WO2015127736A1 - 一种用户隐私保护的方法、设备和系统 - Google Patents

一种用户隐私保护的方法、设备和系统 Download PDF

Info

Publication number
WO2015127736A1
WO2015127736A1 PCT/CN2014/080869 CN2014080869W WO2015127736A1 WO 2015127736 A1 WO2015127736 A1 WO 2015127736A1 CN 2014080869 W CN2014080869 W CN 2014080869W WO 2015127736 A1 WO2015127736 A1 WO 2015127736A1
Authority
WO
WIPO (PCT)
Prior art keywords
location server
user
random value
identifier
router
Prior art date
Application number
PCT/CN2014/080869
Other languages
English (en)
French (fr)
Inventor
何文裕
何承东
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2015127736A1 publication Critical patent/WO2015127736A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • H04L9/0869Generation of secret information including derivation or calculation of cryptographic keys or passwords involving random numbers or seeds
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • H04L9/0866Generation of secret information including derivation or calculation of cryptographic keys or passwords involving user or device identifiers, e.g. serial number, physical or biometrical information, DNA, hand-signature or measurable physical characteristics
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0407Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the identity of one or more communicating identities is hidden
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/02Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/42Anonymization, e.g. involving pseudonyms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/69Identity-dependent
    • H04W12/75Temporary identity

Definitions

  • the present invention relates to communication network application technologies, and in particular, to a method, device, and system for user privacy protection.
  • IP Internet Protocol
  • user IDs long-term identifiers
  • locator ie, network location identifier
  • the terminal may cause IP address reassignment when moving, although the same layer is used by the same user, but the transport layer's quad ( ⁇ local IP, remote IP, local port, remote port>) There has been a change, which will cause the connection to be broken and rebuilt.
  • the required traffic needs to be seamlessly switched between multiple devices, but the traditional TCP/IP network cannot support it.
  • the user identifier UserlD is assigned by the operator and is permanently unchanged; the device identifier DevicelD is assigned by the device manufacturer or operator, and a UserlD Multiple DevicelDs can be associated; the locator Locator is usually an IP address, assigned by the operator or specified by the user, and one DevicelD can be associated with multiple Locators.
  • the locator Locator is usually an IP address, assigned by the operator or specified by the user, and one DevicelD can be associated with multiple Locators.
  • Embodiments of the present invention provide a method, device, and system for user privacy protection. By hiding a user's real ID by using a random user ID, the problem of user privacy exposure is solved, and the security feeling of the user network experience is improved.
  • a method for user privacy protection includes: a user equipment UE sends a registration request message to a location server through a router, so that the location server receives Generating a random value to the UE, and transmitting the random value to the UE, where the registration request message includes a user identifier of the UE, so that the location server according to the random value a common key, a user identifier of the UE, and an identifier of the location server to generate a temporary user identifier, and save the temporary user identifier, the user identifier of the UE, the UE identifier, and the identifier of the location server a relationship, such that the location server identifies, according to the corresponding relationship, a message that includes the temporary user identifier that is sent by the UE, where the common key corresponds to a user identifier of the UE; Receiving the random value sent by the location server;
  • the UE ⁇ generating the temporary user identifier according to the shared key, the user identifier of the UE, the random value, and the identifier of the location server acquired in advance, the common key and the The user ID of the UE corresponds.
  • the first possible implementation manner includes: receiving, by the router, the random value that is sent by the location server by using the router, where the UE sends the location server to send by using the router
  • the authentication request message includes the random value in the authentication request message.
  • the second possible implementation manner includes: receiving, by the router, the random value sent by the location server by using the router, where the UE sends the location server to send by using the router Registration response message, the registration response message includes the random value.
  • a second aspect a method for user privacy protection, comprising: receiving, by a router, a registration request sent by a user equipment UE by using a router
  • the registration request message includes a user identifier of the UE, where the location server generates a random value when the location server receives the registration request message sent by the UE;
  • the router Sending, by the router, the random value to the UE by using the router, so that the UE ⁇ : according to the shared key, the user identifier of the UE, the random value, and a pre-acquired location
  • the identifier of the location server generates a temporary user identifier
  • the location server acquires a common key according to the user identifier of the UE, and generates the temporary user identifier according to the shared key, the user identifier of the UE, the random value, and the identifier of the location server;
  • the location server stores the correspondence between the temporary user identifier, the user identifier of the UE, the identifier of the UE, and the identifier of the location server, and identifies, by using the corresponding relationship, the temporary user that is sent by the UE. Identified message.
  • the location server, by using the router, to send the random value to the UE by using the router includes:
  • the location server sends an authentication request message to the UE by using the router, where the authentication request message includes a random value, so that the UE, according to the shared key, the user identifier of the UE, the random value And pre-acquiring the identifier of the location server to generate a temporary user identifier, where the common key corresponds to the user identifier of the UE.
  • the location server, by using the router, to send the random value to the UE by using the router includes:
  • the location server forwards the registration response message to the UE by using the router, where the registration response message includes a random value, so that the UE, according to the shared key, the user identifier of the UE, the random value And pre-acquiring the identifier of the location server to generate a temporary user identifier, where the common key corresponds to the user identifier of the UE.
  • a third aspect a method for user privacy protection, comprising: sending, by a user equipment, a registration request message to a location server by using a router, where The registration request message includes a user identifier of the UE, so that the location server generates a random value when receiving the registration request message of the UE, and according to the random value, the user identifier of the UE, and the The identifier of the location server generates a temporary user identifier, and saves the correspondence between the temporary user identifier, the user identifier of the UE, the UE identifier, and the identifier of the location server, so that the location server identifies according to the correspondence relationship a message sent by the UE that includes the temporary user identifier;
  • the first possible implementation manner includes: receiving, by the UE, the temporary user identifier by using the router, where the UE receives, by using the router, a registration response message sent by the location server, where The temporary user identifier is included in the registration response message.
  • a method for user privacy protection comprising: receiving, by a router, a registration request message sent by a user equipment UE by using a router, where the registration request message includes a user identifier of the UE, where, when the location server receives When the user equipment UE sends a registration request message, the location server generates a random value;
  • the location server generates a temporary user identifier according to the random value, the user identifier of the UE, and the identifier of the location server; the location server saves the temporary user identifier, the user identifier of the UE, the UE identifier, and Corresponding relationship between the identifiers of the location servers, so that the location server identifies, according to the corresponding relationship, a message that is sent by the UE and includes the temporary user identifier; the location server uses the temporary user by using the router The identity is forwarded to the UE.
  • the location server includes: generating, by the location server, the temporary user identifier according to the random value, the user identifier of the UE, and the identifier of the location server, where The server is based on the random value, the shared key, and the user of the UE The identifier and the identifier of the location server generate a temporary user identity, the common key corresponding to the user identity of the UE.
  • the location server forwarding, by the router, the temporary user identifier to the UE by using the router includes:
  • a user equipment comprising: a communication unit, configured to send, by using a router, a registration request message to a location server, so that the location server generates a random value when receiving the registration request message of the UE, and Transmitting a random value to the UE, where the registration request message includes a user identifier of the UE, so that the location server is configured according to the random value, a common key, a user identifier of the UE, and the location server.
  • the communication unit is further configured to receive, by using the router, the random value sent by the location server a generating unit, configured to: according to the shared key, the user identifier of the UE, Identifier value and said previously acquired location server generating the temporary user identifier, the common key corresponding to the user ID of the UE.
  • the communication unit is specifically configured to:
  • the communication unit is specifically configured to:
  • a location server comprising: a communication unit, configured to receive, by using a router, a registration request message sent by a user equipment UE, where the registration request message includes a user identifier of the UE, where, when the location server receives When the registration request message is sent by the UE, the location server generates a random value;
  • the communication unit is further configured to send the random value to the UE by using the router, so that the UE ⁇ : according to the shared key, the user identifier of the UE, the random value, and Pre-acquiring the identifier of the location server to generate a temporary user identifier;
  • a generating unit configured to acquire a common key according to the user identifier of the UE, and generate the temporary user identifier according to the shared key, the user identifier of the UE, the random value, and an identifier of the location server
  • a storage unit configured to save a correspondence between the temporary user identifier generated by the generating unit, a user identifier of the UE, the UE identifier, and an identifier of the location server, and identify the A message sent by the UE that includes the temporary user identity.
  • the communication unit is specifically configured to:
  • the communications unit is specifically configured to:
  • the router Transmitting, by the router, a registration response message to the UE, where the registration response message includes a random value, so that the UE according to the shared key, the user identifier of the UE, the random value, and the pre-acquired
  • the identifier of the location server generates a temporary user identifier, and the common key corresponds to a user identifier of the UE.
  • a user equipment comprising: a sending unit, configured to send, by using a router, a registration request message to a location server, where the registration request message includes a user identifier of the UE, so that the location server receives the location Generating a random value when the registration request message of the UE is generated, and generating a temporary user identifier according to the random value, the user identifier of the UE, and the identifier of the location server, and saving the temporary user identifier, the user of the UE Corresponding relationship between the identifier, the UE identifier, and the identifier of the location server, so that the location server identifies, according to the corresponding relationship, a message that is sent by the UE and includes the temporary user identifier;
  • the receiving unit configured to receive the temporary user identifier by using the router.
  • the receiving unit is specifically configured to:
  • a location server comprising: a communication unit, configured to receive, by using a router, a registration request message sent by a user equipment UE, where the registration request message includes a user identifier of the UE, where, when the location server receives The location server generates a random value when the user equipment UE sends a registration request message, and the generating unit is configured to generate a temporary user identifier according to the random value, the user identifier of the UE, and the identifier of the location server; a storage unit, configured to save a correspondence between the temporary user identifier generated by the generating unit, a user identifier of the UE, a UE identifier, and an identifier of the location server, so that the location server identifies according to the correspondence relationship a message that is sent by the UE and includes the temporary user identifier; the communication unit is further configured to
  • the generating unit is specifically configured to: Generating a temporary user identifier according to the random value, the shared key, the user identifier of the UE, and the identifier of the location server, where the common key corresponds to the user identifier of the UE.
  • the communications unit is specifically configured to:
  • a ninth aspect a communication system, comprising: a location server, a router, and a user equipment UE connected to the router, where the location server is in any one of the sixth aspect or the sixth aspect
  • the user equipment UE is the user equipment described in any one of the possible implementation manners of the fifth aspect or the fifth aspect; or
  • the location server is the location server according to any one of the possible implementations of the eighth aspect or the eighth aspect, wherein the user equipment UE is the seventh aspect or any one of the possible implementation manners of the seventh aspect User equipment.
  • the method, device, and system for user privacy protection provided by the embodiment of the present invention, the user equipment UE sends the user identifier of the user equipment to the location server by using the registration request message, and obtains the shared key according to the user identifier of the UE, and the user equipment The user identifier, the identifier of the pre-obtained location server, and the shared key generate the temporary user identifier.
  • FIG. 1 is a schematic diagram of a network topology structure of a UIP (User Identity Protocol) according to an embodiment of the present invention
  • FIG. 2 is a schematic flowchart of a method for user privacy protection according to an embodiment of the present invention
  • FIG. 3 is a schematic flowchart of another method for user privacy protection according to an embodiment of the present invention.
  • FIG. 4 is a schematic flowchart of a method for user privacy protection according to another embodiment of the present invention
  • FIG. 5 is a schematic flowchart of another method for user privacy protection according to another embodiment of the present invention
  • FIG. 7 is a schematic flowchart of another method for user privacy protection according to another embodiment of the present invention
  • FIG. 8 is a schematic diagram of another embodiment of the present invention.
  • FIG. 9 is a schematic structural diagram of a user equipment according to an embodiment of the present invention
  • FIG. 10 is a schematic structural diagram of a location server according to an embodiment of the present invention
  • FIG. 12 is a schematic structural diagram of a location server according to another embodiment of the present invention
  • FIG. 9 is a schematic structural diagram of a user equipment according to an embodiment of the present invention
  • FIG. 10 is a schematic structural diagram of a location server according to an embodiment of the present invention
  • FIG. 12 is a schematic structural diagram of a location server according to another embodiment
  • FIG. 13 is a schematic structural diagram of a location server according to another embodiment of the present invention
  • FIG. 14 is a schematic structural diagram of a location server according to another embodiment of the present invention
  • a structural diagram of a user equipment is further provided in the embodiment
  • FIG. 16 is a schematic diagram of the structure of a location server provided by another embodiment of the invention
  • FIG. 17 is a schematic structural diagram of a communication system according to an embodiment of the present invention.
  • the present invention is applicable to a User Identity Protocol (UIP) network architecture.
  • UIP User Identity Protocol
  • the UIP network is composed of one or more UIP domains, and one UIP domain is composed of a location server SLS (Subscriber Location Server), one or Multiple domain routers DR (Domain Router), one or more gateway GWs (GateWay).
  • SLS Subscriber Location Server
  • DR Domain Router
  • GateWay Gateway GWs
  • the DR is used to store the mapping relationship between the user identifier User1D and the locator Locator of the user, user data forwarding, and packet address conversion.
  • the intra-domain and inter-domain DRs are connected to each other.
  • SLS is used to save the mapping between the user ID UserlD and the current DR of the user.
  • the UE accesses the UIP domain through the radio access network.
  • the present invention provides a method for user privacy protection. Referring to FIG. 2, on the user equipment side, the specific steps are as follows:
  • the user equipment UE sends a registration request message to the location server by using a router, so that the location server generates a random value when receiving the registration request message of the UE, and sends the random value to the UE.
  • the registration request message includes the user identifier of the UE, so that the location server generates a temporary user identifier according to the random value, the common key, the user identifier of the UE, and the identifier of the location server, and And storing a correspondence between the temporary user identifier, the user identifier of the UE, the UE identifier, and the identifier of the location server, so that the location server identifies, according to the correspondence, that the temporary user that is sent by the UE is included
  • the method for obtaining the shared key may be an authentication and key agreement AKA (Authentication and Key Agreement) or other key negotiation method.
  • the user equipment UE User Equipment
  • the domain router DR Domain Router
  • the basic information of the UE itself such as the user identifier User1D, the device identifier Device ID, and the locator Locator.
  • SLS Subscriber Location Server
  • the registration request message further includes: a device identifier and/or a locator of the UE.
  • the UE receives, by using a router, a random value sent by the location server.
  • the UE generates a temporary user identifier according to the shared key, the user identifier of the UE, the random value, and the identifier of the pre-acquired location server.
  • the common key corresponds to a user identifier of the UE.
  • the UE may obtain the random value nonce generated by the SL S according to the authentication request message received before the shared key SKey is negotiated with the SLS, and generate the SLS ID of the SLS, the SKey and the UserlD of the UE according to the nonce, the pre-acquired SLS.
  • Temporary User ID TempUser ID or,
  • the received registration response message obtains a random value of nonce, and generates a temporary user identifier TempUser ID according to the nonce, the SLS SLS ID, the SKey, and the UE's own UserlD; or
  • the UE generates the TempUser ID according to the nonce sent by the SLS.
