WO2015039502A1 - Communication authentication method and apparatus, and terminal device - Google Patents

Communication authentication method and apparatus, and terminal device Download PDF

Info

Publication number
WO2015039502A1
WO2015039502A1 PCT/CN2014/083640 CN2014083640W WO2015039502A1 WO 2015039502 A1 WO2015039502 A1 WO 2015039502A1 CN 2014083640 W CN2014083640 W CN 2014083640W WO 2015039502 A1 WO2015039502 A1 WO 2015039502A1
Authority
WO
WIPO (PCT)
Prior art keywords
token
terminal device
authentication system
account
operator
Prior art date
Application number
PCT/CN2014/083640
Other languages
French (fr)
Chinese (zh)
Inventor
李靖
简海燕
叶婉玲
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2015039502A1 publication Critical patent/WO2015039502A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/321Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority
    • H04L9/3213Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority using tickets or tokens, e.g. Kerberos
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0815Network architectures or network communication protocols for network security for authentication of entities providing single-sign-on or federations
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/50Network services
    • H04L67/53Network services using third party service providers
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/168Implementing security features at a particular protocol layer above the transport layer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/10Architectures or entities
    • H04L65/1016IP multimedia subsystem [IMS]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/02Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a communication authentication method and apparatus, and a terminal device. Background technique
  • Real-time communication (English: Web Real-Time Communications, abbreviation: WebRTC)
  • WebRTC Web Real-Time Communications
  • IMS Internet Protocol Multimedia Subsystem
  • the authentication method of the real-time communication service of the webpage provided by the operator the user needs to use the third-party application server (English: 3 M Party WEB server) account and password to log in to the third-party application website.
  • the user needs to use the WebRTC service for example, the user uses Taobao.
  • the carrier username English: webID
  • password English: Password
  • the technical problem to be solved by the present invention is that when a user uses a service provided by an operator through a third-party application website, multiple logins are required, and the process is complicated.
  • the present invention provides a communication authentication method, including:
  • the third-party authentication system And receiving, by the third-party authentication system, the access authentication request sent by the terminal device, where the access authentication request carries the third-party application identifier and the first token, where the a token is a token allocated by the third-party authentication system according to the account, and the account is an account allocated by the third-party authentication system for the terminal device;
  • Receiving the account corresponding to the first token sent by the third-party authentication system acquiring a user identifier bound to the account, and assigning a second token and an IP address of the gateway according to the user identifier, so as to
  • the terminal device uses the service provided by the operator after the gateway authenticates the second token, and the user identifier is an identifier that the operator authentication system allocates for the user.
  • the first token sent by the third-party authentication system is received in a case where the user identifier bound to the account is not present Before the corresponding account, the obtaining the user identifier bound to the account, the method further includes: sending a user identifier input request to the terminal device;
  • the binding relationship between the account and the user identifier is recorded.
  • Allocating the second token and the IP address according to the user identifier Sending, by the terminal device, the second token and the IP address, so that the terminal device sends an authentication request of the second token to the gateway according to the IP address;
  • the receiving the access authentication request sent by the terminal device includes:
  • the present invention provides a communication authentication method, including:
  • the third-party authentication request carries a first token
  • the first token is a token that is allocated by the third-party authentication system according to an account provided by the terminal device, and the account is An account that is allocated to the terminal device by the third-party authentication system
  • the account corresponding to the first token is sent to the operator authentication system, to And causing the operator authentication system to obtain the user identifier bound to the account.
  • the method before receiving the third-party authentication request sent by the operator authentication system, the method includes:
  • the present invention provides a communication authentication method, including:
  • the terminal device After the third-party authentication system passes the authentication of the account provided by the terminal device, the terminal device sends an access authentication request to the operator authentication system, where the access authentication request carries the third-party application identifier and the first token.
  • the first token is a token that is allocated by the third-party authentication system according to the account of the terminal device, so that the operator authentication system requests the third-party authentication system to the first according to the third-party application identifier.
  • the token is authenticated to obtain the user identifier bound to the account;
  • the gateway After the gateway authenticates the second token, the service provided by the operator is used.
  • the acquiring the user identifier bound to the account includes:
  • the present invention provides a communication authentication apparatus, including:
  • a first receiving module configured to receive an access authentication request sent by the terminal device when the third-party authentication system passes the account verification provided by the terminal device, where the access authentication request carries the third-party application identifier and the a token, the first token is a token allocated by the third-party authentication system according to the account, and the account is an account allocated by the third-party authentication system to the terminal device;
  • a first sending module connected to the first receiving module, configured to apply the identifier to the third party
  • Corresponding third-party authentication system sends a third-party authentication request, where the third-party authentication request carries the first token
  • a second receiving module configured to receive the account corresponding to the first token sent by the third-party authentication system
  • a first processing module configured to be connected to the second receiving module, configured to acquire a user identifier bound to the account, and allocate an IP address of the second token and the gateway according to the user identifier, so that the terminal device is in the After the gateway authenticates the second token, the service provided by the operator is used, and the user identifier is an identifier that is allocated by the communication authentication device to the user.
  • the communication authentication apparatus further includes:
  • a second sending module configured to be connected to the first processing module, configured to send a user identity input request to the terminal device
  • the second processing module is configured to be connected to the second receiving module and the first processing module, and configured to record the binding relationship between the account and the user identifier after receiving the user identifier sent by the terminal device.
  • the first processing module specifically includes:
  • a distribution submodule configured to allocate the second token and the IP address according to the user identifier
  • a first sending submodule connected to the allocation submodule, configured to send the first to the terminal device a second token and the IP address, so that the terminal device sends an authentication request of the second token to the gateway according to the IP address
  • a second sending submodule configured to send the user identifier to the gateway, where the second token is authenticated in the communication authentication device, so that the gateway is located according to the user identifier
  • the core network of the operator initiates user registration, and after the registration is completed, the user is allowed to use the service provided by the operator through the terminal device.
  • the first receiving module is further configured to receive the access authentication request from the terminal device by using an operator authentication portal;
  • the second sending module is further configured to send the user identity input request to the terminal device by using the operator authentication portal;
  • the second processing module specifically includes:
  • a first receiving submodule configured to receive, by the operator authentication portal, the user identifier from the terminal device
  • the recording submodule is connected to the first receiving submodule and configured to record a binding relationship between the account and the user identifier.
  • the present invention provides a communication authentication apparatus, including:
  • a receiving module configured to receive a third-party authentication request sent by the operator authentication system, where the third-party authentication request carries a first token, where the first token is allocated by the communication authentication device according to an account provided by the terminal device a token, where the account is an account allocated by the communication authentication device for the terminal device;
  • a first sending module configured to be connected to the receiving module, configured to send the account corresponding to the first token to the operator authentication system, if the first token is authenticated, to The carrier authentication system obtains the user identifier bound to the account.
  • the device further includes: a verification module, configured to verify an account provided by the terminal device;
  • a second sending module configured to be connected to the verification module, configured to return the first token to the terminal device if the verification module passes the verification.
  • the present invention provides a terminal device, including:
  • a sending module configured to send an access authentication request to the operator authentication system, where the third party authentication system passes the account verification provided by the terminal device, where the access authentication request is Carrying a third-party application identifier and a first token, where the first token is a token allocated by the third-party authentication system according to an account of the terminal device, so that the operator authentication system is based on the third-party application. Identifying that the third-party authentication system authenticates the first token to obtain a user identifier bound to the account;
  • a receiving module configured to receive an IP address of the second token and the gateway sent by the operator authentication system, where the IP address of the second token and the gateway is an order allocated by the operator authentication system according to the user identifier Card and IP address;
  • the control module is connected to the receiving module, and is configured to use the service provided by the operator after the gateway authenticates the second token.
  • the receiving module is further configured to: when the carrier authentication system does not have the user identifier bound to the account, The quotient authentication system receives the user identification input request;
  • the sending module is further configured to send the user identifier input by the user to the operator authentication system, so that the operator authentication system records the binding of the account and the user identifier to the communication authentication of the embodiment.
  • the user only needs to provide an account once to log in once on the terminal device. After the account is verified by the third-party authentication system, the user can obtain the authorization of the service registered by the user identifier bound to the account. Thus using the service, the process is simple and the user experience is good.
  • FIG. 1 is a flowchart of a communication authentication method according to Embodiment 1 of the present invention.
  • FIG. 2 is a flowchart of a communication authentication method according to Embodiment 2 of the present invention
  • 3 is a flowchart of a communication authentication method according to Embodiment 3 of the present invention
  • FIG. 4 is a flowchart of a communication authentication method according to Embodiment 4 of the present invention.
  • FIG. 5 is a flowchart of a communication authentication method according to Embodiment 5 of the present invention.
  • FIG. 6 is a structural block diagram of a communication authentication apparatus according to Embodiment 6 of the present invention.
  • FIG. 7 is a structural block diagram of a communication authentication apparatus according to Embodiment 7 of the present invention.
  • Embodiment 8 is a structural block diagram of a communication authentication apparatus according to Embodiment 8 of the present invention.
  • FIG. 9 is a structural block diagram of a terminal device according to Embodiment 9 of the present invention.
  • FIG. 10 is a block diagram showing the structure of a communication authentication apparatus according to Embodiment 10 of the present invention. detailed description
  • the communication authentication method may include:
  • Step S100 Receive an access authentication request sent by the terminal device, where the third-party application identifier and the first token are carried in the access authentication request, where the third-party authentication system passes the account verification provided by the terminal device. .
  • the first token is the third party authentication system according to the account An assigned account, where the account is an account allocated by the third-party authentication system for the terminal device.
  • the user can use a terminal device (English: terminal equipment, abbreviation: TE), for example: mobile phone, personal computer (English: personal computer, abbreviation: PC), tablet, etc., to log in to a third-party application website (for example: Taobao.com) , Sina.com, Dangdang.com, Mushroom Street, etc.).
  • the third-party application website may include its own authentication system, referred to as a third-party authentication system. After the user is authenticated by the third-party authentication system, the third-party application website can be logged in. The third-party application website can then be used to provide services provided by operators (for example, China Mobile, China Unicom, China Telecom, IMS service providers, etc.).
  • the service may be a real-time communication WebRTC service such as a voice service, a video service, a file transmission service, and the like. For example: If you use your mobile phone to log in to Mushroom Street for shopping, you can click on the video displayed on the mushroom street interface to contact the seller's dialog box and the seller for video communication.
  • the third-party application website and the carrier authentication system are two operating systems, after the user logs in to the third-party application website, the operator authentication system needs to authenticate the user's identity.
  • the third-party authentication system can verify whether the account is a legal account assigned by the third-party authentication system for the user. Whether the password corresponding to the account is accurate. Therefore, when the user provides an account to the third-party authentication system through the terminal device, the user can provide the password corresponding to the account to the third-party authentication system. In the case that the third-party authentication system passes the verification, the third-party authentication system may assign the first token corresponding to the account to the user according to the account.
  • the receiving the access authentication request sent by the terminal device includes: receiving, by the operator authentication portal, the access authentication request from the terminal device.
  • the operator authentication portal may receive the access authentication request sent by the terminal device, and then the operator authentication system receives the access authentication request sent by the operator authentication portal.
  • Step S120 Send a third-party authentication request to the third-party authentication system corresponding to the third-party application identifier, where the third-party authentication request carries the first token.
  • An interface device can be set inside or outside the carrier authentication system.
  • the interface device is configured to be external to the operator authentication system, and the interface device forwards information between the operator authentication system and the third-party authentication system, and the operator authentication system sends a third-party authentication request to the interface device.
  • the third-party authentication request is forwarded by the interface device to the third-party authentication system.
  • the interface device is set inside the operator authentication system, and the operator authentication system can directly send a third-party authentication request to the third-party authentication system.
  • the operator authentication system can learn, according to the third-party application identifier carried in the access authentication request, which third-party application website is accessed by the third-party application website, and can use the interface device to apply to the third-party application website.
  • the third-party authentication system sends a third-party authentication request that carries the first token, and may also directly send a third-party authentication request that carries the first token to the third-party authentication system of the third-party application website.
  • the carrier authentication system can learn that the access authentication request is accessed by the Taobao network according to the third-party application identifier, and the third-party authentication request can be sent to the Taobao authentication system through the interface device.
  • the third-party authentication request may be directly sent to the Taobao authentication system, where the third-party authentication request carries the first token corresponding to the user name of the Taobao network allocated by the Taobao authentication system.
  • Step S140 Receive the account corresponding to the first token sent by the third-party authentication system, obtain a user identifier bound to the account, and allocate a second token and an IP address of the gateway according to the user identifier. So that the terminal device uses the service provided by the operator after the gateway authenticates the second token.
  • the user identifier is an identifier assigned by the operator authentication system to the user.
  • the operator authentication system can receive the account sent by the third-party authentication system through the interface device, and the operator authentication system can directly receive the account sent by the third-party authentication system.
  • the account number in the step S140 may include only the account number allocated by the third-party authentication system for the terminal device.
  • the operator authentication system may also receive the first token corresponding to the account through the interface device or directly.
  • the operator authentication system can obtain a user identifier bound to the account according to the account, and the user identifier can include an IP multimedia subsystem.
  • There is a user ID i (English: Internet Protocol Multimedia Subsystem Public User Identity, IMPU), IP Multimedia Subsystem Private User Identity (IMI), and users sign up with operators.
  • the operator authentication system may allocate the IP address of the second token and the gateway according to the obtained user identifier, and send the IP address of the second token and the gateway to the terminal device, so that the terminal device may be in the After the gateway authenticates the second token, the user can directly use the service provided by the operator. For example: If the third-party application website is Taobao, if the first token of the Taobao authentication system is passed, the operator authentication system can directly receive the user name of the Taobao network sent by the Taobao authentication system through the interface device, and then the operator authentication.
  • the system can obtain a user identifier such as a mobile phone number bound to the user name of Taobao. After the subsequent gateway is replaced by the user registration, the user can directly use the terminal device to use the service registered by the operator and the mobile phone number bound to the Taobao user name.
  • a user identifier such as a mobile phone number bound to the user name of Taobao.
  • the user only needs to provide an account once to log in once on the terminal device. After the account is verified by the third-party authentication system, the user identity of the account can be obtained through the operator authentication system.
  • the authorization of the registered business, thereby using the service, the process is simple and the user experience is good.
  • FIG. 2 is a flow chart of a communication authentication method according to Embodiment 2 of the present invention.
  • the same steps in Fig. 2 as those in Fig. 1 have the same functions, and a detailed description of these steps will be omitted for the sake of brevity.
  • the method may further include: Step S200: Send a user identifier input request to the terminal device.
  • the operator authentication system may search whether the account is bound with the user identifier. If the user identifier is not associated with the account, the S200 can be performed. The operator authentication system can request the terminal device to send the user identifier. On the other hand, if there is a user identifier bound to the account, the foregoing step S140 can be performed, and the operator authentication system can obtain the user identifier bound to the account.
  • the China Mobile authentication system can be based on the Taobao network.
  • the user name is used to find out whether the user name of the Taobao network is bound to the mobile phone number of the user. If the mobile phone number of the user is not bound, the China Mobile authentication system can request the user to send the mobile phone number through the mobile phone.
  • the sending the user identifier input request to the terminal device includes: sending, by the operator authentication portal, the user identifier input request to the terminal device.
  • the operator authentication system may send a user identity input request to the operator authentication portal, and then the carrier authentication portal sends a user identity input request to the terminal device.
  • Step S220 After receiving the user identifier sent by the terminal device, record a binding relationship between the account and the user identifier.
  • step S220 may specifically include:
  • the operator authentication system may receive the user identifier from the terminal device through the operator authentication portal, and the operator authentication system may record the binding relationship between the account and the user identifier. among them, The user can input only the IMPU or IMPI through the terminal device, and can input both the IMPU and the IMPIo. Because the IMPU has a certain mapping relationship with the IMPI, the operator authentication system can find the corresponding IMPI according to the IMPU input by the user through the terminal device. The user can also input only the user ID that the user has signed with the operator through the terminal device. The operator authentication system cannot authenticate the user ID and can authenticate to the home subscriber server (English: Home Subscriber Server, HSS) in the IMS core network of the operator.
  • HSS Home Subscriber Server
  • the operator authentication system may record the binding relationship between the account and the user identifier.
  • the account may include only the account assigned by the third-party authentication system for the terminal device in step S220. For example: If the user logs in to Taobao through the mobile phone and uses the mobile phone function of China Mobile on Taobao, the China Mobile authentication system can receive the mobile phone number of the user from the mobile phone through the China Mobile Authentication Portal, the China Mobile authentication system can record Taobao. The binding relationship between the username and the user's mobile number. After the subsequent user registration is completed, the service registered by the mobile phone number provided by China Mobile and bound to the Taobao user name can be directly used.
  • Step S240 Allocate the second token and an IP address of the gateway according to the user identifier.
  • Step S260 Send the second token and the IP address to the terminal device, so that the terminal device sends an authentication request of the second token to the gateway according to the IP address.
  • Taobao a third-party application website
  • China Mobile a third-party application website
  • the China Mobile authentication system can assign the second token and the IP address of the gateway (English: gateway) to the mobile phone according to the mobile phone number.
  • the China Mobile authentication system can send the second token and the IP address to the mobile phone, and the mobile phone can find a gateway corresponding to the IP address according to the IP address, and establish a communication channel with the gateway, and the gateway can be sent to China.
  • the mobile authentication system sends a second token authentication request.
  • Step S280 If the second token is authenticated and passed in the operator authentication system, send the user identifier to the gateway, so that the gateway is shipped according to the user identifier.
  • the core network of the business initiates user registration, and after the registration is completed, the user is allowed to use the service provided by the operator through the terminal device.
  • the operator authentication system may allocate the IP address of the second token and the gateway, and send the allocated second token and the IP address of the gateway to the terminal device, where The terminal device may send an authentication request of the second token to the gateway according to the IP address.
  • the gateway may send the second token authentication request to the operator authentication system.
  • the operator authentication system can authenticate whether the second token passes. If the operator authentication system authenticates that the second token passes, the user identifier can be sent to the gateway.
  • the gateway can register according to the user identifier instead of the user to the core network, for example, the IMS core network, and the gateway can indicate that the user of the core network has been authenticated, and the authentication challenge is no longer needed. After the gateway replaces the user registration, the user can directly use the service provided by the operator through the terminal device.
  • the user only needs to provide an account once to log in once on the terminal device. After the account is verified by the third-party authentication system, the user identity of the account can be obtained through the operator authentication system.
  • the authorization of the registered business, thereby using the service, the process is simple and the user experience is good.
  • FIG. 3 is a flowchart of a communication authentication method according to Embodiment 3 of the present invention. As shown in FIG. 3, the communication authentication method may include:
  • Step S300 Receive a third-party authentication request sent by the operator authentication system, where the third-party authentication request carries a first token, where the first token is a token that is allocated by the third-party authentication system according to the account provided by the terminal device.
  • the account is allocated by the third-party authentication system for the terminal device. account number.
  • the method before receiving the third-party authentication request sent by the operator authentication system, the method includes: verifying an account provided by the terminal device; and returning to the terminal device if the verification is passed First token.
  • the third-party application website may include its own authentication system, which is referred to as a third-party authentication system, and may also include its own application server, which is referred to as a third-party application server.
  • the third-party authentication system can verify whether the account is a legal account assigned by the third-party authentication system for the user. Whether the password corresponding to the account is accurate. Therefore, when the user provides an account to the third-party authentication system through the terminal device, the user can provide the password corresponding to the account to the third-party authentication system. When the third-party authentication system verifies that the account has passed, the third-party authentication system may assign the first token corresponding to the account to the user according to the account.
  • An interface device can be set inside or outside the third-party authentication system.
  • the interface device is set up outside the third-party authentication system, and the interface device forwards information between the operator authentication system and the third-party authentication system, and the interface device receives the third-party authentication request sent by the operator authentication system.
  • the third-party authentication system receives the third-party authentication request forwarded by the interface device.
  • the interface device is set in the third-party authentication system, and the third-party authentication system can directly receive the third-party authentication request sent by the carrier authentication system.
  • Taobao a third-party application website
  • the Taobao server third-party application server
  • the Taobao network authentication system can verify the Taobao user name. If the Taobao authentication system verifies that the user name of the Taobao network passes, the Taobao authentication system can assign a first token corresponding to the username to the user, and instruct the mobile phone to jump. Go to the Taobao server.
  • step S320 if the first token is authenticated, the account corresponding to the first token is sent to the operator authentication system, so that the operator authentication system obtains the account number.
  • the specified user ID The specified user ID.
  • the third-party authentication system may send an account corresponding to the first token to the operator authentication system through the interface device, and the third-party authentication system may directly authenticate the carrier.
  • the system sends an account corresponding to the first token.
  • the operator authentication system can obtain the user identifier bound to the account according to the account. After the subsequent user registration is completed, the service registered by the operator and the user identifier bound to the account can be directly used.
  • the user only needs to provide an account once to log in once, and the third-party authentication system verifies the account. After the account is verified, the account can be obtained through the operator authentication system. The user identifies the authorization of the registered service, thereby using the service, and the process is simple and the user experience is good.
  • the communication authentication method may include:
  • Step S400 In the case that the account authentication provided by the third-party authentication system for the terminal device passes, the terminal device sends an access authentication request to the operator authentication system, where the access authentication request carries the third-party application identifier and the first order.
  • the first token is a token allocated by the third-party authentication system according to an account of the terminal device, so that the operator authentication system requests the third-party authentication system according to the third-party application identifier.
  • the first token is authenticated to obtain the account The user ID of the number binding.
  • the user may log in to the third-party application website by using the terminal device.
  • the third-party application website may include its own authentication system, which is referred to as a third-party authentication system, and may also include its own application server, which is referred to as a third-party application server. If the third-party authentication system verifies that the account provided by the terminal device passes, the terminal device can receive the first token corresponding to the account assigned by the third-party authentication system. The terminal device may send an access authentication request carrying the third-party application identifier and the first token to the operator authentication system.
  • Taobao a third-party application website
  • the Taobao server third-party application server
  • the Taobao network authentication system can authenticate whether the Taobao user name is passed. If the username of the Taobao network is authenticated, the Taobao authentication system can assign a first token to the user and instruct the mobile phone to jump to the Taobao server. If the user needs to use the service provided by China Mobile, the user can send an access authentication request carrying the Taobao application identifier (third-party application identifier) and the first token to the China Mobile authentication system.
  • the acquiring the user identifier bound to the account includes: if the operator authentication system does not have the user identifier bound to the account, The operator authentication system receives the user identification input request;
  • Taobao a third-party application website
  • China Mobile a third-party application website
  • the mobile phone function of China Mobile (operator) on Taobao finds that there is no binding to the user name of Taobao.
  • the mobile phone number the mobile phone can receive the mobile phone number input request sent by the China Mobile authentication system.
  • the user can send the mobile phone number to the China Mobile authentication system through the mobile phone.
  • China Mobile's authentication system can record the binding relationship between the mobile phone number and the user name of Taobao. After the subsequent user registration is completed, you can directly use China.
  • Step S420 Receive an IP address of a second token and a gateway sent by the operator authentication system, where the IP address of the second token and the gateway is a token and an IP that are allocated by the carrier authentication system according to the user identifier. address.
  • Step S440 After the gateway authenticates the second token, use the service provided by the operator, specifically, the terminal device may receive the second token and the IP address of the gateway sent by the operator authentication system, according to the gateway. The IP address finds the corresponding gateway, and sends an authentication request for the second token to the gateway. And the gateway sends the authentication request of the second token to the carrier authentication system.
  • the operator authentication system After receiving the authentication request of the second token, the operator authentication system may authenticate whether the second token passes, and if the carrier authenticates After the system authenticates that the second token passes, the user identifier may be sent to the gateway, and the gateway may perform user registration according to the user identifier instead of the user. After the gateway is replaced by the user registration, the user can directly use the terminal device to directly register the service registered by the operator with the user ID bound to the account.
  • the communication authentication method is described by taking the operator authentication system, the third-party authentication system, and the terminal device as an example, those skilled in the art can understand that the present invention is not limited thereto, and other names have different functions but similar functions.
  • the ability of the communication device to perform the functions of the present invention is within the scope of the present invention.
  • the user only needs to provide an account once to log in once on the terminal device. After the account is verified by the third-party authentication system, the user identity of the account can be obtained through the operator authentication system.
  • the authorization of the registered business, thereby using the service, the process is simple and the user experience is good.
  • FIG. 5 is a flowchart of a communication authentication method according to Embodiment 5 of the present invention.
  • the communication authentication method may include: Step 501: The terminal device sends an HTTP GET (IP address of the third-party application server) command to the third-party application server, where the command indicates that the terminal device obtains the IP address of the third-party application server.
  • HTTP GET IP address of the third-party application server
  • Step 502 The third-party application server sends an HTTP 200 OK (login page of the third-party application server) command to the terminal device, where the command indicates that the terminal device successfully loads the login page of the third-party application server.
  • HTTP 200 OK login page of the third-party application server
  • Step 503 The terminal device sends a POST (Account, Password) command to the third-party authentication system.
  • the command indicates that the user can log in to the third-party application server by using the account and the password corresponding to the account, and clicking to log in to the third-party application server. Then redirect to a third-party authentication system to verify the account.
  • POST Account, Password
  • Step 504 The third-party authentication system sends a 302 (Authentication Pass, Assign First Token) command to the terminal device, where the command indicates that the third-party authentication system verifies the account provided by the user through the terminal device, in the process of verifying, Verify that the account is a legal account assigned to the user by the third-party authentication system. You can also verify that the password corresponding to the account is accurate. Therefore, the user can provide the account corresponding to the account to the third-party authentication system while providing the account to the third-party authentication system through the terminal device. If the third-party authentication system verifies that the account is approved, the third-party authentication system can assign a first token (token1) corresponding to the account to the user, and instruct the terminal device to re-joke to the third-party application server.
  • a 302 Authentication Pass, Assign First Token
  • Step 505 The terminal device sends a POST (authentication pass) to the third-party application server, where the command indicates that the terminal device notifies the third-party application server that the third-party authentication system verifies that the account is approved.
  • POST authentication pass
  • Step 506 The third-party application server sends an HTTP 200 OK command to the terminal device, where the command indicates that the third-party application server notifies the terminal device that the third-party authentication system has verified that the account is approved.
  • the user may log in to the third-party application website by using the terminal device.
  • the third-party application website may include its own authentication system, which is referred to as a third-party authentication system, and may also include its own application server, which is referred to as a third-party application server.
  • the third-party authentication system can assign a first token corresponding to the account to the user, and send the first token to the terminal device.
  • Step 507 The terminal device sends an HTTP GET (Service Request) command to the third-party application server, where the command indicates that the user can send a service request to the third-party application server by using the terminal device, where the service request carries the login service mode and the operator.
  • the identifier of the carrier is the identifier of the carrier to which the service to be used by the user belongs.
  • Step 508 The third-party application server sends an HTTP 200 OK (IP address of the operator authentication portal) command to the terminal device, where the third-party application server obtains the user to log in to the service through the terminal device according to the received service request.
  • the mode is one-time login, and the IP address of the carrier authentication portal can be sent to the terminal device.
