performed according to the stored first terminal identification information to open the application of the application client.
12、 根据权利要求 11 所述的方法, 其特征在于, 在所述应用客户端接 收访问请求消息后, 所述方法还包括: 12. The method according to claim 11, characterized in that, after the application client receives the access request message, the method further includes:
判断是否存储终端设备的第一终端标识信息; Determine whether to store the first terminal identification information of the terminal device;
若未存储所述终端设备的第一终端标识信息,发送第一请求消息给所述 终端中间件, 所述第一请求消息请求获取所述第一终端标识信息; If the first terminal identification information of the terminal device is not stored, send a first request message to the terminal middleware, where the first request message requests acquisition of the first terminal identification information;
获取终端中间件开放的所述第一终端标识信息; Obtain the first terminal identification information opened by the terminal middleware;
存储所述第一终端标识信息。 Store the first terminal identification information.
13、 根据权利要求 12所述的方法, 其特征在于, 所述第一请求消息携 带所述应用客户端的第一应用名, 以使得所述终端中间件根据所述第一应用 名, 判断所述应用是否合法, 且所述应用合法时开放所述第一终端标识信息 给所述应用客户端。 13. The method according to claim 12, wherein the first request message carries the first application name of the application client, so that the terminal middleware determines the first application name based on the first application name. Whether the application is legal, and when the application is legal, the first terminal identification information is opened to the application client.
14、 根据权利要求 12所述的方法, 其特征在于, 所述第一请求消息携 带所述应用客户端的第一应用名, 以使得所述终端中间件根据所述第一应用 名, 判断所述应用是否合法, 且所述应用合法时根据所述第一应用名判断所 述应用是否首次调用所述第一终端标识信息, 且在确定所述应用是首次调用 所述第一终端标识信息后,请求用户授权向应用客户端开放所述第一终端标 识信息,在接收到用户返回的向所述应用客户端开放所述第一终端标识信息 的授权响应后, 开放所述第一终端标识信息给所述应用客户端。 14. The method according to claim 12, characterized in that the first request message carries the first application name of the application client, so that the terminal middleware determines the first application name based on the first application name. Whether the application is legal, and when the application is legal, it is determined based on the first application name whether the application calls the first terminal identification information for the first time, and after determining that the application calls the first terminal identification information for the first time, Request the user's authorization to open the first terminal identification information to the application client, and after receiving the authorization response returned by the user to open the first terminal identification information to the application client, open the first terminal identification information to the application client. The application client.
15、 根据权利要求 11-14任一项所述的方法, 其特征在于, 所述根据存 储的第一终端标识信息进行登录认证, 以打开所述应用客户端的应用具体包 括: 15. The method according to any one of claims 11 to 14, wherein the login authentication based on the stored first terminal identification information to open the application of the application client specifically includes:
发送请求认证的第二请求消息给所述终端中间件, 所述第二请求消息携 带所述应用客户端的第一应用名和所述存储的第一终端标识信息, 以使得所 述终端中间件对所述第一应用名和所述存储的第一终端标识信息进行认证; 若接收所述终端中间件发送的认证成功的指示消息, 打开所述应用客户 端的应用。 Send a second request message requesting authentication to the terminal middleware, where the second request message carries the first application name of the application client and the stored first terminal identification information, so that the terminal middleware can Perform authentication using the first application name and the stored first terminal identification information; If the authentication success indication message sent by the terminal middleware is received, the application of the application client is opened.
16、 根据权利要求 15所述的方法, 其特征在于, 所述方法还包括: 接收所述终端中间件发送的登录该应用时是否需要登录密码的指示信 息并存储; 16. The method according to claim 15, characterized in that the method further includes: receiving and storing the indication information sent by the terminal middleware indicating whether a login password is required when logging in to the application;
所述若接收所述终端中间件发送的认证成功的指示消息,打开所述应用 客户端的应用具体包括: If the authentication success indication message sent by the terminal middleware is received, opening the application client application specifically includes:
若接收所述终端中间件发送的认证成功的指示消息,根据所述是否需要 登录密码的指示信息, 确定是否需要登录密码; If the authentication success indication message sent by the terminal middleware is received, determine whether a login password is required based on the indication information of whether a login password is required;