  • the UE receives the temporary user identifier TempUser ID that has been generated by the SLS by receiving the registration response message sent by the SLS.
  • the present invention provides a method for user privacy protection. Referring to FIG. 3, on the location server side, the specific steps are as follows:
  • the location server receives, by using a router, a registration request message sent by the user equipment UE.
  • the registration request message includes a user identifier of the UE, where the location server generates a random value when the location server receives the registration request message sent by the UE.
  • the registration request message further includes a user equipment identifier Device ID and a Locator of the UE or the Locator of the UE.
  • the location server sends a random value to the UE by using a router, so that the location
  • the UE generates a temporary user identifier according to the shared key, the user identifier of the UE, the random value, and the identifier of the pre-acquired location server.
  • the location server generates a temporary user identifier according to the shared key, the user identifier of the UE, the random value, and the identifier of the location server.
  • the method for obtaining the shared key may be an authentication and key agreement AKA (Authentication and Key Agreement) or another key negotiation method.
  • the subscriber location server SLS Subscriber Location Server
  • the SLS After the shared key SKey is obtained by the UE, the SLS generates a random value nonce, and the SLS generates a temporary user identifier TempUser ID according to the nonce, the SLS SLS ID, the SKey and the UE's own UserlD before sending the registration response message carrying the nonce; Or,
  • the SLS After receiving the authentication response message sent by the UE, the SLS generates a nonce, and generates a TempUser ID according to the nonce, and sends the generated TempUser ID to the UE by sending a registration response message.
  • the location server saves a correspondence between the temporary user identifier, the user identifier of the UE, the UE identifier, and the identifier of the location server, and identifies, by using the correspondence, the message that is sent by the UE and includes the temporary user identifier.
  • the SLS stores a mapping relationship between the temporary user identifier TempUser ID and the user identifier User ID, the device identifier Device ID, and the locator Locator of the UE.
  • the user equipment UE sends the user identifier of the user equipment to the location server by using the registration request message, and obtains the shared key, the user identifier of the user equipment according to the user identifier of the UE, The identifier of the location server obtained in advance and the shared key generate a temporary user identifier, by utilizing The random user ID hides the user's real ID, solves the problem of user privacy exposure, and improves the security of the user's network experience.
  • the present invention provides another method for user privacy protection. Referring to FIG. 4, on the user equipment side, the specific steps are as follows:
  • the user equipment UE sends a registration request message to the location server through the router.
  • the registration request message includes the user identifier of the UE, so that the location server generates a random value when receiving the registration request message of the UE, and according to the random value, the user identifier of the UE, and the location
  • the identifier of the location server generates a temporary user identifier, and saves the correspondence between the temporary user identifier, the user identifier of the UE, the UE identifier, and the identifier of the location server, so that the location server according to the correspondence relationship
  • a message containing the temporary user identity sent by the UE is identified.
  • the UE receives the temporary user identifier by using a router.
  • the UE receives the registration response message sent by the location server by using the router, where the registration response message includes the temporary user identifier.
  • the present invention provides another method for user privacy protection. Referring to FIG. 5, on the location server side, the specific steps are as follows:
  • the location server receives, by using a router, a registration request message sent by the user equipment UE.
  • the registration request message includes the user identifier of the UE, where the location server generates a random value when the location server receives the registration request message sent by the user equipment UE.
  • the location server generates a temporary user identifier according to the random value, the user identifier of the UE, and the identifier of the location server.
  • the location server saves the correspondence between the temporary user identifier, the user identifier of the UE, the UE identifier, and the identifier of the location server, so that the location server identifies, according to the correspondence, a message that is sent by the UE and includes the temporary user identifier.
  • the SLS saves the temporary user ID TempUser ID. A mapping relationship with the user ID of the UE, the device identifier Device ID, and the locator Locator.
  • the location server forwards the temporary user identifier to the UE by using a router.
  • the location server forwards the registration response message to the UE by using the router, where the registration response message includes the temporary user identifier.
  • the user privacy protection method provided by the embodiment of the present invention, the location server generates a temporary user identifier according to the randomly generated random value, and sends the temporary user identifier to the user equipment UE via the router through the registration response message, thereby hiding the user by using the random user ID.
  • the real ID solves the problem of user privacy exposure and improves the security of the user's network experience.
  • the router in the embodiment of the present invention uses the domain router DR and the location server as the user location server SLS as an example.
  • the method for implementing the user privacy protection provided by the embodiment of the present invention is not specifically limited. Specifically, the following description will be made in conjunction with specific embodiments.
  • the first embodiment can be based on the embodiment shown in FIG. 2 or FIG. 3, and the embodiment of the present invention provides a method for user privacy protection.
  • the user location server is provided.
  • the SLS and the user equipment UE generate a shared key SKey through negotiation, and generate a temporary user identifier TempUser1D according to the SKey, the SLS, or the ID of the UE.
  • the specific steps are as follows:
  • the user equipment UE sends a registration request message to the location server by using a router, so that the location server generates a random value when receiving the registration request message of the UE, and sends the random value to the UE.
  • the registration request message includes the user identifier of the UE, so that the location server generates a temporary user identifier according to the random value, the common key, the user identifier of the UE, and the identifier of the location server, and And storing a correspondence between the temporary user identifier, the user identifier of the UE, the UE identifier, and the identifier of the location server, so that the location server identifies, according to the correspondence, that the temporary user that is sent by the UE is included
  • the identified message, the common key and the The user ID of the UE corresponds.
  • the method for obtaining the shared key here may be an authentication and key agreement AKA (Authentication and Key Agreement) or other key negotiation method.
  • the registration request message further includes: a device identifier
  • the user equipment UE can forward the registration request message through the domain router DR (Domain Router), and send the basic information of the UE itself, such as the user identifier UserID, the device identifier Device ID, and the locator Locator to the user location server SLS. (Subscriber Location Server), so that the SL S acquires basic information (ie, basic parameters) of the UE according to the registration request message of the UE.
  • the domain router DR Domain Router
  • the basic information of the UE itself such as the user identifier UserID, the device identifier Device ID, and the locator Locator to the user location server SLS. (Subscriber Location Server), so that the SL S acquires basic information (ie, basic parameters) of the UE according to the registration request message of the UE.
  • the location server receives, by using a router, a registration request message sent by the user equipment UE.
  • the registration request message includes a user identifier of the UE, where the location server generates a random value when the location server receives the registration request message sent by the UE.
  • the registration request message further includes a user equipment identifier Device ID and a Locator of the UE or the Locator of the UE.
  • the domain router DR is used to perform the function of forwarding signaling packets between the UE and the SLS.
  • the location server sends a random value to the UE by using a router, so that the UE generates a temporary user identifier according to the shared key, the user identifier of the UE, the random value, and the identifier of the pre-acquired location server.
  • the random value can be represented by nonce.
  • the method for implementing user privacy protection provided by the embodiment of the present invention is preferred, and is not specifically limited.
  • the location server carries a random value in the authentication request message and sends it to the UE through the router.
  • the UE receives a random value sent by the location server by using a router.
  • the UE receives the authentication request message sent by the location server by using the router, where the authentication request message includes the random value. 505.
  • the UE sends an authentication response message to the location server by using the router according to the authentication request message.
  • the location server receives an authentication response message sent by the UE through the router.
  • the location server generates a temporary user identifier according to the shared key, the user identifier of the UE, the random value, and the identifier of the location server.
  • the method for obtaining the shared key may be an authentication and key agreement AKA (Authentication and Key Agreement) or another key negotiation method.
  • AKA Authentication and Key Agreement
  • the temporary user ID is exemplified by the temporary user ID TempUser ID: where the TempUser ID is generated as:
  • TempUser ID KDF(SKey, UserID, SLS ID, nonce) is the temporary user ID.
  • the TempUser ID is generated by the SLS based on the SKey obtained by the negotiation, the UserlD of the UE, the SLS ID, and the nonce generated by the SLS.
  • SKey is a shared key of the SLS and the UE
  • the SLS ID is the SLS ID, such as the UUID (Universally Unique Identifier) identifier.
  • the nonce is the random value generated by the SLS.
  • the UE generates a temporary user identifier according to the shared key, the user identifier of the UE, a random value, and an identifier of the pre-acquired location server.
  • the common key corresponds to a user identifier of the UE.
  • the UE generates a temporary user identifier TempUser ID according to the random value nonce obtained in the authentication request message, the SKey negotiated with the SLS, the pre-acquired SLS ID, and the UE's own UserlD.
  • the location server saves a correspondence between the temporary user identifier, the user identifier of the UE, the UE identifier, and the identifier of the location server, and identifies, by using the correspondence, the message that is sent by the UE and includes the temporary user identifier.
  • the SLS saves the temporary user ID TempUser ID. A mapping relationship with the user ID of the UE, the device identifier Device ID, and the locator Locator.
  • the location server sends a registration response message to the UE through the router.
  • the UE receives the registration response message sent by the location server through the router.
  • the user privacy protection method provided by the embodiment of the present invention, the user equipment UE sends the user identifier of the user equipment to the location server by using the registration request message, and obtains the shared key, the user identifier of the user equipment according to the user identifier of the UE, The identifier of the location server obtained in advance and the temporary user ID generated by the shared key are used to hide the user's real ID by using the random user ID, thereby solving the problem of user privacy exposure and improving the security of the user's network experience.
  • the second embodiment can be based on the embodiment shown in FIG. 2 or FIG. 3. Referring to FIG. 7, the embodiment of the present invention provides a method for user privacy protection.
  • the user location server is provided.
  • the SLS and the user equipment UE negotiate to generate a shared key SKey, where the SLS generates a random value nonce after the UE and the SLS negotiate to generate an SKey, and the SLS generates a temporary user identifier TempUser1D according to the SKey, the SLS and the ID of the UE, and then forwards the registration response via the DR.
  • the message sends the nonce to the UE, so that the UE generates the TempUser1D according to the nonce.
  • the user equipment UE sends a registration request message to the location server through the router, so that the location server generates a random value when receiving the registration request message of the UE, and sends the random value to the UE.
  • the registration request message includes the user identifier of the UE, so that the location server generates a temporary user identifier according to the random value, the common key, the user identifier of the UE, and the identifier of the location server, and And storing a correspondence between the temporary user identifier, the user identifier of the UE, the UE identifier, and the identifier of the location server, so that the location server identifies, according to the correspondence, that the temporary user that is sent by the UE is included
  • the registration request message further includes: a device identifier and/or a location of the UE
  • the user equipment UE User Equipment
  • the location server receives, by using a router, a registration request message sent by the user equipment UE.
  • the registration request message includes a user identifier of the UE, where the location server generates a random value when the location server receives the registration request message sent by the UE.
  • the registration request message further includes a user equipment identifier Device ID and a Locator of the UE or the Locator of the UE.
  • the domain router DR is used to perform the function of forwarding signaling packets between the UE and the SLS.
  • the location server sends a random value to the UE by using a router, so that the UE generates a temporary user identifier according to the shared key, the user identifier of the UE, the random value, and the identifier of the pre-acquired location server.
  • the random value can be represented by nonce.
  • the location server carries a random value in the authentication request message and sends it to the UE through the router.
  • the location server sends an authentication request message to the UE through the router.
  • the authentication request message sent by the SLS to the UE through the DR is not limited to whether the random value nonce is a random value nonce required to generate the TempUser ID.
  • the difference from the first embodiment is that the random value nonce used to generate the TempUser ID in the embodiment of the present invention may be a new nonce regenerated by the SL S, that is, the authentication request message sent to the UE in this step may not be reused. Nonce.
  • the UE receives a random value sent by the location server by using a router.
  • the UE receives the authentication request message sent by the location server by using the router, where the authentication request message includes the random value.
  • the UE sends an authentication response message to the location server by using the router according to the authentication request message.
  • the location server receives an authentication response message sent by the UE through the router.
  • the location server generates a temporary user identifier according to the shared key, the user identifier of the UE, the random value, and the identifier of the location server.
  • the method for obtaining the shared key may be an authentication and key agreement AKA (Authentication and Key Agreement) or another key negotiation method.
  • AKA Authentication and Key Agreement
  • the temporary user ID is exemplified by the temporary user ID TempUser ID: where the TempUser ID is generated as:
  • TempUser ID KDF(SKey, UserID, SLS ID, nonce) is the temporary user ID.
  • the TempUser ID is generated by the SLS based on the SKey obtained by the negotiation, the UserlD of the UE, the SLS ID, and the nonce generated by the SLS.
  • SKey is a shared key of the SLS and the UE
  • the SLS ID is the SLS ID, such as the UUID (Universally Unique Identifier) identifier.
  • the nonce is the random value generated by the SLS.
  • the location server sends a random value to the UE through the router.
  • the registration response message further includes: a random value nonce generated by the SLS, so that the UE generates the TempUser ID according to the random value nonce.
  • the location server forwards the registration response message to the UE by using the router, where the registration response message includes a random value, so that the UE according to the shared key, the user identifier of the UE, the random value, and the advance
  • the obtained identifier of the location server generates a temporary user identifier, and the UE acquires the shared key according to the user identifier of the UE.
  • the location server saves a correspondence between the temporary user identifier, the user identifier of the UE, the UE identifier, and the identifier of the location server, and identifies, by the correspondence, the message that is sent by the UE and includes the temporary user identifier.
  • the SLS stores the mapping relationship between the temporary user identifier TempUser ID and the UE's user identifier User ID, device identifier Device ID, and locator Locator.
  • the UE receives a random value sent by the location server by using a router.
  • the UE receives the registration response message sent by the location server by using the router, where the registration response message includes the random value.
  • the UE generates a temporary user identifier according to the shared key, the user identifier of the UE, the random value, and the identifier of the pre-acquired location server.
  • the UE acquires the shared key according to the user identifier of the UE, where the UE obtains the random value nonin obtained from the authentication request message, the SKey negotiated with the SLS, the pre-acquired SLS ID, and the UE's own UserlD generation temporary.
  • User ID TempUser ID User ID TempUser ID.
  • the user equipment UE sends the user identifier of the user equipment to the location server through the registration request message, and obtains the shared key by negotiating with the location server, and then according to the user identifier of the user equipment,
  • the obtained location server identifier and the shared key generate a temporary user identifier, and the user's real ID is hidden by using the random user ID, thereby solving the problem of user privacy exposure and improving the security feeling of the user network experience.
  • the difference between the embodiment of the present invention and the first embodiment is that the random value nonce generated by the SLS for generating the TempUser ID is after the shared key SKey is negotiated with the UE, and the random value nonce of the TempUser ID is generated after the TempUser ID is generated.
  • the message is sent to the UE through the DR.
  • the random value nonce used to generate the TempUser ID is different from the nonce carried when the authentication request message is sent.
  • the third embodiment can be based on the embodiment shown in FIG. 4 or FIG. 5.
  • the embodiment of the present invention provides a method for user privacy protection.
  • the user location server is provided.