  • the third-party application server can receive the service request sent by the user through the terminal device, and obtain the manner in which the user logs in to the service through the terminal device, and if the user needs to use the account once to log in through the terminal device, the device can directly obtain the service request.
  • the third-party application server may send the IP address of the carrier authentication portal to the terminal device.
  • Step 509 The terminal device sends an access authentication request to the operator authentication portal, where the access authentication request carries a third-party application identifier and a first token, where the first token is a third-party authentication system according to the account allocation brand.
  • Step 510 The operator authentication portal sends the foregoing access authentication request to the operator authentication system. Specifically, the operator authentication portal may receive the access authentication request sent by the terminal device, and then the operator authentication system receives the access authentication request sent by the operator authentication portal.
  • Step 511 The operator authentication system sends a third-party authentication request to the third-party authentication system corresponding to the third-party application identifier, where the third-party authentication request carries the first token.
  • An interface device can be set inside or outside the carrier authentication system.
  • the interface device is set outside the operator authentication system, and the interface device forwards information between the operator authentication system and the third-party authentication system, and the operator authentication system sends the third-party authentication request.
  • the third-party authentication request is forwarded to the third-party authentication system by the interface device.
  • the interface device is set inside the operator authentication system, and the operator authentication system can directly send a third-party authentication request to the third-party authentication system.
  • Step 512 The third-party authentication system authenticates the first token. If the third-party authentication system authenticates the first token, the account corresponding to the first token may be sent to the operator authentication system.
  • An interface device can be set inside or outside the third-party authentication system.
  • the interface device is disposed outside the third-party authentication system, and the interface device can receive the account corresponding to the first token sent by the third-party authentication system, and forward the first token to the operator authentication system.
  • the interface device is set in the third-party authentication system, and the third-party authentication system can directly send the account corresponding to the first token to the operator authentication system.
  • Step 513 The operator authentication system searches whether the account is bound to the user identifier.
  • the user identifier may include any one or more of the user names that the IMPU and the IMPK user subscribe to. If the account is not bound to the user identifier, the operator authentication system may send a user identity input request to the operator authentication portal, and perform steps 514 to 516 to request the user to input the user identifier; if the account is bound with the user identifier, execute Step 517: The operator authentication system allocates a second token to the user.
  • Step 514 The operator authentication portal sends a user identity input request to the terminal device, and requests the user to input the user identifier and password.
  • Step 515 The terminal device sends a POST (User Identity, Password) command to the operator authentication portal.
  • the command indicates that the user can input the user identifier and password through the terminal device, and then the terminal device sends the user identifier to the operator authentication portal.
  • the user can input any one or more of the IMPU, the IMPI, and the user name signed by the user and the operator through the terminal device. Since the IMPU has a certain mapping relationship with the IMPI, the operator authentication system can find the corresponding IMPI according to the IMPU input by the user through the terminal device.
  • Step 516 The operator authentication portal sends an HTTP GET authentication (user identification, password) command to the operator authentication system, where the command indicates that the operator authentication system can receive the operator authentication portal.
  • HTTP GET authentication user identification, password
  • step 513 to step 516 if the account is not bound with the user identifier, the terminal device is requested to input the user identifier, and the input user identifier can be authenticated by the operator authentication system, but the operator authentication system cannot be authenticated.
  • the user ID can be authenticated to the HSS. If the HSS authentication user ID is passed, the carrier authentication system can record the binding relationship between the account and the user ID.
  • Step 517 The operator authentication system sends an HTTP 200 OK (second token, IP address of the gateway) command to the operator authentication portal, where the command indicates that the operator authentication system can allocate the second terminal to the terminal device according to the user identifier.
  • the token token2
  • the token token2
  • the IP address of the gateway and send a second token to the carrier authentication portal.
  • Step 518 The operator authentication portal sends an HTTP 200 OK (second token, IP address of the gateway) command to the terminal device, where the command indicates that the operator authentication portal can send the second token and the IP address of the gateway to the terminal device. So that the terminal device can send an authentication request of the second token to the gateway according to the IP address.
  • HTTP 200 OK second token, IP address of the gateway
  • Step 519a The terminal device sends an HTTP GET (Web Socket Request) command to the gateway.
  • Step 519b The gateway sends an HTTP GET (Web Socket Response) command to the terminal device.
  • the commands of step 519a and step 519b indicate that the terminal device can access the gateway corresponding to the IP address according to the IP address of the gateway sent by the operator authentication portal, and establish a web socket (English: websocket) channel with the gateway.
  • Step 520 The terminal device sends an authentication request of the second token to the gateway, where the second token authentication request carries the second token.
  • Step 521 The gateway sends an HTTP GET authentication (second token) command to the operator authentication system, where the command indicates that the gateway can send the second token authentication request to the operator authentication system.
  • HTTP GET authentication second token
  • Step 522 The operator authentication system sends an HTTP 200 OK (second token valid, user identifier, authenticated pass) command to the gateway, where the command indicates that the operator authentication system can authenticate whether the second token sent by the gateway passes.
  • the carrier authentication system authenticates the second token and can go to the gateway. Sending a user identifier corresponding to the second token.
  • Step 523 The gateway sends a SIP Register (User Identity, Passed, Without Challenge Process) command to the core network, for example, the IMS core network, where the command indicates that the gateway can register the user to the core network, and indicates that the user of the core network has Authentication does not require an authentication challenge process.
  • SIP Register User Identity, Passed, Without Challenge Process
  • Step 524 The core network sends a SIP 200 OK command to the gateway, where the command indicates that the core network can notify the gateway that the registration is successful.
  • Step 525 The gateway notifies the user that the authentication is passed, and the user has already registered, and the user can directly use the user-registered service provided by the operator, such as a voice service, a video service, and a data transmission service, through the terminal device.
  • the operator such as a voice service, a video service, and a data transmission service
  • the embodiment may be used for one login, specifically: after the user logs in to the third-party application server by using the account on the terminal device, You can obtain the authorization of the user's registered service without entering the operator's username and password.
  • BP The user only needs to use the account to log in once through the terminal device, and the user can register the service.
  • the communication authentication method is described by using a terminal device, a carrier authentication system, a carrier authentication portal, a third-party application server, a third-party authentication system, a gateway, and a core network as an example, those skilled in the art can understand that The present invention is not limited thereto, and other communication devices having different names but similar functions can perform the functions of the present invention, and are all within the scope of the present invention.
  • the user only needs to provide an account once to log in once on the terminal device. After the account is verified by the third-party authentication system, the user identity of the account can be obtained through the operator authentication system.
  • the authorization of the registered business, thereby using the service, the process is simple and the user experience is good.
  • FIG. 6 is a block diagram showing the structure of a communication authentication apparatus according to a sixth embodiment of the present invention.
  • the communication authentication apparatus 600 provided in this embodiment is used to implement the communication authentication method provided in the first embodiment shown in FIG.
  • the communication authentication apparatus 600 can include:
  • the first receiving module 620 is configured to receive an access authentication request sent by the terminal device when the third-party authentication system passes the account verification provided by the terminal device, where the access authentication request carries the third-party application identifier and
  • the first token is a token that is allocated by the third-party authentication system according to the account, and the account is an account that the third-party authentication system allocates for the terminal device.
  • the user can use a terminal device, such as a mobile phone, a personal computer, a tablet computer, etc., to log in to a third-party application website (for example: Taobao, Sina, Dangdang, Mushroom Street, etc.).
  • the third-party application website may include its own authentication system, referred to as a third-party authentication system.
  • the third-party application website can be logged in.
  • the third-party application website can then be used to provide services provided by operators (for example, China Mobile, China Unicom, China Telecom, IMS service providers, etc.).
  • the service may be a real-time communication of a webpage, such as a voice service, a video service, a file transmission service, and the like.
  • a voice service a voice service
  • a video service a file transmission service
  • file transmission service a file transmission service
  • the third-party authentication system can verify whether the account is a legal account assigned by the third-party authentication system for the user. Whether the password corresponding to the account is accurate. Therefore, when the user provides an account to the third-party authentication system through the terminal device, the user can provide the password corresponding to the account to the third-party authentication system. In the case that the third-party authentication system passes the verification, the third-party authentication system may assign the first token corresponding to the account to the user according to the account.
  • the first receiving module 620 is further configured to receive the access authentication request from the terminal device by using an operator authentication terminal.
  • the operator authentication portal may receive the access authentication request sent by the terminal device, and then the first receiving module 620 receives the access authentication request sent by the operator authentication portal.
  • a first sending module 640 connected to the first receiving module 620, configured to send to the third party Sending a third-party authentication request by using the third-party authentication system corresponding to the identifier, where the third-party authentication request carries the first token.
  • An interface device can be provided inside or outside the communication authentication device 600.
  • the interface device is disposed outside the communication authentication device 600, and the interface device forwards information between the communication authentication device 600 and the third-party authentication system, and the first sending module 640 of the communication authentication device 600 sends a third-party authentication request. Sended to the interface device, and the interface device forwards the third-party authentication request to the third-party authentication system.
  • the interface device is disposed inside the communication authentication device 600, and the first sending module 640 of the communication authentication device 600 can directly send a third-party authentication request to the third-party authentication system.
  • the communication authentication apparatus 600 can learn, according to the third-party application identifier carried in the access authentication request received by the first receiving module 620, which third-party application website is accessed by the access authentication request, and can pass the interface.
  • the device sends a third-party authentication request that carries the first token to the third-party authentication system of the third-party application website, and may also send the first-party sending module 640 to the third-party authentication system of the third-party application website.
  • a third-party authentication request for a token For a specific example, refer to the related description of step S120 in the first embodiment.
  • the second receiving module 660 is configured to receive the account corresponding to the first token sent by the third-party authentication system.
  • the first processing module 680 is connected to the second receiving module 660, configured to acquire a user identifier bound to the account, and allocate a second token and an IP address of the gateway according to the user identifier, so that the terminal device After the gateway authenticates the second token, the service provided by the operator is used.
  • the user identifier is an identifier assigned by the communication authentication device 600 to the user.
  • the communication authentication device 600 can receive the account that is sent by the third-party authentication system by using the interface device, and the communication authentication device 600 can also receive the third-party authentication by using the second receiving module 660.
  • the communication authentication device 600 can also receive the first token corresponding to the account by using the interface device or the second receiving module 660.
  • the first processing module 680 can obtain the user identifier bound to the account according to the account, and the user identifier can include any one or more of an IMPU, an IMPI, and a user name signed by the user and the operator. For example, mobile phone number, email address, ID number, etc.
  • the first processing module 680 can allocate the IP address of the second token and the gateway according to the obtained user identifier, and send the IP address of the second token and the gateway to the terminal device, so that the terminal device can After the gateway authenticates the second token, the user can directly use the service provided by the operator.
  • the interface device or the second receiving module 660 can receive the user name of the Taobao network sent by the Taobao authentication system, and then the first The processing module 680 can obtain a user identifier, such as a mobile phone number, bound to the username of the Taobao network. After the subsequent gateway is replaced by the user registration, the user can directly use the terminal device to use the service registered by the operator and the mobile phone number bound to the Taobao user name.
  • the user only needs to provide an account once to perform a login on the terminal device. After the account is verified by the third-party authentication system, the account authentication can be obtained by using the communication authentication device of this embodiment.
  • the user identifies the authorization of the registered service, thereby using the service, the process is simple, and the user experience is good.
  • FIG. 7 is a block diagram showing the structure of a communication authentication apparatus according to a seventh embodiment of the present invention.
  • the communication authentication apparatus 700 provided in this embodiment is used to implement the communication authentication method provided in the second embodiment shown in FIG. 2.
  • the same components in Fig. 7 as those in Fig. 6 have the same functions, and a detailed description of these components will be omitted for the sake of brevity.
  • the communication authentication apparatus 700 shown in FIG. 7 may further include:
  • a second sending module 720 connected to the first processing module 680, for the terminal device Send a user ID input request.
  • the first processing module 680 can search whether the account is bound with the user identifier. If there is no user identifier bound to the account, the second sending module 720 may request the terminal device to send the user identifier. On the other hand, if there is a user identifier bound to the account, the first processing module 680 can obtain the user identifier bound to the account.
  • the processing module 680 can find, according to the user name of the Taobao network, whether the user name of the Taobao network is bound to the mobile phone number of the user. If the mobile phone number of the user is not bound, the second sending module 720 of China Mobile can request the user to send the mobile phone through the mobile phone. cellphone number.
  • the second sending module 720 is further configured to send the user identity input request to the terminal device by using the operator authentication portal.
  • the second sending module 720 may send a user identifier input request to the operator authentication portal, and then the portal authenticates the portal to the terminal.
  • the device sends a user ID input request.
  • the second processing module 740 is connected to the second receiving module 660 and the first processing module 680, and configured to: after receiving the user identifier sent by the terminal device, record the binding of the account and the user identifier. Relationship.
  • the second processing module 740 specifically includes:
  • the first receiving submodule 741 is configured to receive, by using the operator authentication portal, the user identifier from the terminal device;
  • the recording sub-module 742 is connected to the first receiving sub-module 741, and is configured to record a binding relationship between the account and the user identifier.
  • the first receiving submodule 741 can receive from the terminal device through the operator authentication portal.
  • the user identifier the recording submodule 742 can record the binding relationship between the account and the user identifier.
  • the user can input only the IMPU or IMPI through the terminal device, and can input both the IMPU and the IMPI. Because the IMPU has a certain mapping relationship with the IMPI, the communication authentication apparatus 700 can find the corresponding IMPI according to the IMPU input by the user through the terminal device.
  • the user can also input only the user ID that the user has signed with the operator through the terminal device.
  • the communication authentication apparatus 700 cannot authenticate the user identity and can authenticate to the home subscriber server in the operator's IMS core network. If the HSS authenticates the user ID, the recording submodule 742 can record the binding relationship between the account and the user identifier.
  • the related description in step S220 in the second embodiment refer to the related description in step S220 in the second embodiment.
  • the first processing module 680 specifically includes:
  • the distribution submodule 681 is configured to allocate the second token and the IP address according to the user identifier.
  • the first sending submodule 682 is connected to the allocating submodule 681, and configured to send the second token and the IP address to the terminal device, so that the terminal device sends the The gateway sends an authentication request for the second token.
  • the distribution sub-module 681 can assign the second token and the IP address of the gateway to the mobile phone according to the mobile phone number.
  • the first sending submodule 682 can send the second token and the IP address to the mobile phone, and the mobile phone can find a gateway corresponding to the IP address according to the IP address, and establish a communication channel with the gateway.
  • the gateway can send a second token authentication request to the China Mobile Communications Authentication Device 700.
  • a second sending submodule 683 configured to send the user identifier to the gateway, so that the gateway is based on the user identifier, if the second token is authenticated in the communication authentication apparatus 700
  • User registration is initiated to the operator's core network, and after the registration is completed, the user is allowed to use the service provided by the operator through the terminal device.
  • the distribution submodule 681 can allocate the second token and the IP address of the gateway to the terminal device, and the first sending submodule 682 sends the allocated second token and the IP address of the gateway to the terminal device, where the terminal device
  • the authentication request of the second token may be sent to the gateway according to the IP address.
  • the gateway may send the authentication request of the second token to the communication authentication apparatus 700.
  • the communication authentication apparatus 700 can authenticate whether the second token passes. If the communication authentication apparatus 700 authenticates that the second token passes, the second sending submodule 683 can transmit the user identifier to the gateway.
  • the gateway can register the user to the core network, such as the IMS core network, according to the user identifier, and the gateway can indicate that the user of the core network has been authenticated, and the authentication challenge is no longer needed.
  • the user can directly use the communication authentication device of the embodiment of the present invention provided by the operator through the terminal device, and the user only needs to provide an account once to log in once on the terminal device, and the third-party authentication system After the account authentication is passed, the communication authentication device of the embodiment can obtain the authorization of the service registered by the user identifier bound to the account, so that the service is simple, and the user experience is good.
  • FIG. 8 is a block diagram showing the structure of a communication authentication apparatus according to an eighth embodiment of the present invention.
  • the communication authentication apparatus 800 provided in this embodiment is used to implement the communication authentication method provided in the third embodiment shown in FIG.
  • the communication authentication apparatus 800 can include:
  • the verification module 810 is configured to verify an account provided by the terminal device.
  • the second sending module 820 is connected to the verification module 810, and is configured to return the first token to the terminal device if the verification module 810 passes the verification.
  • the user may log in to the third-party application website by using the terminal device.
  • the third-party application website may include its own authentication system, which is referred to as a third-party authentication system, and may also include its own application server, which is referred to as a third-party application server.
  • the verification module 810 of the communication authentication device 800 can verify the account provided by the terminal device. If the verification module 810 verifies that the account is approved, the second sending module 820 can Returning the first token to the terminal device.
  • Taobao a third-party application website
  • the Taobao server third-party application server
  • the verification module 810 of the communication authentication device 800 can verify the user name of the Taobao. If the verification module 810 verifies that the username of the Taobao network passes, the second sending module 820 of the Taobao network may return the first token to the mobile phone.
  • the receiving module 830 is configured to receive a third-party authentication request sent by the operator authentication system, where the third-party authentication request carries a first token, where the first token is an account provided by the communication authentication device 800 according to the terminal device.
  • the assigned token is an account that the communication authentication device 800 allocates for the terminal device.
  • the first sending module 840 is connected to the receiving module 830, and configured to send the account corresponding to the first token to the operator authentication system, if the first token is authenticated, to And causing the operator authentication system to obtain the user identifier bound to the account.
  • an interface device can be provided inside or outside the communication authentication device 800.
  • the interface device is disposed outside the communication authentication device 800, and the interface device forwards information between the operator authentication system and the communication authentication device 800, and the interface device receives the third-party authentication request sent by the operator authentication system.
  • the receiving module 830 receives the third-party authentication request forwarded by the interface device.
  • the interface device is disposed inside the communication authentication device 800, and the receiving module 830 can directly receive the third-party authentication request sent by the operator authentication system.
  • the communication authentication device 800 can directly send the account corresponding to the first token to the operator authentication system by using the first sending module 840, and the communication authentication device 800 can also pass
  • the first sending module 840 sends the account corresponding to the first token to the interface device, and the interface device sends the account to the operator authentication system.
  • the operator authentication system can obtain the user identifier bound to the account according to the account, and the subsequent user is registered.
  • the communication authentication device of the embodiment of the present invention which is registered by the operator and is associated with the account identifier, can be directly used.
  • the user only needs to provide an account once to log in once on the terminal device, and the verification module verifies the account.
  • the service authentication system can obtain the authorization of the service registered by the user ID bound to the account, so that the service is simple, and the user experience is good.
  • FIG. 9 is a structural block diagram of a terminal device according to Embodiment 9 of the present invention.
  • the terminal device 900 provided in this embodiment is used to implement the communication authentication method provided in Embodiment 4 shown in FIG.
  • the terminal device 900 may include:
  • the sending module 920 is configured to send an access authentication request to the operator authentication system, where the third-party application identifier and the first order are carried in the access authentication request, where the third-party authentication system passes the account verification provided by the terminal device.
  • the first token is a token allocated by the third-party authentication system according to an account of the terminal device, so that the operator authentication system requests the third-party authentication system according to the third-party application identifier.
  • the first token is authenticated to obtain a user identifier bound to the account.
  • the user may log in to the third-party application website by using the terminal device.
  • the third-party application website may include its own authentication system, which is referred to as a third-party authentication system, and may also include its own application server, which is referred to as a third-party application server. If the third-party authentication system verifies that the account provided by the terminal device 900 passes, the terminal device 900 can receive the first token corresponding to the account that is allocated by the third-party authentication system.
  • the sending module 920 can send an access authentication request carrying the third-party application identifier and the first token to the operator authentication system.
  • Taobao a third-party application website
  • the Taobao server third-party application server
  • the Taobao authentication system can authenticate whether the user name of the Taobao network passes. If the username of the Taobao network is authenticated, the Taobao authentication system can assign a first token to the user and instruct the mobile phone to jump to the Taobao server. If the user needs to use the service provided by China Mobile, the sending module 920 may send an access authentication request carrying the Taobao application identifier (third-party application identifier) and the first token to the China Mobile authentication system.
  • the receiving module 940 is configured to receive an IP address of the second token and the gateway sent by the operator authentication system, where the IP address of the second token and the gateway is allocated by the carrier authentication system according to the user identifier. Token and IP address.
  • the receiving module 940 is further configured to receive a user from the operator authentication system if the operator authentication system does not have the user identifier bound to the account. Identifies the input request.
  • the sending module 920 is further configured to send the user identifier input by the user to the operator authentication system, so that the operator authentication system records the account and the user identifier. Binding relationship.
  • the receiving module 940 of the mobile phone can receive the mobile phone number input request sent by the China Mobile authentication system. After receiving the mobile phone number input request, the receiving module 940 can send the mobile phone number to the China Mobile authentication system through the sending module 920 of the mobile phone.
  • the China Mobile authentication system can record the binding relationship between the mobile phone number and the user name of Taobao. After the subsequent user registration is completed, the service registered by the mobile phone number bound by the mobile phone name of the Taobao network can be directly used.
  • the control module 960 is connected to the receiving module 940, and is configured to use the service provided by the operator after the gateway authenticates the second token.
  • the receiving module 940 can receive the second token and the gateway sent by the operator authentication system.
  • the IP address of the control module 960 can find the corresponding gateway according to the IP address of the gateway, and send an authentication request of the second token to the gateway.
  • the gateway sends the authentication request of the second token to the carrier authentication system.
  • the operator authentication system may authenticate whether the second token passes, and if the carrier authenticates
  • the user identifier may be sent to the gateway, and the gateway may perform user registration according to the user identifier instead of the user.
  • the gateway is replaced by the user registration, the user can directly use the terminal device to use the service registered by the operator and the user identifier bound to the account.
  • the user only needs to provide an account once to log in once on the terminal device. After the account is verified by the third-party authentication system, the user identity system bound to the account can be obtained through the operator authentication system. The authorization of the registered business, thereby using the service, the process is simple and the user experience is good.
  • FIG 10 is a block diagram showing the structure of a communication authentication apparatus according to Embodiment 10 of the present invention.
  • the communication authentication device 1000 may be a host server having a computing capability, a personal computer PC, or a portable computer or terminal that can be carried.
  • the specific embodiment of the present invention does not limit the specific implementation of the computing node.
  • the communication authentication apparatus 1000 includes a processor (English: processor) 1010, a communication interface (English interface: Communications Interface) 1020, a memory (English: memory array) 1030, and a bus 1040.
  • the processor 1010, the communication interface 1020, and the memory 1030 complete communication with each other through the bus 1040.
  • the communication interface 1020 is configured to implement communication between network elements such as a third-party authentication system, a terminal device, and an operator authentication system.
  • the processor 1010 is configured to execute a program.
  • the processor 1010 may be a central processing unit CPU, or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention.
  • Memory 1030 can be used to store programs and data.
  • the area storing the program may include an operating system, an application required by at least one of the foregoing modules (for example, the first processing module 680); and the area for storing the data may include the first order allocated by the communication authentication method according to the embodiment. Card, user ID, second token, etc.
  • the memory 1030 may include a high speed RAM memory, and may also include a non-volatile memory, such as at least one disk memory.
  • Memory 1030 can also be a memory array.
  • the memory 1030 may also be partitioned, and the blocks may be combined into a virtual volume according to certain rules.
  • the above program may be a program code including computer operating instructions. This program can be used to:
  • the third-party authentication system And receiving, by the third-party authentication system, the access authentication request sent by the terminal device, where the access authentication request carries the third-party application identifier and the first token, where the a token is a token allocated by the third-party authentication system according to the account, and the account is an account allocated by the third-party authentication system for the terminal device;
  • Receiving the account corresponding to the first token sent by the third-party authentication system acquiring a user identifier bound to the account, and assigning a second token and an IP address of the gateway according to the user identifier, so as to
  • the terminal device uses the service provided by the operator after the gateway authenticates the second token, and the user identifier is an identifier that the operator authentication system allocates for the user.
  • the method further includes:
  • the binding relationship between the account and the user identifier is recorded.
  • the IP address of the second token and the gateway is allocated according to the user identifier, so that the terminal device uses the carrier after the gateway authenticates the second token. Services provided, including:
  • the gateway And sending, by the gateway, the user identifier to the gateway, so that the gateway initiates user registration to the core network of the operator according to the user identifier, where the second token is authenticated and passed in the carrier authentication system. After the registration is completed, the user is caused to use the service provided by the operator through the terminal device.
  • the receiving the access authentication request sent by the terminal device includes:
  • the program can also be used to:
  • the third-party authentication request carries a first token
  • the first token is a token that is allocated by the third-party authentication system according to an account provided by the terminal device, and the account is An account that is allocated to the terminal device by the third-party authentication system; in the case that the first token is authenticated, the account corresponding to the first token is sent to the operator authentication system, to Having the operator authentication system acquire the user bound to the account Logo.
  • the method before receiving the third-party authentication request sent by the operator authentication system, the method includes:
  • the first token is returned to the terminal device.
  • the program can also be used to:
  • the terminal device After the third-party authentication system passes the authentication of the account provided by the terminal device, the terminal device sends an access authentication request to the operator authentication system, where the access authentication request carries the third-party application identifier and the first token.
  • the first token is a token that is allocated by the third-party authentication system according to the account of the terminal device, so that the operator authentication system requests the third-party authentication system to the first according to the third-party application identifier.
  • the token is authenticated to obtain the user identifier bound to the account;
  • the gateway After the gateway authenticates the second token, the service provided by the operator is used.
  • the acquiring the user identifier bound to the account includes: if the operator authentication system does not have the user identifier bound to the account, The operator authentication system receives the user identification input request;
  • the user only needs to provide an account once to log in once on the terminal device. After the account is verified by the third-party authentication system, the user identity system bound to the account can be obtained through the operator authentication system. The authorization of the registered business, thereby using the service, the process is simple and the user experience is good.
  • the various exemplary elements and algorithms of the embodiments described herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the solution. A person skilled in the art can select different methods for implementing the described functions for a particular application, but such implementation should not be considered to be beyond the scope of the present invention.
  • the function is implemented in the form of computer software and sold or used as a stand-alone product, it may be considered to some extent that all or part of the technical solution of the present invention (for example, a part contributing to the prior art) is It is embodied in the form of computer software products.
  • the computer software product is typically stored in a computer readable storage medium and includes instructions for causing a computer device (which may be a personal computer, server, or network device, etc.) to perform all or part of the steps of various embodiments of the present invention. .
  • the foregoing storage medium includes a USB flash drive, a mobile hard disk, a read-only memory (English: Read-Only Memory, abbreviation: ROM), a random access memory (English: Random Access Memory, abbreviation: RAM), a magnetic disk or an optical disk, and the like.
  • ROM Read-Only Memory
  • RAM Random Access Memory

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Power Engineering (AREA)
  • Telephonic Communication Services (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

The present invention relates to a communication authentication method and apparatus, and a terminal device. The communication authentication method comprises: in the case where verification of an account number provided by a third-party authentication system on a terminal device is passed, receiving an access authentication request sent by the terminal device; sending a third-party authentication request to the third-party authentication system corresponding to a third-party application identifier; and receiving an account number corresponding to a first token sent by the third-party authentication system, acquiring a user identifier bound to the account number, and allocating a second token and an IP address of a gateway according to the user identifier, so that the terminal device uses a service provided by an operator after the second token is authenticated by the gateway. In the embodiments of the present invention, a user only needs to provide an account number once on a terminal device log in once, and after a third-party authentication system verifies the account number, the user can obtain an authorization of a service registered by a user identifier which is bound to the account number through an operator authentication system, so that the service is used, the process is simple, and the user experience is good.