若不需要登录密码,根据所述存储的第一终端标识信息打开所述应用客 户端的应用; If a login password is not required, open the application of the application client according to the stored first terminal identification information;
若需要登录密码,根据所述存储的第一终端标识信息和输入的登录密码 打开所述应用客户端的应用。 If a login password is required, open the application client application according to the stored first terminal identification information and the entered login password.
17、 根据权利要求 14-16任一项所述的方法, 其特征在于, 所述获取终 端中间件开放的第一终端标识信息具体包括: 17. The method according to any one of claims 14 to 16, wherein the obtaining the first terminal identification information opened by the terminal middleware specifically includes:
获取所述终端中间件开放的加密的第一终端标识信息, 其中, 所述加密 的第一终端标识信息是所述终端中间件根据所述第一应用名和所述第一终 端标识信息, 釆用高级加密标准 AES所生成的; Obtain the encrypted first terminal identification information opened by the terminal middleware, wherein the encrypted first terminal identification information is used by the terminal middleware according to the first application name and the first terminal identification information. Generated by Advanced Encryption Standard AES;
所述存储所述第一终端标识信息具体包括: The storing of the first terminal identification information specifically includes:
存储所述加密的第一终端标识信息, 以使得所述存储的第一终端标识信 息具体为加密的第一终端标识信息。 The encrypted first terminal identification information is stored, so that the stored first terminal identification information is specifically encrypted first terminal identification information.
18、 根据权利要求 11-17任一项所述的方法, 其特征在于, 所述终端标 识信息具体包括: 18. The method according to any one of claims 11 to 17, characterized in that the terminal identification information specifically includes:
终端设备中 SIM卡的国际移动用户识别码 IMSI; International Mobile Subscriber Identity IMSI of the SIM card in the terminal device;
和 /或 and / or
终端设备的国际移动终端识别码 IMEI; The International Mobile Terminal Identity IMEI of the terminal device;
和 /或 and / or
终端设备的介质访问控制 MAC地址。 The media access control MAC address of the end device.
19、 一种终端中间件, 其特征在于, 所述终端中间件包含获取单元、 开 放单元; 19. A terminal middleware, characterized in that the terminal middleware includes an acquisition unit, an opening unit put unit;
所述获取单元, 用于获取终端设备的终端标识信息, 其中, 所述终端标 识信息至少包含第一终端标识信息; The obtaining unit is used to obtain terminal identification information of a terminal device, wherein the terminal identification information at least includes first terminal identification information;
所述开放单元, 用于将所述第一终端标识信息开放给应用客户端, 以使 得所述应用客户端获取并存储所述第一终端标识信息, 并在接收访问请求消 息后, 根据所述第一终端标识信息进行登录认证。 The opening unit is configured to open the first terminal identification information to an application client, so that the application client obtains and stores the first terminal identification information, and after receiving the access request message, according to the The first terminal identification information is used for login authentication.
20、 根据权利要求 19所述的终端中间件, 其特征在于, 所述终端中间 件还包含接收单元; 20. The terminal middleware according to claim 19, characterized in that the terminal middleware further includes a receiving unit;
所述接收单元, 用于在所述获取单元获取所述终端设备的终端标识信息 后, 所述开放单元将所述第一终端标识信息开放给所述应用客户端之前, 接 收所述应用客户端发送的第一请求消息, 所述第一请求消息请求获取所述第 一终端标识信息。 The receiving unit is configured to receive the application client after the obtaining unit obtains the terminal identification information of the terminal device and before the opening unit opens the first terminal identification information to the application client. The first request message sent, the first request message requests to obtain the first terminal identification information.
21、 根据权利要求 20所述的终端中间件, 其特征在于, 所述终端中间 件还包括判断单元、 执行单元; 21. The terminal middleware according to claim 20, characterized in that the terminal middleware further includes a judgment unit and an execution unit;
所述第一请求消息携带所述应用客户端的第一应用名; The first request message carries the first application name of the application client;
所述判断单元, 用于在所述接收单元接收所述应用客户端发送的第一请 求消息之后, 根据所述第一应用名, 判断所述应用是否合法; The judging unit is configured to judge whether the application is legal based on the first application name after the receiving unit receives the first request message sent by the application client;
所述执行单元, 还用于若所述应用合法, 执行将所述第一终端标识信息 开放给应用客户端的步骤。 The execution unit is also configured to execute the step of opening the first terminal identification information to the application client if the application is legal.