  • the SLS and the user equipment UE negotiate to generate a shared key SKey.
  • the SLS generates a temporary user identifier TempUser1D according to the SKey, the SLS and the ID of the UE, and then forwards the TempUser1D to the UE via the DR.
  • the specific steps are as follows: 701.
  • the user equipment UE sends a registration request message to the location server by using a router.
  • the registration request message includes the user identifier of the UE, so that the location server generates a random value when receiving the registration request message of the UE, and according to the random value, the user identifier of the UE, and the location
  • the identifier of the location server generates a temporary user identifier, and saves the correspondence between the temporary user identifier, the user identifier of the UE, the UE identifier, and the identifier of the location server, so that the location server according to the correspondence relationship
  • a message containing the temporary user identity sent by the UE is identified.
  • the registration request message further includes: a device identifier and/or a locator of the UE.
  • the user equipment UE can forward the registration request message through the domain router DR (Domain Router), and send the basic information of the UE itself, such as the user identifier UserID, the device identifier Device ID, and the locator Locator to the user location server SLS. (Subscriber Location Server), so that the SLS obtains basic information (ie, basic parameters) of the UE according to the registration request message of the UE.
  • the domain router DR Domain Router
  • SLS Subscriber Location Server
  • the location server receives, by using a router, a registration request message sent by the user equipment UE.
  • the registration request message includes the user identifier of the UE, where the location server generates a random value when the location server receives the registration request message sent by the user equipment UE; where the domain router DR is used for forwarding
  • the location server sends an authentication request message to the UE by using a router.
  • the UE receives an authentication request message sent by the location server by using a router.
  • the UE sends an authentication response message to the location server by using the router according to the authentication request message.
  • the location server receives an authentication response message sent by the UE through the router.
  • the location server generates a temporary user identifier according to the random value, the user identifier of the UE, and the identifier of the location server.
  • the relevant parameter includes at least the random value, the user identifier of the UE, and the identifier of the location server.
  • the related parameter further includes a common key, and the location server is configured according to the random value and the shared secret.
  • the key, the user identification of the UE, and the identifier of the location server generate a temporary user identification.
  • the location server acquires a common key according to the user identifier of the UE.
  • the SLS may generate the temporary user identifier TempUser ID according to the SKey, the basic information of the UE, the random value nonce, and the identifier SLS ID of the SLS, as described in the first embodiment and the second embodiment.
  • the SLS may also generate a TempUser ID according to the random value nonce.
  • the location server saves a correspondence between the temporary user identifier, the user identifier of the UE, the UE identifier, and the identifier of the location server, so that the location server identifies, according to the correspondence, the message that is sent by the UE and includes the temporary user identifier.
  • the SLS stores the mapping relationship between the temporary user identifier TempUser ID and the UE's user identifier User ID, device identifier Device ID, and locator Locator.
  • the location server forwards the temporary user identifier to the UE through the router.
  • the location server forwards the registration response message to the UE by using the router, where the registration response message includes the temporary user identifier.
  • the UE receives the temporary user identifier by using a router.
  • the UE receives the registration response message sent by the location server by using the router, where the registration response message includes the temporary user identifier.
  • the user privacy protection method provided by the embodiment of the present invention, the location server generates a temporary user identifier according to the randomly generated random value, and sends the temporary user identifier to the user equipment UE via the router through the registration response message, thereby hiding the user by using the random user ID.
  • the real ID solves the problem of user privacy exposure and improves the security of the user's network experience.
  • the present invention provides a user equipment UE 8 , which can be implemented by the user equipment UE 8 Any user privacy protection method provided by the embodiment of the present invention, as shown in FIG.
  • a communication unit 81 configured to send a registration request message to a location server through a router, so that the location server receives And generating, by the UE, a random value, and sending the random value to the UE, where the registration request message includes a user identifier of the UE, so that the location server is configured according to the random value.
  • the location server identifies, according to the correspondence, a message that includes the temporary user identifier that is sent by the UE, where the common key corresponds to a user identifier of the UE; and the communication unit 81 is further configured to: Receiving, by the router, the random value sent by the location server; generating unit 82, configured to use, according to the shared key A user identifier of the UE, an identifier of the random values and the pre-acquired location server generating the temporary user identifier, the user identifier corresponding to the common key with the UE.
  • the user equipment UE sends the user identifier of the user equipment to the location server by using the registration request message, and obtains the shared key according to the user identifier of the UE, the user identifier of the user equipment, and the pre-acquired
  • the location server identifier and the shared key generate a temporary user identifier.
  • the communication unit 81 is further configured to: receive, by using the router, an authentication request message sent by the location server, where the authentication request message includes the random value.
  • the communication unit 81 is further configured to: receive, by using the router, a registration response message sent by the location server, where the registration response message includes the random value.
  • the user equipment provided by the embodiment of the present invention, the user equipment UE sends the user identifier of the user equipment to the location server by using a registration request message, and according to the user of the UE Identifying the shared key, the user identifier of the user equipment, the identifier of the location server obtained in advance, and the shared key generating the temporary user identifier, by using the random user
  • the ID hides the user's real ID, solves the problem of user privacy exposure, and improves the security of the user's network experience.
  • the present invention provides a location server SLS 9 , which is based on a method for implementing any user privacy protection provided by an embodiment of the present invention. Referring to FIG. 10 , the present invention includes: Receiving, by the router, a registration request message sent by the user equipment UE, where the registration request message includes a user identifier of the UE, where the location server generates a random when the location server receives the registration request message sent by the UE Value
  • the communication unit 91 is further configured to send, by using the router, the random value to the UE, so that the UE ⁇ : according to the shared key, the user identifier of the UE, the random value, and a pre- Obtaining the identifier of the location server to generate a temporary user identifier;
  • the generating unit 92 is configured to acquire a common key according to the user identifier of the UE, and generate the temporary user according to the shared key, the user identifier of the UE, the random value, and an identifier of the location server.
  • a storage unit 93 configured to store a correspondence between the temporary user identifier, the user identifier of the UE, the UE identifier, and the identifier of the location server generated by the generating unit, and identify by using the corresponding relationship The message sent by the UE that includes the temporary user identifier.
  • the user equipment UE sends the user identifier of the user equipment to the location server by using the registration request message, and obtains the shared key according to the user identifier of the UE, the user identifier of the user equipment, and the pre-acquired
  • the location server identifier and the shared key generate a temporary user identifier.
  • the communication unit 91 is further configured to: send, by using the router, an authentication request message to the UE, where the authentication request message includes a random value, so that The UE ⁇ : generates a temporary user identifier according to the shared key, the user identifier of the UE, the random value, and the identifier of the location server acquired in advance, the common key and the UE User ID corresponds.
  • the communication unit 91 is further configured to: forward, by using the router, a registration response message to the UE, where the registration response message includes a random value, so that the UE ⁇ : according to the shared key
  • the user identifier of the UE, the random value, and the identifier of the location server acquired in advance generate a temporary user identifier, where the common key corresponds to the user identifier of the UE.
  • the user equipment UE sends the user identifier of the user equipment to the location server by using the registration request message, and obtains the shared key according to the user identifier of the UE, the user identifier of the user equipment, and the pre-acquired
  • the location server identifier and the shared key generate a temporary user identifier.
  • the sending unit 1001 is configured to send, by using a router, a registration request message to the location server, where the registration request message includes a user identifier of the UE, so that the location server generates a random value when receiving the registration request message of the UE. Generating a temporary user identifier according to the random value, the user identifier of the UE, and the identifier of the location server, and saving the temporary user identifier, the user identifier of the UE, the UE identifier, and the location server. Corresponding relationship of the identifier, so that the location server identifies, according to the corresponding relationship, a message that is sent by the UE and includes the temporary user identifier;
  • the receiving unit 1002 is configured to receive the temporary user identifier by using the router.
  • the user equipment UE sends the user identifier of the user equipment to the location server by using the registration request message, and obtains the shared key according to the user identifier of the UE, the user identifier of the user equipment, and the pre-acquired
  • the location server's identity and the shared key generate a temporary user identity by utilizing random users
  • the ID hides the user's real ID, solves the problem of user privacy exposure, and improves the security of the user's network experience.
  • the receiving unit 1002 is further configured to: receive, by using the router, a registration response message sent by the location server, where the registration response message includes the temporary user identifier.
  • the location server generates a temporary user identifier according to the randomly generated random value, and sends the temporary user identifier to the user equipment UE through the router through the registration response message, and then hides the user real ID by using the random user ID. It solves the problem of user privacy exposure and improves the security of the user's network experience.
  • the present invention provides a location server SLS 1 1 , which is based on a method for implementing any user privacy protection provided by an embodiment of the present invention.
  • the present invention includes: And receiving, by the router, a registration request message sent by the user equipment UE, where the registration request message includes a user identifier of the UE, where, when the location server receives the registration request message sent by the user equipment UE, The location server generates a random value; the generating unit 1102 is configured to generate a temporary user identifier according to the random value, the user identifier of the UE, and an identifier of the location server; and the storage unit 1103 is configured to save the generation Corresponding relationship between the temporary user identifier generated by the unit, the user identifier of the UE, the UE identifier, and the identifier of the location server, so that the location server identifies, according to the correspondence, that the sending of the UE includes the a message of the temporary user identifier; the communication unit 1 101
  • the user equipment UE sends the user identifier of the user equipment to the location server by using the registration request message, and obtains the shared key according to the user identifier of the UE, the user identifier of the user equipment, and the pre-acquired Location
  • the server's identity and shared key generate temporary user IDs by utilizing random users
  • the ID hides the user's real ID, solves the problem of user privacy exposure, and improves the security of the user's network experience.
  • the generating unit 1102 is further configured to: generate a temporary user identifier according to the random value, the shared key, the user identifier of the UE, and the identifier of the location server, where the common key and the The user ID of the UE corresponds.
  • the communication unit 1101 is further configured to: forward, by using the router, a registration response message to the UE, where the registration response message includes the temporary user identifier.
  • the location server generates a temporary user identifier according to the randomly generated random value, and sends the temporary user identifier to the user equipment UE via the router through the registration response message, thereby hiding the user real ID by using the random user ID. It solves the problem of user privacy exposure and improves the security of the user's network experience.
  • the user equipment UE 12 includes: at least one processor 1201, a memory 1202, a communication port 1203, and a bus 1204.
  • the at least one processor 1201 and the memory 1202 and communication interface 1203 are connected by bus 1204 and complete communication with each other.
  • the bus 1204 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component (PCI) bus, or an Extended Industry Standard Architecture (EISA). Bus, etc.
  • ISA Industry Standard Architecture
  • PCI Peripheral Component
  • EISA Extended Industry Standard Architecture
  • the bus 1304 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in Figure 13, but it does not mean that there is only one bus or one type of bus. among them:
  • the memory 1202 is for storing executable program code, the program code including computer operating instructions.
  • the memory 1202 may include a high speed RAM (random access memory), and may also include a non-volatile memory, such as at least one disk storage device.
  • the processor 1201 may be a central processing unit (Central Processing Unit, Referred to as CPU), or an Application Specific Integrated Circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present invention.
  • the communication interface 1203 is mainly used to implement communication between devices in this embodiment.
  • the processor 1201 is configured to send, by using the at least one communication interface 1203, a registration request message to the location server by using a router, so that the location server generates a random value when receiving the registration request message of the UE, and generates the random value.
  • the registration request message includes the user identifier of the UE, so that the location server is configured according to the random value, the common key, the user identifier of the UE, and the identifier of the location server.
  • generating a temporary user identifier and storing a correspondence between the temporary user identifier, the user identifier of the UE, the UE identifier, and the identifier of the location server, so that the location server identifies another one according to the corresponding relationship a message that includes the temporary user identifier that is sent by the UE, where the common key corresponds to the user identifier of the UE;
  • the processor 1201 is further configured to receive the location server by using the router through the at least one communication interface 1203.
  • the random value sent; the processor 1201 is further configured to: according to the shared key, the user identifier of the UE, The random value and the identifier of the location server acquired in advance generate the temporary user identifier, where the common key corresponds to the user identifier of the UE.
  • the user equipment UE sends the user identifier of the user equipment to the location server by using the registration request message, and obtains the shared key according to the user identifier of the UE, the user identifier of the user equipment, and the pre-acquired
  • the location server identifier and the shared key generate a temporary user identifier.
  • the processor 1201 is further configured to: receive, by using the at least one communication interface 1203, an authentication request message sent by the location server by using the router, where the authentication request message includes the random value.
  • the processor 1201 is further configured to: receive, by using the at least one communication interface 1203, the registration response message sent by the location server by using the router, The random response value is included in the registration response message.
  • the user equipment UE sends the user identifier of the user equipment to the location server by using the registration request message, and obtains the shared key according to the user identifier of the UE, the user identifier of the user equipment, and the pre-acquired
  • the location server identifier and the shared key generate a temporary user identifier.
  • An embodiment of the present invention provides a location server SLS 13 .
  • the location server SLS 13 includes: at least one processor 1301, a memory 1302, a communication port 1303, and a bus 1304.
  • the at least one processor 1301 and the memory 1302 and communication interface 1303 are connected by bus 1304 and complete communication with each other.
  • the bus 1304 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component (PCI) bus, or an Extended Industry Standard Architecture (EISA). Bus, etc.
  • ISA Industry Standard Architecture
  • PCI Peripheral Component
  • EISA Extended Industry Standard Architecture
  • the bus 1304 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in Figure 14, but it does not mean that there is only one bus or one type of bus. among them:
  • Memory 1302 is for storing executable program code, the program code including computer operating instructions.
  • Memory 1302 may include high speed RAM memory and may also include non-volatile memory, such as at least one disk memory.
  • the processor 1301 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more configured to implement the embodiments of the present invention. integrated circuit.
  • the communication interface 1303 is mainly used to implement communication between devices in this embodiment.
  • the processor 1301 is configured to receive, by using the at least one communication interface 1303, a registration request message sent by the user equipment UE by using a router, where the registration request message includes a user identifier of the UE, where the location server receives the UE When the registration request message is sent, the location server generates a random value; the processor 1301 is further configured to send the random value to the UE by using the router by using at least one communication interface 1303, so that the UE is configured according to the a shared key, a user identifier of the problems, the random value, and an identifier of the location server acquired in advance to generate a temporary user identifier.
  • the processor 1301 is further configured to acquire a common key according to the user identifier of the UE. And generating, according to the shared key, the user identifier of the UE, the random value, and the identifier of the location server, the temporary user identifier; the storage 1302, configured to save the temporary generated by the generating unit Corresponding relationship between the user identifier, the user identifier of the UE, the identifier of the UE, and the identifier of the location server, and identifying, by the correspondence, the message that is sent by the UE and that includes the temporary user identifier.
  • the user equipment UE sends the user identifier of the user equipment to the location server by using the registration request message, and obtains the shared key according to the user identifier of the UE, the user identifier of the user equipment, and the pre-acquired
  • the location server identifier and the shared key generate a temporary user identifier.