Description

通信认证方法及装置、 终端设备  Communication authentication method and device, terminal device
本申请要求了 2013年 9月 23日提交的、 申请号为 201310436691.5、 发 明名称为 "通信认证方法及装置、 终端设备"的中国申请的优先权, 其全部 内容通过引用结合在本申请中。 技术领域  The present application claims the priority of the Chinese application filed on Sep. 23, 2013, the disclosure of which is incorporated herein by reference. Technical field
本发明涉及通信技术领域, 尤其涉及一种通信认证方法及装置、 终端设 备。 背景技术  The present invention relates to the field of communications technologies, and in particular, to a communication authentication method and apparatus, and a terminal device. Background technique
网页实时通信(英文: Web Real-Time Communications,缩写: WebRTC) 业务可以使 IP多媒体子系统 (英文: Internet Protocol Multimedia Subsystem, 缩写: IMS )用户通过第三方应用网站接入运营商的 IMS核心网(英文: IMS core) , 以实现第三方应用网站和终端之间的互通。  Real-time communication (English: Web Real-Time Communications, abbreviation: WebRTC) The service enables the IP Multimedia Subsystem (English: Internet Protocol Multimedia Subsystem, abbreviation: IMS) user to access the operator's IMS core network through a third-party application website ( English: IMS core) to enable interoperability between third-party application websites and terminals.
通常的运营商提供的网页实时通信业务的认证方法,用户需要使用第三 方应用服务器(英文: 3M Party WEB server ) 帐号和密码登录第三方应用 网站, 若用户需要使用 WebRTC业务, 例如用户使用淘宝网购物时, 如果采 用网页上的电话功能(通过 IMS )联系卖家, 需要使用运营商用户名 (英文: webID) 和密码 (英文: Password) 登录运营商认证系统, 并认证该运营商 webID如手机号是否有效。 The authentication method of the real-time communication service of the webpage provided by the operator, the user needs to use the third-party application server (English: 3 M Party WEB server) account and password to log in to the third-party application website. If the user needs to use the WebRTC service, for example, the user uses Taobao. When shopping online, if you use the phone function on the webpage (via IMS) to contact the seller, you need to use the carrier username (English: webID) and password (English: Password) to log in to the carrier authentication system and authenticate the carrier's webID such as mobile phone. Whether the number is valid.
综上所述,用户通过第三方应用网站使用运营商提供的 WebRTC业务时, 不仅需要登陆第三方应用网站使用运营商提供的 WebRTC业务, 还需要登录 不同的运营商认证系统。 因此, 用户需要使用多套用户名和密码进行多次登 录, 过程复杂, 影响用户体验。 发明内容 有鉴于此, 本发明要解决的技术问题是, 用户通过第三方应用网站使用 运营商提供的业务时, 需要多次登录, 过程复杂。 In summary, when a user uses a WebRTC service provided by an operator through a third-party application website, the user needs to log in to the third-party application website to use the WebRTC service provided by the operator, and also needs to log in to different operator authentication systems. Therefore, users need to use multiple sets of usernames and passwords to log in multiple times, which is complicated and affects the user experience. Summary of the invention In view of the above, the technical problem to be solved by the present invention is that when a user uses a service provided by an operator through a third-party application website, multiple logins are required, and the process is complicated.
为了解决上述技术问题,在第一方面,本发明提出了一种通信认证方法, 包括:  In order to solve the above technical problem, in a first aspect, the present invention provides a communication authentication method, including:
在第三方认证系统对终端设备提供的账号验证通过的情况下,接收所述 终端设备发送的接入认证请求,所述接入认证请求中携带第三方应用标识和 第一令牌, 所述第一令牌为所述第三方认证系统根据所述账号分配的令牌, 所述账号为所述第三方认证系统为所述终端设备分配的账号;  And receiving, by the third-party authentication system, the access authentication request sent by the terminal device, where the access authentication request carries the third-party application identifier and the first token, where the a token is a token allocated by the third-party authentication system according to the account, and the account is an account allocated by the third-party authentication system for the terminal device;
向所述第三方应用标识对应的所述第三方认证系统发送第三方认证请 求, 所述第三方认证请求中携带所述第一令牌;  Sending, by the third-party authentication system, the third-party authentication request to the third-party authentication system, where the third-party authentication request carries the first token;
接收所述第三方认证系统发送的所述第一令牌对应的所述账号, 获取所 述账号绑定的用户标识, 根据所述用户标识分配第二令牌和网关的 IP地址, 以使得所述终端设备在所述网关对所述第二令牌进行认证后使用运营商提 供的业务, 所述用户标识为运营商认证系统为用户分配的标识。  Receiving the account corresponding to the first token sent by the third-party authentication system, acquiring a user identifier bound to the account, and assigning a second token and an IP address of the gateway according to the user identifier, so as to The terminal device uses the service provided by the operator after the gateway authenticates the second token, and the user identifier is an identifier that the operator authentication system allocates for the user.
结合第一方面, 在第一种可能的实现方式中, 在不存在与所述账号绑定 的所述用户标识的情况下,所述接收所述第三方认证系统发送的所述第一令 牌对应的所述账号之后, 所述获取所述账号绑定的用户标识之前, 还包括: 向所述终端设备发送用户标识输入请求;  With reference to the first aspect, in a first possible implementation, the first token sent by the third-party authentication system is received in a case where the user identifier bound to the account is not present Before the corresponding account, the obtaining the user identifier bound to the account, the method further includes: sending a user identifier input request to the terminal device;
接收所述终端设备发送的所述用户标识之后, 记录所述账号与所述用户 标识的绑定关系。  After receiving the user identifier sent by the terminal device, the binding relationship between the account and the user identifier is recorded.
结合第一方面或第一方面的第一种可能的实现方式,在第二种可能的实 现方式中, 所述根据所述用户标识分配第二令牌和网关的 IP地址, 以使得所 述终端设备在所述网关对所述第二令牌进行认证后使用运营商提供的业务, 包括:  With reference to the first aspect or the first possible implementation manner of the first aspect, in a second possible implementation manner, the assigning the second token and the IP address of the gateway according to the user identifier, so that the terminal After the device authenticates the second token, the device uses the service provided by the operator, including:
根据所述用户标识, 分配所述第二令牌和所述 IP地址; 向所述终端设备发送所述第二令牌和所述 IP地址, 以使得所述终端设备 根据所述 IP地址向所述网关发送所述第二令牌的认证请求; Allocating the second token and the IP address according to the user identifier; Sending, by the terminal device, the second token and the IP address, so that the terminal device sends an authentication request of the second token to the gateway according to the IP address;
在所述第二令牌在所述运营商认证系统内认证通过的情况下, 向所述网 关发送所述用户标识, 以使得所述网关根据所述用户标识向所述运营商的核 心网发起用户注册, 在注册完成之后, 使得所述用户通过所述终端设备使用 所述运营商提供的业务。  And sending, by the gateway, the user identifier to the gateway, so that the gateway initiates to the core network of the operator according to the user identifier, where the second token is authenticated and passed in the carrier authentication system. User registration, after the registration is completed, causes the user to use the service provided by the operator through the terminal device.
结合第一方面的第一种可能的实现方式, 在第三种可能的实现方式中, 所述接收所述终端设备发送的接入认证请求, 具体包括:  With reference to the first possible implementation manner of the first aspect, in a third possible implementation, the receiving the access authentication request sent by the terminal device includes:
通过运营商认证门户从所述终端设备接收所述接入认证请求; 所述向所述终端设备发送用户标识输入请求, 具体包括:  Receiving, by the operator authentication portal, the access authentication request from the terminal device; the sending the user identifier input request to the terminal device, specifically:
通过所述运营商认证门户向所述终端设备发送所述用户标识输入请求; 所述接收所述终端设备发送的所述用户标识之后, 记录所述账号与所述 用户标识的绑定关系, 具体包括:  Transmitting, by the operator authentication portal, the user identifier input request to the terminal device; after receiving the user identifier sent by the terminal device, recording a binding relationship between the account and the user identifier, specifically Includes:
通过所述运营商认证门户从所述终端设备接收所述用户标识; 记录所述账号与所述用户标识的绑定关系。  Receiving, by the operator authentication portal, the user identifier from the terminal device; recording a binding relationship between the account and the user identifier.
第二方面, 本发明提出了一种通信认证方法, 包括:  In a second aspect, the present invention provides a communication authentication method, including:
接收运营商认证系统发送的第三方认证请求,所述第三方认证请求中携 带第一令牌,所述第一令牌是第三方认证系统根据终端设备提供的账号分配 的令牌, 所述账号为所述第三方认证系统为所述终端设备分配的账号; 在所述第一令牌认证通过的情况下, 向所述运营商认证系统发送所述第 一令牌对应的所述账号, 以使所述运营商认证系统获取所述账号绑定的用户 标识。  Receiving a third-party authentication request sent by the operator authentication system, where the third-party authentication request carries a first token, where the first token is a token that is allocated by the third-party authentication system according to an account provided by the terminal device, and the account is An account that is allocated to the terminal device by the third-party authentication system; in the case that the first token is authenticated, the account corresponding to the first token is sent to the operator authentication system, to And causing the operator authentication system to obtain the user identifier bound to the account.
结合第二方面, 在第一种可能的实现方式中, 所述接收运营商认证系统 发送的第三方认证请求之前, 包括:  With reference to the second aspect, in a first possible implementation, before receiving the third-party authentication request sent by the operator authentication system, the method includes:
验证所述终端设备提供的账号; 在验证通过的情况下, 向所述终端设备返回所述第一令牌。 第三方面, 本发明提出了一种通信认证方法, 包括: Verifying the account provided by the terminal device; In case the verification is passed, the first token is returned to the terminal device. In a third aspect, the present invention provides a communication authentication method, including:
在第三方认证系统对终端设备提供的账号验证通过的情况下, 终端设备 向运营商认证系统发送接入认证请求,所述接入认证请求中携带第三方应用 标识和第一令牌,所述第一令牌为所述第三方认证系统根据所述终端设备的 账号分配的令牌, 以使得所述运营商认证系统根据所述第三方应用标识请求 所述第三方认证系统对所述第一令牌进行认证, 以获取所述账号绑定的用户 标识;  After the third-party authentication system passes the authentication of the account provided by the terminal device, the terminal device sends an access authentication request to the operator authentication system, where the access authentication request carries the third-party application identifier and the first token. The first token is a token that is allocated by the third-party authentication system according to the account of the terminal device, so that the operator authentication system requests the third-party authentication system to the first according to the third-party application identifier. The token is authenticated to obtain the user identifier bound to the account;
接收所述运营商认证系统发送的第二令牌和网关的 IP地址, 所述第二令 牌和网关的 IP地址为所述运营商认证系统根据所述用户标识分配的令牌和 IP 地址;  Receiving the second token and the IP address of the gateway sent by the operator authentication system, where the IP address of the second token and the gateway is a token and an IP address allocated by the operator authentication system according to the user identifier;
在所述网关对所述第二令牌进行认证后使用运营商提供的业务。  After the gateway authenticates the second token, the service provided by the operator is used.
结合第三方面, 在第一种可能的实现方式中, 所述获取所述账号绑定的 用户标识, 包括:  With reference to the third aspect, in a first possible implementation manner, the acquiring the user identifier bound to the account includes:
在所述运营商认证系统不存在与所述账号绑定的所述用户标识的情况 下, 从所述运营商认证系统接收用户标识输入请求;  Receiving a user identity input request from the operator authentication system if the operator authentication system does not have the user identity bound to the account;
向所述运营商认证系统发送用户输入的所述用户标识, 以使得所述运营 商认证系统记录所述账号与所述用户标识的绑定关系。  Sending the user identifier input by the user to the operator authentication system, so that the operator authentication system records a binding relationship between the account and the user identifier.
第四方面, 本发明提出了一种通信认证装置, 包括:  In a fourth aspect, the present invention provides a communication authentication apparatus, including:
第一接收模块,用于在第三方认证系统对终端设备提供的账号验证通过 的情况下, 接收所述终端设备发送的接入认证请求, 所述接入认证请求中携 带第三方应用标识和第一令牌,所述第一令牌为所述第三方认证系统根据所 述账号分配的令牌,所述账号为所述第三方认证系统为所述终端设备分配的 账号;  a first receiving module, configured to receive an access authentication request sent by the terminal device when the third-party authentication system passes the account verification provided by the terminal device, where the access authentication request carries the third-party application identifier and the a token, the first token is a token allocated by the third-party authentication system according to the account, and the account is an account allocated by the third-party authentication system to the terminal device;
第一发送模块, 与所述第一接收模块连接, 用于向所述第三方应用标识 对应的所述第三方认证系统发送第三方认证请求,所述第三方认证请求中携 带所述第一令牌; a first sending module, connected to the first receiving module, configured to apply the identifier to the third party Corresponding third-party authentication system sends a third-party authentication request, where the third-party authentication request carries the first token;
第二接收模块,用于接收所述第三方认证系统发送的所述第一令牌对应 的所述账号;  a second receiving module, configured to receive the account corresponding to the first token sent by the third-party authentication system;
第一处理模块, 与所述第二接收模块连接, 用于获取所述账号绑定的用 户标识, 根据所述用户标识分配第二令牌和网关的 IP地址, 以使得所述终端 设备在所述网关对所述第二令牌进行认证后使用运营商提供的业务,所述用 户标识为所述通信认证装置为用户分配的标识。  a first processing module, configured to be connected to the second receiving module, configured to acquire a user identifier bound to the account, and allocate an IP address of the second token and the gateway according to the user identifier, so that the terminal device is in the After the gateway authenticates the second token, the service provided by the operator is used, and the user identifier is an identifier that is allocated by the communication authentication device to the user.
结合第四方面, 在第一种可能的实现方式中, 在不存在与所述账号绑定 的所述用户标识的情况下, 所述通信认证装置还包括:  With reference to the fourth aspect, in a first possible implementation, in a case where the user identifier that is bound to the account is not present, the communication authentication apparatus further includes:
第二发送模块, 与所述第一处理模块连接, 用于向所述终端设备发送用 户标识输入请求;  a second sending module, configured to be connected to the first processing module, configured to send a user identity input request to the terminal device;
第二处理模块, 与所述第二接收模块和所述第一处理模块连接, 用于接 收所述终端设备发送的所述用户标识之后,记录所述账号与所述用户标识的 绑定关系。  The second processing module is configured to be connected to the second receiving module and the first processing module, and configured to record the binding relationship between the account and the user identifier after receiving the user identifier sent by the terminal device.
结合第四方面或第四方面的第一种可能的实现方式,在第二种可能的实 现方式中, 所述第一处理模块具体包括:  With reference to the fourth aspect, or the first possible implementation manner of the fourth aspect, in the second possible implementation manner, the first processing module specifically includes:
分配子模块,用于根据所述用户标识,分配所述第二令牌和所述 IP地址; 第一发送子模块, 与所述分配子模块连接, 用于向所述终端设备发送所 述第二令牌和所述 IP地址, 以使得所述终端设备根据所述 IP地址向所述网关 发送所述第二令牌的认证请求;  a distribution submodule, configured to allocate the second token and the IP address according to the user identifier; a first sending submodule, connected to the allocation submodule, configured to send the first to the terminal device a second token and the IP address, so that the terminal device sends an authentication request of the second token to the gateway according to the IP address;
第二发送子模块,用于在所述第二令牌在所述通信认证装置内认证通过 的情况下, 向所述网关发送所述用户标识, 以使得所述网关根据所述用户标 识向所述运营商的核心网发起用户注册, 在注册完成之后, 使得所述用户通 过所述终端设备使用所述运营商提供的业务。 结合第四方面的第一种可能的实现方式, 在第三种可能的实现方式中, 所述第一接收模块还用于通过运营商认证门户从所述终端设备接收所述接 入认证请求; a second sending submodule, configured to send the user identifier to the gateway, where the second token is authenticated in the communication authentication device, so that the gateway is located according to the user identifier The core network of the operator initiates user registration, and after the registration is completed, the user is allowed to use the service provided by the operator through the terminal device. With reference to the first possible implementation manner of the fourth aspect, in a third possible implementation, the first receiving module is further configured to receive the access authentication request from the terminal device by using an operator authentication portal;
所述第二发送模块还用于通过所述运营商认证门户向所述终端设备发 送所述用户标识输入请求;  The second sending module is further configured to send the user identity input request to the terminal device by using the operator authentication portal;
所述第二处理模块具体包括:  The second processing module specifically includes:
第一接收子模块,用于通过所述运营商认证门户从所述终端设备接收所 述用户标识;  a first receiving submodule, configured to receive, by the operator authentication portal, the user identifier from the terminal device;
记录子模块, 与所述第一接收子模块连接, 用于记录所述账号与所述用 户标识的绑定关系。  The recording submodule is connected to the first receiving submodule and configured to record a binding relationship between the account and the user identifier.
第五方面, 本发明提出了一种通信认证装置, 包括:  In a fifth aspect, the present invention provides a communication authentication apparatus, including:
接收模块, 用于接收运营商认证系统发送的第三方认证请求, 所述第三 方认证请求中携带第一令牌,所述第一令牌为所述通信认证装置根据终端设 备提供的账号分配的令牌,所述账号为所述通信认证装置为所述终端设备分 配的账号;  a receiving module, configured to receive a third-party authentication request sent by the operator authentication system, where the third-party authentication request carries a first token, where the first token is allocated by the communication authentication device according to an account provided by the terminal device a token, where the account is an account allocated by the communication authentication device for the terminal device;
第一发送模块, 与所述接收模块连接, 用于在所述第一令牌认证通过的 情况下, 向所述运营商认证系统发送所述第一令牌对应的所述账号, 以使所 述运营商认证系统获取所述账号绑定的用户标识。  a first sending module, configured to be connected to the receiving module, configured to send the account corresponding to the first token to the operator authentication system, if the first token is authenticated, to The carrier authentication system obtains the user identifier bound to the account.
结合第五方面, 在第一种可能的实现方式中, 所述装置还包括: 验证模块, 用于验证所述终端设备提供的账号;  With reference to the fifth aspect, in a first possible implementation, the device further includes: a verification module, configured to verify an account provided by the terminal device;
第二发送模块, 与所述验证模块连接, 用于在所述验证模块验证通过的 情况下, 向所述终端设备返回所述第一令牌。  And a second sending module, configured to be connected to the verification module, configured to return the first token to the terminal device if the verification module passes the verification.
第六方面, 本发明提出了一种终端设备, 包括:  In a sixth aspect, the present invention provides a terminal device, including:
发送模块,用于在第三方认证系统对终端设备提供的账号验证通过的情 况下, 终端设备向运营商认证系统发送接入认证请求, 所述接入认证请求中 携带第三方应用标识和第一令牌,所述第一令牌为所述第三方认证系统根据 所述终端设备的账号分配的令牌, 以使得所述运营商认证系统根据所述第三 方应用标识请求所述第三方认证系统对所述第一令牌进行认证, 以获取所述 账号绑定的用户标识; a sending module, configured to send an access authentication request to the operator authentication system, where the third party authentication system passes the account verification provided by the terminal device, where the access authentication request is Carrying a third-party application identifier and a first token, where the first token is a token allocated by the third-party authentication system according to an account of the terminal device, so that the operator authentication system is based on the third-party application. Identifying that the third-party authentication system authenticates the first token to obtain a user identifier bound to the account;
接收模块, 用于接收所述运营商认证系统发送的第二令牌和网关的 IP地 址, 所述第二令牌和网关的 IP地址为所述运营商认证系统根据所述用户标识 分配的令牌和 IP地址;  a receiving module, configured to receive an IP address of the second token and the gateway sent by the operator authentication system, where the IP address of the second token and the gateway is an order allocated by the operator authentication system according to the user identifier Card and IP address;
控制模块, 与所述接收模块连接, 用于在所述网关对所述第二令牌进行 认证后使用运营商提供的业务。  The control module is connected to the receiving module, and is configured to use the service provided by the operator after the gateway authenticates the second token.
结合第六方面, 在第一种可能的实现方式中, 所述接收模块还用于在所 述运营商认证系统不存在与所述账号绑定的所述用户标识的情况下, 从所述 运营商认证系统接收用户标识输入请求;  With reference to the sixth aspect, in a first possible implementation manner, the receiving module is further configured to: when the carrier authentication system does not have the user identifier bound to the account, The quotient authentication system receives the user identification input request;
所述发送模块还用于向所述运营商认证系统发送用户输入的所述用户 标识, 以使得所述运营商认证系统记录所述账号与所述用户标识的绑定关 本实施例的通信认证方法,用户在终端设备上只需要提供一次账号进行 一次登录, 在通过第三方认证系统对该账号验证通过后, 可以通过运营商认 证系统获得该账号绑定的用户标识所注册的业务的授权, 从而使用该业务, 过程简单, 用户体验良好。 附图说明  The sending module is further configured to send the user identifier input by the user to the operator authentication system, so that the operator authentication system records the binding of the account and the user identifier to the communication authentication of the embodiment. The user only needs to provide an account once to log in once on the terminal device. After the account is verified by the third-party authentication system, the user can obtain the authorization of the service registered by the user identifier bound to the account. Thus using the service, the process is simple and the user experience is good. DRAWINGS
包含在说明书中并且构成说明书的一部分的附图与说明书一起示出了 本发明的示例性实施例、 特征和方面, 并且用于解释本发明的原理。  The accompanying drawings, which are incorporated in FIG
图 1为根据本发明实施例一的通信认证方法的流程图;  1 is a flowchart of a communication authentication method according to Embodiment 1 of the present invention;
图 2为根据本发明实施例二的通信认证方法的流程图; 图 3为根据本发明实施例三的通信认证方法的流程图; 2 is a flowchart of a communication authentication method according to Embodiment 2 of the present invention; 3 is a flowchart of a communication authentication method according to Embodiment 3 of the present invention;
图 4为根据本发明实施例四的通信认证方法的流程图;  4 is a flowchart of a communication authentication method according to Embodiment 4 of the present invention;
图 5为根据本发明实施例五的通信认证方法的流程图;  5 is a flowchart of a communication authentication method according to Embodiment 5 of the present invention;
图 6为根据本发明实施例六的通信认证装置的结构框图;  6 is a structural block diagram of a communication authentication apparatus according to Embodiment 6 of the present invention;
图 7为根据本发明实施例七的通信认证装置的结构框图;  7 is a structural block diagram of a communication authentication apparatus according to Embodiment 7 of the present invention;
图 8为根据本发明实施例八的通信认证装置的结构框图;  8 is a structural block diagram of a communication authentication apparatus according to Embodiment 8 of the present invention;
图 9为根据本发明实施例九的终端设备的结构框图; 以及  9 is a structural block diagram of a terminal device according to Embodiment 9 of the present invention;
图 10为根据本发明实施例十的通信认证装置的结构框图。 具体实施方式  Figure 10 is a block diagram showing the structure of a communication authentication apparatus according to Embodiment 10 of the present invention. detailed description
以下将参考附图详细说明本发明的各种示例性实施例、 特征和方面。 附 图中相同的附图标记表示功能相同或相似的元件。尽管在附图中示出了实施 例的各种方面, 但是除非特别指出, 不必按比例绘制附图。  Various exemplary embodiments, features, and aspects of the invention are described in detail below with reference to the drawings. The same reference numerals in the drawings denote the same or similar elements. The various aspects of the embodiments are shown in the drawings, and the drawings are not necessarily drawn to scale unless otherwise indicated.
在这里专用的词"示例性 "意为 "用作例子、 实施例或说明性"。 这里作为 "示例性"所说明的任何实施例不必解释为优于或好于其它实施例。  The word "exemplary" is used exclusively herein to mean "serving as an example, embodiment, or illustrative." Any embodiment described herein as "exemplary" is not necessarily to be construed as preferred or advantageous.
另外, 为了更好的说明本发明, 在下文的具体实施方式中给出了众多的 具体细节。 本领域技术人员应当理解, 没有这些具体细节, 本发明同样可以 实施。 在另外一些实例中, 对于大家熟知的方法、 手段、 元件和电路未作详 细描述, 以便于凸显本发明的主旨。  Further, in order to better illustrate the invention, numerous specific details are set forth in the Detailed Description. Those skilled in the art will appreciate that the present invention may be practiced without these specific details. In other instances, well-known methods, means, components, and circuits have not been described in detail in order to facilitate the invention.
实施例 1  Example 1
图 1为根据本发明实施例一的通信认证方法的流程图。 如图 1所示, 该通 信认证方法可以包括:  1 is a flow chart of a communication authentication method according to a first embodiment of the present invention. As shown in FIG. 1, the communication authentication method may include:
歩骤 S100、 在第三方认证系统对终端设备提供的账号验证通过的情况 下, 接收所述终端设备发送的接入认证请求, 所述接入认证请求中携带第三 方应用标识和第一令牌。所述第一令牌为所述第三方认证系统根据所述账号 分配的令牌, 所述账号为所述第三方认证系统为所述终端设备分配的账号。 具体地,用户可以使用终端设备(英文: terminal equipment,缩写: TE), 例如: 手机、 个人计算机(英文: personal computer, 缩写: PC)、 平板电脑 等, 登录第三方应用网站 (例如: 淘宝网、 新浪网、 当当网、 蘑菇街等)。 其中, 第三方应用网站可以包括自己的认证系统, 简称第三方认证系统。 在 用户通过第三方认证系统的验证后, 可以登录该第三方应用网站。 然后可以 通过该第三方应用网站使用运营商(例如: 中国移动、 中国联通、 中国电信、 IMS业务提供商等) 提供的业务。 其中, 业务可以为网页实时通信 WebRTC 业务例如: 语音业务、 视频业务、 文件传输业务等 IMS业务。 例如: 用户使 用手机登录蘑菇街进行购物, 可以点击蘑菇街界面显示的视频联系卖家的对 话框和卖家进行视频交流。 但是, 由于第三方应用网站和运营商认证系统是 两个运营系统, 因此, 用户登录第三方应用网站之后, 运营商认证系统需要 对用户的身份进行认证。 Step S100: Receive an access authentication request sent by the terminal device, where the third-party application identifier and the first token are carried in the access authentication request, where the third-party authentication system passes the account verification provided by the terminal device. . The first token is the third party authentication system according to the account An assigned account, where the account is an account allocated by the third-party authentication system for the terminal device. Specifically, the user can use a terminal device (English: terminal equipment, abbreviation: TE), for example: mobile phone, personal computer (English: personal computer, abbreviation: PC), tablet, etc., to log in to a third-party application website (for example: Taobao.com) , Sina.com, Dangdang.com, Mushroom Street, etc.). The third-party application website may include its own authentication system, referred to as a third-party authentication system. After the user is authenticated by the third-party authentication system, the third-party application website can be logged in. The third-party application website can then be used to provide services provided by operators (for example, China Mobile, China Unicom, China Telecom, IMS service providers, etc.). The service may be a real-time communication WebRTC service such as a voice service, a video service, a file transmission service, and the like. For example: If you use your mobile phone to log in to Mushroom Street for shopping, you can click on the video displayed on the mushroom street interface to contact the seller's dialog box and the seller for video communication. However, since the third-party application website and the carrier authentication system are two operating systems, after the user logs in to the third-party application website, the operator authentication system needs to authenticate the user's identity.