22、 根据权利要求 20所述的终端中间件, 其特征在于, 所述终端中间 件还包括判断单元、 请求单元、 存储单元、 执行单元; 22. The terminal middleware according to claim 20, characterized in that the terminal middleware also includes a judgment unit, a request unit, a storage unit, and an execution unit;
所述第一请求消息携带所述应用客户端的第一应用名; The first request message carries the first application name of the application client;
所述判断单元, 用于在所述接收单元接收所述应用客户端发送的第一请 求消息之后, 根据所述第一应用名, 判断所述应用是否合法; The judging unit is configured to judge whether the application is legal based on the first application name after the receiving unit receives the first request message sent by the application client;
所述判断单元, 还用于若所述应用合法, 根据所述第一应用名判断所述 应用是否首次调用所述第一终端标识信息; The determination unit is also configured to determine whether the application calls the first terminal identification information for the first time according to the first application name if the application is legal;
所述请求单元, 用于若所述应用首次调用所述第一终端标识信息, 请求 用户授权向所述应用客户端开放所述第一终端标识信息; The requesting unit is configured to request user authorization to open the first terminal identification information to the application client if the application calls the first terminal identification information for the first time;
所述接收单元,还用于接收用户返回的向所述应用客户端开放所述第一 终端标识信息的 4吏权响应; The receiving unit is also configured to receive a request returned by the user to open the first application client. 4 official response of terminal identification information;
所述存储单元, 用于保存所述第一应用名和所述第一终端标识信息的对 应关系; The storage unit is used to store the corresponding relationship between the first application name and the first terminal identification information;
所述执行单元, 用于执行所述将所述第一终端标识信息开放给应用客户 端的步骤。 The execution unit is configured to execute the step of opening the first terminal identification information to an application client.
23、 根据权利要求 22所述的终端中间件, 其特征在于, 所述请求单元 请求用户授权向所述应用客户端开放所述第一终端标识信息具体包括: 发送认证短信, 请求用户通过输入所述认证短信的内容进行授权; 或 23. The terminal middleware according to claim 22, wherein the requesting unit requests the user to authorize opening the first terminal identification information to the application client specifically includes: sending an authentication text message, and requesting the user to input the required information. authorize the content of the above authentication SMS; or
提供授权界面, 请求用户在授权界面进行授权。 Provide an authorization interface and request users to authorize on the authorization interface.
24、 根据权利要求 22或 23所述的终端中间件, 其特征在于, 所述终端 中间件还包含检查单元、 发送单元; 24. The terminal middleware according to claim 22 or 23, characterized in that the terminal middleware also includes a checking unit and a sending unit;
所述接收单元,还用于接收所述应用客户端发送的请求认证的第二请求 消息, 所述第二请求消息携带所述应用客户端的第一应用名和所述应用客户 端存储的第一终端标识信息; The receiving unit is also configured to receive a second request message requesting authentication sent by the application client. The second request message carries the first application name of the application client and the first terminal stored in the application client. identification information;
所述检查单元, 用于检查是否存储所述第一应用名和所述应用客户端存 储的第一终端标识信息的对应关系; The checking unit is configured to check whether the corresponding relationship between the first application name and the first terminal identification information stored by the application client is stored;
所述发送单元, 还用于若存储, 发送认证成功的指示消息给所述应用客 户端, 以使得所述应用客户端根据所述应用客户端存储的第一终端标识信息 打开所述应用客户端的应用。 The sending unit is further configured to, if stored, send an authentication success indication message to the application client, so that the application client opens the application client according to the first terminal identification information stored in the application client. application.
25、 根据权利要求 24所述的终端中间件, 其特征在于, 25. The terminal middleware according to claim 24, characterized in that,
所述发送单元, 还用于在所述若存储, 发送认证成功的指示消息给所述 应用客户端前,发送预先存储的登录该应用时是否需要登录密码的指示信息 给所述应用客户端; The sending unit is further configured to send the pre-stored indication information of whether a login password is required when logging in to the application to the application client before sending the authentication success indication message to the application client if stored;
若存储, 所述发送单元发送认证成功的指示消息给所述应用客户端, 以 使得所述应用客户端根据所述应用客户端存储的第一终端标识信息打开所 述应用客户端的应用具体包括: If stored, the sending unit sends an authentication success indication message to the application client, so that the application client opens the application of the application client according to the first terminal identification information stored in the application client. The specific steps include:
若存储, 发送认证成功的指示消息给所述应用客户端, 以使得所述应用 客户端根据所述应用客户端存储的第一终端标识信息和所述是否需要登录 密码的指示信息打开所述应用客户端的应用。 If stored, send an authentication success indication message to the application client, so that the application client determines whether to log in based on the first terminal identification information stored in the application client and whether login is required. Password instructions open the application client application.
26、 根据权利要求 22-25任一项所述的终端中间件, 其特征在于, 所述 终端中间件还包含生成单元; 26. The terminal middleware according to any one of claims 22 to 25, characterized in that the terminal middleware further includes a generation unit;
所述生成单元, 用于在所述接收单元接收用户返回的向所述应用客户端 开放所述第一终端标识信息的授权响应后,根据所述第一应用名和所述第一 终端标识信息, 釆用高级加密标准 AES, 生成所述第一应用名对应的加密的 第一终端标识信息; The generating unit is configured to, after the receiving unit receives the authorization response returned by the user for opening the first terminal identification information to the application client, based on the first application name and the first terminal identification information, Using Advanced Encryption Standard AES, generate encrypted first terminal identification information corresponding to the first application name;
所述存储单元保存所述第一应用名和所述第一终端标识信息的对应关 系具体包括: The storage unit storing the corresponding relationship between the first application name and the first terminal identification information specifically includes:
保存所述加密的第一终端标识信息和所述第一应用名的对应关系; 所述开放单元将所述第一终端标识信息开放给所述应用客户端具体包 括: Saving the corresponding relationship between the encrypted first terminal identification information and the first application name; The opening unit opening the first terminal identification information to the application client specifically includes:
将所述加密的第一终端标识信息开放给所述应用客户端, 以使得所述应 用客户端获取并存储所述加密的第一终端标识信息, 以使得所述应用客户端 存储的第一终端标识信息具体为加密的第一终端标识信息。 Open the encrypted first terminal identification information to the application client, so that the application client obtains and stores the encrypted first terminal identification information, so that the first terminal stored by the application client The identification information is specifically encrypted first terminal identification information.
27、 根据权利要求 21-26任一项所述的终端中间件, 其特征在于, 所述 判断单元根据所述第一应用名, 判断所述应用是否合法具体包括: 27. The terminal middleware according to any one of claims 21 to 26, characterized in that the determination unit determines whether the application is legal based on the first application name specifically includes:
读取本地数据库信息; Read local database information;
判断所述本地数据库信息中是否包含所述第一应用名; Determine whether the local database information contains the first application name;
若所述本地数据库信息中包含所述第一应用名, 确定所述应用合法; 若所述本地数据库信息中未包含所述第一应用名,向能力开放平台 /应用 商店请求获取所述第一应用名; If the local database information contains the first application name, determine that the application is legal; if the local database information does not contain the first application name, request the capability opening platform/application store to obtain the first application name. application name;
若接收到所述能力开放平台 /应用商店发送的所述第一应用名,确定所述 应用合法; If the first application name sent by the capability opening platform/application store is received, determine that the application is legal;
存储所述第一应用名; Store the first application name;
若未接收到所述能力开放平台 /应用商店发送的所述第一应用名,确定所 述应用不合法。 If the first application name sent by the capability opening platform/application store is not received, it is determined that the application is illegal.
28、 根据权利要求 19-27任一项所述的终端中间件, 其特征在于, 所述 终端标识信息具体包括: 终端设备中用户识别模块 SIM卡的国际移动用户识别码 IMSI; 28. The terminal middleware according to any one of claims 19 to 27, characterized in that the terminal identification information specifically includes: The International Mobile Subscriber Identity IMSI of the SIM card of the subscriber identification module in the terminal device;
和 /或 and / or
终端设备的国际移动终端识别码 IMEI; The International Mobile Terminal Identity IMEI of the terminal device;
和 /或 and / or
终端设备的介质访问控制 MAC地址。 The media access control MAC address of the end device.
29、 一种应用客户端, 其特征在于, 所述应用客户端包含接收单元、 登 录认证单元; 29. An application client, characterized in that the application client includes a receiving unit and a login authentication unit;