  • the processor 1301 is further configured to: send, by using the at least one communication interface 1303, an authentication request message to the UE by using the router, where the authentication request message includes a random value, so that the UE is configured according to the The shared key, the user identifier of the UE, the random value, and the identifier of the location server acquired in advance generate a temporary user identifier, where the common key corresponds to the user identifier of the UE.
  • the processor 1301 is further configured to: forward, by using the at least one communication interface 1303, a registration response message to the UE by using the router, where the registration response message includes a random value, so that the UE is configured according to the The shared key, the user identifier of the UE, the random value, and the identifier of the location server acquired in advance generate a temporary user identifier, where the common key corresponds to the user identifier of the UE.
  • the user equipment UE sends the user identifier of the user equipment to the location server by using a registration request message, and according to the UE
  • the user identifier acquires the shared key, the user identifier of the user equipment, the identifier of the location server obtained in advance, and the shared key to generate the temporary user identifier, by using the random user
  • the user equipment UE 14 includes: at least one processor 1401 , a memory 1402 , a communication port 1403 , and a bus 1404 .
  • the at least one processor 1401 and the memory 1402 and communication interface 1403 are connected by bus 1404 and complete communication with each other.
  • the bus 1404 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component (PCI) bus, or an Extended Industry Standard Architecture (EISA). Bus, etc.
  • ISA Industry Standard Architecture
  • PCI Peripheral Component
  • EISA Extended Industry Standard Architecture
  • the bus 1404 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in Figure 15, but it does not mean that there is only one bus or one type of bus. among them:
  • the memory 1402 is for storing executable program code, the program code including computer operating instructions.
  • the memory 1402 may include a high speed RAM memory and may also include a non-volatile memory such as at least one disk memory.
  • the processor 1401 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more configured to implement the embodiments of the present invention. integrated circuit.
  • the communication interface 1403 is mainly used to implement communication between devices in this embodiment.
  • the processor 1401 is configured to send, by using the at least one communication interface 1403, a registration request message to the location server by using a router, where the registration request message includes a user identifier of the UE, so that the location server receives the UE.
  • the processor 1401 is further configured to pass the router through the at least one communication interface 1403 Receiving the temporary user identification.
  • the user equipment UE sends the user identifier of the user equipment to the location server by using the registration request message, and obtains the shared key according to the user identifier of the UE, the user identifier of the user equipment, and the pre-acquired
  • the location server identifier and the shared key generate a temporary user identifier.
  • the processor 1401 is further configured to receive, by using the at least one communication interface 1403, the registration response message sent by the location server by using the router, where the registration response message includes the temporary user identifier.
  • the location server In the user equipment provided by the embodiment of the present invention, the location server generates a temporary user identifier according to the randomly generated random value, and sends the temporary user identifier to the user equipment UE through the router through the registration response message, and then hides the user real ID by using the random user ID. It solves the problem of user privacy exposure and improves the security of the user's network experience.
  • An embodiment of the present invention provides a location server SLS 15 . Referring to FIG. 16 , the location server SLS 15 includes: at least one processor 1501 , a memory 1502 , a communication port 1503 , and a bus 1504 . The at least one processor 1501 and the memory 1502 and communication interface 1503 are connected by bus 1504 and complete communication with each other.
  • the bus 1504 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component (PCI) bus, or an Extended Industry Standard Architecture (EISA). Bus, etc.
  • ISA Industry Standard Architecture
  • PCI Peripheral Component
  • EISA Extended Industry Standard Architecture
  • the bus 1504 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in Figure 16, but it does not mean that there is only one bus or one type of bus. among them:
  • the memory 1502 is configured to store executable program code, where the program code includes a calculation Machine operation instructions.
  • Memory 1 502 may include high speed RAM memory and may also include non-volatile memory, such as at least one disk memory.
  • the processor 1501 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more configured to implement the embodiments of the present invention. integrated circuit.
  • CPU central processing unit
  • ASIC application specific integrated circuit
  • the communication interface 1503 is mainly used to implement communication between devices in this embodiment.
  • the processor 1501 is configured to receive, by using the at least one communication interface 1503, a registration request message sent by the user equipment UE by using a router, where the registration request message includes a user identifier of the UE, where the location server receives the The location server generates a random value when the user equipment UE sends the registration request message; the processor 1501 is further configured to generate a temporary user identifier according to the random value, the user identifier of the UE, and the identifier of the location server;
  • the storage 1502 is configured to save a correspondence between the temporary user identifier generated by the generating unit, a user identifier of the UE, a UE identifier, and an identifier of the location server, so that the location server identifies according to the correspondence relationship a message that is sent by the UE that includes the temporary user identifier; the processor 1501 is further configured to forward, by using the at least one communication interface 1 503,
  • the user equipment UE sends the user identifier of the user equipment to the location server by using the registration request message, and obtains the shared key according to the user identifier of the UE, the user identifier of the user equipment, and the pre-acquired
  • the location server identifier and the shared key generate a temporary user identifier.
  • the processor 1501 is further configured to: generate a temporary user identifier according to the random value, a shared key, a user identifier of the UE, and an identifier of the location server, where the common key is The user ID of the UE corresponds.
  • the processor 1501 is further configured to: forward, by using the at least one communication interface 1503, a registration response message to the UE by using the router, where the registration response message includes the temporary user identifier.
  • the location server provided by the embodiment of the present invention, the location server generates a temporary user identifier according to the randomly generated random value, and sends the temporary user identifier to the user equipment UE via the router through the registration response message, thereby hiding the user real ID by using the random user ID. It solves the problem of user privacy exposure and improves the security of the user's network experience.