第三方认证系统对用户通过终端设备提供的账号(例如某一淘宝网的用 户名)进行验证的过程中, 除了验证账号是否是第三方认证系统为用户分配 的合法的账号之外, 还可以验证账号对应的密码是否准确。 因此, 用户通过 终端设备向第三方认证系统提供账号的同时,可以一并将账号对应的密码提 供给第三方认证系统。在第三方认证系统验证通过的情况下, 第三方认证系 统可以根据该账号为用户分配与该账号对应的第一令牌。  In the process of verifying the account provided by the user through the terminal device (for example, the username of a certain Taobao network), the third-party authentication system can verify whether the account is a legal account assigned by the third-party authentication system for the user. Whether the password corresponding to the account is accurate. Therefore, when the user provides an account to the third-party authentication system through the terminal device, the user can provide the password corresponding to the account to the third-party authentication system. In the case that the third-party authentication system passes the verification, the third-party authentication system may assign the first token corresponding to the account to the user according to the account.
在一种可能的实现方式中, 所述接收所述终端设备发送的接入认证请 求,具体包括:通过运营商认证门户从所述终端设备接收所述接入认证请求。  In a possible implementation, the receiving the access authentication request sent by the terminal device includes: receiving, by the operator authentication portal, the access authentication request from the terminal device.
具体地, 运营商认证门户可以接收该终端设备发送的接入认证请求, 再 由运营商认证系统接收该运营商认证门户发送的接入认证请求。  Specifically, the operator authentication portal may receive the access authentication request sent by the terminal device, and then the operator authentication system receives the access authentication request sent by the operator authentication portal.
歩骤 S120、向所述第三方应用标识对应的所述第三方认证系统发送第三 方认证请求, 所述第三方认证请求中携带所述第一令牌。 可以在运营商认证系统内部或者外部设置一个接口设备。 一种情况下, 该接口设备设置在运营商认证系统的外部, 该接口设备在运营商认证系统和 第三方认证系统之间转发信息,运营商认证系统将第三方认证请求发送给该 接口设备, 再由该接口设备将该第三方认证请求转发给第三方认证系统。 另 —种情况下, 该接口设备设置在运营商认证系统的内部, 运营商认证系统可 以直接向第三方认证系统发送第三方认证请求。 Step S120: Send a third-party authentication request to the third-party authentication system corresponding to the third-party application identifier, where the third-party authentication request carries the first token. An interface device can be set inside or outside the carrier authentication system. In one case, the interface device is configured to be external to the operator authentication system, and the interface device forwards information between the operator authentication system and the third-party authentication system, and the operator authentication system sends a third-party authentication request to the interface device. The third-party authentication request is forwarded by the interface device to the third-party authentication system. In another case, the interface device is set inside the operator authentication system, and the operator authentication system can directly send a third-party authentication request to the third-party authentication system.
具体地,运营商认证系统可以根据接入认证请求中携带的第三方应用标 识, 获知该接入认证请求是由哪一个第三方应用网站接入的, 可以通过接口 设备向该第三方应用网站的第三方认证系统发送携带所述第一令牌的第三 方认证请求, 也可以直接向该第三方应用网站的第三方认证系统发送携带所 述第一令牌的第三方认证请求。 例如: 若第三方应用网站为淘宝网, 运营商 认证系统可以根据该第三方应用标识获知该接入认证请求是由淘宝网接入 的, 可以通过接口设备向淘宝网认证系统发送第三方认证请求, 也可以直接 向淘宝网认证系统发送第三方认证请求, 该第三方认证请求中携带了由该淘 宝网认证系统分配的与淘宝网的用户名相对应的第一令牌。  Specifically, the operator authentication system can learn, according to the third-party application identifier carried in the access authentication request, which third-party application website is accessed by the third-party application website, and can use the interface device to apply to the third-party application website. The third-party authentication system sends a third-party authentication request that carries the first token, and may also directly send a third-party authentication request that carries the first token to the third-party authentication system of the third-party application website. For example, if the third-party application website is Taobao, the carrier authentication system can learn that the access authentication request is accessed by the Taobao network according to the third-party application identifier, and the third-party authentication request can be sent to the Taobao authentication system through the interface device. The third-party authentication request may be directly sent to the Taobao authentication system, where the third-party authentication request carries the first token corresponding to the user name of the Taobao network allocated by the Taobao authentication system.
歩骤 S140、接收所述第三方认证系统发送的所述第一令牌对应的所述账 号, 获取所述账号绑定的用户标识, 根据所述用户标识分配第二令牌和网关 的 IP地址, 以使得所述终端设备在所述网关对所述第二令牌进行认证后使用 运营商提供的业务。 所述用户标识为运营商认证系统为用户分配的标识。  Step S140: Receive the account corresponding to the first token sent by the third-party authentication system, obtain a user identifier bound to the account, and allocate a second token and an IP address of the gateway according to the user identifier. So that the terminal device uses the service provided by the operator after the gateway authenticates the second token. The user identifier is an identifier assigned by the operator authentication system to the user.
具体地, 若第三方认证系统认证第一令牌通过, 运营商认证系统可以通 过接口设备接收该第三方认证系统发送的账号,运营商认证系统也可以直接 接收该第三方认证系统发送的账号。 其中, 该帐号在歩骤 S140中, 可以只包 括第三方认证系统为终端设备分配的账号。运营商认证系统还可以通过接口 设备或直接接收到与该账号对应的第一令牌。 然后, 运营商认证系统可以根 据账号, 获取与该帐号绑定的用户标识, 该用户标识可以包括 IP多媒体子系 统公有用户标 i只 (英文: Internet Protocol Multimedia Subsystem Public User Identity,缩写: IMPU)、 IP多媒体子系统私有用户标识(英文: Internet Protocol Multimedia Subsystem Private User Identity, 缩写: IMPI) 和用户与运营商签 约的用户名中的任意一种或者多种。 例如手机号码、 邮箱、 身份证号码等。 最后, 运营商认证系统可以根据获取到的用户标识, 分配第二令牌和网关的 IP地址, 并将该第二令牌和网关的 IP地址发送给终端设备, 以使得所述终端 设备可以在所述网关对所述第二令牌进行认证后,用户可以直接使用运营商 提供的业务。 例如: 若第三方应用网站为淘宝网, 若淘宝网认证系统认证第 一令牌通过,运营商认证系统可以通过接口设备或直接接收淘宝网认证系统 发送的淘宝网的用户名, 然后运营商认证系统可以获取与淘宝网的用户名绑 定的用户标识例如手机号码。 后续网关代替用户注册完成之后, 用户可以通 过终端设备直接使用运营商提供的与该淘宝网的用户名绑定的手机号码所 注册的业务。 Specifically, if the third-party authentication system authenticates the first token, the operator authentication system can receive the account sent by the third-party authentication system through the interface device, and the operator authentication system can directly receive the account sent by the third-party authentication system. The account number in the step S140 may include only the account number allocated by the third-party authentication system for the terminal device. The operator authentication system may also receive the first token corresponding to the account through the interface device or directly. Then, the operator authentication system can obtain a user identifier bound to the account according to the account, and the user identifier can include an IP multimedia subsystem. There is a user ID i (English: Internet Protocol Multimedia Subsystem Public User Identity, IMPU), IP Multimedia Subsystem Private User Identity (IMI), and users sign up with operators. Any one or more of the user names. For example, mobile phone number, email address, ID number, etc. Finally, the operator authentication system may allocate the IP address of the second token and the gateway according to the obtained user identifier, and send the IP address of the second token and the gateway to the terminal device, so that the terminal device may be in the After the gateway authenticates the second token, the user can directly use the service provided by the operator. For example: If the third-party application website is Taobao, if the first token of the Taobao authentication system is passed, the operator authentication system can directly receive the user name of the Taobao network sent by the Taobao authentication system through the interface device, and then the operator authentication. The system can obtain a user identifier such as a mobile phone number bound to the user name of Taobao. After the subsequent gateway is replaced by the user registration, the user can directly use the terminal device to use the service registered by the operator and the mobile phone number bound to the Taobao user name.
需要注意的是, 尽管以运营商认证系统、 第三方认证系统作为示例介绍 了通信认证方法, 但本领域技术人员能够理解, 本发明应不限于此, 名称不 同、 但功能类似的其它通信设备能够完成本发明的功能, 都属于本发明的保 护范围。  It should be noted that although the communication authentication method is introduced by using the operator authentication system and the third-party authentication system as an example, those skilled in the art can understand that the present invention is not limited thereto, and other communication devices with different names but similar functions can The completion of the functions of the present invention is within the scope of the present invention.
本发明实施例的通信认证方法,用户在终端设备上只需要提供一次账号 进行一次登录, 在通过第三方认证系统对该账号验证通过后, 可以通过运营 商认证系统获得该账号绑定的用户标识所注册的业务的授权, 从而使用该业 务, 过程简单, 用户体验良好。  In the communication authentication method of the embodiment of the present invention, the user only needs to provide an account once to log in once on the terminal device. After the account is verified by the third-party authentication system, the user identity of the account can be obtained through the operator authentication system. The authorization of the registered business, thereby using the service, the process is simple and the user experience is good.
实施例 2  Example 2
图 2为根据本发明实施例二的通信认证方法的流程图。 图 2中标号与图 1 相同的歩骤具有相同的功能, 为简明起见, 省略对这些歩骤的详细说明。  2 is a flow chart of a communication authentication method according to Embodiment 2 of the present invention. The same steps in Fig. 2 as those in Fig. 1 have the same functions, and a detailed description of these steps will be omitted for the sake of brevity.
如图 2所示, 图 2所示的通信认证方法与图 1所示通信认证方法的主要区 别在于,除了包括上述实施例一中的歩骤 S100和歩骤 S120之外,还可以包括: 歩骤 S200、 向所述终端设备发送用户标识输入请求。 As shown in FIG. 2, the communication authentication method shown in FIG. 2 and the main area of the communication authentication method shown in FIG. In addition, in addition to the step S100 and the step S120 in the first embodiment, the method may further include: Step S200: Send a user identifier input request to the terminal device.
具体地, 若接收到第三方认证系统发送的与第一令牌对应的账号, 运营 商认证系统可以查找该账号是否绑定了用户标识。若不存在与该帐号绑定的 用户标识, 则可以执行上述歩骤 S200, 运营商认证系统可以请求终端设备发 送用户标识。 反之, 若存在与该帐号绑定的用户标识, 则可以执行上述歩骤 S140, 运营商认证系统可以获取与该账号绑定的用户标识。 例如: 若用户通 过手机登录淘宝网, 并且使用淘宝网上的中国移动的电话功能, 若中国移动 认证系统接收到淘宝网认证系统发送的淘宝网的用户名, 中国移动认证系统 可以根据该淘宝网的用户名查找该淘宝网的用户名是否绑定了用户的手机 号码, 若没有绑定用户的手机号码, 中国移动认证系统可以请求用户通过手 机发送手机号码。  Specifically, if the account corresponding to the first token sent by the third-party authentication system is received, the operator authentication system may search whether the account is bound with the user identifier. If the user identifier is not associated with the account, the S200 can be performed. The operator authentication system can request the terminal device to send the user identifier. On the other hand, if there is a user identifier bound to the account, the foregoing step S140 can be performed, and the operator authentication system can obtain the user identifier bound to the account. For example: If the user logs in to Taobao through the mobile phone and uses the mobile phone function of China Mobile on Taobao, if the China Mobile authentication system receives the user name of the Taobao network sent by the Taobao authentication system, the China Mobile authentication system can be based on the Taobao network. The user name is used to find out whether the user name of the Taobao network is bound to the mobile phone number of the user. If the mobile phone number of the user is not bound, the China Mobile authentication system can request the user to send the mobile phone number through the mobile phone.
在一种可能的实现方式中, 所述向所述终端设备发送用户标识输入请 求, 具体包括: 通过所述运营商认证门户向所述终端设备发送所述用户标识 输入请求。  In a possible implementation, the sending the user identifier input request to the terminal device includes: sending, by the operator authentication portal, the user identifier input request to the terminal device.
具体地, 若不存在与上述账号绑定的用户标识, 则运营商认证系统可以 向运营商认证门户发送用户标识输入请求, 再由该运营商认证门户向该终端 设备发送用户标识输入请求。  Specifically, if there is no user identifier bound to the account, the operator authentication system may send a user identity input request to the operator authentication portal, and then the carrier authentication portal sends a user identity input request to the terminal device.
歩骤 S220、接收所述终端设备发送的所述用户标识之后, 记录所述账号 与所述用户标识的绑定关系。  Step S220: After receiving the user identifier sent by the terminal device, record a binding relationship between the account and the user identifier.
在一种可能的实现方式中, 上述歩骤 S220具体可以包括:  In a possible implementation manner, the foregoing step S220 may specifically include:
通过所述运营商认证门户从所述终端设备接收所述用户标识;  Receiving, by the operator authentication portal, the user identifier from the terminal device;
记录所述账号与所述用户标识的绑定关系。  Recording a binding relationship between the account and the user identifier.
具体地,运营商认证系统可以通过运营商认证门户从终端设备接收用户 标识,运营商认证系统可以记录所述账号与所述用户标识的绑定关系。其中, 用户可以通过终端设备只输入 IMPU或 IMPI, 也可以既输入 IMPU又输入 IMPIo 由于 IMPU与 IMPI存在一定的映射关系, 运营商认证系统可以根据用 户通过终端设备输入的 IMPU查找到对应的 IMPI。 用户还可以通过终端设备 只输入用户与运营商签约的用户标识。 运营商认证系统无法认证该用户标 识,可以到运营商的 IMS核心网中的归属用户服务器(英文: Home Subscriber Server, 缩写: HSS)进行认证。 若 HSS认证该用户标识通过, 运营商认证系 统可以记录账号与用户标识的绑定关系, 其中, 该帐号在歩骤 S220中, 可以 只包括第三方认证系统为终端设备分配的账号。 例如: 若用户通过手机登录 淘宝网, 并且使用淘宝网上的中国移动的电话功能, 中国移动认证系统通过 中国移动认证门户从手机接收到该用户的手机号码之后, 中国移动认证系统 可以记录淘宝网的用户名与该用户的手机号码的绑定关系。后续用户注册完 成之后, 可以直接使用中国移动提供的与该淘宝网的用户名绑定的手机号码 所注册的业务。 Specifically, the operator authentication system may receive the user identifier from the terminal device through the operator authentication portal, and the operator authentication system may record the binding relationship between the account and the user identifier. among them, The user can input only the IMPU or IMPI through the terminal device, and can input both the IMPU and the IMPIo. Because the IMPU has a certain mapping relationship with the IMPI, the operator authentication system can find the corresponding IMPI according to the IMPU input by the user through the terminal device. The user can also input only the user ID that the user has signed with the operator through the terminal device. The operator authentication system cannot authenticate the user ID and can authenticate to the home subscriber server (English: Home Subscriber Server, HSS) in the IMS core network of the operator. If the HSS authenticates the user ID, the operator authentication system may record the binding relationship between the account and the user identifier. The account may include only the account assigned by the third-party authentication system for the terminal device in step S220. For example: If the user logs in to Taobao through the mobile phone and uses the mobile phone function of China Mobile on Taobao, the China Mobile authentication system can receive the mobile phone number of the user from the mobile phone through the China Mobile Authentication Portal, the China Mobile authentication system can record Taobao. The binding relationship between the username and the user's mobile number. After the subsequent user registration is completed, the service registered by the mobile phone number provided by China Mobile and bound to the Taobao user name can be directly used.
歩骤 S240、根据所述用户标识,分配所述第二令牌和所述网关的 IP地址。 歩骤 S260、 向所述终端设备发送所述第二令牌和所述 IP地址, 以使得所 述终端设备根据所述 IP地址向所述网关发送所述第二令牌的认证请求。  Step S240: Allocate the second token and an IP address of the gateway according to the user identifier. Step S260: Send the second token and the IP address to the terminal device, so that the terminal device sends an authentication request of the second token to the gateway according to the IP address.
例如, 若用户通过手机登录淘宝网 (第三方应用网站), 并且使用淘宝 网上的中国移动 (运营商) 的电话功能, 若中国移动认证系统获取了与淘宝 网的用户名绑定的手机号码, 则中国移动认证系统可以根据该手机号码为该 手机分配第二令牌和网关(英文: gateway) 的 IP地址。 此外, 中国移动认证 系统可以将该第二令牌和该 IP地址发送给该手机, 该手机可以根据该 IP地址 找到与该 IP地址对应的网关, 与该网关建立通信通道, 该网关可以向中国移 动认证系统发送第二令牌认证请求。  For example, if the user logs in to Taobao (a third-party application website) through a mobile phone and uses the mobile phone function of China Mobile (operator) on Taobao, if the China Mobile authentication system obtains the mobile phone number bound to the user name of Taobao. , the China Mobile authentication system can assign the second token and the IP address of the gateway (English: gateway) to the mobile phone according to the mobile phone number. In addition, the China Mobile authentication system can send the second token and the IP address to the mobile phone, and the mobile phone can find a gateway corresponding to the IP address according to the IP address, and establish a communication channel with the gateway, and the gateway can be sent to China. The mobile authentication system sends a second token authentication request.
歩骤 S280、 在所述第二令牌在所述运营商认证系统内认证通过的情况 下, 向所述网关发送所述用户标识, 以使得所述网关根据所述用户标识向运 营商的核心网发起用户注册, 在注册完成之后, 使得所述用户通过所述终端 设备使用所述运营商提供的业务。 Step S280: If the second token is authenticated and passed in the operator authentication system, send the user identifier to the gateway, so that the gateway is shipped according to the user identifier. The core network of the business initiates user registration, and after the registration is completed, the user is allowed to use the service provided by the operator through the terminal device.
具体地, 上述歩骤 S240〜歩骤 S280中, 运营商认证系统可以分配第二令 牌和网关的 IP地址, 并将该分配的第二令牌和网关的 IP地址发送给该终端设 备, 该终端设备可以根据该 IP地址向该网关发送第二令牌的认证请求。 网关 接收到该第二令牌的认证请求之后, 可以向该运营商认证系统发送该第二令 牌的认证请求。 该运营商认证系统可以认证该第二令牌是否通过, 若该运营 商认证系统认证该第二令牌通过, 则可以将用户标识发送给网关。 网关可以 根据该用户标识, 代替用户到核心网例如 IMS核心网进行注册, 并且, 网关 可以指示核心网该用户已经认证, 不再需要进行鉴权挑战。 在网关代替用户 注册之后, 用户可以通过终端设备直接使用运营商提供的业务。  Specifically, in the foregoing steps S240 to S280, the operator authentication system may allocate the IP address of the second token and the gateway, and send the allocated second token and the IP address of the gateway to the terminal device, where The terminal device may send an authentication request of the second token to the gateway according to the IP address. After receiving the authentication request of the second token, the gateway may send the second token authentication request to the operator authentication system. The operator authentication system can authenticate whether the second token passes. If the operator authentication system authenticates that the second token passes, the user identifier can be sent to the gateway. The gateway can register according to the user identifier instead of the user to the core network, for example, the IMS core network, and the gateway can indicate that the user of the core network has been authenticated, and the authentication challenge is no longer needed. After the gateway replaces the user registration, the user can directly use the service provided by the operator through the terminal device.
需要注意的是, 尽管以运营商认证系统、 第三方认证系统作为示例介绍 了通信认证方法, 但本领域技术人员能够理解, 本发明应不限于此, 名称不 同、 但功能类似的其它通信设备能够完成本发明的功能, 都属于本发明的保 护范围。  It should be noted that although the communication authentication method is introduced by using the operator authentication system and the third-party authentication system as an example, those skilled in the art can understand that the present invention is not limited thereto, and other communication devices with different names but similar functions can The completion of the functions of the present invention is within the scope of the present invention.
本发明实施例的通信认证方法,用户在终端设备上只需要提供一次账号 进行一次登录, 在通过第三方认证系统对该账号验证通过后, 可以通过运营 商认证系统获得该账号绑定的用户标识所注册的业务的授权, 从而使用该业 务, 过程简单, 用户体验良好。  In the communication authentication method of the embodiment of the present invention, the user only needs to provide an account once to log in once on the terminal device. After the account is verified by the third-party authentication system, the user identity of the account can be obtained through the operator authentication system. The authorization of the registered business, thereby using the service, the process is simple and the user experience is good.
实施例 3  Example 3
图 3为根据本发明实施例三的通信认证方法的流程图。 如图 3所示, 该通 信认证方法可以包括:  FIG. 3 is a flowchart of a communication authentication method according to Embodiment 3 of the present invention. As shown in FIG. 3, the communication authentication method may include:
歩骤 S300、接收运营商认证系统发送的第三方认证请求, 所述第三方认 证请求中携带第一令牌,所述第一令牌是第三方认证系统根据终端设备提供 的账号分配的令牌,所述账号为所述第三方认证系统为所述终端设备分配的 账号。 Step S300: Receive a third-party authentication request sent by the operator authentication system, where the third-party authentication request carries a first token, where the first token is a token that is allocated by the third-party authentication system according to the account provided by the terminal device. The account is allocated by the third-party authentication system for the terminal device. account number.
在一种可能的实现方式中,所述接收运营商认证系统发送的第三方认证 请求之前, 包括: 验证所述终端设备提供的账号; 在验证通过的情况下, 向 所述终端设备返回所述第一令牌。  In a possible implementation manner, before receiving the third-party authentication request sent by the operator authentication system, the method includes: verifying an account provided by the terminal device; and returning to the terminal device if the verification is passed First token.
具体地, 用户可以使用终端设备登录第三方应用网站, 第三方应用网站 可以包括自己的认证系统, 简称第三方认证系统, 还可以包括自己的应用服 务器, 简称第三方应用服务器。  Specifically, the user may log in to the third-party application website by using the terminal device. The third-party application website may include its own authentication system, which is referred to as a third-party authentication system, and may also include its own application server, which is referred to as a third-party application server.
第三方认证系统对用户通过终端设备提供的帐号(例如某一淘宝网的用 户名)进行验证的过程中, 除了验证账号是否是第三方认证系统为用户分配 的合法的账号之外, 还可以验证账号对应的密码是否准确。 因此, 用户通过 终端设备向第三方认证系统提供账号的同时,可以一并将账号对应的密码提 供给第三方认证系统。在第三方认证系统验证该账号通过的情况下, 第三方 认证系统可以根据该帐号为用户分配与该账号相对应的第一令牌。  In the process of authenticating the account provided by the user through the terminal device (for example, the username of a certain Taobao network), the third-party authentication system can verify whether the account is a legal account assigned by the third-party authentication system for the user. Whether the password corresponding to the account is accurate. Therefore, when the user provides an account to the third-party authentication system through the terminal device, the user can provide the password corresponding to the account to the third-party authentication system. When the third-party authentication system verifies that the account has passed, the third-party authentication system may assign the first token corresponding to the account to the user according to the account.
可以在第三方认证系统内部或者外部设置一个接口设备。 一种情况下, 该接口设备设置在第三方认证系统的外部, 该接口设备在运营商认证系统和 第三方认证系统之间转发信息, 该接口设备接收运营商认证系统发送的第三 方认证请求, 再由第三方认证系统接收该接口设备转发的该第三方认证请 求。 另一种情况下, 该接口设备设置在第三方认证系统的内部, 第三方认证 系统可以直接接收运营商认证系统发送的第三方认证请求。  An interface device can be set inside or outside the third-party authentication system. In one case, the interface device is set up outside the third-party authentication system, and the interface device forwards information between the operator authentication system and the third-party authentication system, and the interface device receives the third-party authentication request sent by the operator authentication system. The third-party authentication system receives the third-party authentication request forwarded by the interface device. In another case, the interface device is set in the third-party authentication system, and the third-party authentication system can directly receive the third-party authentication request sent by the carrier authentication system.
例如: 若用户通过手机登录淘宝网 (第三方应用网站), 并且使用淘宝 网上的中国移动(运营商)的电话功能, 淘宝网服务器(第三方应用服务器) 弹出一个对话框, 用户输入淘宝网的用户名 (帐号)和密码之后, 点击登录 后会定向到淘宝网认证系统 (第三方认证系统), 该淘宝网认证系统可以验 证该淘宝网的用户名。 若淘宝网认证系统验证该淘宝网的用户名通过, 则淘 宝网认证系统可以为用户分配与该用户名对应的第一令牌, 并指示手机跳转 到该淘宝网服务器。 For example: If the user logs in to Taobao (a third-party application website) through the mobile phone and uses the mobile phone function of China Mobile (operator) on Taobao, the Taobao server (third-party application server) pops up a dialog box, and the user inputs Taobao. After the user name (account number) and password, click Login to direct to the Taobao network authentication system (third-party authentication system), the Taobao network authentication system can verify the Taobao user name. If the Taobao authentication system verifies that the user name of the Taobao network passes, the Taobao authentication system can assign a first token corresponding to the username to the user, and instruct the mobile phone to jump. Go to the Taobao server.
歩骤 S320、在所述第一令牌认证通过的情况下, 向所述运营商认证系统 发送所述第一令牌对应的所述账号, 以使所述运营商认证系统获取所述账号 绑定的用户标识。  In step S320, if the first token is authenticated, the account corresponding to the first token is sent to the operator authentication system, so that the operator authentication system obtains the account number. The specified user ID.