所述接收单元, 用于接收访问请求消息, 所述访问请求消息请求打开所 述应用客户端的应用; The receiving unit is configured to receive an access request message requesting to open an application of the application client;
所述登录认证单元, 用于根据存储的第一终端标识信息进行登录认证, 以打开所述应用客户端的应用。 The login authentication unit is configured to perform login authentication according to the stored first terminal identification information to open the application of the application client.
30、 根据权利要求 29所述的应用客户端, 其特征在于, 所述应用客户 端还包含判断单元、 发送单元、 获取单元、 第一存储单元; 30. The application client according to claim 29, characterized in that the application client also includes a judgment unit, a sending unit, an acquisition unit, and a first storage unit;
所述判断单元, 用于在所述接收单元接收访问请求消息后, 判断是否存 储终端设备的第一终端标识信息; The judging unit is configured to judge whether to store the first terminal identification information of the terminal device after the receiving unit receives the access request message;
所述发送单元, 用于若未存储所述终端设备的第一终端标识信息, 发送 第一请求消息给所述终端中间件, 所述第一请求消息请求获取所述第一终端 标识信息; The sending unit is configured to send a first request message to the terminal middleware if the first terminal identification information of the terminal device is not stored, and the first request message requests acquisition of the first terminal identification information;
所述获取单元, 用于获取终端中间件开放的所述第一终端标识信息; 所述第一存储单元, 用于存储所述第一终端标识信息。 The obtaining unit is used to obtain the first terminal identification information opened by the terminal middleware; the first storage unit is used to store the first terminal identification information.
31、 根据权利要求 30所述的应用客户端, 其特征在于, 所述第一请求 消息携带所述应用客户端的第一应用名, 以使得所述终端中间件根据所述第 一应用名, 判断所述应用是否合法, 且所述应用合法时开放所述第一终端标 识信息给所述应用客户端。 31. The application client according to claim 30, wherein the first request message carries the first application name of the application client, so that the terminal middleware determines based on the first application name. Whether the application is legal, and when the application is legal, the first terminal identification information is opened to the application client.
32、 根据权利要求 30所述的应用客户端, 其特征在于, 所述第一请求 消息携带所述应用客户端的第一应用名, 以使得所述终端中间件根据所述第 一应用名, 判断所述应用是否合法, 且所述应用合法时根据所述第一应用名 判断所述应用是否首次调用所述第一终端标识信息, 且在确定所述应用是首 次调用所述第一终端标识信息后,请求用户授权向应用客户端开放所述第一 终端标识信息,在接收到用户返回的向所述应用客户端开放所述第一终端标 识信息的授权响应后, 开放所述第一终端标识信息给所述应用客户端。 32. The application client according to claim 30, wherein the first request message carries the first application name of the application client, so that the terminal middleware determines based on the first application name. Whether the application is legal, and when the application is legal, it is determined according to the first application name whether the application calls the first terminal identification information for the first time, and when it is determined that the application calls the first terminal identification information for the first time Finally, request user authorization to open the first The terminal identification information is: after receiving the authorization response returned by the user for opening the first terminal identification information to the application client, opening the first terminal identification information to the application client.
33、 根据权利要求 29-32任一项所述的应用客户端, 其特征在于, 所述 登录认证单元根据存储的第一终端标识信息进行登录认证, 以打开所述应用 客户端的应用具体包括: 33. The application client according to any one of claims 29 to 32, wherein the login authentication unit performs login authentication according to the stored first terminal identification information to open the application of the application client, which specifically includes:
发送请求认证的第二请求消息给所述终端中间件, 所述第二请求消息携 带所述应用客户端的第一应用名和所述存储的第一终端标识信息, 以使得所 述终端中间件对所述第一应用名和所述存储的第一终端标识信息进行认证; 若接收所述终端中间件发送的认证成功的指示消息, 打开所述应用客户 端的应用。 Send a second request message requesting authentication to the terminal middleware, where the second request message carries the first application name of the application client and the stored first terminal identification information, so that the terminal middleware can The first application name and the stored first terminal identification information are used for authentication; if an authentication success indication message sent by the terminal middleware is received, the application of the application client is opened.
34、 根据权利要求 33所述的应用客户端, 其特征在于, 所述应用客户 端还包含第二存储单元; 34. The application client according to claim 33, characterized in that, the application client further includes a second storage unit;