  • the embodiment of the present invention provides a communication system 16, which is shown in FIG. 17, and includes: a location server SLS 1601, a domain router DR 1602, and a user equipment UE 1603 connected to the DR, where the location server SLS 1601 is as shown in FIG.
  • the location device server SLS; the user equipment UE 1603 is the user equipment UE shown in FIG. 9; or the location server SLS 1601 is the location server SLS shown in FIG. 12; the user equipment UE 1603 is the user shown in FIG. Device UE; or,
  • the location server SLS 1601 is the location server SLS shown in FIG. 14; the user equipment UE 1603 is the user equipment UE shown in FIG. 13; or the location server SLS 1601 is the location server SLS shown in FIG. 16; The UE 1603 is the user equipment UE shown in FIG.
  • the user equipment UE sends the user identifier of the user equipment to the location server by using the registration request message, and obtains the shared key according to the user identifier of the UE, the user identifier of the user equipment, and the pre-acquired
  • the location server identifier and the shared key generate a temporary user identifier, which solves the problem of user privacy exposure by hiding the user's real ID by using the random user ID, and improves the user network. The security of the experience.
  • Computer readable media includes both computer storage media and communication media including any medium that facilitates transfer of a computer program from one location to another.
  • a storage medium may be any available media that can be accessed by a computer.
  • the computer readable medium may comprise RAM, ROM (Read Only Memory) or other optical disk storage, magnetic disk storage media or other magnetic storage device, or can be used for carrying or storing instructions or The desired program code in the form of a data structure and any other medium that can be accessed by a computer.
  • Any connection may suitably be a computer readable medium.
  • a disk and a disc include a compact disc (CD), a laser disc, a compact disc, a digital versatile disc (DVD), a floppy disc, and a Blu-ray disc, wherein the disc is usually magnetically copied, and the disc is The laser is used to optically replicate the data. Combinations of the above should also be included within the scope of the computer readable media.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)

Abstract

本发明的实施例公开一种用户隐私保护的方法、设备和系统,涉及通信网络应用技术,通过利用随机用户ID隐藏用户真实ID,解决了用户隐私暴露的问题,提升了用户网络体验的安全感。该方法包括:用户设备UE通过路由器向位置服务器发送注册请求消息;所述UE通过所述路由器接收所述位置服务器发送的所述随机值;所述UE根据所述共享密钥,所述UE的用户标识,所述随机值以及预先获取的所述位置服务器的标识符生成所述临时用户标识,所述共同密钥与所述UE的用户标识对应。本发明的实施例应用于隐藏用户设备的真实ID。

Description

一种用户隐私保护的方法、 设备和系统 技术领域 本发明涉及通信网络应用技术,尤其涉及一种用户隐私保护的 方法、 设备和系统。
背景技术
随着网络安全越来越被全球所关注, IP(Internet Protocol , 因 特网协议)地址的安全, 以及用户 ID的安全得到了广泛的关注, 其 中, 由于长期以来 IP地址既是标识符 ( 即主机身份标识), 又是定 位符(即网络位置标识;), 这使得传输层与网络层的分离不够彻底。 这使得传统 TCP/IP 网络无法支持主机多宿主场景, 即同一主机的 多个网卡同时接入网络, 切换网卡会导致 IP变化、 业务中断。 在移动网络中, 终端移动时可能引起 IP地址重分配, 尽管在 同一个终端同一个用户使用下, 但传输层的四元组 ( <本地 IP,远端 IP,本地端口,远端端口 > )却发生了变化,这将导致连接中断并重建。 若出现一个用户多台设备的场景,要求的业务流量需要在多台设备 间无缝切换, 而传统的 TCP/IP 网络却无法支持。 在现有解决技术中 , 在用户 身份协议 UIP ( User Identity Protocol ) 的网络架构中, 用户标识符 UserlD由运营商分配, 永久 不变; 设备标识符 DevicelD 由设备制造商或运营商分配, 一个 UserlD可以关联多个 DevicelD ; 定位符 Locator通常为 IP地址, 由运营商分配或用户指定, 一个 DevicelD可以关联多个 Locator。 但是关于网络安全, 攻击者很有可能将根据用户 ID跟踪用户的位 置信息, 其中由于某些国家的用户 ID可能采取一定的编码规则, 例如不同地区的用户其 ID的前缀不一样。 因此攻击者可以根据用 户 ID的前缀猜测其隐私信息, 例如地理位置。 若攻击者根据用户 ID 获得其订阅的业务将会得到用户大量的隐私信息, 威胁到了用 户隐私安全和财产安全。
发明内容 本发明的实施例提供一种用户隐私保护的方法、 设备和系统, 通过利用随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露的问 题, 提升了用户网络体验的安全感。 为达到上述目 的, 本发明的实施例采用如下技术方案: 第一方面, 一种用户隐私保护的方法, 包括: 用户设备 UE通过路由器向位置服务器发送注册请求消息, 以 使得所述位置服务器在接收到所述 UE的注册请求消息时生成随机 值, 并将所述随机值发送给所述 UE , 所述注册请求消息中包含所 述 UE的用户标识, 以使得所述位置服务器根据所述随机值、 共同 密钥、 所述 UE的用户标识以及所述位置服务器的标识符生成临时 用户标识, 并保存所述临时用户标识、 所述 UE 的用户标识、 UE 标识以及所述位置服务器的标识的对应关系,以使得所述位置服务 器根据所述对应关系识别所述 UE的发送的包含所述临时用户标识 的消息, 所述共同密钥与所述 UE的用户标识对应; 所述 U E通过所述路由器接收所述位置服务器发送的所述随机 值;
所述 UE ^:艮据所述共享密钥, 所述 UE的用户标识, 所述随机 值以及预先获取的所述位置服务器的标识符生成所述临时用户标 识, 所述共同密钥与所述 UE的用户标识对应。 结合第一方面, 在第一种可能的实现方式中具体包括, 所述 U E通过所述路由器接收所述位置服务器发送的所述随机值包括: 所述 U E通过所述路由器接收所述位置服务器发送的认证请求 消息, 所述认证请求消息中包括所述随机值。 结合第一方面, 在第二种可能的实现方式中具体包括, 所述 U E通过所述路由器接收所述位置服务器发送的所述随机值包括: 所述 U E通过所述路由器接收所述位置服务器发送的注册响应 消息, 所述注册响应消息中包括所述随机值。
第二方面, 一种用户隐私保护的方法, 包括: 位置服务器通过路由器接收用户设备 UE 发送的注册请求消 息, 所述注册请求消息中包含所述 UE的用户标识, 其中, 当所述 位置服务器接收所述 UE发送的注册请求消息时, 所述位置服务器 生成随机值;
所述位置服务器通过所述路由器将所述随机值发送给所述 UE , 以使得所述 UE ^:艮据所述共享密钥, 所述 UE的用户标识, 所 述随机值以及预先获取的所述位置服务器的标识符生成临时用户 标识;
所述位置服务器根据所述 UE的用户标识获取共同密钥, 并根 据所述共享密钥, 所述 UE的用户标识, 所述随机值以及所述位置 服务器的标识符生成所述临时用户标识;
所述位置服务器保存所述临时用户标识、所述 UE的用户标识、 所述 UE标识以及所述位置服务器的标识的对应关系, 并通过所述 对应关系识别所述 UE发送的包含所述临时用户标识的消息。
结合第二方面, 在第一种可能的实现方式中具体包括, 所述位 置服务器通过所述路由器将所述随机值发送给所述 UE包括:
所述位置服务器通过所述路由器向所述 UE 发送认证请求消 息, 所述认证请求消息中包括随机值, 以使得所述 UE根据所述共 享密钥, 所述 UE的用户标识, 所述随机值以及预先获取的所述位 置服务器的标识符生成临时用户标识, 所述共同密钥与所述 UE的 用户标识对应。
结合第二方面, 在第二种可能的实现方式中具体包括, 所述位 置服务器通过所述路由器将所述随机值发送给所述 UE包括:
所述位置服务器通过所述路由器向所述 UE 转发注册响应消 息, 所述注册响应消息中包括随机值, 以使得所述 UE根据所述共 享密钥, 所述 UE的用户标识, 所述随机值以及预先获取的所述位 置服务器的标识符生成临时用户标识, 所述共同密钥与所述 UE的 用户标识对应。
第三方面, 一种用户隐私保护的方法, 包括: 用户设备 UE通过路由器向位置服务器发送注册请求消息, 所 述注册请求消息中包含所述 UE的用户标识, 以使得所述位置服务 器在接收到所述 UE的注册请求消息时生成随机值, 并根据所述随 机值、 所述 UE的用户标识以及所述位置服务器的标识符生成临时 用户标识, 并保存所述临时用户标识、 所述 UE 的用户标识、 UE 标识以及所述位置服务器的标识的对应关系,以使得所述位置服务 器根据所述对应关系识别所述 UE的发送的包含所述临时用户标识 的消息;
所述 UE通过所述路由器接收所述临时用户标识。 结合第三方面, 在第一种可能的实现方式中具体包括, 所述 UE通过所述路由器接收所述临时用户标识包括: 所述 U E通过所述路由器接收所述位置服务器发送的注册响应 消息, 所述注册响应消息中包括所述临时用户标识。 第四方面, 一种用户隐私保护的方法, 包括: 位置服务器通过路由器接收用户设备 UE 发送的注册请求消 息, 所述注册请求消息中包含所述 UE的用户标识, 其中, 当所述 位置服务器接收所述用户设备 UE发送的注册请求消息时, 所述位 置服务器生成随机值;
所述位置服务器根据所述随机值、 所述 UE的用户标识以及所 述位置服务器的标识符生成临时用户标识; 所述位置服务器保存所述临时用户标识、所述 UE的用户标识、 UE标识以及所述位置服务器的标识的对应关系, 以使得所述位置 服务器根据所述对应关系识别所述 UE的发送的包含所述临时用户 标识的消息; 所述位置服务器通过所述路由器将所述临时用户标识转发至 所述 UE。 结合第四方面, 在第一种可能实现的方式中具体包括, 所述位 置服务器根据所述随机值、 所述 UE的用户标识以及所述位置服务 器的标识符生成临时用户标识包括: 所述位置服务器根据所述随机值、 共享密钥、 所述 UE的用户 标识以及所述位置服务器的标识符生成临时用户标识,所述共同密 钥与所述 UE的用户标识对应。 结合第四方面, 在第二种可能实现的方式中具体包括, 所述位 置服务器通过所述路由器将所述临时用户标识转发至所述 UE , 包 括:
所述位置服务器通过所述路由器转发注册响应消息至所述 UE , 所述注册响应消息中包括所述临时用户标识。 第五方面, 一种用户设备, 包括: 通信单元, 用于通过路由器向位置服务器发送注册请求消息, 以使得所述位置服务器在接收到所述 U E的注册请求消息时生成随 机值, 并将所述随机值发送给所述 UE , 所述注册请求消息中包含 所述 UE的用户标识, 以使得所述位置服务器根据所述随机值、 共 同密钥、 所述 UE的用户标识以及所述位置服务器的标识符生成临 时用户标识, 并保存所述临时用户标识、 所述 UE的用户标识、 UE 标识以及所述位置服务器的标识的对应关系,以使得所述位置服务 器根据所述对应关系识别所述 UE的发送的包含所述临时用户标识 的消息, 所述共同密钥与所述 UE的用户标识对应; 所述通信单元,还用于通过所述路由器接收所述位置服务器发 送的所述随机值; 生成单元, 用于根据所述共享密钥, 所述 UE的用户标识, 所 述随机值以及预先获取的所述位置服务器的标识符生成所述临时 用户标识, 所述共同密钥与所述 UE的用户标识对应。 结合第五方面, 在第一种可能实现的方式中具体包括, 所述通 信单元, 具体还用于:
通过所述路由器接收所述位置服务器发送的认证请求消息,所 述认证请求消息中包括所述随机值。 结合第五方面, 在第二种可能的实现方式中具体包括, 所述通 信单元, 具体还用于:
通过所述路由器接收所述位置服务器发送的注册响应消息,所 述注册响应消息中包括所述随机值。
第六方面, 一种位置服务器, 包括: 通信单元, 用于通过路由器接收用户设备 UE发送的注册请求 消息, 所述注册请求消息中包含所述 UE的用户标识, 其中, 当所 述位置服务器接收所述 UE发送的注册请求消息时, 所述位置服务 器生成随机值;
所述通信单元,还用于通过所述路由器将所述随机值发送给所 述 UE , 以使得所述 UE ^:艮据所述共享密钥, 所述 UE的用户标识, 所述随机值以及预先获取的所述位置服务器的标识符生成临时用 户标识;
生成单元, 用于根据所述 UE的用户标识获取共同密钥, 并根 据所述共享密钥, 所述 UE的用户标识, 所述随机值以及所述位置 服务器的标识符生成所述临时用户标识; 存储单元, 用于保存所述生成单元生成的所述临时用户标识、 所述 UE的用户标识、 所述 UE标识以及所述位置服务器的标识的 对应关系, 并通过所述对应关系识别所述 UE发送的包含所述临时 用户标识的消息。 结合第六方面, 在第一种可能的实现方式中具体包括, 所述通 信单元, 具体还用于:
通过所述路由器向所述 UE发送认证请求消息, 所述认证请求 消息中包括随机值, 以使得所述 UE根据所述共享密钥, 所述 UE 的用户标识,所述随机值以及预先获取的所述位置服务器的标识符 生成临时用户标识, 所述共同密钥与所述 UE的用户标识对应。 结合第六方面, 在第二种可能的实现方式中具体包括, 所述通 信单元, 具体还用于:
通过所述路由器向所述 UE转发注册响应消息, 所述注册响应 消息中包括随机值, 以使得所述 UE根据所述共享密钥, 所述 UE 的用户标识,所述随机值以及预先获取的所述位置服务器的标识符 生成临时用户标识, 所述共同密钥与所述 UE的用户标识对应。 第七方面, 一种用户设备, 包括: 发送单元, 用于通过路由器向位置服务器发送注册请求消息, 所述注册请求消息中包含所述 UE的用户标识, 以使得所述位置服 务器在接收到所述 UE的注册请求消息时生成随机值, 并根据所述 随机值、 所述 UE的用户标识以及所述位置服务器的标识符生成临 时用户标识, 并保存所述临时用户标识、 所述 UE的用户标识、 UE 标识以及所述位置服务器的标识的对应关系,以使得所述位置服务 器根据所述对应关系识别所述 UE的发送的包含所述临时用户标识 的消息;
接收单元, 用于通过所述路由器接收所述临时用户标识。 结合第七方面, 在第一种可能实现的方式中具体包括, 所述接 收单元, 具体还用于:
通过所述路由器接收所述位置服务器发送的注册响应消息,所 述注册响应消息中包括所述临时用户标识。 第八方面, 一种位置服务器, 包括: 通信单元, 用于通过路由器接收用户设备 UE发送的注册请求 消息, 所述注册请求消息中包含所述 UE的用户标识, 其中, 当所 述位置服务器接收所述用户设备 UE发送的注册请求消息时, 所述 位置服务器生成随机值; 生成单元, 用于根据所述随机值、 所述 UE的用户标识以及所 述位置服务器的标识符生成临时用户标识; 存储单元, 用于保存所述生成单元生成的所述临时用户标识、 所述 UE 的用户标识、 UE标识以及所述位置服务器的标识的对应 关系, 以使得所述位置服务器根据所述对应关系识别所述 UE的发 送的包含所述临时用户标识的消息; 所述通信单元,还用于通过所述路由器将所述生成单元生成的 所述临时用户标识转发至所述 UE。 结合第八方面, 在第一种可能实现的方式中具体包括, 所述生 成单元, 具体还用于: 根据所述随机值、 共享密钥、 所述 UE的用户标识以及所述位 置服务器的标识符生成临时用户标识, 所述共同密钥与所述 UE的 用户标识对应。 结合第八方面, 在第二种可能的实现方式中具体包括, 所述通 信单元, 具体还用于:
通过所述路由器转发注册响应消息至所述 UE , 所述注册响应 消息中包括所述临时用户标识。 第九方面, 一种通信系统, 包括: 位置服务器、 路由器以及与 所述路由器连接的用户设备 UE , 其中, 所述位置服务器为第六方面或第六方面中任一种可能的实现 方式所述的位置服务器; 所述用户设备 UE为第五方面或第五方面中任一种可能的实现 方式所述的用户设备; 或者,
所述位置服务器为第八方面或第八方面中任一种可能的实现 方式所述的位置服务器; 所述用户设备 UE为第七方面或第七方面中任一种可能的实现 方式所述的用户设备。 本发明实施例提供的用户隐私保护的方法、 设备和系统, 用户 设备 UE通过注册请求消息将用户设备的用户标识发送至位置服务 器, 并根据该 UE的用户标识获取所述共享密钥, 用户设备的用户 标识,预先获得的位置服务器的标识以及共享密钥生成临时用户标 识, 通过利用随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露 的问题, 提升了用户网络体验的安全感。
附图说明 为了更清楚地说明本发明实施例中的技术方案,下面将对实施 例描述中所需要使用的附图作简单地介绍, 显而易见地, 下面描述 中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来 讲, 在不付出创造性劳动的前提下, 还可以根据这些附图获得其他 的附图。 图 1为本发明实施例提供的一种 UIP ( User Identity Protocol, 用 户身份协议) 的网络拓朴结构示意图; 图 2为本发明实施例提供的一种用户隐私保护的方法的流程示意 图;
图 3为本发明实施例提供的另一种用户隐私保护的方法的流程示 意图;
图 4为本发明另一实施例提供的一种用户隐私保护的方法的流程 示意图; 图 5为本发明另一实施例提供的另一种用户隐私保护的方法的流 程示意图; 图 6为本发明又一实施例提供的一种用户隐私保护的方法的流程 示意图; 图 7为本发明又一实施例提供的另一种用户隐私保护的方法的流 程示意图; 图 8为本发明又一实施例提供的再一种用户隐私保护的方法的流 程示意图; 图 9为本发明实施例提供的一种用户设备的结构示意图; 图 10为本发明实施例提供的一种位置服务器的结构示意图; 图 1 1为本发明另一实施例提供的一种用户设备的结构示意图; 图 12为本发明另一实施例提供的一种位置服务器的结构示意图; 图 13为本发明又一实施例提供的一种用户设备的结构示意图; 图 14为本发明又一实施例提供的一种位置服务器的结构示意图; 图 15为本发明再一实施例提供的一种用户设备的结构示意图; 图 16为本发明再一实施例提供的一种位置服务器的结构示意图; 图 17为本发明实施例提供的一种通信系统的结构示意图。
具体实施方式 下面将结合本发明实施例中的附图,对本发明实施例中的技术 方案进行清楚、 完整地描述, 显然, 所描述的实施例仅仅是本发明 一部分实施例, 而不是全部的实施例。 基于本发明中的实施例, 本 领域普通技术人员在没有作出创造性劳动前提下所获得的所有其 他实施例, 都属于本发明保护的范围。 本发明适用于用户身份协议 UIP ( User Identity Protocol )网络 架构, 其中如图 1 所示, UIP 网络由一个或多个 UIP域组成, 一个 UIP域由一个位置服务器 SLS ( Subscriber Location Server ) , 一个 或多个域路由器 DR ( Domain Router ) , 一个或多个网关 GW ( GateWay ) 组成。 其中, DR用于保存用户标识 UserlD及该用户 的定位符 Locator的映射关系、 用户数据转发以及报文地址变换, 域内、 域间的 DR相互连结。 SLS 用于保存用户标识 UserlD及用 户 当前 DR的映射关系。 UE通过无线接入网接入 UIP域。 而本发 明提供一种用户隐私保护的方法, 参照图 2所示, 在用户设备侧, 具体步骤如下所述:
101、 用户设备 UE 通过路由器向位置服务器发送注册请求消 息, 以使得该位置服务器在接收到 UE的注册请求消息时生成随机 值, 并将该随机值发送给该 UE。 其中, 注册请求消息中包含所述 UE的用户标识, 以使得所述 位置服务器根据所述随机值、 共同密钥、 所述 UE的用户标识以及 所述位置服务器的标识符生成临时用户标识,并保存所述临时用户 标识、 所述 UE 的用户标识、 UE标识以及所述位置服务器的标识 的对应关系, 以使得所述位置服务器根据所述对应关系识别所述 UE 的发送的包含所述临时用户标识的消息, 所述共同密钥与所述 UE的用户标识对应。 这里获取共享密钥的方法可以是认证与 密钥协商 AKA (Authentication and Key Agreement)或者其他密钥协商方法。 这里用户设备 UE ( User Equipment ) 可以通过域 ^路由器 DR ( Domain Router )转发注册请求消息, 将 UE本身的基本信息, 例 如用户标识 UserlD、 设备标识符 Device ID和定位符 Locator发送 至用户位置服务器 SLS ( Subscriber Location Server ), 以便 SLS根 据 UE的注册请求消息获取 UE的基本信息 ( 即基础参数)。 其中, 注册请求消息还包括: 设备标识符和 /或 UE的定位符。
102、 UE通过路由器接收该位置服务器发送的随机值。
103、 UE 根据共享密钥, UE 的用户标识, 随机值以及预先 获取的位置服务器的标识符生成临时用户标识。 其中, 该共同密钥与所述 UE的用户标识对应。 这里 UE可以根据与 SLS协商得到共享密钥 SKey之前接收到 的认证请求消息,获取由 SL S生成的随机值 nonce,并根据该 nonce , 预先获取的 SLS 的 SLS ID, SKey和 UE 自身的 UserlD生成临时 用户标识 TempUser ID; 或者,
根据与 SLS协商得到共享密钥 SKey之后,接收的注册响应消 息中获取随机值 nonce, 并根据该 nonce, SLS的 SLS ID, SKey和 UE 自身的 UserlD生成临时用户标识 TempUser ID; 或者,
除 UE 自身根据 SLS发送的 nonce生成 TempUser ID夕卜, 可选 的, UE通过接收 SLS发送的注册响应消息接收 SLS 已经生成的临 时用户标识 TempUser ID。 本发明提供一种用户隐私保护的方法, 参照图 3所示, 在位置 服务器侧, 具体步骤如下所述:
201、 位置服务器通过路由器接收用户设备 UE 发送的注册请 求消息。
这里注册请求消息中包含该 UE的用户标识, 其中, 当位置服 务器接收 UE发送的注册请求消息时, 位置服务器生成随机值。
其中, 该注册请求消息还包括用户设备标识符 Device ID 和 I 或 UE的定位符 Locator。
202、 位置服务器通过路由器将随机值发送给 UE, 以使得该 UE根据共享密钥, UE的用户标识, 随机值以及预先获取的位置服 务器的标识符生成临时用户标识。
203、 位置服务器根据该共享密钥, UE的用户标识, 随机值 以及位置服务器的标识符生成临时用户标识。 其中 , 获取共享密钥的方法可以是认证与密钥协商 AKA (Authentication and Key Agreement)或者其他密钥协商方法。 这里用户位置服务器 SLS ( Subscriber Location Server ) 可以 根据与 UE协商得到共享密钥 SKey之前, SLS生成的随机值 nonce , 并根据该 nonce , SLS 自身的 SLS ID , SKey和 UE的 UserlD生成 临时用户标识 TempUser ID ; 或者,
根据与 UE 协商得到共享密钥 SKey 之后, SLS 生成随机值 nonce ,并在发送携带 nonce的注册响应消息之前 SLS根据该 nonce , SLS 的 SLS ID , SKey 和 UE 自身的 UserlD 生成临时用户标识 TempUser ID ; 或者,
SLS在接收到 UE发送的认证响应消息之后, SLS生成 nonce , 并根据 nonce生成 TempUser ID , 通过发送注册响应消息将生成的 TempUser ID发送至 UE。
204、 位置服务器保存临时用户标识、 UE的用户标识、 UE标 识以及位置服务器的标识的对应关系, 并通过该对应关系识别 UE 发送的包含临时用户标识的消息。 其中, 可选的, 该 SLS 保存的是临时用户标识 TempUser ID 与 UE的用户标识 User ID、设备标识符 Device ID和定位符 Locator 的映射关系。 本发明实施例提供的用户隐私保护的方法, 用户设备 UE通过 注册请求消息将用户设备的用户标识发送至位置服务器,并根据该 UE 的用户标识获取所述共享密钥, 用户设备的用户标识, 预先获 得的位置服务器的标识以及共享密钥生成临时用户标识,通过利用 随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升 了用户网络体验的安全感。 本发明提供另一种用户隐私保护的方法, 参照图 4所示, 在用 户设备侧, 具体步骤如下所述:
301、 用户设备 UE 通过路由器向位置服务器发送注册请求消 息。 其中, 注册请求消息中包含所述 UE的用户标识, 以使得所述 位置服务器在接收到所述 UE的注册请求消息时生成随机值, 并根 据所述随机值、 所述 UE的用户标识以及所述位置服务器的标识符 生成临时用户标识, 并保存所述临时用户标识、 所述 UE的用户标 识、 UE标识以及所述位置服务器的标识的对应关系, 以使得所述 位置服务器根据所述对应关系识别所述 UE的发送的包含所述临时 用户标识的消息。
302、 UE通过路由器接收临时用户标识。 其中, UE通过所述路由器接收所述位置服务器发送的注册响 应消息, 所述注册响应消息中包括所述临时用户标识。 本发明提供另一种用户隐私保护的方法, 参照图 5所示, 在位 置服务器侧, 具体步骤如下所述:
401、 位置服务器通过路由器接收用户设备 UE 发送的注册请 求消息。 这里注册请求消息中包含所述 UE的用户标识, 其中, 当所述 位置服务器接收所述用户设备 UE发送的注册请求消息时, 所述位 置服务器生成随机值。
402、 位置服务器根据随机值、 UE的用户标识以及位置服务器 的标识符生成临时用户标识。
403、 位置服务器保存该临时用户标识、 UE 的用户标识、 UE 标识以及位置服务器的标识的对应关系,以使得该位置服务器根据 该对应关系识别 UE的发送的包含临时用户标识的消息。 其中, 可选的, 该 SLS 保存的是临时用户标识 TempUser ID 与 UE的用户标识 User ID、设备标识符 Device ID和定位符 Locator 的映射关系。
404、 位置服务器通过路由器将该临时用户标识转发至 UE。 其中, 位置服务器通过所述路由器转发注册响应消息至所述 UE , 所述注册响应消息中包括所述临时用户标识。 本发明实施例提供的用户隐私保护的方法,位置服务器根据随 机生成的随机值生成临时用户标识,并通过注册响应消息携带临时 用户标识经由路由器发送至用户设备 UE , 进而通过利用随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升了用户网 络体验的安全感。 本发明实施例中的路由器以域路由器 DR , 位置服务器以用户 位置服务器 SLS 为例进行说明, 以实现本发明实施例提供的用户 隐私保护的方法为准, 不作具体限定。 具体的, 以下结合具体的实施例进行说明。 实施例一 可以在图 2或图 3所示的实施例的基础上, 参照图 6所示, 本 发明的实施例提供了一种用户隐私保护的方法, 参照图 6所示, 为 用户位置服务器 SLS与用户设备 UE通过协商生成共享密钥 SKey , 并根据 SKey , SLS和或 UE 的 ID生成临时用户标识 TempUserlD 的过程, 具体步骤如下:
501、 用户设备 UE 通过路由器向位置服务器发送注册请求消 息, 以使得改位置服务器在接收到 UE的注册请求消息时生成随机 值, 并将该随机值发送给该 UE。 其中, 注册请求消息中包含所述 UE的用户标识, 以使得所述 位置服务器根据所述随机值、 共同密钥、 所述 UE的用户标识以及 所述位置服务器的标识符生成临时用户标识,并保存所述临时用户 标识、 所述 UE 的用户标识、 UE标识以及所述位置服务器的标识 的对应关系, 以使得所述位置服务器根据所述对应关系识别所述 UE 的发送的包含所述临时用户标识的消息, 所述共同密钥与所述 UE的用户标识对应。 这里获取共享密钥 的方法可以是认证与 密钥协商 AKA (Authentication and Key Agreement)或者其他密钥协商方法。 可选的, 注册请求消息还包括: 设备标识符和 /或 UE 的定位 付 。
这里用户设备 UE ( User Equipment ) 可以通过域 ^路由器 DR ( Domain Router )转发注册请求消息, 将 UE本身的基本信息, 例 如用户标识 UserID、 设备标识符 Device ID和定位符 Locator发送 至用户位置服务器 SLS ( Subscriber Location Server ) , 以便 SL S根 据 UE的注册请求消息获取 UE的基本信息 ( 即基础参数)。
502、 位置服务器通过路由器接收用户设备 UE 发送的注册请 求消息。
这里注册请求消息中包含该 UE的用户标识, 其中, 当位置服 务器接收 UE发送的注册请求消息时, 位置服务器生成随机值。
其中, 该注册请求消息还包括用户设备标识符 Device ID 和 I 或 UE的定位符 Locator。
这里域路由器 DR用于承担转发 UE与 SLS之间信令交互报文 的功能。
503、 位置服务器通过路由器将随机值发送给 UE , 以使得该 UE根据共享密钥, UE的用户标识, 随机值以及预先获取的位置服 务器的标识符生成临时用户标识。
其中随机值可以用 nonce表示。 以实现本发明实施例提供的一 种用户隐私保护的方法为准, 具体不做限定。
这里位置服务器在认证请求消息中携带随机值,并通过路由器 发送至 UE。
504、 UE通过路由器接收该位置服务器发送的随机值。
其中 UE通过所述路由器接收所述位置服务器发送的认证请求 消息, 所述认证请求消息中包括所述随机值。 505、 UE根据该认证请求消息通过路由器向位置服务器发送认 证响应消息。
506、 位置服务器接收 UE通过路由器发送的认证响应消息。
507、 位置服务器根据该共享密钥, UE的用户标识, 随机值以 及位置服务器的标识符生成临时用户标识。 其中 , 获取共享密钥的方法可以是认证与密钥协商 AKA (Authentication and Key Agreement)或者其他密钥协商方法。 这里临时用户标识以临时用户标识 TempUser ID为例: 其中, TempUser ID的生成方法可表示为:
TempUser ID=KDF(SKey,UserID,SLS ID, nonce) 即临时用户标识 TempUser ID为 SLS根据协商得到的 SKey , UE的 UserlD , SLS ID 以及 SLS生成的 nonce生成; 其中:
SKey是 SLS和 UE的某个共享的密钥;
SLS ID( SLS标识)是 SLS的 ID ,比如 UUID(Universally Unique Identifier)形式的标识符; nonce是 SLS产生的随机值。
508、 UE 根据共享密钥, UE 的用户标识, 随机值以及预先 获取的位置服务器的标识符生成临时用户标识。 其中, 该共同密钥与所述 UE的用户标识对应。 这里 UE根据认证请求消息中获取到的随机值 nonce , 与 SLS 协商得到的 SKey , 预先获取的 SLS 的 ID 以及 UE 自身的 UserlD 生成临时用户标识 TempUser ID。
509、 位置服务器保存临时用户标识、 UE的用户标识、 UE标 识以及位置服务器的标识的对应关系, 并通过该对应关系识别 UE 发送的包含临时用户标识的消息。 其中, 可选的, 该 SLS 保存的是临时用户标识 TempUser ID 与 UE的用户标识 User ID、设备标识符 Device ID和定位符 Locator 的映射关系。
5 10、 位置服务器通过路由器向 UE发送注册响应消息。
5 1 1、 UE通过路由器接收位置服务器发送的注册响应消息。 本发明实施例提供的用户隐私保护的方法, 用户设备 UE通过 注册请求消息将用户设备的用户标识发送至位置服务器,并根据该 UE 的用户标识获取所述共享密钥, 用户设备的用户标识, 预先获 得的位置服务器的标识以及共享密钥生成临时用户标识,通过利用 随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升 了用户网络体验的安全感。 实施例二 可以在图 2或图 3所示的实施例的基础上, 参照图 7所示, 本 发明的实施例提供了一种用户隐私保护的方法, 参照图 7所示, 为 用户位置服务器 SLS与用户设备 UE通过协商生成共享密钥 SKey , 其中在 UE与 SLS协商生成 SKey之后 SLS生成随机值 nonce , SLS 根据 SKey , SLS和或 UE 的 ID生成临时用户标识 TempUserlD , 再经由 DR转发注册响应消息将 nonce发送至 UE , 以便 UE根据 nonce生成 TempUserlD的过程, 具体步骤如下:
601 用户设备 UE 通过路由器向位置服务器发送注册请求消 息, 以使得改位置服务器在接收到 UE的注册请求消息时生成随机 值, 并将该随机值发送给该 UE。 其中, 注册请求消息中包含所述 UE的用户标识, 以使得所述 位置服务器根据所述随机值、 共同密钥、 所述 UE的用户标识以及 所述位置服务器的标识符生成临时用户标识,并保存所述临时用户 标识、 所述 UE 的用户标识、 UE标识以及所述位置服务器的标识 的对应关系, 以使得所述位置服务器根据所述对应关系识别所述 UE 的发送的包含所述临时用户标识的消息, 所述共同密钥与所述 UE的用户标识对应。 可选的, 注册请求消息还包括: 设备标识符和 /或 UE 的定位 这里用户设备 UE ( User Equipment ) 可以通过域 ^路由器 DR ( Domain Router )转发注册请求消息, 将 UE本身的基本信息, 例 如用户标识 UserID、 设备标识符 Device ID和定位符 Locator发送 至用户位置服务器 SLS ( Subscriber Location Server ) , 以便 SL S根 据 UE的注册请求消息获取 UE的基本信息 ( 即基础参数)。