具体地, 若第三方认证系统认证第一令牌通过, 则第三方认证系统可以 通过接口设备向运营商认证系统发送与第一令牌对应的账号,第三方认证系 统也可以直接向运营商认证系统发送与第一令牌对应的账号。该运营商认证 系统可以根据该账号获取到与该账号绑定的用户标识, 后续用户注册完成之 后, 可以直接使用运营商提供的与该账号绑定的用户标识所注册的业务。  Specifically, if the third-party authentication system authenticates the first token, the third-party authentication system may send an account corresponding to the first token to the operator authentication system through the interface device, and the third-party authentication system may directly authenticate the carrier. The system sends an account corresponding to the first token. The operator authentication system can obtain the user identifier bound to the account according to the account. After the subsequent user registration is completed, the service registered by the operator and the user identifier bound to the account can be directly used.
需要注意的是, 尽管以运营商认证系统、 第三方认证系统作为示例介绍 了通信认证方法, 但本领域技术人员能够理解, 本发明应不限于此, 名称不 同、 但功能类似的其它通信设备能够完成本发明的功能, 都属于本发明的保 护范围。  It should be noted that although the communication authentication method is introduced by using the operator authentication system and the third-party authentication system as an example, those skilled in the art can understand that the present invention is not limited thereto, and other communication devices with different names but similar functions can The completion of the functions of the present invention is within the scope of the present invention.
本发明实施例的通信认证方法,用户在终端设备上只需要提供一次账号 进行一次登录, 第三方认证系统验证该账号, 在该账号验证通过后, 可以通 过运营商认证系统获得该账号绑定的用户标识所注册的业务的授权, 从而使 用该业务, 过程简单, 用户体验良好。  In the communication authentication method of the embodiment of the present invention, the user only needs to provide an account once to log in once, and the third-party authentication system verifies the account. After the account is verified, the account can be obtained through the operator authentication system. The user identifies the authorization of the registered service, thereby using the service, and the process is simple and the user experience is good.
实施例 4  Example 4
图 4为根据本发明实施例四的通信认证方法的流程图。 如图 4所示, 该通 信认证方法可以包括:  4 is a flow chart of a communication authentication method according to Embodiment 4 of the present invention. As shown in FIG. 4, the communication authentication method may include:
歩骤 S400、 在第三方认证系统对终端设备提供的账号验证通过的情况 下, 终端设备向运营商认证系统发送接入认证请求, 所述接入认证请求中携 带第三方应用标识和第一令牌,所述第一令牌为所述第三方认证系统根据所 述终端设备的账号分配的令牌, 以使得所述运营商认证系统根据所述第三方 应用标识请求所述第三方认证系统对所述第一令牌进行认证, 以获取所述账 号绑定的用户标识。 Step S400: In the case that the account authentication provided by the third-party authentication system for the terminal device passes, the terminal device sends an access authentication request to the operator authentication system, where the access authentication request carries the third-party application identifier and the first order. a card, the first token is a token allocated by the third-party authentication system according to an account of the terminal device, so that the operator authentication system requests the third-party authentication system according to the third-party application identifier. The first token is authenticated to obtain the account The user ID of the number binding.
具体地, 用户可以使用终端设备登录第三方应用网站, 第三方应用网站 可以包括自己的认证系统, 简称第三方认证系统, 还可以包括自己的应用服 务器, 简称第三方应用服务器。 若第三方认证系统验证终端设备提供的账号 通过, 则该终端设备可以接收该第三方认证系统分配的与该账号相对应的第 一令牌。终端设备可以向运营商认证系统发送携带了第三方应用标识和第一 令牌的接入认证请求。例如:若用户通过手机登录淘宝网(第三方应用网站), 并且使用淘宝网上的中国移动 (运营商) 的电话功能, 淘宝网服务器(第三 方应用服务器)弹出一个对话框, 用户输入淘宝网的用户名和密码之后, 点 击登录后会定向到淘宝网认证系统 (第三方认证系统), 该淘宝网认证系统 可以认证该淘宝网的用户名是否通过。 若认证该淘宝网的用户名通过, 则淘 宝网认证系统可以为用户分配第一令牌, 并指示手机跳转到该淘宝网服务 器。 若用户需要使用中国移动提供的业务, 则可以向中国移动认证系统发送 携带了淘宝网应用标识 (第三方应用标识) 和第一令牌的接入认证请求。  Specifically, the user may log in to the third-party application website by using the terminal device. The third-party application website may include its own authentication system, which is referred to as a third-party authentication system, and may also include its own application server, which is referred to as a third-party application server. If the third-party authentication system verifies that the account provided by the terminal device passes, the terminal device can receive the first token corresponding to the account assigned by the third-party authentication system. The terminal device may send an access authentication request carrying the third-party application identifier and the first token to the operator authentication system. For example, if the user logs in to Taobao (a third-party application website) through the mobile phone and uses the mobile phone function of China Mobile (operator) on Taobao, the Taobao server (third-party application server) pops up a dialog box, and the user inputs Taobao. After the user name and password, click Login will be directed to the Taobao network authentication system (third-party authentication system), the Taobao network authentication system can authenticate whether the Taobao user name is passed. If the username of the Taobao network is authenticated, the Taobao authentication system can assign a first token to the user and instruct the mobile phone to jump to the Taobao server. If the user needs to use the service provided by China Mobile, the user can send an access authentication request carrying the Taobao application identifier (third-party application identifier) and the first token to the China Mobile authentication system.
在一种可能的实现方式中, 所述获取所述账号绑定的用户标识, 包括: 在所述运营商认证系统不存在与所述账号绑定的所述用户标识的情况 下, 从所述运营商认证系统接收用户标识输入请求;  In a possible implementation, the acquiring the user identifier bound to the account includes: if the operator authentication system does not have the user identifier bound to the account, The operator authentication system receives the user identification input request;
向所述运营商认证系统发送用户输入的所述用户标识, 以使得所述运营 商认证系统记录所述账号与所述用户标识的绑定关系。  Sending the user identifier input by the user to the operator authentication system, so that the operator authentication system records a binding relationship between the account and the user identifier.
例如, 若用户通过手机登录淘宝网 (第三方应用网站), 并且使用淘宝 网上的中国移动 (运营商) 的电话功能, 若中国移动认证系统查找到不存在 与淘宝网的用户名绑定的手机号码, 则手机可以接收中国移动认证系统发送 的手机号码输入请求。接收到该手机号码输入请求之后, 用户可以通过手机 向中国移动认证系统发送手机号码。中国移动认证系统可以记录该手机号码 和淘宝网的用户名的绑定关系, 后续用户注册完成之后, 可以直接使用中国 移动提供的与该淘宝网的用户名绑定的手机号码所注册的业务。 歩骤 S420、 接收运营商认证系统发送的第二令牌和网关的 IP地址, 所述 第二令牌和网关的 IP地址为所述运营商认证系统根据所述用户标识分配的 令牌和 IP地址。 For example, if the user logs in to Taobao (a third-party application website) through a mobile phone and uses the mobile phone function of China Mobile (operator) on Taobao, if the China Mobile authentication system finds that there is no binding to the user name of Taobao. The mobile phone number, the mobile phone can receive the mobile phone number input request sent by the China Mobile authentication system. After receiving the mobile phone number input request, the user can send the mobile phone number to the China Mobile authentication system through the mobile phone. China Mobile's authentication system can record the binding relationship between the mobile phone number and the user name of Taobao. After the subsequent user registration is completed, you can directly use China. The service registered by the mobile phone number that is provided by the mobile phone and bound to the user name of the Taobao. Step S420: Receive an IP address of a second token and a gateway sent by the operator authentication system, where the IP address of the second token and the gateway is a token and an IP that are allocated by the carrier authentication system according to the user identifier. address.
歩骤 S440、在所述网关对所述第二令牌进行认证后使用运营商提供的业 具体地, 终端设备可以接收运营商认证系统发送的第二令牌和网关的 IP 地址, 根据网关的 IP地址查找到对应的网关, 并向该网关发送第二令牌的认 证请求。 再由网关向该运营商认证系统发送该第二令牌的认证请求, 运营商 认证系统接收到该第二令牌的认证请求之后, 可以认证该第二令牌是否通 过, 若该运营商认证系统认证该第二令牌通过, 则可以将用户标识发送给网 关, 网关可以根据该用户标识代替用户进行用户注册。 在网关代替用户注册 完成之后,用户可以通过终端设备直接使用运营商提供的与该账号绑定的用 户标识所注册的业务。  Step S440: After the gateway authenticates the second token, use the service provided by the operator, specifically, the terminal device may receive the second token and the IP address of the gateway sent by the operator authentication system, according to the gateway. The IP address finds the corresponding gateway, and sends an authentication request for the second token to the gateway. And the gateway sends the authentication request of the second token to the carrier authentication system. After receiving the authentication request of the second token, the operator authentication system may authenticate whether the second token passes, and if the carrier authenticates After the system authenticates that the second token passes, the user identifier may be sent to the gateway, and the gateway may perform user registration according to the user identifier instead of the user. After the gateway is replaced by the user registration, the user can directly use the terminal device to directly register the service registered by the operator with the user ID bound to the account.
需要注意的是, 尽管以运营商认证系统、 第三方认证系统和终端设备作 为示例介绍了通信认证方法, 但本领域技术人员能够理解, 本发明应不限于 此, 名称不同、 但功能类似的其它通信设备能够完成本发明的功能, 都属于 本发明的保护范围。  It should be noted that although the communication authentication method is described by taking the operator authentication system, the third-party authentication system, and the terminal device as an example, those skilled in the art can understand that the present invention is not limited thereto, and other names have different functions but similar functions. The ability of the communication device to perform the functions of the present invention is within the scope of the present invention.
本发明实施例的通信认证方法,用户在终端设备上只需要提供一次账号 进行一次登录, 在通过第三方认证系统对该账号验证通过后, 可以通过运营 商认证系统获得该账号绑定的用户标识所注册的业务的授权, 从而使用该业 务, 过程简单, 用户体验良好。  In the communication authentication method of the embodiment of the present invention, the user only needs to provide an account once to log in once on the terminal device. After the account is verified by the third-party authentication system, the user identity of the account can be obtained through the operator authentication system. The authorization of the registered business, thereby using the service, the process is simple and the user experience is good.
实施例 5  Example 5
图 5为根据本发明实施例五的通信认证方法的流程图。 如图 5所示, 该通 信认证方法可以包括: 歩骤 501、终端设备向第三方应用服务器发送 HTTP GET (第三方应用服 务器的 IP地址)命令,该命令表示终端设备获取第三方应用服务器的 IP地址。 FIG. 5 is a flowchart of a communication authentication method according to Embodiment 5 of the present invention. As shown in FIG. 5, the communication authentication method may include: Step 501: The terminal device sends an HTTP GET (IP address of the third-party application server) command to the third-party application server, where the command indicates that the terminal device obtains the IP address of the third-party application server.
歩骤 502、 第三方应用服务器向终端设备发送 HTTP 200 OK (载入第三 方应用服务器的登录页面)命令, 该命令表示终端设备成功加载第三方应用 服务器的登录页面。  Step 502: The third-party application server sends an HTTP 200 OK (login page of the third-party application server) command to the terminal device, where the command indicates that the terminal device successfully loads the login page of the third-party application server.
歩骤 503、 终端设备向第三方认证系统发送 POST (账号, 密码) 命令, 该命令表示用户可以通过终端设备使用账号和与该帐号对应的密码登录第 三方应用服务器, 点击登录第三方应用服务器后再重定向到第三方认证系统 验证该账号。  Step 503: The terminal device sends a POST (Account, Password) command to the third-party authentication system. The command indicates that the user can log in to the third-party application server by using the account and the password corresponding to the account, and clicking to log in to the third-party application server. Then redirect to a third-party authentication system to verify the account.
歩骤 504、 第三方认证系统向终端设备发送 302 (认证通过, 分配第一令 牌)命令, 该命令表示第三方认证系统对用户通过终端设备提供的账号进行 验证, 在验证的过程中, 除了验证账号是否是第三方认证系统为用户分配的 合法的账号之外, 还可以验证账号对应的密码是否准确。 因此, 用户通过终 端设备向第三方认证系统提供账号的同时,可以一并将账号对应的密码提供 给第三方认证系统。 若第三方认证系统验证上述帐号通过, 第三方认证系统 可以根据该帐号为用户分配与该账号对应的第一令牌(tokenl ), 并指示终端 设备重新跳转到第三方应用服务器。  Step 504: The third-party authentication system sends a 302 (Authentication Pass, Assign First Token) command to the terminal device, where the command indicates that the third-party authentication system verifies the account provided by the user through the terminal device, in the process of verifying, Verify that the account is a legal account assigned to the user by the third-party authentication system. You can also verify that the password corresponding to the account is accurate. Therefore, the user can provide the account corresponding to the account to the third-party authentication system while providing the account to the third-party authentication system through the terminal device. If the third-party authentication system verifies that the account is approved, the third-party authentication system can assign a first token (token1) corresponding to the account to the user, and instruct the terminal device to re-joke to the third-party application server.
歩骤 505、 终端设备向第三方应用服务器发送 POST (认证通过), 该命 令表示终端设备通知第三方应用服务器第三方认证系统验证上述账号通过。  Step 505: The terminal device sends a POST (authentication pass) to the third-party application server, where the command indicates that the terminal device notifies the third-party application server that the third-party authentication system verifies that the account is approved.
歩骤 506、 第三方应用服务器向终端设备发送 HTTP 200 OK命令, 该命 令表示第三方应用服务器通知终端设备已经知晓了第三方认证系统验证上 述账号通过。  Step 506: The third-party application server sends an HTTP 200 OK command to the terminal device, where the command indicates that the third-party application server notifies the terminal device that the third-party authentication system has verified that the account is approved.
具体地, 用户可以使用终端设备登录第三方应用网站, 第三方应用网站 可以包括自己的认证系统, 简称第三方认证系统, 还可以包括自己的应用服 务器, 简称第三方应用服务器。 上述歩骤 501〜歩骤 506中, 若第三方认证系 统验证账号通过, 则第三方认证系统可以为用户分配与该账号相对应的第一 令牌, 并向终端设备发送第一令牌。 Specifically, the user may log in to the third-party application website by using the terminal device. The third-party application website may include its own authentication system, which is referred to as a third-party authentication system, and may also include its own application server, which is referred to as a third-party application server. In the above steps 501 to 506, if the third party authentication system After the verification account is passed, the third-party authentication system can assign a first token corresponding to the account to the user, and send the first token to the terminal device.
歩骤 507、 终端设备向第三方应用服务器发送 HTTP GET (业务请求)命 令, 该命令表示用户可以通过终端设备向第三方应用服务器发送业务请求, 该业务请求中携带了登录业务的方式和运营商标识, 该运营商标识为用户需 要使用的业务所属的运营商的标识。  Step 507: The terminal device sends an HTTP GET (Service Request) command to the third-party application server, where the command indicates that the user can send a service request to the third-party application server by using the terminal device, where the service request carries the login service mode and the operator. The identifier of the carrier is the identifier of the carrier to which the service to be used by the user belongs.
歩骤 508、 第三方应用服务器向终端设备发送 HTTP 200 OK (运营商认 证门户的 IP地址)命令, 该命令表示若第三方应用服务器根据接收到的业务 请求, 获取到用户通过终端设备登录业务的方式为一次登录, 可以向终端设 备发送运营商认证门户的 IP地址。  Step 508: The third-party application server sends an HTTP 200 OK (IP address of the operator authentication portal) command to the terminal device, where the third-party application server obtains the user to log in to the service through the terminal device according to the received service request. The mode is one-time login, and the IP address of the carrier authentication portal can be sent to the terminal device.
具体地, 第三方应用服务器可以接收用户通过终端设备发送的业务请 求, 可以从该业务请求中获取用户通过终端设备登录业务的方式, 若获取到 用户通过终端设备需要使用账号一次登录就可以直接获得业务的授权, 则第 三方应用服务器可以向终端设备发送运营商认证门户的 IP地址。  Specifically, the third-party application server can receive the service request sent by the user through the terminal device, and obtain the manner in which the user logs in to the service through the terminal device, and if the user needs to use the account once to log in through the terminal device, the device can directly obtain the service request. For the authorization of the service, the third-party application server may send the IP address of the carrier authentication portal to the terminal device.
歩骤 509、 终端设备向运营商认证门户发送接入认证请求, 该接入认证 请求中携带第三方应用标识和第一令牌, 该第一令牌为第三方认证系统根据 上述账号分配的令牌。  Step 509: The terminal device sends an access authentication request to the operator authentication portal, where the access authentication request carries a third-party application identifier and a first token, where the first token is a third-party authentication system according to the account allocation brand.
歩骤 510、 运营商认证门户向运营商认证系统发送上述接入认证请求。 具体地, 运营商认证门户可以接收该终端设备发送的接入认证请求, 再 由运营商认证系统接收该运营商认证门户发送的接入认证请求。  Step 510: The operator authentication portal sends the foregoing access authentication request to the operator authentication system. Specifically, the operator authentication portal may receive the access authentication request sent by the terminal device, and then the operator authentication system receives the access authentication request sent by the operator authentication portal.
歩骤 511、 运营商认证系统向第三方应用标识对应的第三方认证系统发 送第三方认证请求, 该第三方认证请求中携带了上述第一令牌。  Step 511: The operator authentication system sends a third-party authentication request to the third-party authentication system corresponding to the third-party application identifier, where the third-party authentication request carries the first token.
可以在运营商认证系统的内部或者外部设置一个接口设备。 一种情况 下, 该接口设备设置在运营商认证系统的外部, 该接口设备在运营商认证系 统和第三方认证系统之间转发信息,运营商认证系统将第三方认证请求发送 给该接口设备, 再由该接口设备将该第三方认证请求转发给第三方认证系 统。 另一种情况下, 该接口设备设置在运营商认证系统的内部, 运营商认证 系统可以直接向第三方认证系统发送第三方认证请求。 An interface device can be set inside or outside the carrier authentication system. In one case, the interface device is set outside the operator authentication system, and the interface device forwards information between the operator authentication system and the third-party authentication system, and the operator authentication system sends the third-party authentication request. The third-party authentication request is forwarded to the third-party authentication system by the interface device. In another case, the interface device is set inside the operator authentication system, and the operator authentication system can directly send a third-party authentication request to the third-party authentication system.
歩骤 512、 第三方认证系统认证第一令牌, 若第三方认证系统认证第一 令牌通过, 可以向运营商认证系统发送与该第一令牌对应的账号。  Step 512: The third-party authentication system authenticates the first token. If the third-party authentication system authenticates the first token, the account corresponding to the first token may be sent to the operator authentication system.
可以在第三方认证系统的内部或者外部设置一个接口设备。 一种情况 下, 该接口设备设置在第三方认证系统的外部, 该接口设备可以接收第三方 认证系统发送的与第一令牌对应的账号, 并向运营商认证系统转发该与第一 令牌对应的账号;另一种情况下,该接口设备设置在第三方认证系统的内部, 第三方认证系统可以直接向运营商认证系统发送该与第一令牌对应的账号。  An interface device can be set inside or outside the third-party authentication system. In one case, the interface device is disposed outside the third-party authentication system, and the interface device can receive the account corresponding to the first token sent by the third-party authentication system, and forward the first token to the operator authentication system. In the other case, the interface device is set in the third-party authentication system, and the third-party authentication system can directly send the account corresponding to the first token to the operator authentication system.
歩骤 513、 运营商认证系统查找账号是否绑定了用户标识; 该用户标识 可以包括 IMPU、 IMPK用户与运营商签约的用户名中的任意一种或者多种。 若账号没有绑定用户标识,运营商认证系统可以向运营商认证门户发送用户 标识输入请求, 并执行歩骤 514〜歩骤 516, 请求用户输入用户标识; 若账号 绑定了用户标识, 则执行歩骤 517, 运营商认证系统为用户分配第二令牌。  Step 513: The operator authentication system searches whether the account is bound to the user identifier. The user identifier may include any one or more of the user names that the IMPU and the IMPK user subscribe to. If the account is not bound to the user identifier, the operator authentication system may send a user identity input request to the operator authentication portal, and perform steps 514 to 516 to request the user to input the user identifier; if the account is bound with the user identifier, execute Step 517: The operator authentication system allocates a second token to the user.
歩骤 514、 运营商认证门户向终端设备发送用户标识输入请求, 请求用 户输入用户标识和密码。  Step 514: The operator authentication portal sends a user identity input request to the terminal device, and requests the user to input the user identifier and password.
歩骤 515、 终端设备向运营商认证门户发送 POST (用户标识, 密码)命 令, 该命令表示用户可以通过终端设备输入用户标识和密码, 再由终端设备 向运营商认证门户发送该用户标识。 其中, 用户可以通过终端设备输入 IMPU、 IMPI、用户与运营商签约的用户名中的任意一种或者多种。由于 IMPU 与 IMPI存在一定的映射关系,运营商认证系统可以根据用户通过终端设备输 入的 IMPU查找到对应的 IMPI。  Step 515: The terminal device sends a POST (User Identity, Password) command to the operator authentication portal. The command indicates that the user can input the user identifier and password through the terminal device, and then the terminal device sends the user identifier to the operator authentication portal. The user can input any one or more of the IMPU, the IMPI, and the user name signed by the user and the operator through the terminal device. Since the IMPU has a certain mapping relationship with the IMPI, the operator authentication system can find the corresponding IMPI according to the IMPU input by the user through the terminal device.
歩骤 516、运营商认证门户向运营商认证系统发送 HTTP GET认证(用户 标识, 密码)命令, 该命令表示运营商认证系统可以接收运营商认证门户发 送的用户标识和密码。 Step 516: The operator authentication portal sends an HTTP GET authentication (user identification, password) command to the operator authentication system, where the command indicates that the operator authentication system can receive the operator authentication portal. User ID and password sent.
具体地, 上述歩骤 513〜歩骤 516, 若账号没有绑定用户标识, 则请求终 端设备输入用户标识, 该输入的用户标识可以到运营商认证系统进行认证, 但是, 运营商认证系统无法认证用户标识, 可以到 HSS进行认证, 若 HSS认 证用户标识通过, 则运营商认证系统可以记录账号和用户标识的绑定关系。  Specifically, in step 513 to step 516, if the account is not bound with the user identifier, the terminal device is requested to input the user identifier, and the input user identifier can be authenticated by the operator authentication system, but the operator authentication system cannot be authenticated. The user ID can be authenticated to the HSS. If the HSS authentication user ID is passed, the carrier authentication system can record the binding relationship between the account and the user ID.
歩骤 517、 运营商认证系统向运营商认证门户发送 HTTP 200 OK (第二 令牌, 网关的 IP地址)命令, 该命令表示运营商认证系统可以根据用户标识, 为所述终端设备分配第二令牌 (token2) 和网关的 IP地址, 并向运营商认证 门户发送第二令牌。  Step 517: The operator authentication system sends an HTTP 200 OK (second token, IP address of the gateway) command to the operator authentication portal, where the command indicates that the operator authentication system can allocate the second terminal to the terminal device according to the user identifier. The token (token2) and the IP address of the gateway, and send a second token to the carrier authentication portal.
歩骤 518、 运营商认证门户向终端设备发送 HTTP 200 OK (第二令牌, 网关的 IP地址)命令, 该命令表示运营商认证门户可以向终端设备发送第二 令牌和网关的 IP地址, 以使得所述终端设备可以根据所述 IP地址向所述网关 发送所述第二令牌的认证请求。  Step 518: The operator authentication portal sends an HTTP 200 OK (second token, IP address of the gateway) command to the terminal device, where the command indicates that the operator authentication portal can send the second token and the IP address of the gateway to the terminal device. So that the terminal device can send an authentication request of the second token to the gateway according to the IP address.
歩骤 519a、 终端设备向网关发送 HTTP GET (网页套接字请求) 命令; 歩骤 519b、 网关向终端设备发送 HTTP GET (网页套接字响应) 命令。 歩骤 519a和歩骤 519b的命令表示终端设备可以根据运营商认证门户发 送的网关的 IP地址, 访问与该 IP地址对应的网关, 并和该网关建立网页套接 字 (英文: websocket) 通道。  Step 519a: The terminal device sends an HTTP GET (Web Socket Request) command to the gateway. Step 519b: The gateway sends an HTTP GET (Web Socket Response) command to the terminal device. The commands of step 519a and step 519b indicate that the terminal device can access the gateway corresponding to the IP address according to the IP address of the gateway sent by the operator authentication portal, and establish a web socket (English: websocket) channel with the gateway.
歩骤 520、 终端设备向网关发送第二令牌的认证请求, 该第二令牌认证 请求中携带了第二令牌。  Step 520: The terminal device sends an authentication request of the second token to the gateway, where the second token authentication request carries the second token.
歩骤 521、网关向运营商认证系统发送 HTTP GET认证(第二令牌)命令, 该命令表示网关可以向运营商认证系统发送第二令牌的认证请求。  Step 521: The gateway sends an HTTP GET authentication (second token) command to the operator authentication system, where the command indicates that the gateway can send the second token authentication request to the operator authentication system.
歩骤 522、 运营商认证系统向网关发送 HTTP 200 OK (第二令牌有效, 用户标识, 已认证通过)命令, 该命令表示运营商认证系统可以认证网关发 送的第二令牌是否通过, 若运营商认证系统认证第二令牌通过, 可以向网关 发送与第二令牌对应的用户标识。 Step 522: The operator authentication system sends an HTTP 200 OK (second token valid, user identifier, authenticated pass) command to the gateway, where the command indicates that the operator authentication system can authenticate whether the second token sent by the gateway passes. The carrier authentication system authenticates the second token and can go to the gateway. Sending a user identifier corresponding to the second token.
歩骤 523、 网关向核心网例如 IMS核心网发送 SIP Register (用户标识, 已 认证通过, 不含挑战过程)命令, 该命令表示网关可以代替用户到核心网进 行注册, 并指示核心网该用户已经认证无需鉴权挑战过程。  Step 523: The gateway sends a SIP Register (User Identity, Passed, Without Challenge Process) command to the core network, for example, the IMS core network, where the command indicates that the gateway can register the user to the core network, and indicates that the user of the core network has Authentication does not require an authentication challenge process.