所述接收单元,还用于接收所述终端中间件发送的登录该应用时是否需 要登录密码的指示信息; The receiving unit is also used to receive indication information sent by the terminal middleware indicating whether a login password is required when logging in to the application;
所述第二存储单元, 用于存储所述是否需要登录密码的指示信息; 所述若接收所述终端中间件发送的认证成功的指示消息,打开所述应用 客户端的应用具体包括: The second storage unit is used to store the indication information of whether a login password is required; if the authentication success indication message sent by the terminal middleware is received, opening the application client application specifically includes:
若接收所述终端中间件发送的认证成功的指示消息,根据所述是否需要 登录密码的指示信息, 确定是否需要登录密码; If the authentication success indication message sent by the terminal middleware is received, determine whether a login password is required based on the indication information of whether a login password is required;
若不需要登录密码,根据所述存储的第一终端标识信息打开所述应用客 户端的应用; If a login password is not required, open the application of the application client according to the stored first terminal identification information;
若需要登录密码,根据所述存储的第一终端标识信息和输入的登录密码 打开所述应用客户端的应用。 If a login password is required, open the application client application according to the stored first terminal identification information and the entered login password.
35、 根据权利要求 32-34任一项所述的应用客户端, 其特征在于, 所述获取单元获取终端中间件开放的第一终端标识信息具体包括: 获取所述终端中间件开放的加密的第一终端标识信息, 其中, 所述加密 的第一终端标识信息是所述终端中间件根据所述第一应用名和所述第一终 端标识信息, 釆用高级加密标准 AES所生成的; 35. The application client according to any one of claims 32 to 34, characterized in that, the obtaining unit obtaining the first terminal identification information opened by the terminal middleware specifically includes: obtaining the encrypted information opened by the terminal middleware. First terminal identification information, wherein the encrypted first terminal identification information is generated by the terminal middleware using the Advanced Encryption Standard AES based on the first application name and the first terminal identification information;
所述第一存储单元存储所述第一终端标识信息具体包括: 存储所述加密的第一终端标识信息, 以使得所述存储的第一终端标识信 息具体为加密的第一终端标识信息。 The first storage unit storing the first terminal identification information specifically includes: The encrypted first terminal identification information is stored, so that the stored first terminal identification information is specifically encrypted first terminal identification information.
36、 根据权利要求 29-35任一项所述的应用客户端, 其特征在于, 所述 终端标识信息具体包括: 36. The application client according to any one of claims 29 to 35, characterized in that the terminal identification information specifically includes:
终端设备中 SIM卡的国际移动用户识别码 IMSI; International Mobile Subscriber Identity IMSI of the SIM card in the terminal device;
和 /或 and / or
终端设备的国际移动终端识别码 IMEI; The International Mobile Terminal Identity IMEI of the terminal device;
和 /或 and / or
终端设备的介质访问控制 MAC地址。 The media access control MAC address of the end device.
37、 一种身份识别的系统, 其特征在于, 所述身份识别的系统包终端中 间件和应用客户端; 37. An identity recognition system, characterized in that the identity recognition system includes terminal middleware and application client;
所述终端中间件, 用于获取终端设备的终端标识信息, 其中, 所述终端 标识信息至少包含第一终端标识信息; The terminal middleware is used to obtain terminal identification information of a terminal device, wherein the terminal identification information at least includes first terminal identification information;
所述终端中间件, 还用于将所述第一终端标识信息开放给应用客户端, 以使得所述应用客户端获取并存储所述第一终端标识信息; The terminal middleware is also configured to open the first terminal identification information to an application client, so that the application client obtains and stores the first terminal identification information;
所述应用客户端, 用于接收访问请求消息, 所述访问请求消息请求打开 所述应用客户端的应用; The application client is used to receive an access request message, and the access request message requests to open the application of the application client;
所述应用客户端, 还用于根据存储的第一终端标识信息进行登录认证, 以打开所述应用客户端的应用。 The application client is also configured to perform login authentication according to the stored first terminal identification information to open the application of the application client.
PCT/CN2014/075513 2013-05-13 2014-04-16 Identity recognition method, device and system WO2014183526A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201310173612.6A CN103249045B (en) 2013-05-13 2013-05-13 A kind of methods, devices and systems of identification
CN201310173612.6 2013-05-13