602、 位置服务器通过路由器接收用户设备 UE 发送的注册请 求消息。
这里注册请求消息中包含该 UE的用户标识, 其中, 当位置服 务器接收 UE发送的注册请求消息时, 位置服务器生成随机值。
其中, 该注册请求消息还包括用户设备标识符 Device ID 和 I 或 UE的定位符 Locator。 这里域路由器 DR用于承担转发 UE与 SLS之间信令交互报文 的功能。
603、 位置服务器通过路由器将随机值发送给 UE , 以使得该 UE根据共享密钥, UE的用户标识, 随机值以及预先获取的位置服 务器的标识符生成临时用户标识。 其中随机值可以用 nonce表示。 以实现本发明实施例提供的一 种用户隐私保护的方法为准, 具体不做限定。
这里位置服务器在认证请求消息中携带随机值,并通过路由器 发送至 UE。 位置服务器通过路由器向 UE发送认证请求消息。
这里 SLS通过 DR向 UE发送的认证请求消息中不限定为随机 值 nonce是否为生成 TempUser ID所需的随机值 nonce。 与实施例 一中的区别在于本发明实施例中用于生成 TempUser ID 的随机值 nonce可以为 SL S重新产生的一个新的 nonce , 即可以不重用本步 骤中向 UE发送的认证请求消息中的 nonce。
604、 UE通过路由器接收该位置服务器发送的随机值。 其中 UE通过所述路由器接收所述位置服务器发送的认证请求 消息, 所述认证请求消息中包括所述随机值。 605、 UE根据该认证请求消息通过路由器向位置服务器发送认 证响应消息。
606、 位置服务器接收 UE通过路由器发送的认证响应消息。
607、 位置服务器根据该共享密钥, UE的用户标识, 随机值以 及位置服务器的标识符生成临时用户标识。 其中 , 获取共享密钥的方法可以是认证与密钥协商 AKA (Authentication and Key Agreement)或者其他密钥协商方法。 这里临时用户标识以临时用户标识 TempUser ID为例: 其中, TempUser ID的生成方法可表示为:
TempUser ID=KDF(SKey,UserID,SLS ID, nonce) 即临时用户标识 TempUser ID为 SLS根据协商得到的 SKey , UE的 UserlD , SLS ID 以及 SLS生成的 nonce生成; 其中:
SKey是 SLS和 UE的某个共享的密钥;
SLS ID( SLS标识)是 SLS的 ID ,比如 UUID(Universally Unique Identifier)形式的标识符; nonce是 SLS产生的随机值。
608、 位置服务器通过路由器将随机值发送给 UE。 其中, 注册响应消息, 还包括: SLS生成的随机值 nonce , 以 便 UE根据随机值 nonce生成所述 TempUser ID。 位置服务器通过所述路由器向所述 UE转发注册响应消息, 所 述注册响应消息中包括随机值,以使得所述 UE根据所述共享密钥, 所述 UE的用户标识, 所述随机值以及预先获取的所述位置服务器 的标识符生成临时用户标识, 所述 UE根据所述 UE的用户标识获 取所述共享密钥。
609、 位置服务器保存临时用户标识、 UE的用户标识、 UE标 识以及位置服务器的标识的对应关系, 并通过该对应关系识别 UE 发送的包含临时用户标识的消息。 这里具体的, SLS保存的是临时用户标识 TempUser ID与 UE 的用户标识 User ID、 设备标识符 Device ID和定位符 Locator的映 射关系。
610、 UE通过路由器接收位置服务器发送的随机值。 其中, UE通过所述路由器接收所述位置服务器发送的注册响 应消息, 所述注册响应消息中包括所述随机值。
61 1、 UE根据共享密钥, UE的用户标识, 随机值以及预先获 取的位置服务器的标识符生成临时用户标识。 其中, UE根据所述 UE的用户标识获取所述共享密钥 这里 UE根据认证请求消息中获取到的随机值 nonce , 与 SLS 协商得到的 SKey , 预先获取的 SLS 的 ID 以及 UE 自身的 UserlD 生成临时用户标识 TempUser ID。 本发明实施例提供的用户隐私保护的方法, 用户设备 UE通过 注册请求消息将用户设备的用户标识发送至位置服务器,并通过与 位置服务器协商得到共享密钥, 再根据用户设备的用户标识, 预先 获得的位置服务器的标识以及共享密钥生成临时用户标识,通过利 用随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提 升了用户网络体验的安全感。 本发明实施例与实施例一的区别在于 SLS用于生成 TempUser ID的随机值 nonce为在与 UE协商得到共享密钥 SKey之后, 并在 生成 TempUser ID之后将生成 TempUser ID的随机值 nonce通过注 册响应消息通过 DR发送至 UE。 其中, 用于生成 TempUser ID的 随机值 nonce为可以与发送认证请求消息时所携带的 nonce不同。 实施例三 可以在图 4或图 5所示的实施例的基础上, 参照图 8所示, 本 发明的实施例提供了一种用户隐私保护的方法, 参照图 8所示, 为 用户位置服务器 SLS与用户设备 UE通过协商生成共享密钥 SKey , SLS根据 SKey , SLS和 UE的 ID生成临时用户标识 TempUserlD , 再经由 DR转发 TempUserlD至 UE的过程, 具体步骤如下: 701、 用户设备 UE 通过路由器向位置服务器发送注册请求消 息。 其中, 注册请求消息中包含所述 UE的用户标识, 以使得所述 位置服务器在接收到所述 UE的注册请求消息时生成随机值, 并根 据所述随机值、 所述 UE的用户标识以及所述位置服务器的标识符 生成临时用户标识, 并保存所述临时用户标识、 所述 UE的用户标 识、 UE标识以及所述位置服务器的标识的对应关系, 以使得所述 位置服务器根据所述对应关系识别所述 UE的发送的包含所述临时 用户标识的消息。 其中, 注册请求消息还包括: 设备标识符和 /或 UE的定位符。 这里用户设备 UE ( User Equipment ) 可以通过域 ^路由器 DR ( Domain Router )转发注册请求消息, 将 UE本身的基本信息, 例 如用户标识 UserID、 设备标识符 Device ID和定位符 Locator发送 至用户位置服务器 SLS ( Subscriber Location Server ) , 以便 SLS根 据 UE的注册请求消息获取 UE的基本信息 ( 即基础参数)。
702、 位置服务器通过路由器接收用户设备 UE 发送的注册请 求消息。 其中, 注册请求消息中包含所述 UE的用户标识, 其中, 当所 述位置服务器接收所述用户设备 UE发送的注册请求消息时, 所述 位置服务器生成随机值; 这里域路由器 DR用于承担转发 UE与 SLS之间信令交互报文 的功能。
703、 位置服务器通过路由器向 UE发送认证请求消息。
704、 UE通过路由器接收位置服务器发送的认证请求消息。
705、 UE根据该认证请求消息通过路由器向位置服务器发送认 证响应消息。
706、 位置服务器接收 UE通过路由器发送的认证响应消息。
707、 位置服务器根据随机值、 UE的用户标识以及位置服务器 的标识符生成临时用户标识。 其中, 该相关参数至少包括所述随机值、 所述 UE的用户标识 以及所述位置服务器的标识符; 可选的, 该相关参数还包括共同密钥, 位置服务器根据所述随 机值、 共享密钥、 所述 UE的用户标识以及所述位置服务器的标识 符生成临时用户标识。 其中, 该位置服务器根据所述 UE的用户标识获取共同密钥。 这里如上所述 SLS 可以如实施例一与实施例二中所述的方法 根据 SKey , UE的基本信息, 随机值 nonce 以及 SLS的标识符 SLS ID生成临时用户标识 TempUser ID。 本实施例中 SLS还可以根据随机值 nonce生成 TempUser ID。
708、 位置服务器保存临时用户标识、 UE的用户标识、 UE标 识以及位置服务器的标识的对应关系,以使得该位置服务器根据该 对应关系识别 UE的发送的包含临时用户标识的消息。 这里具体的, SLS保存的是临时用户标识 TempUser ID与 UE 的用户标识 User ID、 设备标识符 Device ID和定位符 Locator的映 射关系。
709、 位置服务器通过路由器将临时用户标识转发至 UE。 其中, 位置服务器通过所述路由器转发注册响应消息至所述 UE , 所述注册响应消息中包括所述临时用户标识。
710、 UE通过路由器接收临时用户标识。 其中, UE通过所述路由器接收所述位置服务器发送的注册响 应消息, 所述注册响应消息中包括所述临时用户标识。 本发明实施例提供的用户隐私保护的方法,位置服务器根据随 机生成的随机值生成临时用户标识,并通过注册响应消息携带临时 用户标识经由路由器发送至用户设备 UE , 进而通过利用随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升了用户网 络体验的安全感。 本发明提供一种用户设备 UE 8 , 该用户设备 UE 8 以可以实现 本发明的实施例所提供的任一用户隐私保护的方法为准, 参照图 9 所示, 包括: 通信单元 81 , 用于通过路由器向位置服务器发送注册请求消 息, 以使得所述位置服务器在接收到所述 UE的注册请求消息时生 成随机值, 并将所述随机值发送给所述 UE , 所述注册请求消息中 包含所述 UE的用户标识,以使得所述位置服务器根据所述随机值、 共同密钥、 所述 UE的用户标识以及所述位置服务器的标识符生成 临时用户标识, 并保存所述临时用户标识、 所述 UE的用户标识、 UE标识以及所述位置服务器的标识的对应关系, 以使得所述位置 服务器根据所述对应关系识别所述 UE的发送的包含所述临时用户 标识的消息, 所述共同密钥与所述 UE的用户标识对应; 通信单元 81 , 还用于通过所述路由器接收所述位置服务器发 送的所述随机值; 生成单元 82 , 用于根据所述共享密钥, 所述 UE的用户标识, 所述随机值以及预先获取的所述位置服务器的标识符生成所述临 时用户标识, 所述共同密钥与所述 UE的用户标识对应。 本发明实施例提供的用户设备, 用户设备 UE通过注册请求消 息将用户设备的用户标识发送至位置服务器, 并根据该 UE的用户 标识获取所述共享密钥, 用户设备的用户标识, 预先获得的位置服 务器的标识以及共享密钥生成临时用户标识, 通过利用随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升了用户网 络体验的安全感。 可选的, 通信单元 81 , 具体还用于: 通过所述路由器接收所 述位置服务器发送的认证请求消息,所述认证请求消息中包括所述 随机值。 可选的, 通信单元 81 , 具体还用于: 通过所述路由器接收所 述位置服务器发送的注册响应消息,所述注册响应消息中包括所述 随机值。 本发明实施例提供的用户设备, 用户设备 UE通过注册请求消 息将用户设备的用户标识发送至位置服务器, 并根据该 UE的用户 标识获取所述共享密钥, 用户设备的用户标识, 预先获得的位置服 务器的标识以及共享密钥生成临时用户标识, 通过利用随机用户
ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升了用户网 络体验的安全感。 本发明提供一种位置服务器 SLS 9 , 该位置服务器 SLS 9 以 可以实现本发明的实施例所提供的任一用户隐私保护的方法为准, 参照图 10所示, 包括: 通信单元 91 ,用于通过路由器接收用户设备 UE发送的注册请 求消息, 所述注册请求消息中包含所述 UE的用户标识, 其中, 当 所述位置服务器接收所述 UE发送的注册请求消息时, 所述位置服 务器生成随机值;
通信单元 91 , 还用于通过所述路由器将所述随机值发送给所 述 UE , 以使得所述 UE ^:艮据所述共享密钥, 所述 UE的用户标识, 所述随机值以及预先获取的所述位置服务器的标识符生成临时用 户标识;
生成单元 92 , 用于根据所述 UE的用户标识获取共同密钥, 并 根据所述共享密钥, 所述 UE的用户标识, 所述随机值以及所述位 置服务器的标识符生成所述临时用户标识; 存储单元 93 , 用于保存所述生成单元生成的所述临时用户标 识、 所述 UE的用户标识、 所述 UE标识以及所述位置服务器的标 识的对应关系, 并通过所述对应关系识别所述 UE发送的包含所述 临时用户标识的消息。
本发明实施例提供的位置服务器, 用户设备 UE通过注册请求 消息将用户设备的用户标识发送至位置服务器, 并根据该 UE的用 户标识获取所述共享密钥, 用户设备的用户标识, 预先获得的位置 服务器的标识以及共享密钥生成临时用户标识,通过利用随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升了用户网 络体验的安全感。 可选的, 通信单元 91 , 具体还用于: 通过所述路由器向所述 UE发送认证请求消息, 所述认证请求消息中包括随机值, 以使得 所述 UE ^:艮据所述共享密钥, 所述 UE的用户标识, 所述随机值以 及预先获取的所述位置服务器的标识符生成临时用户标识,所述共 同密钥与所述 UE的用户标识对应。 可选的, 通信单元 91 , 具体还用于: 通过所述路由器向所述 UE转发注册响应消息, 所述注册响应消息中包括随机值, 以使得 所述 UE ^:艮据所述共享密钥, 所述 UE的用户标识, 所述随机值以 及预先获取的所述位置服务器的标识符生成临时用户标识,所述共 同密钥与所述 UE的用户标识对应。 本发明实施例提供的位置服务器, 用户设备 UE通过注册请求 消息将用户设备的用户标识发送至位置服务器, 并根据该 UE的用 户标识获取所述共享密钥, 用户设备的用户标识, 预先获得的位置 服务器的标识以及共享密钥生成临时用户标识,通过利用随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升了用户网 络体验的安全感。 本发明提供一种用户设备 UE 10 , 该用户设备 UE 10以可以实 现本发明的实施例所提供的任一用户隐私保护的方法为准,参照图 1 1所示, 包括:
发送单元 1001 , 用于通过路由器向位置服务器发送注册请求 消息, 所述注册请求消息中包含所述 UE的用户标识, 以使得所述 位置服务器在接收到所述 UE的注册请求消息时生成随机值, 并根 据所述随机值、 所述 UE的用户标识以及所述位置服务器的标识符 生成临时用户标识, 并保存所述临时用户标识、 所述 UE的用户标 识、 UE标识以及所述位置服务器的标识的对应关系, 以使得所述 位置服务器根据所述对应关系识别所述 UE的发送的包含所述临时 用户标识的消息;
接收单元 1002 , 用于通过所述路由器接收所述临时用户标识。 本发明实施例提供的用户设备, 用户设备 UE通过注册请求消 息将用户设备的用户标识发送至位置服务器, 并根据该 UE的用户 标识获取所述共享密钥, 用户设备的用户标识, 预先获得的位置服 务器的标识以及共享密钥生成临时用户标识, 通过利用随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升了用户网 络体验的安全感。 进一步的, 接收单元 1002 , 具体还用于: 通过所述路由器接 收所述位置服务器发送的注册响应消息,所述注册响应消息中包括 所述临时用户标识。 本发明实施例提供的用户设备,位置服务器根据随机生成的随 机值生成临时用户标识,并通过注册响应消息携带临时用户标识经 由路由器发送至用户设备 UE ,进而通过利用随机用户 ID隐藏用户 真实 ID , 解决了用户隐私暴露的问题, 提升了用户网络体验的安 全感。
本发明提供一种位置服务器 SLS 1 1 , 该位置服务器 SLS 1 1 以可以实现本发明的实施例所提供的任一用户隐私保护的方法为 准, 参照图 12所示, 包括: 通信单元 1 101 ,用于通过路由器接收用户设备 UE发送的注册 请求消息, 所述注册请求消息中包含所述 UE的用户标识, 其中, 当所述位置服务器接收所述用户设备 UE发送的注册请求消息时, 所述位置服务器生成随机值; 生成单元 1 102 , 用于根据所述随机值、 所述 UE的用户标识以 及所述位置服务器的标识符生成临时用户标识; 存储单元 1 103 , 用于保存所述生成单元生成的所述临时用户 标识、 所述 UE 的用户标识、 UE标识以及所述位置服务器的标识 的对应关系, 以使得所述位置服务器根据所述对应关系识别所述 UE的发送的包含所述临时用户标识的消息; 通信单元 1 101 , 还用于通过所述路由器将所述生成单元生成 的所述临时用户标识转发至所述 UE。 本发明实施例提供的位置服务器, 用户设备 UE通过注册请求 消息将用户设备的用户标识发送至位置服务器, 并根据该 UE的用 户标识获取所述共享密钥, 用户设备的用户标识, 预先获得的位置 服务器的标识以及共享密钥生成临时用户标识,通过利用随机用户
ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升了用户网 络体验的安全感。 可选的, 生成单元 1 102 , 具体还用于: 根据所述随机值、 共 享密钥、 所述 UE的用户标识以及所述位置服务器的标识符生成临 时用户标识, 所述共同密钥与所述 UE的用户标识对应。 可选的, 通信单元 1 101 , 具体还用于: 通过所述路由器转发 注册响应消息至所述 UE , 所述注册响应消息中包括所述临时用户 标识。 本发明实施例提供的位置服务器,位置服务器根据随机生成的 随机值生成临时用户标识,并通过注册响应消息携带临时用户标识 经由路由器发送至用户设备 UE ,进而通过利用随机用户 ID隐藏用 户真实 ID , 解决了用户隐私暴露的问题, 提升了用户网络体验的 安全感。
本发明的实施例提供一种用户设备 UE 12 , 参照图 13所示, 该用户设备 UE 12 包括: 至少一个处理器 1201、 存储器 1202、 通 信端口 1203 和总线 1204 , 该至少一个处理器 1201、 存储器 1202 和通信接口 1203通过总线 1204连接并完成相互间的通信。