歩骤 524、 核心网向网关发送 SIP 200 OK命令, 该命令表示核心网可以 通知网关注册成功。  Step 524: The core network sends a SIP 200 OK command to the gateway, where the command indicates that the core network can notify the gateway that the registration is successful.
歩骤 525、 网关通知用户认证通过, 用户已经注册, 用户可以通过终端 设备直接使用运营商提供的用户注册的业务, 例如语音业务、 视频业务、 数 据传输业务等。  Step 525: The gateway notifies the user that the authentication is passed, and the user has already registered, and the user can directly use the user-registered service provided by the operator, such as a voice service, a video service, and a data transmission service, through the terminal device.
具体地, 与用户通过终端设备需要使用多套用户名和密码进行多次登录 的过程相比, 本实施例通过一次登录即可, 具体地: 用户在终端设备上使用 账号登录第三方应用服务器之后,无需再输入运营商用户名和密码就可以获 得用户注册的业务的授权, BP: 用户通过终端设备只需要使用账号进行一次 登录, 就可以使用用户注册的业务。  Specifically, compared with the process in which the user needs to use multiple sets of user names and passwords to perform multiple logins by using the terminal device, the embodiment may be used for one login, specifically: after the user logs in to the third-party application server by using the account on the terminal device, You can obtain the authorization of the user's registered service without entering the operator's username and password. BP: The user only needs to use the account to log in once through the terminal device, and the user can register the service.
需要注意的是, 尽管以终端设备、 运营商认证系统、 运营商认证门户、 第三方应用服务器、 第三方认证系统、 网关和核心网作为示例介绍了通信认 证方法, 但本领域技术人员能够理解, 本发明应不限于此, 名称不同、 但功 能类似的其它通信设备能够完成本发明的功能, 都属于本发明的保护范围。  It should be noted that although the communication authentication method is described by using a terminal device, a carrier authentication system, a carrier authentication portal, a third-party application server, a third-party authentication system, a gateway, and a core network as an example, those skilled in the art can understand that The present invention is not limited thereto, and other communication devices having different names but similar functions can perform the functions of the present invention, and are all within the scope of the present invention.
本发明实施例的通信认证方法,用户在终端设备上只需要提供一次账号 进行一次登录, 在通过第三方认证系统对该账号验证通过后, 可以通过运营 商认证系统获得该账号绑定的用户标识所注册的业务的授权, 从而使用该业 务, 过程简单, 用户体验良好。  In the communication authentication method of the embodiment of the present invention, the user only needs to provide an account once to log in once on the terminal device. After the account is verified by the third-party authentication system, the user identity of the account can be obtained through the operator authentication system. The authorization of the registered business, thereby using the service, the process is simple and the user experience is good.
实施例 6  Example 6
图 6为根据本发明实施例六的通信认证装置的结构框图。 本实施例提供 的通信认证装置 600用于实现图 1所示的实施例一提供的通信认证方法。如图 6所示, 该通信认证装置 600可以包括: Figure 6 is a block diagram showing the structure of a communication authentication apparatus according to a sixth embodiment of the present invention. The communication authentication apparatus 600 provided in this embodiment is used to implement the communication authentication method provided in the first embodiment shown in FIG. As shown As shown in FIG. 6, the communication authentication apparatus 600 can include:
第一接收模块 620, 用于在第三方认证系统对终端设备提供的账号验证 通过的情况下, 接收所述终端设备发送的接入认证请求, 所述接入认证请求 中携带第三方应用标识和第一令牌,所述第一令牌为所述第三方认证系统根 据所述账号分配的令牌,所述账号为所述第三方认证系统为所述终端设备分 配的账号。  The first receiving module 620 is configured to receive an access authentication request sent by the terminal device when the third-party authentication system passes the account verification provided by the terminal device, where the access authentication request carries the third-party application identifier and The first token is a token that is allocated by the third-party authentication system according to the account, and the account is an account that the third-party authentication system allocates for the terminal device.
具体地, 用户可以使用终端设备, 例如: 手机、 个人计算机、 平板电脑 等, 登录第三方应用网站 (例如: 淘宝网、 新浪网、 当当网、 蘑菇街等)。 其中, 第三方应用网站可以包括自己的认证系统, 简称第三方认证系统。 在 用户通过第三方认证系统的验证后, 可以登录该第三方应用网站。 然后可以 通过该第三方应用网站使用运营商(例如: 中国移动、 中国联通、 中国电信、 IMS业务提供商等) 提供的业务。 其中, 业务可以为网页实时通信 WebRTC 业务例如: 语音业务、 视频业务、 文件传输业务等 IMS业务。 具体示例可以 参见上述实施例一中歩骤 S100的相关描述。  Specifically, the user can use a terminal device, such as a mobile phone, a personal computer, a tablet computer, etc., to log in to a third-party application website (for example: Taobao, Sina, Dangdang, Mushroom Street, etc.). The third-party application website may include its own authentication system, referred to as a third-party authentication system. After the user is authenticated by the third-party authentication system, the third-party application website can be logged in. The third-party application website can then be used to provide services provided by operators (for example, China Mobile, China Unicom, China Telecom, IMS service providers, etc.). The service may be a real-time communication of a webpage, such as a voice service, a video service, a file transmission service, and the like. For a specific example, refer to the related description of step S100 in the first embodiment.
第三方认证系统对用户通过终端设备提供的账号(例如某一淘宝网的用 户名)进行验证的过程中, 除了验证账号是否是第三方认证系统为用户分配 的合法的账号之外, 还可以验证账号对应的密码是否准确。 因此, 用户通过 终端设备向第三方认证系统提供账号的同时,可以一并将账号对应的密码提 供给第三方认证系统。在第三方认证系统验证通过的情况下, 第三方认证系 统可以根据该账号为用户分配与该账号对应的第一令牌。  In the process of verifying the account provided by the user through the terminal device (for example, the username of a certain Taobao network), the third-party authentication system can verify whether the account is a legal account assigned by the third-party authentication system for the user. Whether the password corresponding to the account is accurate. Therefore, when the user provides an account to the third-party authentication system through the terminal device, the user can provide the password corresponding to the account to the third-party authentication system. In the case that the third-party authentication system passes the verification, the third-party authentication system may assign the first token corresponding to the account to the user according to the account.
在一种可能的实现方式中, 第一接收模块 620还用于通过运营商认证门 户从所述终端设备接收所述接入认证请求。  In a possible implementation, the first receiving module 620 is further configured to receive the access authentication request from the terminal device by using an operator authentication terminal.
具体地, 运营商认证门户可以接收该终端设备发送的接入认证请求, 再 由第一接收模块 620接收该运营商认证门户发送的接入认证请求。  Specifically, the operator authentication portal may receive the access authentication request sent by the terminal device, and then the first receiving module 620 receives the access authentication request sent by the operator authentication portal.
第一发送模块 640, 与所述第一接收模块 620连接, 用于向所述第三方应 用标识对应的所述第三方认证系统发送第三方认证请求,所述第三方认证请 求中携带所述第一令牌。 a first sending module 640, connected to the first receiving module 620, configured to send to the third party Sending a third-party authentication request by using the third-party authentication system corresponding to the identifier, where the third-party authentication request carries the first token.
可以在通信认证装置 600的内部或者外部设置一个接口设备。 一种情况 下, 该接口设备设置在通信认证装置 600的外部, 该接口设备在通信认证装 置 600和第三方认证系统之间转发信息, 通信认证装置 600的第一发送模块 640将第三方认证请求发送给该接口设备, 再由该接口设备将该第三方认证 请求转发给第三方认证系统。 另一种情况下, 该接口设备设置在通信认证装 置 600的内部, 通信认证装置 600的第一发送模块 640可以直接向第三方认证 系统发送第三方认证请求。  An interface device can be provided inside or outside the communication authentication device 600. In one case, the interface device is disposed outside the communication authentication device 600, and the interface device forwards information between the communication authentication device 600 and the third-party authentication system, and the first sending module 640 of the communication authentication device 600 sends a third-party authentication request. Sended to the interface device, and the interface device forwards the third-party authentication request to the third-party authentication system. In another case, the interface device is disposed inside the communication authentication device 600, and the first sending module 640 of the communication authentication device 600 can directly send a third-party authentication request to the third-party authentication system.
具体地,通信认证装置 600可以根据第一接收模块 620接收到的接入认证 请求中携带的第三方应用标识, 获知该接入认证请求是由哪一个第三方应用 网站接入的,可以通过接口设备向该第三方应用网站的第三方认证系统发送 携带所述第一令牌的第三方认证请求, 也可以由第一发送模块 640向该第三 方应用网站的第三方认证系统发送携带所述第一令牌的第三方认证请求。具 体示例可以参见上述实施例一中歩骤 S120的相关描述。  Specifically, the communication authentication apparatus 600 can learn, according to the third-party application identifier carried in the access authentication request received by the first receiving module 620, which third-party application website is accessed by the access authentication request, and can pass the interface. The device sends a third-party authentication request that carries the first token to the third-party authentication system of the third-party application website, and may also send the first-party sending module 640 to the third-party authentication system of the third-party application website. A third-party authentication request for a token. For a specific example, refer to the related description of step S120 in the first embodiment.
第二接收模块 660, 用于接收所述第三方认证系统发送的所述第一令牌 对应的所述账号。  The second receiving module 660 is configured to receive the account corresponding to the first token sent by the third-party authentication system.
第一处理模块 680, 与所述第二接收模块 660连接, 用于获取所述账号绑 定的用户标识, 根据所述用户标识分配第二令牌和网关的 IP地址, 以使得所 述终端设备在所述网关对所述第二令牌进行认证后使用运营商提供的业务。 所述用户标识为通信认证装置 600为用户分配的标识。  The first processing module 680 is connected to the second receiving module 660, configured to acquire a user identifier bound to the account, and allocate a second token and an IP address of the gateway according to the user identifier, so that the terminal device After the gateway authenticates the second token, the service provided by the operator is used. The user identifier is an identifier assigned by the communication authentication device 600 to the user.
具体地, 若第三方认证系统认证第一令牌通过, 通信认证装置 600可以 通过接口设备接收该第三方认证系统发送的账号, 通信认证装置 600也可以 通过第二接收模块 660接收该第三方认证系统发送的账号。通信认证装置 600 还可以通过接口设备或第二接收模块 660接收到与该账号对应的第一令牌。 然后, 第一处理模块 680可以根据账号, 获取与该帐号绑定的用户标识, 该 用户标识可以包括 IMPU、 IMPI和用户与运营商签约的用户名中的任意一种 或者多种。 例如手机号码、 邮箱、 身份证号码等。 最后, 第一处理模块 680 可以根据获取到的用户标识, 分配第二令牌和网关的 IP地址, 并将该第二令 牌和网关的 IP地址发送给终端设备, 以使得所述终端设备可以在所述网关对 所述第二令牌进行认证后, 用户可以直接使用运营商提供的业务。 例如: 若 第三方应用网站为淘宝网, 若淘宝网认证系统认证第一令牌通过, 可以通过 接口设备或第二接收模块 660接收到淘宝网认证系统发送的淘宝网的用户 名, 然后第一处理模块 680可以获取与淘宝网的用户名绑定的用户标识例如 手机号码。 后续网关代替用户注册完成之后, 用户可以直接通过终端设备使 用运营商提供的与该淘宝网的用户名绑定的手机号码所注册的业务。 Specifically, if the third-party authentication system authenticates that the first token passes, the communication authentication device 600 can receive the account that is sent by the third-party authentication system by using the interface device, and the communication authentication device 600 can also receive the third-party authentication by using the second receiving module 660. The account number sent by the system. The communication authentication device 600 can also receive the first token corresponding to the account by using the interface device or the second receiving module 660. Then, the first processing module 680 can obtain the user identifier bound to the account according to the account, and the user identifier can include any one or more of an IMPU, an IMPI, and a user name signed by the user and the operator. For example, mobile phone number, email address, ID number, etc. Finally, the first processing module 680 can allocate the IP address of the second token and the gateway according to the obtained user identifier, and send the IP address of the second token and the gateway to the terminal device, so that the terminal device can After the gateway authenticates the second token, the user can directly use the service provided by the operator. For example, if the third-party application website is Taobao, if the Taobao authentication system authenticates the first token, the interface device or the second receiving module 660 can receive the user name of the Taobao network sent by the Taobao authentication system, and then the first The processing module 680 can obtain a user identifier, such as a mobile phone number, bound to the username of the Taobao network. After the subsequent gateway is replaced by the user registration, the user can directly use the terminal device to use the service registered by the operator and the mobile phone number bound to the Taobao user name.
本发明实施例的通信认证装置,用户在终端设备上只需要提供一次账号 进行一次登录, 在通过第三方认证系统对该账号验证通过后, 可以通过本实 施例的通信认证装置获得该账号绑定的用户标识所注册的业务的授权, 从而 使用该业务, 过程简单, 用户体验良好。  In the communication authentication apparatus of the embodiment of the present invention, the user only needs to provide an account once to perform a login on the terminal device. After the account is verified by the third-party authentication system, the account authentication can be obtained by using the communication authentication device of this embodiment. The user identifies the authorization of the registered service, thereby using the service, the process is simple, and the user experience is good.
实施例 7  Example 7
图 7为根据本发明实施例七的通信认证装置的结构框图。 本实施例提供 的通信认证装置 700用于实现图 2所示的实施例二提供的通信认证方法。 图 7 中标号与图 6相同的组件具有相同的功能, 为简明起见, 省略对这些组件的 详细说明。  Figure 7 is a block diagram showing the structure of a communication authentication apparatus according to a seventh embodiment of the present invention. The communication authentication apparatus 700 provided in this embodiment is used to implement the communication authentication method provided in the second embodiment shown in FIG. 2. The same components in Fig. 7 as those in Fig. 6 have the same functions, and a detailed description of these components will be omitted for the sake of brevity.
如图 7所示, 图 7所示的通信认证装置 700与图 6所示通信认证装置 600的 主要区别在于, 除了包括上述实施例六中的第一接收模块 620、 第一发送模 块 640、 第二接收模块 660和第一处理模块 680之外, 在不存在与所述账号绑 定的所述用户标识的情况下, 所述通信认证装置 700还可以包括:  As shown in FIG. 7, the main difference between the communication authentication apparatus 700 shown in FIG. 7 and the communication authentication apparatus 600 shown in FIG. 6 is that the first receiving module 620, the first transmitting module 640, and the first embodiment are included in the sixth embodiment. In addition to the receiving module 660 and the first processing module 680, the communication authentication apparatus 700 may further include:
第二发送模块 720, 与所述第一处理模块 680连接, 用于向所述终端设备 发送用户标识输入请求。 a second sending module 720, connected to the first processing module 680, for the terminal device Send a user ID input request.
具体地, 若第二接收模块 660接收到第三方认证系统发送的与第一令牌 对应的账号, 第一处理模块 680可以查找该账号是否绑定了用户标识。 若不 存在与该帐号绑定的用户标识, 则可以通过第二发送模块 720请求终端设备 发送用户标识。反之,若存在与该帐号绑定的用户标识,则第一处理模块 680 可以获取与该账号绑定的用户标识。 例如: 若用户通过手机登录淘宝网, 并 且使用淘宝网上的中国移动的电话功能, 若中国移动的第二接收模块 660接 收到淘宝网认证系统发送的淘宝网的用户名, 中国移动的第一处理模块 680 可以根据该淘宝网的用户名查找该淘宝网的用户名是否绑定了用户的手机 号码, 若没有绑定用户的手机号码, 中国移动的第二发送模块 720可以请求 用户通过手机发送手机号码。  Specifically, if the second receiving module 660 receives the account corresponding to the first token sent by the third-party authentication system, the first processing module 680 can search whether the account is bound with the user identifier. If there is no user identifier bound to the account, the second sending module 720 may request the terminal device to send the user identifier. On the other hand, if there is a user identifier bound to the account, the first processing module 680 can obtain the user identifier bound to the account. For example: If the user logs in to Taobao through the mobile phone and uses the mobile phone function of China Mobile on Taobao, if China Mobile's second receiving module 660 receives the Taobao network user name sent by the Taobao authentication system, China Mobile's first The processing module 680 can find, according to the user name of the Taobao network, whether the user name of the Taobao network is bound to the mobile phone number of the user. If the mobile phone number of the user is not bound, the second sending module 720 of China Mobile can request the user to send the mobile phone through the mobile phone. cellphone number.
在一种可能的实现方式中, 所述第二发送模块 720还用于通过所述运营 商认证门户向所述终端设备发送所述用户标识输入请求。  In a possible implementation, the second sending module 720 is further configured to send the user identity input request to the terminal device by using the operator authentication portal.
具体地, 若第一处理模块 680查找到不存在与上述账号绑定的用户标识, 则第二发送模块 720可以向运营商认证门户发送用户标识输入请求, 再由该 运营商认证门户向该终端设备发送用户标识输入请求。  Specifically, if the first processing module 680 finds that there is no user identifier bound to the account, the second sending module 720 may send a user identifier input request to the operator authentication portal, and then the portal authenticates the portal to the terminal. The device sends a user ID input request.
第二处理模块 740, 与所述第二接收模块 660和所述第一处理模块 680连 接, 用于接收所述终端设备发送的所述用户标识之后, 记录所述账号与所述 用户标识的绑定关系。  The second processing module 740 is connected to the second receiving module 660 and the first processing module 680, and configured to: after receiving the user identifier sent by the terminal device, record the binding of the account and the user identifier. Relationship.
在一种可能的实现方式中, 所述第二处理模块 740具体包括:  In a possible implementation manner, the second processing module 740 specifically includes:
第一接收子模块 741, 用于通过所述运营商认证门户从所述终端设备接 收所述用户标识;  The first receiving submodule 741 is configured to receive, by using the operator authentication portal, the user identifier from the terminal device;
记录子模块 742, 与所述第一接收子模块 741连接, 用于记录所述账号与 所述用户标识的绑定关系。  The recording sub-module 742 is connected to the first receiving sub-module 741, and is configured to record a binding relationship between the account and the user identifier.
具体地, 第一接收子模块 741可以通过运营商认证门户从终端设备接收 用户标识, 记录子模块 742可以记录所述账号与所述用户标识的绑定关系。 其中, 用户可以通过终端设备只输入 IMPU或 IMPI, 也可以既输入 IMPU又输 入 IMPI。 由于 IMPU与 IMPI存在一定的映射关系,通信认证装置 700可以根据 用户通过终端设备输入的 IMPU查找到对应的 IMPI。 用户还可以通过终端设 备只输入用户与运营商签约的用户标识。 通信认证装置 700无法认证该用户 标识, 可以到运营商的 IMS核心网中的归属用户服务器进行认证。 若 HSS认 证该用户标识通过, 记录子模块 742可以记录账号与用户标识的绑定关系。 具体示例可以参见上述实施例二中的歩骤 S220中的相关描述。 Specifically, the first receiving submodule 741 can receive from the terminal device through the operator authentication portal. The user identifier, the recording submodule 742 can record the binding relationship between the account and the user identifier. The user can input only the IMPU or IMPI through the terminal device, and can input both the IMPU and the IMPI. Because the IMPU has a certain mapping relationship with the IMPI, the communication authentication apparatus 700 can find the corresponding IMPI according to the IMPU input by the user through the terminal device. The user can also input only the user ID that the user has signed with the operator through the terminal device. The communication authentication apparatus 700 cannot authenticate the user identity and can authenticate to the home subscriber server in the operator's IMS core network. If the HSS authenticates the user ID, the recording submodule 742 can record the binding relationship between the account and the user identifier. For a specific example, refer to the related description in step S220 in the second embodiment.
在一种可能的实现方式中, 所述第一处理模块 680具体包括:  In a possible implementation manner, the first processing module 680 specifically includes:
分配子模块 681, 用于根据所述用户标识, 分配所述第二令牌和所述 IP 地址。  The distribution submodule 681 is configured to allocate the second token and the IP address according to the user identifier.
第一发送子模块 682, 与所述分配子模块 681连接, 用于向所述终端设备 发送所述第二令牌和所述 IP地址, 以使得所述终端设备根据所述 IP地址向所 述网关发送所述第二令牌的认证请求。  The first sending submodule 682 is connected to the allocating submodule 681, and configured to send the second token and the IP address to the terminal device, so that the terminal device sends the The gateway sends an authentication request for the second token.
例如, 若用户通过手机登录淘宝网 (第三方应用网站), 并且使用淘宝 网上的中国移动 (运营商) 的电话功能, 若中国移动的第一处理模块 680获 取了与淘宝网的用户名绑定的手机号码, 则分配子模块 681可以根据该手机 号码为该手机分配第二令牌和网关的 IP地址。 此外, 第一发送子模块 682可 以将该第二令牌和该 IP地址发送给该手机, 该手机可以根据该 IP地址找到与 该 IP地址对应的网关, 与该网关建立通信通道。 该网关可以向中国移动通信 认证装置 700发送第二令牌认证请求。  For example, if the user logs in to Taobao (a third-party application website) through a mobile phone and uses the mobile phone function of China Mobile (operator) on Taobao, if the first processing module 680 of China Mobile obtains the user name tied to Taobao. For the fixed mobile phone number, the distribution sub-module 681 can assign the second token and the IP address of the gateway to the mobile phone according to the mobile phone number. In addition, the first sending submodule 682 can send the second token and the IP address to the mobile phone, and the mobile phone can find a gateway corresponding to the IP address according to the IP address, and establish a communication channel with the gateway. The gateway can send a second token authentication request to the China Mobile Communications Authentication Device 700.
第二发送子模块 683,用于在所述第二令牌在所述通信认证装置 700内认 证通过的情况下, 向所述网关发送所述用户标识, 以使得所述网关根据所述 用户标识向运营商的核心网发起用户注册, 在注册完成之后, 使得所述用户 通过所述终端设备使用所述运营商提供的业务。 具体地, 分配子模块 681可以为终端设备分配第二令牌和网关的 IP地址, 第一发送子模块 682将该分配的第二令牌和网关的 IP地址发送给该终端设 备, 该终端设备可以根据该 IP地址向该网关发送第二令牌的认证请求。 网关 接收到该第二令牌的认证请求之后, 可以向通信认证装置 700发送该第二令 牌的认证请求。 通信认证装置 700可以认证该第二令牌是否通过, 若通信认 证装置 700认证该第二令牌通过, 则第二发送子模块 683可以将用户标识发送 给网关。 网关可以根据该用户标识代替用户到核心网例如 IMS核心网进行注 册, 并且, 网关可以指示核心网该用户已经认证, 不再需要进行鉴权挑战。 在网关代替用户注册之后,用户可以通过终端设备直接使用运营商提供的业 本发明实施例的通信认证装置,用户在终端设备上只需要提供一次账号 进行一次登录, 在通过第三方认证系统对该帐号验证通过后, 可以通过本实 施例的通信认证装置获得该账号绑定的用户标识所注册的业务的授权, 从而 使用该业务, 过程简单, 用户体验良好。 a second sending submodule 683, configured to send the user identifier to the gateway, so that the gateway is based on the user identifier, if the second token is authenticated in the communication authentication apparatus 700 User registration is initiated to the operator's core network, and after the registration is completed, the user is allowed to use the service provided by the operator through the terminal device. Specifically, the distribution submodule 681 can allocate the second token and the IP address of the gateway to the terminal device, and the first sending submodule 682 sends the allocated second token and the IP address of the gateway to the terminal device, where the terminal device The authentication request of the second token may be sent to the gateway according to the IP address. After receiving the authentication request of the second token, the gateway may send the authentication request of the second token to the communication authentication apparatus 700. The communication authentication apparatus 700 can authenticate whether the second token passes. If the communication authentication apparatus 700 authenticates that the second token passes, the second sending submodule 683 can transmit the user identifier to the gateway. The gateway can register the user to the core network, such as the IMS core network, according to the user identifier, and the gateway can indicate that the user of the core network has been authenticated, and the authentication challenge is no longer needed. After the gateway is used to replace the user registration, the user can directly use the communication authentication device of the embodiment of the present invention provided by the operator through the terminal device, and the user only needs to provide an account once to log in once on the terminal device, and the third-party authentication system After the account authentication is passed, the communication authentication device of the embodiment can obtain the authorization of the service registered by the user identifier bound to the account, so that the service is simple, and the user experience is good.
实施例 8  Example 8
图 8为根据本发明实施例八的通信认证装置的结构框图。 本实施例提供 的通信认证装置 800用于实现图 3所示的实施例三提供的通信认证方法。如图 8所示, 该通信认证装置 800可以包括:  Figure 8 is a block diagram showing the structure of a communication authentication apparatus according to an eighth embodiment of the present invention. The communication authentication apparatus 800 provided in this embodiment is used to implement the communication authentication method provided in the third embodiment shown in FIG. As shown in FIG. 8, the communication authentication apparatus 800 can include:
验证模块 810, 用于验证终端设备提供的账号。  The verification module 810 is configured to verify an account provided by the terminal device.
第二发送模块 820, 与所述验证模块 810连接, 用于在验证模块 810验证 通过的情况下, 向所述终端设备返回所述第一令牌。  The second sending module 820 is connected to the verification module 810, and is configured to return the first token to the terminal device if the verification module 810 passes the verification.
具体地, 用户可以使用终端设备登录第三方应用网站, 第三方应用网站 可以包括自己的认证系统, 简称第三方认证系统, 还可以包括自己的应用服 务器, 简称第三方应用服务器。 通信认证装置 800的验证模块 810可以验证终 端设备提供的账号, 若验证模块 810验证该账号通过, 则第二发送模块 820可 以向所述终端设备返回所述第一令牌。 Specifically, the user may log in to the third-party application website by using the terminal device. The third-party application website may include its own authentication system, which is referred to as a third-party authentication system, and may also include its own application server, which is referred to as a third-party application server. The verification module 810 of the communication authentication device 800 can verify the account provided by the terminal device. If the verification module 810 verifies that the account is approved, the second sending module 820 can Returning the first token to the terminal device.