Publications (1)

Publication Number Publication Date
WO2014183526A1 true WO2014183526A1 (en) 2014-11-20

Family

ID=48928211

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/075513 WO2014183526A1 (en) 2013-05-13 2014-04-16 Identity recognition method, device and system

Country Status (2)

Country Link
CN (1) CN103249045B (en)
WO (1) WO2014183526A1 (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105049410A (en) * 2015-05-28 2015-11-11 北京奇艺世纪科技有限公司 Method, device and system for logging in account
CN107743114A (en) * 2016-12-15 2018-02-27 腾讯科技(深圳)有限公司 A kind of Network Access Method, device and system
CN112765587A (en) * 2021-01-20 2021-05-07 Oppo广东移动通信有限公司 Service operation verification method and device, control method and device, and server

Families Citing this family (24)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103249045B (en) * 2013-05-13 2016-08-10 华为技术有限公司 A kind of methods, devices and systems of identification
WO2015024261A1 (en) * 2013-08-23 2015-02-26 华为技术有限公司 Internet account number management method, manager, server and system
CN103731268A (en) * 2013-09-23 2014-04-16 中兴通讯股份有限公司 Terminal, network side device, and terminal application control method and system
CN104468096B (en) * 2014-12-01 2018-01-05 公安部第三研究所 Based on key disperse computing realize network electronic identification information protection method
CN105790945B (en) * 2014-12-22 2019-09-03 中国移动通信集团公司 A kind of authentication method, device and system realizing user's unique identities and authenticating
CN104539399B (en) * 2015-01-22 2018-07-13 上海云鱼智能科技有限公司 The code identification means of communication of equipment with wireless communication function
CN104820797B (en) * 2015-04-13 2018-07-03 努比亚技术有限公司 Using the management method and device of account
CN106161392B (en) * 2015-04-17 2019-08-23 深圳市腾讯计算机系统有限公司 A kind of auth method and equipment
CN105100415B (en) * 2015-05-28 2018-03-30 努比亚技术有限公司 Login method, mobile terminal
CN104902028B (en) * 2015-06-19 2019-02-15 广州密码科技有限公司 A kind of a key login authentication method, apparatus and system
CN105072112A (en) * 2015-08-07 2015-11-18 中国联合网络通信集团有限公司 Identity authentication method and identity authentication device
CN106919827B (en) * 2015-12-24 2020-04-17 北京奇虎科技有限公司 Wireless unlocking method, computer equipment and network server
TWI595796B (en) * 2016-01-21 2017-08-11 拓連科技股份有限公司 Methods and systems for registration management between electronic devices, and related computer program products
CN105786630B (en) * 2016-02-26 2019-02-15 浪潮通用软件有限公司 A kind of Web API regulation method based on middleware
CN107135075B (en) * 2016-02-29 2020-12-04 义乌兰思体育用品有限公司 Authorization method and device for user operation
CN106452738A (en) * 2016-09-21 2017-02-22 北京神州绿盟信息安全科技股份有限公司 Authentication method, device and system for logging in equipment
CN107872428A (en) * 2016-09-26 2018-04-03 平安科技(深圳)有限公司 The login method and device of application program
CN107889093A (en) * 2016-09-29 2018-04-06 北京京东尚科信息技术有限公司 The method and apparatus for managing the application of mobile terminal
CN106790240B (en) * 2017-01-22 2021-04-23 常卫华 Password-free login method, device and system based on third party authentication
CN109361535B (en) * 2018-09-27 2022-08-05 北京小米移动软件有限公司 Intelligent device binding method and device and storage medium
CN109286933B (en) * 2018-10-18 2021-11-30 世纪龙信息网络有限责任公司 Authentication method, device, system, computer equipment and storage medium
CN110290055B (en) * 2019-06-25 2021-09-10 携程计算机技术(上海)有限公司 Method and system for communication between WeChat applet WebView and native component
CN112398792B (en) * 2019-08-15 2022-07-05 奇安信安全技术(珠海)有限公司 Login protection method, client, central control management equipment and storage medium
CN111245803B (en) * 2020-01-06 2021-12-07 上海孚厘科技有限公司 Method for acquiring MAC address of computer equipment through browser