例如: 若用户通过手机登录淘宝网 (第三方应用网站), 并且使用淘宝 网上的中国移动(运营商)的电话功能, 淘宝网服务器(第三方应用服务器) 弹出一个对话框, 用户输入淘宝网的用户名 (帐号)和密码之后, 点击登录 后会定向到淘宝网通信认证装置 800, 该通信认证装置 800的验证模块 810可 以验证该淘宝网的用户名。 若验证模块 810验证该淘宝网的用户名通过, 则 该淘宝网的第二发送模块 820可以向手机返回第一令牌。  For example: If the user logs in to Taobao (a third-party application website) through the mobile phone and uses the mobile phone function of China Mobile (operator) on Taobao, the Taobao server (third-party application server) pops up a dialog box, and the user inputs Taobao. After the user name (account) and the password, the login is directed to the Taobao communication authentication device 800, and the verification module 810 of the communication authentication device 800 can verify the user name of the Taobao. If the verification module 810 verifies that the username of the Taobao network passes, the second sending module 820 of the Taobao network may return the first token to the mobile phone.
接收模块 830, 用于接收运营商认证系统发送的第三方认证请求, 所述 第三方认证请求中携带第一令牌, 所述第一令牌为所述通信认证装置 800根 据终端设备提供的账号分配的令牌, 所述账号为所述通信认证装置 800为所 述终端设备分配的账号。  The receiving module 830 is configured to receive a third-party authentication request sent by the operator authentication system, where the third-party authentication request carries a first token, where the first token is an account provided by the communication authentication device 800 according to the terminal device. The assigned token is an account that the communication authentication device 800 allocates for the terminal device.
第一发送模块 840, 与所述接收模块 830连接, 用于在所述第一令牌认证 通过的情况下, 向所述运营商认证系统发送所述第一令牌对应的所述账号, 以使所述运营商认证系统获取所述账号绑定的用户标识。  The first sending module 840 is connected to the receiving module 830, and configured to send the account corresponding to the first token to the operator authentication system, if the first token is authenticated, to And causing the operator authentication system to obtain the user identifier bound to the account.
其中, 可以在通信认证装置 800的内部或者外部设置一个接口设备。 一 种情况下, 该接口设备设置在通信认证装置 800的外部, 该接口设备在运营 商认证系统和通信认证装置 800之间转发信息, 该接口设备接收运营商认证 系统发送的第三方认证请求, 再由接收模块 830接收该接口设备转发的该第 三方认证请求。 另一种情况下, 该接口设备设置在通信认证装置 800的内部, 接收模块 830可以直接接收运营商认证系统发送的第三方认证请求。  Among them, an interface device can be provided inside or outside the communication authentication device 800. In one case, the interface device is disposed outside the communication authentication device 800, and the interface device forwards information between the operator authentication system and the communication authentication device 800, and the interface device receives the third-party authentication request sent by the operator authentication system. The receiving module 830 receives the third-party authentication request forwarded by the interface device. In another case, the interface device is disposed inside the communication authentication device 800, and the receiving module 830 can directly receive the third-party authentication request sent by the operator authentication system.
具体地, 若通信认证装置 800认证第一令牌通过, 通信认证装置 800可以 通过第一发送模块 840直接将与第一令牌对应的账号发送给运营商认证系 统,通信认证装置 800也可以通过第一发送模块 840将与第一令牌对应的账号 发送给接口设备, 再由接口设备将该账号发送给运营商认证系统。 该运营商 认证系统可以根据该账号获取到与该账号绑定的用户标识,后续用户注册完 成之后, 可以直接使用运营商提供的与该账号绑定的用户标识所注册的业 本发明实施例的通信认证装置,用户在终端设备上只需要提供一次账号 进行一次登录, 验证模块验证该帐号, 在该帐号验证通过后, 可以通过运营 商认证系统获得该账号绑定的用户标识所注册的业务的授权, 从而使用该业 务, 过程简单, 用户体验良好。 Specifically, if the communication authentication device 800 authenticates that the first token passes, the communication authentication device 800 can directly send the account corresponding to the first token to the operator authentication system by using the first sending module 840, and the communication authentication device 800 can also pass The first sending module 840 sends the account corresponding to the first token to the interface device, and the interface device sends the account to the operator authentication system. The operator authentication system can obtain the user identifier bound to the account according to the account, and the subsequent user is registered. After the configuration, the communication authentication device of the embodiment of the present invention, which is registered by the operator and is associated with the account identifier, can be directly used. The user only needs to provide an account once to log in once on the terminal device, and the verification module verifies the account. After the account is verified, the service authentication system can obtain the authorization of the service registered by the user ID bound to the account, so that the service is simple, and the user experience is good.
实施例 9  Example 9
图 9为根据本发明实施例九的终端设备的结构框图。 本实施例提供的终 端设备 900用于实现图 4所示的实施例四提供的通信认证方法。 如图 9所示, 该终端设备 900可以包括:  FIG. 9 is a structural block diagram of a terminal device according to Embodiment 9 of the present invention. The terminal device 900 provided in this embodiment is used to implement the communication authentication method provided in Embodiment 4 shown in FIG. As shown in FIG. 9, the terminal device 900 may include:
发送模块 920, 用于在第三方认证系统对终端设备提供的账号验证通过 的情况下, 向运营商认证系统发送接入认证请求, 所述接入认证请求中携带 第三方应用标识和第一令牌,所述第一令牌为所述第三方认证系统根据所述 终端设备的账号分配的令牌, 以使得所述运营商认证系统根据所述第三方应 用标识请求所述第三方认证系统对所述第一令牌进行认证, 以获取所述账号 绑定的用户标识。  The sending module 920 is configured to send an access authentication request to the operator authentication system, where the third-party application identifier and the first order are carried in the access authentication request, where the third-party authentication system passes the account verification provided by the terminal device. a card, the first token is a token allocated by the third-party authentication system according to an account of the terminal device, so that the operator authentication system requests the third-party authentication system according to the third-party application identifier. The first token is authenticated to obtain a user identifier bound to the account.
具体地, 用户可以使用终端设备登录第三方应用网站, 第三方应用网站 可以包括自己的认证系统, 简称第三方认证系统, 还可以包括自己的应用服 务器, 简称第三方应用服务器。 若第三方认证系统验证终端设备 900提供的 账号通过, 则终端设备 900可以接收该第三方认证系统分配的与该账号相对 应的第一令牌。 发送模块 920可以向运营商认证系统发送携带了第三方应用 标识和第一令牌的接入认证请求。 例如: 若用户通过手机登录淘宝网 (第三 方应用网站), 并且使用淘宝网上的中国移动 (运营商) 的电话功能, 淘宝 网服务器(第三方应用服务器)弹出一个对话框, 用户输入淘宝网的用户名 和密码之后, 点击登录后会定向到淘宝网认证系统 (第三方认证系统), 该 淘宝网认证系统可以认证该淘宝网的用户名是否通过。若认证该淘宝网的用 户名通过, 则淘宝网认证系统可以为用户分配第一令牌, 并指示手机跳转到 该淘宝网服务器。 若用户需要使用中国移动提供的业务, 则发送模块 920可 以向中国移动认证系统发送携带了淘宝网应用标识(第三方应用标识)和第 一令牌的接入认证请求。 Specifically, the user may log in to the third-party application website by using the terminal device. The third-party application website may include its own authentication system, which is referred to as a third-party authentication system, and may also include its own application server, which is referred to as a third-party application server. If the third-party authentication system verifies that the account provided by the terminal device 900 passes, the terminal device 900 can receive the first token corresponding to the account that is allocated by the third-party authentication system. The sending module 920 can send an access authentication request carrying the third-party application identifier and the first token to the operator authentication system. For example: If the user logs in to Taobao (a third-party application website) through the mobile phone, and uses the mobile phone function of China Mobile (operator) on Taobao, the Taobao server (third-party application server) pops up a dialog box, and the user inputs Taobao. After the user name and password, click on the login will be directed to the Taobao certification system (third-party authentication system), The Taobao authentication system can authenticate whether the user name of the Taobao network passes. If the username of the Taobao network is authenticated, the Taobao authentication system can assign a first token to the user and instruct the mobile phone to jump to the Taobao server. If the user needs to use the service provided by China Mobile, the sending module 920 may send an access authentication request carrying the Taobao application identifier (third-party application identifier) and the first token to the China Mobile authentication system.
接收模块 940, 用于接收所述运营商认证系统发送的第二令牌和网关的 IP地址, 所述第二令牌和网关的 IP地址为所述运营商认证系统根据所述用户 标识分配的令牌和 IP地址。  The receiving module 940 is configured to receive an IP address of the second token and the gateway sent by the operator authentication system, where the IP address of the second token and the gateway is allocated by the carrier authentication system according to the user identifier. Token and IP address.
在一种可能的实现方式中, 所述接收模块 940还用于在所述运营商认证 系统不存在与所述账号绑定的所述用户标识的情况下, 从所述运营商认证系 统接收用户标识输入请求。  In a possible implementation, the receiving module 940 is further configured to receive a user from the operator authentication system if the operator authentication system does not have the user identifier bound to the account. Identifies the input request.
在一种可能的实现方式中, 所述发送模块 920还用于向所述运营商认证 系统发送用户输入的所述用户标识, 以使得所述运营商认证系统记录所述账 号与所述用户标识的绑定关系。  In a possible implementation, the sending module 920 is further configured to send the user identifier input by the user to the operator authentication system, so that the operator authentication system records the account and the user identifier. Binding relationship.
例如, 若用户通过手机登录淘宝网 (第三方应用网站), 并且使用淘宝 网上的中国移动 (运营商) 的电话功能, 若中国移动认证系统查找到不存在 与淘宝网的用户名绑定的手机号码, 则手机的接收模块 940可以接收中国移 动认证系统发送的手机号码输入请求。 接收模块 940接收到该手机号码输入 请求之后, 用户可以通过手机的发送模块 920向中国移动认证系统发送手机 号码。 中国移动认证系统可以记录该手机号码和淘宝网的用户名的绑定关 系, 后续用户注册完成之后, 可以直接使用中国移动提供的与该淘宝网的用 户名绑定的手机号码所注册的业务。  For example, if the user logs in to Taobao (a third-party application website) through a mobile phone and uses the mobile phone function of China Mobile (operator) on Taobao, if the China Mobile authentication system finds that there is no binding to the user name of Taobao. The mobile phone number, the receiving module 940 of the mobile phone can receive the mobile phone number input request sent by the China Mobile authentication system. After receiving the mobile phone number input request, the receiving module 940 can send the mobile phone number to the China Mobile authentication system through the sending module 920 of the mobile phone. The China Mobile authentication system can record the binding relationship between the mobile phone number and the user name of Taobao. After the subsequent user registration is completed, the service registered by the mobile phone number bound by the mobile phone name of the Taobao network can be directly used.
控制模块 960, 与所述接收模块 940连接, 用于在所述网关对所述第二令 牌进行认证后使用运营商提供的业务。  The control module 960 is connected to the receiving module 940, and is configured to use the service provided by the operator after the gateway authenticates the second token.
具体地, 接收模块 940可以接收运营商认证系统发送的第二令牌和网关 的 IP地址,控制模块 960可以根据网关的 IP地址查找到对应的网关,并向该网 关发送第二令牌的认证请求。再由网关向该运营商认证系统发送该第二令牌 的认证请求, 运营商认证系统接收到该第二令牌的认证请求之后, 可以认证 该第二令牌是否通过, 若该运营商认证系统认证该第二令牌通过, 则可以将 用户标识发送给网关, 网关可以根据该用户标识代替用户进行用户注册。 在 网关代替用户注册完成之后,用户可以通过终端设备直接使用运营商提供的 与该账号绑定的用户标识所注册的业务。 Specifically, the receiving module 940 can receive the second token and the gateway sent by the operator authentication system. The IP address of the control module 960 can find the corresponding gateway according to the IP address of the gateway, and send an authentication request of the second token to the gateway. And the gateway sends the authentication request of the second token to the carrier authentication system. After receiving the authentication request of the second token, the operator authentication system may authenticate whether the second token passes, and if the carrier authenticates After the system authenticates that the second token passes, the user identifier may be sent to the gateway, and the gateway may perform user registration according to the user identifier instead of the user. After the gateway is replaced by the user registration, the user can directly use the terminal device to use the service registered by the operator and the user identifier bound to the account.
本发明实施例的终端设备,用户在终端设备上只需要提供一次账号进行 一次登录, 在通过第三方认证系统对该账号验证通过后, 可以通过运营商认 证系统获得该账号绑定的用户标识所注册的业务的授权, 从而使用该业务, 过程简单, 用户体验良好。  In the terminal device of the embodiment of the present invention, the user only needs to provide an account once to log in once on the terminal device. After the account is verified by the third-party authentication system, the user identity system bound to the account can be obtained through the operator authentication system. The authorization of the registered business, thereby using the service, the process is simple and the user experience is good.
实施例 10  Example 10
图 10为根据本发明实施例十的通信认证装置的结构框图。所述通信认证 装置 1000可以是具备计算能力的主机服务器、个人计算机 PC、或者可携带的 便携式计算机或终端等。本发明具体实施例并不对计算节点的具体实现做限 定。  Figure 10 is a block diagram showing the structure of a communication authentication apparatus according to Embodiment 10 of the present invention. The communication authentication device 1000 may be a host server having a computing capability, a personal computer PC, or a portable computer or terminal that can be carried. The specific embodiment of the present invention does not limit the specific implementation of the computing node.
所述通信认证装置 1000包括处理器 (英文: processor)1010、 通信接口 (英 文: Communications Interface) 1020、存储器 (英文: memory array) 1030禾口总线 1040。 其中, 处理器 1010、 通信接口 1020、 以及存储器 1030通过总线 1040完 成相互间的通信。  The communication authentication apparatus 1000 includes a processor (English: processor) 1010, a communication interface (English interface: Communications Interface) 1020, a memory (English: memory array) 1030, and a bus 1040. The processor 1010, the communication interface 1020, and the memory 1030 complete communication with each other through the bus 1040.
通信接口 1020用于实现第三方认证系统、 终端设备、 运营商认证系统等 网元之间的通信。  The communication interface 1020 is configured to implement communication between network elements such as a third-party authentication system, a terminal device, and an operator authentication system.
处理器 1010用于执行程序。 处理器 1010可能是一个中央处理器 CPU, 或 者是专用集成电路 (英文: Application Specific Integrated Circuit, 缩写: ASIC) , 或者是被配置成实施本发明实施例的一个或多个集成电路。 存储器 1030可用于存储程序和数据。 其中, 存储程序的区域可以包括操 作系统、 至少一个上述各个模块所需的应用程序 (例如第一处理模块 680 ); 存储数据的区域可以包括根据本实施例的通信认证方法所分配的第一令牌、 用户标识、第二令牌等。 此外, 存储器 1030可能包括高速 RAM存储器, 也可 能还包括非易失性存储器 (英文: non-volatile memory), 例如至少一个磁盘存 储器。 存储器 1030也可以是存储器阵列。 存储器 1030还可能被分块, 并且所 述块可按一定的规则组合成虚拟卷。 The processor 1010 is configured to execute a program. The processor 1010 may be a central processing unit CPU, or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention. Memory 1030 can be used to store programs and data. The area storing the program may include an operating system, an application required by at least one of the foregoing modules (for example, the first processing module 680); and the area for storing the data may include the first order allocated by the communication authentication method according to the embodiment. Card, user ID, second token, etc. In addition, the memory 1030 may include a high speed RAM memory, and may also include a non-volatile memory, such as at least one disk memory. Memory 1030 can also be a memory array. The memory 1030 may also be partitioned, and the blocks may be combined into a virtual volume according to certain rules.
在一种可能的实施方式中, 上述程序可为包括计算机操作指令的程序代 码。 该程序具体可用于:  In a possible implementation, the above program may be a program code including computer operating instructions. This program can be used to:
在第三方认证系统对终端设备提供的账号验证通过的情况下,接收所述 终端设备发送的接入认证请求,所述接入认证请求中携带第三方应用标识和 第一令牌, 所述第一令牌为所述第三方认证系统根据所述账号分配的令牌, 所述账号为所述第三方认证系统为所述终端设备分配的账号;  And receiving, by the third-party authentication system, the access authentication request sent by the terminal device, where the access authentication request carries the third-party application identifier and the first token, where the a token is a token allocated by the third-party authentication system according to the account, and the account is an account allocated by the third-party authentication system for the terminal device;
向所述第三方应用标识对应的所述第三方认证系统发送第三方认证请 求, 所述第三方认证请求中携带所述第一令牌;  Sending, by the third-party authentication system, the third-party authentication request to the third-party authentication system, where the third-party authentication request carries the first token;
接收所述第三方认证系统发送的所述第一令牌对应的所述账号, 获取所 述账号绑定的用户标识, 根据所述用户标识分配第二令牌和网关的 IP地址, 以使得所述终端设备在所述网关对所述第二令牌进行认证后使用运营商提 供的业务, 所述用户标识为运营商认证系统为用户分配的标识。  Receiving the account corresponding to the first token sent by the third-party authentication system, acquiring a user identifier bound to the account, and assigning a second token and an IP address of the gateway according to the user identifier, so as to The terminal device uses the service provided by the operator after the gateway authenticates the second token, and the user identifier is an identifier that the operator authentication system allocates for the user.
在一种可能的实现方式中,在不存在与所述账号绑定的所述用户标识的 情况下,所述接收所述第三方认证系统发送的所述第一令牌对应的所述账号 之后, 所述获取所述账号绑定的用户标识之前, 还包括:  In a possible implementation, after the user identifier that is bound to the account is not present, after receiving the account corresponding to the first token sent by the third-party authentication system, Before the obtaining the user identifier bound to the account, the method further includes:
向所述终端设备发送用户标识输入请求;  Sending a user identity input request to the terminal device;
接收所述终端设备发送的所述用户标识之后, 记录所述账号与所述用户 标识的绑定关系。 在一种可能的实现方式中,所述根据所述用户标识分配第二令牌和网关 的 IP地址, 以使得所述终端设备在所述网关对所述第二令牌进行认证后使用 运营商提供的业务, 包括: After receiving the user identifier sent by the terminal device, the binding relationship between the account and the user identifier is recorded. In a possible implementation, the IP address of the second token and the gateway is allocated according to the user identifier, so that the terminal device uses the carrier after the gateway authenticates the second token. Services provided, including:
根据所述用户标识, 分配所述第二令牌和所述 IP地址;  Allocating the second token and the IP address according to the user identifier;
向所述终端设备发送所述第二令牌和所述 IP地址, 以使得所述终端设备 根据所述 IP地址向所述网关发送所述第二令牌的认证请求;  Sending the second token and the IP address to the terminal device, so that the terminal device sends an authentication request of the second token to the gateway according to the IP address;
在所述第二令牌在所述运营商认证系统内认证通过的情况下, 向所述网 关发送所述用户标识, 以使得所述网关根据所述用户标识向运营商的核心网 发起用户注册, 在注册完成之后, 使得所述用户通过所述终端设备使用所述 运营商提供的业务。  And sending, by the gateway, the user identifier to the gateway, so that the gateway initiates user registration to the core network of the operator according to the user identifier, where the second token is authenticated and passed in the carrier authentication system. After the registration is completed, the user is caused to use the service provided by the operator through the terminal device.
在一种可能的实现方式中, 所述接收所述终端设备发送的接入认证请 求, 具体包括:  In a possible implementation, the receiving the access authentication request sent by the terminal device includes:
通过运营商认证门户从所述终端设备接收所述接入认证请求; 所述向所述终端设备发送用户标识输入请求, 具体包括:  Receiving, by the operator authentication portal, the access authentication request from the terminal device; the sending the user identifier input request to the terminal device, specifically:
通过所述运营商认证门户向所述终端设备发送所述用户标识输入请求; 所述接收所述终端设备发送的所述用户标识之后, 记录所述账号与所述 用户标识的绑定关系, 具体包括:  Transmitting, by the operator authentication portal, the user identifier input request to the terminal device; after receiving the user identifier sent by the terminal device, recording a binding relationship between the account and the user identifier, specifically Includes:
通过所述运营商认证门户从所述终端设备接收所述用户标识; 记录所述账号与所述用户标识的绑定关系。  Receiving, by the operator authentication portal, the user identifier from the terminal device; recording a binding relationship between the account and the user identifier.
该程序具体还可用于:  The program can also be used to:
接收运营商认证系统发送的第三方认证请求,所述第三方认证请求中携 带第一令牌,所述第一令牌是第三方认证系统根据终端设备提供的账号分配 的令牌, 所述账号为所述第三方认证系统为所述终端设备分配的账号; 在所述第一令牌认证通过的情况下, 向所述运营商认证系统发送所述第 一令牌对应的所述账号, 以使所述运营商认证系统获取所述账号绑定的用户 标识。 Receiving a third-party authentication request sent by the operator authentication system, where the third-party authentication request carries a first token, where the first token is a token that is allocated by the third-party authentication system according to an account provided by the terminal device, and the account is An account that is allocated to the terminal device by the third-party authentication system; in the case that the first token is authenticated, the account corresponding to the first token is sent to the operator authentication system, to Having the operator authentication system acquire the user bound to the account Logo.
在一种可能的实现方式中,所述接收运营商认证系统发送的第三方认证 请求之前, 包括:  In a possible implementation, before receiving the third-party authentication request sent by the operator authentication system, the method includes:
验证所述终端设备提供的账号;  Verifying the account provided by the terminal device;
在验证通过的情况下, 向所述终端设备返回所述第一令牌。  In case the verification is passed, the first token is returned to the terminal device.
该程序具体还可用于:  The program can also be used to:
在第三方认证系统对终端设备提供的账号验证通过的情况下, 终端设备 向运营商认证系统发送接入认证请求,所述接入认证请求中携带第三方应用 标识和第一令牌,所述第一令牌为所述第三方认证系统根据所述终端设备的 账号分配的令牌, 以使得所述运营商认证系统根据所述第三方应用标识请求 所述第三方认证系统对所述第一令牌进行认证, 以获取所述账号绑定的用户 标识;  After the third-party authentication system passes the authentication of the account provided by the terminal device, the terminal device sends an access authentication request to the operator authentication system, where the access authentication request carries the third-party application identifier and the first token. The first token is a token that is allocated by the third-party authentication system according to the account of the terminal device, so that the operator authentication system requests the third-party authentication system to the first according to the third-party application identifier. The token is authenticated to obtain the user identifier bound to the account;
接收所述运营商认证系统发送的第二令牌和网关的 IP地址, 所述第二令 牌和网关的 IP地址为所述运营商认证系统根据所述用户标识分配的令牌和 IP 地址;  Receiving the second token and the IP address of the gateway sent by the operator authentication system, where the IP address of the second token and the gateway is a token and an IP address allocated by the operator authentication system according to the user identifier;
在所述网关对所述第二令牌进行认证后使用运营商提供的业务。  After the gateway authenticates the second token, the service provided by the operator is used.
在一种可能的实现方式中, 所述获取所述账号绑定的用户标识, 包括: 在所述运营商认证系统不存在与所述账号绑定的所述用户标识的情况 下, 从所述运营商认证系统接收用户标识输入请求;  In a possible implementation, the acquiring the user identifier bound to the account includes: if the operator authentication system does not have the user identifier bound to the account, The operator authentication system receives the user identification input request;
向所述运营商认证系统发送用户输入的所述用户标识, 以使得所述运营 商认证系统记录所述账号与所述用户标识的绑定关系。  Sending the user identifier input by the user to the operator authentication system, so that the operator authentication system records a binding relationship between the account and the user identifier.
本实施例的通信认证装置,用户在终端设备上只需要提供一次账号进行 一次登录, 在通过第三方认证系统对该账号验证通过后, 可以通过运营商认 证系统获得该账号绑定的用户标识所注册的业务的授权, 从而使用该业务, 过程简单, 用户体验良好。 本领域普通技术人员可以意识到, 本文所描述的实施例中的各示例性单 元及算法歩骤,能够以电子硬件、或者计算机软件和电子硬件的结合来实现。 这些功能究竟以硬件还是软件形式来实现,取决于技术方案的特定应用和设 计约束条件。专业技术人员可以针对特定的应用选择不同的方法来实现所描 述的功能, 但是这种实现不应认为超出本发明的范围。 In the communication authentication device of the embodiment, the user only needs to provide an account once to log in once on the terminal device. After the account is verified by the third-party authentication system, the user identity system bound to the account can be obtained through the operator authentication system. The authorization of the registered business, thereby using the service, the process is simple and the user experience is good. Those of ordinary skill in the art will appreciate that the various exemplary elements and algorithms of the embodiments described herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the solution. A person skilled in the art can select different methods for implementing the described functions for a particular application, but such implementation should not be considered to be beyond the scope of the present invention.
如果以计算机软件的形式来实现所述功能并作为独立的产品销售或使 用时, 则在一定程度上可认为本发明的技术方案的全部或部分(例如对现有 技术做出贡献的部分)是以计算机软件产品的形式体现的。 该计算机软件产 品通常存储在计算机可读取的存储介质中,包括若干指令用以使得计算机设 备(可以是个人计算机、 服务器、 或者网络设备等)执行本发明各实施例方 法的全部或部分歩骤。 而前述的存储介质包括 U盘、 移动硬盘、 只读存储器 (英文: Read-Only Memory,缩写: ROM)、随机存取存储器(英文: Random Access Memory, 缩写: RAM)、 磁碟或者光盘等各种可以存储程序代码的 介质。  If the function is implemented in the form of computer software and sold or used as a stand-alone product, it may be considered to some extent that all or part of the technical solution of the present invention (for example, a part contributing to the prior art) is It is embodied in the form of computer software products. The computer software product is typically stored in a computer readable storage medium and includes instructions for causing a computer device (which may be a personal computer, server, or network device, etc.) to perform all or part of the steps of various embodiments of the present invention. . The foregoing storage medium includes a USB flash drive, a mobile hard disk, a read-only memory (English: Read-Only Memory, abbreviation: ROM), a random access memory (English: Random Access Memory, abbreviation: RAM), a magnetic disk or an optical disk, and the like. A medium that can store program code.
以上所述, 仅为本发明的具体实施方式, 但本发明的保护范围并不局限 于此, 任何熟悉本技术领域的技术人员在本发明揭露的技术范围内, 可轻易 想到变化或替换, 都应涵盖在本发明的保护范围之内。 因此, 本发明的保护 范围应所述以权利要求的保护范围为准。  The above is only the specific embodiment of the present invention, but the scope of the present invention is not limited thereto, and any person skilled in the art can easily think of changes or substitutions within the technical scope of the present invention. It should be covered by the scope of the present invention. Therefore, the scope of the invention should be determined by the scope of the claims.