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101610502A (en) * 2009-07-23 2009-12-23 江苏鸿信系统集成有限公司 Based on the method that moves the different business systems mobile information integration of using door
CN102026195A (en) * 2010-12-17 2011-04-20 北京交通大学 One-time password (OTP) based mobile terminal identity authentication method and system
CN102111349A (en) * 2009-12-25 2011-06-29 上海格尔软件股份有限公司 Security certificate gateway
CN103249045A (en) * 2013-05-13 2013-08-14 华为技术有限公司 Identification method, device and system

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101610502A (en) * 2009-07-23 2009-12-23 江苏鸿信系统集成有限公司 Based on the method that moves the different business systems mobile information integration of using door
CN102111349A (en) * 2009-12-25 2011-06-29 上海格尔软件股份有限公司 Security certificate gateway
CN102026195A (en) * 2010-12-17 2011-04-20 北京交通大学 One-time password (OTP) based mobile terminal identity authentication method and system
CN103249045A (en) * 2013-05-13 2013-08-14 华为技术有限公司 Identification method, device and system

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105049410A (en) * 2015-05-28 2015-11-11 北京奇艺世纪科技有限公司 Method, device and system for logging in account
CN105049410B (en) * 2015-05-28 2018-08-07 北京奇艺世纪科技有限公司 A kind of account login method, apparatus and system
CN107743114A (en) * 2016-12-15 2018-02-27 腾讯科技(深圳)有限公司 A kind of Network Access Method, device and system
CN107743114B (en) * 2016-12-15 2020-03-17 腾讯科技(深圳)有限公司 Network access method, device and system
CN112765587A (en) * 2021-01-20 2021-05-07 Oppo广东移动通信有限公司 Service operation verification method and device, control method and device, and server

Also Published As

Publication number Publication date
CN103249045A (en) 2013-08-14
CN103249045B (en) 2016-08-10

Similar Documents

Publication Publication Date Title
WO2014183526A1 (en) Identity recognition method, device and system
US20200162255A1 (en) System for improved identification and authentication
US8606234B2 (en) Methods and apparatus for provisioning devices with secrets
EP3223549B1 (en) Wireless network access method and access apparatus, client and storage medium
US9038138B2 (en) Device token protocol for authorization and persistent authentication shared across applications
US11510054B2 (en) Methods, apparatuses, and computer program products for performing identification and authentication by linking mobile device biometric confirmation with third-party mobile device account association
US10594695B2 (en) Authentication arrangement
US8769289B1 (en) Authentication of a user accessing a protected resource using multi-channel protocol
DK2924944T3 (en) Presence authentication
US11823007B2 (en) Obtaining device posture of a third party managed device
WO2018014760A1 (en) Method and device for providing and obtaining graphic code information, and terminal
JP2014525077A (en) Authentication system via two communication devices
TWI632798B (en) Server, mobile terminal, and network real-name authentication system and method
CN101986598B (en) Authentication method, server and system
US20160149894A1 (en) System and method for providing multi factor authentication
WO2016078419A1 (en) Open authorization method, device and open platform
KR20130109322A (en) Apparatus and method to enable a user authentication in a communication system
JP2014528129A (en) How to control access to Internet-based applications
CN106161475B (en) Method and device for realizing user authentication
FI128171B (en) Network authentication
KR20150036371A (en) Voucher authorization for cloud server
KR20130103537A (en) User account recovery
US11601807B2 (en) Mobile device authentication using different channels
KR20220167366A (en) Cross authentication method and system between online service server and client
WO2020257156A1 (en) Method and chip for authenticating to a device and corresponding authentication device and system

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14798123

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 14798123

Country of ref document: EP

Kind code of ref document: A1