Claims

权 利 要 求 书 claims
1、 一种通信认证方法, 其特征在于, 包括: 1. A communication authentication method, characterized by including:
在第三方认证系统对终端设备提供的账号验证通过的情况下,接收所述 终端设备发送的接入认证请求,所述接入认证请求中携带第三方应用标识和 第一令牌, 所述第一令牌为所述第三方认证系统根据所述账号分配的令牌, 所述账号为所述第三方认证系统为所述终端设备分配的账号; When the third-party authentication system passes the verification of the account provided by the terminal device, receiving an access authentication request sent by the terminal device, where the access authentication request carries the third-party application identification and the first token, and the third A token is a token assigned by the third-party authentication system according to the account number, and the account number is an account assigned by the third-party authentication system to the terminal device;
向所述第三方应用标识对应的所述第三方认证系统发送第三方认证请 求, 所述第三方认证请求中携带所述第一令牌; Send a third-party authentication request to the third-party authentication system corresponding to the third-party application identification, where the third-party authentication request carries the first token;
接收所述第三方认证系统发送的所述第一令牌对应的所述账号, 获取所 述账号绑定的用户标识, 根据所述用户标识分配第二令牌和网关的 IP地址, 以使得所述终端设备在所述网关对所述第二令牌进行认证后使用运营商提 供的业务, 所述用户标识为运营商认证系统为用户分配的标识。 Receive the account corresponding to the first token sent by the third-party authentication system, obtain the user identification bound to the account, and allocate the second token and the IP address of the gateway according to the user identification, so that the The terminal device uses the service provided by the operator after the gateway authenticates the second token, and the user identification is an identification assigned to the user by the operator's authentication system.
2、 根据权利要求 1所述的通信认证方法, 其特征在于, 在不存在与所述 账号绑定的所述用户标识的情况下,所述接收所述第三方认证系统发送的所 述第一令牌对应的所述账号之后, 所述获取所述账号绑定的用户标识之前, 还包括: 2. The communication authentication method according to claim 1, characterized in that, in the case where the user identification bound to the account does not exist, the first step of receiving the first authentication message sent by the third-party authentication system is After obtaining the account number corresponding to the token and before obtaining the user ID bound to the account, it also includes:
向所述终端设备发送用户标识输入请求; Send a user identification input request to the terminal device;
接收所述终端设备发送的所述用户标识之后, 记录所述账号与所述用户 标识的绑定关系。 After receiving the user identification sent by the terminal device, the binding relationship between the account and the user identification is recorded.
3、 根据权利要求 1或 2所述的通信认证方法, 其特征在于, 所述根据所 述用户标识分配第二令牌和网关的 IP地址, 以使得所述终端设备在所述网关 对所述第二令牌进行认证后使用运营商提供的业务, 包括: 3. The communication authentication method according to claim 1 or 2, characterized in that, the second token and the IP address of the gateway are allocated according to the user identification, so that the terminal device authenticates the gateway to the After the second token is authenticated, the services provided by the operator are used, including:
根据所述用户标识, 分配所述第二令牌和所述 IP地址; According to the user identification, allocate the second token and the IP address;
向所述终端设备发送所述第二令牌和所述 IP地址, 以使得所述终端设备 根据所述 IP地址向所述网关发送所述第二令牌的认证请求; 在所述第二令牌在所述运营商认证系统内认证通过的情况下, 向所述网 关发送所述用户标识, 以使得所述网关根据所述用户标识向所述运营商的核 心网发起用户注册, 在注册完成之后, 使得所述用户通过所述终端设备使用 所述运营商提供的业务。 Send the second token and the IP address to the terminal device, so that the terminal device sends an authentication request for the second token to the gateway according to the IP address; When the second token is authenticated in the operator authentication system, the user identification is sent to the gateway, so that the gateway initiates an operation to the operator's core network based on the user identification. User registration, after the registration is completed, enables the user to use services provided by the operator through the terminal device.
4、 根据权利要求 2所述的通信认证方法, 其特征在于, 所述接收所述终 端设备发送的接入认证请求, 具体包括: 4. The communication authentication method according to claim 2, wherein the receiving the access authentication request sent by the terminal device specifically includes:
通过运营商认证门户从所述终端设备接收所述接入认证请求; 所述向所述终端设备发送用户标识输入请求, 具体包括: Receive the access authentication request from the terminal device through the operator authentication portal; and send the user identification input request to the terminal device, specifically including:
通过所述运营商认证门户向所述终端设备发送所述用户标识输入请求; 所述接收所述终端设备发送的所述用户标识之后, 记录所述账号与所述 用户标识的绑定关系, 具体包括: Send the user identification input request to the terminal device through the operator authentication portal; after receiving the user identification sent by the terminal device, record the binding relationship between the account number and the user identification, specifically include:
通过所述运营商认证门户从所述终端设备接收所述用户标识; 记录所述账号与所述用户标识的绑定关系。 Receive the user identification from the terminal device through the operator authentication portal; record the binding relationship between the account number and the user identification.
5、 一种通信认证方法, 其特征在于, 包括: 5. A communication authentication method, characterized by including:
接收运营商认证系统发送的第三方认证请求,所述第三方认证请求中携 带第一令牌,所述第一令牌是第三方认证系统根据终端设备提供的账号分配 的令牌, 所述账号为所述第三方认证系统为所述终端设备分配的账号; 在所述第一令牌认证通过的情况下, 向所述运营商认证系统发送所述第 一令牌对应的所述账号, 以使所述运营商认证系统获取所述账号绑定的用户 标识。 Receive a third-party authentication request sent by the operator's authentication system, the third-party authentication request carries a first token, the first token is a token allocated by the third-party authentication system according to the account provided by the terminal device, and the account The account number assigned to the terminal device by the third-party authentication system; if the first token authentication passes, send the account number corresponding to the first token to the operator authentication system, to The operator authentication system is caused to obtain the user identification bound to the account.
6、 根据权利要求 5所述的通信认证方法, 其特征在于, 所述接收运营商 认证系统发送的第三方认证请求之前, 包括: 6. The communication authentication method according to claim 5, characterized in that, before receiving the third-party authentication request sent by the operator authentication system, the method includes:
验证所述终端设备提供的账号; Verify the account provided by the terminal device;
在验证通过的情况下, 向所述终端设备返回所述第一令牌。 If the verification passes, the first token is returned to the terminal device.
7、 一种通信认证方法, 其特征在于, 包括: 在第三方认证系统对终端设备提供的账号验证通过的情况下, 终端设备 向运营商认证系统发送接入认证请求,所述接入认证请求中携带第三方应用 标识和第一令牌,所述第一令牌为所述第三方认证系统根据所述终端设备的 账号分配的令牌, 以使得所述运营商认证系统根据所述第三方应用标识请求 所述第三方认证系统对所述第一令牌进行认证, 以获取所述账号绑定的用户 标识; 7. A communication authentication method, characterized by including: When the third-party authentication system passes the verification of the account provided by the terminal device, the terminal device sends an access authentication request to the operator authentication system, and the access authentication request carries the third-party application identifier and the first token. The first token is a token allocated by the third-party authentication system according to the account of the terminal device, so that the operator authentication system requests the third-party authentication system to verify the first token according to the third-party application identifier. The token is authenticated to obtain the user ID bound to the account;
接收所述运营商认证系统发送的第二令牌和网关的 IP地址, 所述第二令 牌和网关的 IP地址为所述运营商认证系统根据所述用户标识分配的令牌和 IP 地址; Receive the second token and the IP address of the gateway sent by the operator authentication system, where the second token and the IP address of the gateway are the token and IP address allocated by the operator authentication system according to the user identification;
在所述网关对所述第二令牌进行认证后使用运营商提供的业务。 After the gateway authenticates the second token, the service provided by the operator is used.
8、 根据权利要求 7所述的通信认证方法, 其特征在于, 所述获取所述账 号绑定的用户标识, 包括: 8. The communication authentication method according to claim 7, wherein the obtaining the user identification bound to the account includes:
在所述运营商认证系统不存在与所述账号绑定的所述用户标识的情况 下, 从所述运营商认证系统接收用户标识输入请求; In the case where the user identification bound to the account does not exist in the operator authentication system, receive a user identification input request from the operator authentication system;
向所述运营商认证系统发送用户输入的所述用户标识, 以使得所述运营 商认证系统记录所述账号与所述用户标识的绑定关系。 Send the user identification input by the user to the operator authentication system, so that the operator authentication system records the binding relationship between the account and the user identification.
9、 一种通信认证装置, 其特征在于, 包括: 9. A communication authentication device, characterized by including:
第一接收模块,用于在第三方认证系统对终端设备提供的账号验证通过 的情况下, 接收所述终端设备发送的接入认证请求, 所述接入认证请求中携 带第三方应用标识和第一令牌,所述第一令牌为所述第三方认证系统根据所 述账号分配的令牌,所述账号为所述第三方认证系统为所述终端设备分配的 账号; The first receiving module is configured to receive an access authentication request sent by the terminal device when the third-party authentication system passes the verification of the account provided by the terminal device. The access authentication request carries the third-party application identifier and the third-party application identifier. A token, the first token is a token assigned by the third-party authentication system according to the account number, and the account number is an account assigned by the third-party authentication system to the terminal device;
第一发送模块, 与所述第一接收模块连接, 用于向所述第三方应用标识 对应的所述第三方认证系统发送第三方认证请求,所述第三方认证请求中携 带所述第一令牌; 第二接收模块,用于接收所述第三方认证系统发送的所述第一令牌对应 的所述账号; A first sending module, connected to the first receiving module, is used to send a third-party authentication request to the third-party authentication system corresponding to the third-party application identifier, where the third-party authentication request carries the first command Card; a second receiving module, configured to receive the account number corresponding to the first token sent by the third-party authentication system;
第一处理模块, 与所述第二接收模块连接, 用于获取所述账号绑定的用 户标识, 根据所述用户标识分配第二令牌和网关的 IP地址, 以使得所述终端 设备在所述网关对所述第二令牌进行认证后使用运营商提供的业务,所述用 户标识为所述通信认证装置为用户分配的标识。 A first processing module, connected to the second receiving module, is used to obtain the user identification bound to the account, and allocate a second token and the IP address of the gateway according to the user identification, so that the terminal device is located where The gateway uses the service provided by the operator after authenticating the second token, and the user identification is an identification assigned to the user by the communication authentication device.
10、 根据权利要求 9所述的通信认证装置, 其特征在于, 在不存在与所 述账号绑定的所述用户标识的情况下, 所述通信认证装置还包括: 10. The communication authentication device according to claim 9, characterized in that, in the absence of the user identification bound to the account, the communication authentication device further includes:
第二发送模块, 与所述第一处理模块连接, 用于向所述终端设备发送用 户标识输入请求; A second sending module, connected to the first processing module, is used to send a user identification input request to the terminal device;
第二处理模块, 与所述第二接收模块和所述第一处理模块连接, 用于接 收所述终端设备发送的所述用户标识之后,记录所述账号与所述用户标识的 绑定关系。 The second processing module is connected to the second receiving module and the first processing module, and is configured to record the binding relationship between the account and the user identification after receiving the user identification sent by the terminal device.
11、 根据权利要求 9或 10所述的通信认证装置, 其特征在于, 所述第一 处理模块具体包括: 11. The communication authentication device according to claim 9 or 10, characterized in that the first processing module specifically includes:
分配子模块,用于根据所述用户标识,分配所述第二令牌和所述 IP地址; 第一发送子模块, 与所述分配子模块连接, 用于向所述终端设备发送所 述第二令牌和所述 IP地址, 以使得所述终端设备根据所述 IP地址向所述网关 发送所述第二令牌的认证请求; a distribution sub-module, configured to distribute the second token and the IP address according to the user identification; a first sending sub-module, connected to the distribution sub-module, used to send the third token to the terminal device two tokens and the IP address, so that the terminal device sends an authentication request for the second token to the gateway according to the IP address;
第二发送子模块,用于在所述第二令牌在所述通信认证装置内认证通过 的情况下, 向所述网关发送所述用户标识, 以使得所述网关根据所述用户标 识向所述运营商的核心网发起用户注册, 在注册完成之后, 使得所述用户通 过所述终端设备使用所述运营商提供的业务。 The second sending submodule is configured to send the user identification to the gateway when the second token is authenticated in the communication authentication device, so that the gateway sends the user identification to the user identification according to the user identification. The operator's core network initiates user registration. After the registration is completed, the user is allowed to use the services provided by the operator through the terminal device.
12、 根据权利要求 10所述的通信认证装置, 其特征在于, 12. The communication authentication device according to claim 10, characterized in that,
所述第一接收模块还用于通过运营商认证门户从所述终端设备接收所 述接入认证请求; The first receiving module is also configured to receive the information from the terminal device through the operator authentication portal. The above access authentication request;
所述第二发送模块还用于通过所述运营商认证门户向所述终端设备发 送所述用户标识输入请求; The second sending module is also configured to send the user identification input request to the terminal device through the operator authentication portal;
所述第二处理模块具体包括: The second processing module specifically includes:
第一接收子模块,用于通过所述运营商认证门户从所述终端设备接收所 述用户标识; The first receiving sub-module is used to receive the user identification from the terminal device through the operator authentication portal;
记录子模块, 与所述第一接收子模块连接, 用于记录所述账号与所述用 户标识的绑定关系。 The recording sub-module is connected to the first receiving sub-module and is used to record the binding relationship between the account and the user identification.
13、 一种通信认证装置, 其特征在于, 包括: 13. A communication authentication device, characterized by including:
接收模块, 用于接收运营商认证系统发送的第三方认证请求, 所述第三 方认证请求中携带第一令牌,所述第一令牌为所述通信认证装置根据终端设 备提供的账号分配的令牌,所述账号为所述通信认证装置为所述终端设备分 配的账号; A receiving module, configured to receive a third-party authentication request sent by the operator authentication system. The third-party authentication request carries a first token. The first token is assigned by the communication authentication device according to the account provided by the terminal device. Token, the account is the account assigned by the communication authentication device to the terminal device;
第一发送模块, 与所述接收模块连接, 用于在所述第一令牌认证通过的 情况下, 向所述运营商认证系统发送所述第一令牌对应的所述账号, 以使所 述运营商认证系统获取所述账号绑定的用户标识。 The first sending module is connected to the receiving module, and is used to send the account number corresponding to the first token to the operator authentication system when the first token authentication passes, so that the The operator authentication system obtains the user ID bound to the account.
14、 根据权利要求 13所述的通信认证装置, 其特征在于, 所述装置还包 括: 14. The communication authentication device according to claim 13, characterized in that the device further includes:
验证模块, 用于验证所述终端设备提供的账号; A verification module, used to verify the account provided by the terminal device;
第二发送模块, 与所述验证模块连接, 用于在所述验证模块验证通过的 情况下, 向所述终端设备返回所述第一令牌。 The second sending module is connected to the verification module, and is used to return the first token to the terminal device if the verification module passes the verification.
15、 一种终端设备, 其特征在于, 包括: 15. A terminal device, characterized in that it includes:
发送模块,用于在第三方认证系统对终端设备提供的账号验证通过的情 况下, 向运营商认证系统发送接入认证请求, 所述接入认证请求中携带第三 方应用标识和第一令牌,所述第一令牌为所述第三方认证系统根据所述终端 设备的账号分配的令牌, 以使得所述运营商认证系统根据所述第三方应用标 识请求所述第三方认证系统对所述第一令牌进行认证, 以获取所述账号绑定 的用户标识; A sending module, configured to send an access authentication request to the operator authentication system when the third-party authentication system passes the verification of the account provided by the terminal device, where the access authentication request carries the third-party application identifier and the first token , the first token is the third-party authentication system according to the terminal The token assigned by the device's account, so that the operator authentication system requests the third-party authentication system to authenticate the first token according to the third-party application identifier to obtain the user identifier bound to the account ;
接收模块, 用于接收所述运营商认证系统发送的第二令牌和网关的 IP地 址, 所述第二令牌和网关的 IP地址为所述运营商认证系统根据所述用户标识 分配的令牌和 IP地址; A receiving module, configured to receive the second token and the IP address of the gateway sent by the operator authentication system, where the second token and the IP address of the gateway are the tokens assigned by the operator authentication system according to the user identity. Brand and IP address;
控制模块, 与所述接收模块连接, 用于在所述网关对所述第二令牌进行 认证后使用运营商提供的业务。 The control module is connected to the receiving module and is used to use the service provided by the operator after the gateway authenticates the second token.
16、 根据权利要求 15所述的终端设备, 其特征在于, 16. The terminal device according to claim 15, characterized in that,
所述接收模块还用于在所述运营商认证系统不存在与所述账号绑定的 所述用户标识的情况下, 从所述运营商认证系统接收用户标识输入请求; 所述发送模块还用于向所述运营商认证系统发送用户输入的所述用户 标识, 以使得所述运营商认证系统记录所述账号与所述用户标识的绑定关 The receiving module is also configured to receive a user identification input request from the operator authentication system when the user identification bound to the account does not exist in the operator authentication system; the sending module is also configured to: The user identification input by the user is sent to the operator authentication system, so that the operator authentication system records the binding relationship between the account and the user identification.
PCT/CN2014/083640 2013-09-23 2014-08-04 Communication authentication method and apparatus, and terminal device WO2015039502A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201310436691.5 2013-09-23
CN201310436691.5A CN104468487B (en) 2013-09-23 2013-09-23 Communication authentication method and device, terminal device

Publications (1)

Publication Number Publication Date
WO2015039502A1 true WO2015039502A1 (en) 2015-03-26

Family

ID=52688189

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/083640 WO2015039502A1 (en) 2013-09-23 2014-08-04 Communication authentication method and apparatus, and terminal device

Country Status (2)

Country Link
CN (1) CN104468487B (en)
WO (1) WO2015039502A1 (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108768991A (en) * 2018-05-18 2018-11-06 阿里巴巴集团控股有限公司 A kind of reality people's authentication method and system
CN111080253A (en) * 2019-12-11 2020-04-28 深圳供电局有限公司 Random sun type power transmission line field operation method and system
CN115174161A (en) * 2022-06-15 2022-10-11 平安银行股份有限公司 Account login method and device, electronic equipment and storage medium
CN115412331A (en) * 2022-08-25 2022-11-29 聚好看科技股份有限公司 Application login method, electronic equipment and server

Families Citing this family (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107079008B (en) * 2015-03-27 2020-02-21 华为技术有限公司 User authentication method, device and system
CN105072608B (en) * 2015-06-30 2019-02-12 青岛海信移动通信技术股份有限公司 A kind of method and device of administrative authentication token
CN105050081B (en) 2015-08-19 2017-03-22 腾讯科技(深圳)有限公司 Method, device and system for connecting network access device to wireless network access point
CN106470190A (en) * 2015-08-19 2017-03-01 中兴通讯股份有限公司 A kind of Web real-time communication platform authentication cut-in method and device
CN105897675A (en) * 2015-11-27 2016-08-24 乐视云计算有限公司 Video service providing method, access authentication method, server and system
CN108605038B (en) * 2016-01-26 2022-02-25 金金哲 Internet portal system and using method thereof
CN107147496A (en) * 2017-04-28 2017-09-08 广东网金控股股份有限公司 Under a kind of service-oriented technological frame between different application unified authorization certification method
CN109474600B (en) * 2018-11-20 2021-06-18 麒麟合盛网络技术股份有限公司 Account binding method, system, device and equipment
CN110049106B (en) * 2019-03-22 2022-02-08 口碑(上海)信息技术有限公司 Service request processing system and method
CN112492017A (en) * 2020-11-24 2021-03-12 航天信息股份有限公司 Websocket connection method and system based on token authentication
CN113037741B (en) * 2021-03-04 2023-08-11 腾讯科技(深圳)有限公司 Authentication method, authentication device, computer equipment and storage medium
CN114268474A (en) * 2021-12-13 2022-04-01 中国联合网络通信集团有限公司 Operator application login control method, device, equipment and storage medium
CN115987636B (en) * 2022-12-22 2023-07-18 北京深盾科技股份有限公司 Information security implementation method, device and storage medium

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101427511A (en) * 2006-04-07 2009-05-06 戴尔产品有限公司 Authentication service for facilitating access to services
CN102739708A (en) * 2011-04-07 2012-10-17 腾讯科技(深圳)有限公司 System and method for accessing third party application based on cloud platform
CN103124252A (en) * 2011-11-18 2013-05-29 华为软件技术有限公司 Client application access authentication processing method and device

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101350717B (en) * 2007-07-18 2011-04-27 中国移动通信集团公司 Method and system for logging on third party server through instant communication software
CN101834834A (en) * 2009-03-09 2010-09-15 华为软件技术有限公司 Authentication method, device and system
CN102082775A (en) * 2009-11-27 2011-06-01 中国移动通信集团公司 Method, device and system for managing subscriber identity
CN103051630B (en) * 2012-12-21 2016-01-27 微梦创科网络科技(中国)有限公司 Method, the Apparatus and system of third-party application mandate is realized based on open platform

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101427511A (en) * 2006-04-07 2009-05-06 戴尔产品有限公司 Authentication service for facilitating access to services
CN102739708A (en) * 2011-04-07 2012-10-17 腾讯科技(深圳)有限公司 System and method for accessing third party application based on cloud platform
CN103124252A (en) * 2011-11-18 2013-05-29 华为软件技术有限公司 Client application access authentication processing method and device

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108768991A (en) * 2018-05-18 2018-11-06 阿里巴巴集团控股有限公司 A kind of reality people's authentication method and system
CN108768991B (en) * 2018-05-18 2020-08-04 阿里巴巴集团控股有限公司 Real person authentication method and system
CN111080253A (en) * 2019-12-11 2020-04-28 深圳供电局有限公司 Random sun type power transmission line field operation method and system
CN111080253B (en) * 2019-12-11 2023-03-03 深圳供电局有限公司 Random sun type power transmission line field operation method and system
CN115174161A (en) * 2022-06-15 2022-10-11 平安银行股份有限公司 Account login method and device, electronic equipment and storage medium
CN115174161B (en) * 2022-06-15 2023-06-13 平安银行股份有限公司 Account login method and device, electronic equipment and storage medium
CN115412331A (en) * 2022-08-25 2022-11-29 聚好看科技股份有限公司 Application login method, electronic equipment and server

Also Published As

Publication number Publication date
CN104468487A (en) 2015-03-25
CN104468487B (en) 2018-10-19

Similar Documents

Publication Publication Date Title
WO2015039502A1 (en) Communication authentication method and apparatus, and terminal device
US10594695B2 (en) Authentication arrangement
WO2021057889A1 (en) Data processing method and apparatus, electronic device, and storage medium
US9584615B2 (en) Redirecting access requests to an authorized server system for a cloud service
US8499343B2 (en) Hosted media content service systems and methods
EP2633667B1 (en) System and method for on the fly protocol conversion in obtaining policy enforcement information
TWI477163B (en) User-based authentication for realtime communications
US20190095598A1 (en) Device, control method of the same, and storage medium
US10834067B2 (en) Method of access by a telecommunications terminal to a database hosted by a service platform that is accessible via a telecommunications network
WO2014131279A1 (en) Bidirectional authorization system, client and method
US20130007867A1 (en) Network Identity for Software-as-a-Service Authentication
CN110365701B (en) Client terminal equipment management method and device, computing equipment and storage medium
WO2019040658A1 (en) Hybrid single sign-on for software applications and services using classic and modern identity providers
US20120278854A1 (en) System and method for device addressing
KR102645768B1 (en) System for managing multiple identity and method thereof
US20200076797A1 (en) System and data processing method
US20240031352A1 (en) Mobile device enabled desktop tethered and tetherless authentication
JP5565408B2 (en) ID authentication system, ID authentication method, authentication server, terminal device, authentication method of authentication server, communication method of terminal device, and program
US20190028460A1 (en) Low-overhead single sign on
US20150101059A1 (en) Application License Verification
CN106161356B (en) Method and system for rapidly logging in website through client
CN111949959A (en) Authorization authentication method and device in Oauth protocol
CN113038192B (en) Video processing method and device, electronic equipment and storage medium
CN110198540B (en) Portal authentication method and device
US9742776B2 (en) Contact identification validation via social invitation

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14845390

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 14845390

Country of ref document: EP

Kind code of ref document: A1