该总线 1204 可以是工业标准体系结构 ( Industry Standard Architecture , 简称为 ISA ) 总线、 夕卜部设备互连 ( Peripheral Component , 简称为 PCI )总线或扩展工业标准体系结构( Extended Industry Standard Architecture , 简称为 EISA )总线等。 该总线 1304 可以分为地址总线、 数据总线、 控制总线等。 为便于表示, 图 13 中仅用一条粗线表示, 但并不表示仅有一根总线或一种类型的总 线。 其中:
存储器 1202用于存储可执行程序代码, 该程序代码包括计算 机操作指令。 存储器 1202 可能包含高速 RAM ( Random Access Memory ,随机存储器),也可能还包括非易失性存储器( non-volatile memory ) , 例如至少一个磁盘存 4诸器。 处理器 1201可能是一个中央处理器( Central Processing Unit , 简称为 CPU ),或者是特定集成电路( Application Specific Integrated Circuit , 简称为 ASIC ) , 或者是被配置成实施本发明实施例的一个 或多个集成电路。 通信接口 1203 , 主要用于实现本实施例中的装置之间的通信。 其中, 处理器 1201 , 用于通过至少一个通信接口 1203通过路 由器向位置服务器发送注册请求消息,以使得所述位置服务器在接 收到所述 UE的注册请求消息时生成随机值, 并将所述随机值发送 给所述 UE , 所述注册请求消息中包含所述 UE 的用户标识, 以使 得所述位置服务器根据所述随机值、 共同密钥、 所述 UE的用户标 识以及所述位置服务器的标识符生成临时用户标识,并保存所述临 时用户标识、 所述 UE 的用户标识、 UE标识以及所述位置服务器 的标识的对应关系,以使得所述位置服务器根据所述对应关系识另 'J 所述 UE的发送的包含所述临时用户标识的消息, 所述共同密钥与 所述 UE的用户标识对应; 处理器 1201 , 还用于通过至少一个通信接口 1203通过所述路 由器接收所述位置服务器发送的所述随机值; 处理器 1201 ,还用于根据所述共享密钥,所述 UE的用户标识, 所述随机值以及预先获取的所述位置服务器的标识符生成所述临 时用户标识, 所述共同密钥与所述 UE的用户标识对应。 本发明实施例提供的用户设备, 用户设备 UE通过注册请求消 息将用户设备的用户标识发送至位置服务器, 并根据该 UE的用户 标识获取所述共享密钥, 用户设备的用户标识, 预先获得的位置服 务器的标识以及共享密钥生成临时用户标识, 通过利用随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升了用户网 络体验的安全感。 可选的, 处理器 1201 , 具体还用于: 通过至少一个通信接口 1203 通过所述路由器接收所述位置服务器发送的认证请求消息, 所述认证请求消息中包括所述随机值。 可选的, 处理器 1201 , 具体还用于: 通过至少一个通信接口 1203 通过所述路由器接收所述位置服务器发送的注册响应消息, 所述注册响应消息中包括所述随机值。 本发明实施例提供的用户设备, 用户设备 UE通过注册请求消 息将用户设备的用户标识发送至位置服务器, 并根据该 UE的用户 标识获取所述共享密钥, 用户设备的用户标识, 预先获得的位置服 务器的标识以及共享密钥生成临时用户标识, 通过利用随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升了用户网 络体验的安全感。 本发明的实施例提供一种位置服务器 SLS 13 ,参照图 14所示, 该位置服务器 SLS 13 包括: 至少一个处理器 1301、 存储器 1302、 通信端口 1303和总线 1304 ,该至少一个处理器 1301、存储器 1302 和通信接口 1303通过总线 1304连接并完成相互间的通信。 该总线 1304 可以是工业标准体系结构 ( Industry Standard Architecture , 简称为 ISA ) 总线、 夕卜部设备互连 ( Peripheral Component , 简称为 PCI )总线或扩展工业标准体系结构( Extended Industry Standard Architecture , 简称为 EISA )总线等。 该总线 1304 可以分为地址总线、 数据总线、 控制总线等。 为便于表示, 图 14 中仅用一条粗线表示, 但并不表示仅有一根总线或一种类型的总 线。 其中:
存储器 1302用于存储可执行程序代码, 该程序代码包括计算 机操作指令。 存储器 1302 可能包含高速 RAM存储器, 也可能还 包括非易失性存储器( non-volatile memory ) , 例如至少一个磁盘存 储器。
处理器 1301可能是一个中央处理器( Central Processing Unit , 简称为 CPU ),或者是特定集成电路( Application Specific Integrated Circuit , 简称为 ASIC ) , 或者是被配置成实施本发明实施例的一个 或多个集成电路。 通信接口 1303 , 主要用于实现本实施例中的装置之间的通信。 其中, 处理器 1301 , 用于通过至少一个通信接口 1303通过路 由器接收用户设备 UE发送的注册请求消息, 所述注册请求消息中 包含所述 UE 的用户标识, 其中, 当所述位置服务器接收所述 UE 发送的注册请求消息时, 所述位置服务器生成随机值; 处理器 1301 , 还用于通过至少一个通信接口 1303通过所述路 由器将所述随机值发送给所述 UE , 以使得所述 UE根据所述共享 密钥, 所述 UE的用户标识, 所述随机值以及预先获取的所述位置 服务器的标识符生成临时用户标识; 处理器 1301 , 还用于根据所述 UE的用户标识获取共同密钥, 并根据所述共享密钥, 所述 UE的用户标识, 所述随机值以及所述 位置服务器的标识符生成所述临时用户标识; 存储器 1302 , 用于保存所述生成单元生成的所述临时用户标 识、 所述 UE的用户标识、 所述 UE标识以及所述位置服务器的标 识的对应关系, 并通过所述对应关系识别所述 UE发送的包含所述 临时用户标识的消息。 本发明实施例提供的位置服务器, 用户设备 UE通过注册请求 消息将用户设备的用户标识发送至位置服务器, 并根据该 UE的用 户标识获取所述共享密钥, 用户设备的用户标识, 预先获得的位置 服务器的标识以及共享密钥生成临时用户标识,通过利用随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升了用户网 络体验的安全感。 可选的, 处理器 1301 , 具体还用于: 通过至少一个通信接口 1303通过所述路由器向所述 UE发送认证请求消息,所述认证请求 消息中包括随机值, 以使得所述 UE根据所述共享密钥, 所述 UE 的用户标识,所述随机值以及预先获取的所述位置服务器的标识符 生成临时用户标识, 所述共同密钥与所述 UE的用户标识对应。 可选的, 处理器 1301 , 具体还用于: 通过至少一个通信接口 1303通过所述路由器向所述 UE转发注册响应消息,所述注册响应 消息中包括随机值, 以使得所述 UE根据所述共享密钥, 所述 UE 的用户标识,所述随机值以及预先获取的所述位置服务器的标识符 生成临时用户标识, 所述共同密钥与所述 UE的用户标识对应。 本发明实施例提供的位置服务器, 用户设备 UE通过注册请求 消息将用户设备的用户标识发送至位置服务器, 并根据该 UE的用 户标识获取所述共享密钥, 用户设备的用户标识, 预先获得的位置 服务器的标识以及共享密钥生成临时用户标识,通过利用随机用户
ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升了用户网 络体验的安全感。 本发明的实施例提供一种用户设备 UE 14 , 参照图 15所示, 该用户设备 UE 14 包括: 至少一个处理器 1401、 存储器 1402、 通 信端口 1403 和总线 1404 , 该至少一个处理器 1401、 存储器 1402 和通信接口 1403通过总线 1404连接并完成相互间的通信。 该总线 1404 可以是工业标准体系结构 ( Industry Standard Architecture , 简称为 ISA ) 总线、 夕卜部设备互连 ( Peripheral Component , 简称为 PCI )总线或扩展工业标准体系结构( Extended Industry Standard Architecture , 简称为 EISA )总线等。 该总线 1404 可以分为地址总线、 数据总线、 控制总线等。 为便于表示, 图 15 中仅用一条粗线表示, 但并不表示仅有一根总线或一种类型的总 线。 其中:
存储器 1402用于存储可执行程序代码, 该程序代码包括计算 机操作指令。 存储器 1402 可能包含高速 RAM存储器, 也可能还 包括非易失性存储器( non-volatile memory ) , 例如至少一个磁盘存 储器。 处理器 1401可能是一个中央处理器( Central Processing Unit , 简称为 CPU ),或者是特定集成电路( Application Specific Integrated Circuit , 简称为 ASIC ) , 或者是被配置成实施本发明实施例的一个 或多个集成电路。 通信接口 1403 , 主要用于实现本实施例中的装置之间的通信。 其中, 处理器 1401 , 用于通过至少一个通信接口 1403通过路 由器向位置服务器发送注册请求消息,所述注册请求消息中包含所 述 UE的用户标识, 以使得所述位置服务器在接收到所述 UE的注 册请求消息时生成随机值, 并根据所述随机值、 所述 UE的用户标 识以及所述位置服务器的标识符生成临时用户标识,并保存所述临 时用户标识、 所述 UE 的用户标识、 UE标识以及所述位置服务器 的标识的对应关系,以使得所述位置服务器根据所述对应关系识别 所述 UE的发送的包含所述临时用户标识的消息; 处理器 1401 , 还用于通过至少一个通信接口 1403通过所述路 由器接收所述临时用户标识。 本发明实施例提供的用户设备, 用户设备 UE通过注册请求消 息将用户设备的用户标识发送至位置服务器, 并根据该 UE的用户 标识获取所述共享密钥, 用户设备的用户标识, 预先获得的位置服 务器的标识以及共享密钥生成临时用户标识, 通过利用随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升了用户网 络体验的安全感。 进一步的, 处理器 1401 , 具体还用于通过至少一个通信接口 1403 通过所述路由器接收所述位置服务器发送的注册响应消息, 所述注册响应消息中包括所述临时用户标识。 本发明实施例提供的用户设备,位置服务器根据随机生成的随 机值生成临时用户标识,并通过注册响应消息携带临时用户标识经 由路由器发送至用户设备 UE ,进而通过利用随机用户 ID隐藏用户 真实 ID , 解决了用户隐私暴露的问题, 提升了用户网络体验的安 全感。 本发明的实施例提供一种位置服务器 SLS 15 ,参照图 16所示, 该位置服务器 SLS 15 包括: 至少一个处理器 1501、 存储器 1502、 通信端口 1503和总线 1504 ,该至少一个处理器 1501、存储器 1502 和通信接口 1503通过总线 1504连接并完成相互间的通信。 该总线 1504 可以是工业标准体系结构 ( Industry Standard Architecture , 简称为 ISA ) 总线、 夕卜部设备互连 ( Peripheral Component , 简称为 PCI )总线或扩展工业标准体系结构( Extended Industry Standard Architecture , 简称为 EISA )总线等。 该总线 1504 可以分为地址总线、 数据总线、 控制总线等。 为便于表示, 图 16 中仅用一条粗线表示, 但并不表示仅有一根总线或一种类型的总 线。 其中:
存储器 1502用于存储可执行程序代码, 该程序代码包括计算 机操作指令。 存储器 1 502 可能包含高速 RAM存储器, 也可能还 包括非易失性存储器( non-volatile memory ) , 例如至少一个磁盘存 储器。
处理器 1501可能是一个中央处理器( Central Processing Unit , 简称为 CPU ),或者是特定集成电路( Application Specific Integrated Circuit , 简称为 ASIC ) , 或者是被配置成实施本发明实施例的一个 或多个集成电路。
通信接口 1503 , 主要用于实现本实施例中的装置之间的通信。 其中, 处理器 1501 , 用于通过至少一个通信接口 1503通过路 由器接收用户设备 UE发送的注册请求消息, 所述注册请求消息中 包含所述 UE的用户标识, 其中, 当所述位置服务器接收所述用户 设备 UE发送的注册请求消息时, 所述位置服务器生成随机值; 处理器 1501 , 还用于根据所述随机值、 所述 UE的用户标识以 及所述位置服务器的标识符生成临时用户标识; 存储器 1502 , 用于保存所述生成单元生成的所述临时用户标 识、 所述 UE 的用户标识、 UE标识以及所述位置服务器的标识的 对应关系, 以使得所述位置服务器根据所述对应关系识别所述 UE 的发送的包含所述临时用户标识的消息; 处理器 1501 , 还用于通过至少一个通信接口 1 503通过所述路 由器将所述生成单元生成的所述临时用户标识转发至所述 UE。 本发明实施例提供的位置服务器, 用户设备 UE通过注册请求 消息将用户设备的用户标识发送至位置服务器, 并根据该 UE的用 户标识获取所述共享密钥, 用户设备的用户标识, 预先获得的位置 服务器的标识以及共享密钥生成临时用户标识,通过利用随机用户 ID隐藏用户真实 ID , 解决了用户隐私暴露的问题, 提升了用户网 络体验的安全感。 可选的, 处理器 1501 , 具体还用于: 根据所述随机值、 共享 密钥、 所述 UE的用户标识以及所述位置服务器的标识符生成临时 用户标识, 所述共同密钥与所述 UE的用户标识对应。 可选的, 处理器 1501, 具体还用于: 通过至少一个通信接口 1503通过所述路由器转发注册响应消息至所述 UE , 所述注册响应 消息中包括所述临时用户标识。 本发明实施例提供的位置服务器,位置服务器根据随机生成的 随机值生成临时用户标识,并通过注册响应消息携带临时用户标识 经由路由器发送至用户设备 UE,进而通过利用随机用户 ID隐藏用 户真实 ID, 解决了用户隐私暴露的问题, 提升了用户网络体验的 安全感。
本发明的实施例提供一种通信系统 16,参照图 17所示, 包括: 位置服务器 SLS 1601、 域路由器 DR 1602以及与 DR连接的用户 设备 UE 1603, 其中, 该位置服务器 SLS 1601为图 10所示的位置服务器 SLS; 该用户设备 UE 1603为图 9所示的用户设备 UE; 或者, 该位置服务器 SLS 1601为图 12所示的位置服务器 SLS; 该用户设备 UE 1603为图 11所示的用户设备 UE; 或者,
该位置服务器 SLS 1601为图 14所示的位置服务器 SLS; 该用户设备 UE 1603为图 13所示的用户设备 UE; 或者, 该位置服务器 SLS 1601为图 16所示的位置服务器 SLS; 该用户设备 UE 1603为图 15所示的用户设备 UE。 本发明实施例提供的通信系统, 用户设备 UE通过注册请求消 息将用户设备的用户标识发送至位置服务器, 并根据该 UE的用户 标识获取所述共享密钥, 用户设备的用户标识, 预先获得的位置服 务器的标识以及共享密钥生成临时用户标识, 通过利用随机用户 ID隐藏用户真实 ID, 解决了用户隐私暴露的问题, 提升了用户网 络体验的安全感。 通过以上的实施方式的描述,所属领域的技术人员可以清楚地 了解到本发明可以用硬件实现, 或固件实现, 或它们的组合方式来 实现。 当使用软件实现时, 可以将上述功能存储在计算机可读介质 中或作为计算机可读介质上的一个或多个指令或代码进行传输。计 算机可读介质包括计算机存储介质和通信介质,其中通信介质包括 便于从一个地方向另一个地方传送计算机程序的任何介质。存储介 质可以是计算机能够存取的任何可用介质。 以此为例但不限于: 计 算机可读介质可以包括 RAM、 ROM ( Read Only Memory , 只读存 储器)或其他光盘存储、 磁盘存储介质或者其他磁存储设备、 或者 能够用于携带或存储具有指令或数据结构形式的期望的程序代码 并能够由计算机存取的任何其他介质。 此外。 任何连接可以适当的 成为计算机可读介质。 例如, 如果软件是使用同轴电缆、 光纤光缆、 双绞线、 数字用户线 ( DSL ) 或者诸如红外线、 无线电和微波之类 的无线技术从网站、服务器或者其他远程源传输的,那么同轴电缆、 光纤光缆、 双绞线、 DSL或者诸如红外线、 无线和微波之类的无线 技术包括在所属介质的定影中。 如本发明所使用的, 盘 ( Disk ) 和 碟( disc )包括压缩光碟( CD )、激光碟、光碟、数字通用光碟( DVD )、 软盘和蓝光光碟, 其中盘通常磁性的复制数据, 而碟则用激光来光 学的复制数据。上面的组合也应当包括在计算机可读介质的保护范 围之内。
以上所述, 仅为本发明的具体实施方式, 但本发明的保护范围 并不局限于此,任何熟悉本技术领域的技术人员在本发明揭露的技 术范围内, 可轻易想到变化或替换, 都应涵盖在本发明的保护范围 之内。因此,本发明的保护范围应所述以权利要求的保护范围为准。

Claims

权 利 要 求 书
1、 一种用户隐私保护的方法, 其特征在于, 包括: 用户设备 UE 通过路由器向位置服务器发送注册请求消息, 以使得 所述位置服务器在接收到所述 UE的注册请求消息时生成随机值,并将所 述随机值发送给所述 UE ,所述注册请求消息中包含所述 UE的用户标识 , 以使得所述位置服务器根据所述随机值、 共同密钥、 所述 UE的用户标识 以及所述位置服务器的标识符生成临时用户标识, 并保存所述临时用户 标识、 所述 UE的用户标识、 UE标识以及所述位置服务器的标识的对应 关系,以使得所述位置服务器根据所述对应关系识别所述 U E的发送的包 含所述临时用户标识的消息, 所述共同密钥与所述 UE的用户标识对应; 所述 UE通过所述路由器接收所述位置服务器发送的所述随机值; 所述 UE根据所述共享密钥, 所述 UE的用户标识, 所述随机值以及 预先获取的所述位置服务器的标识符生成所述临时用户标识, 所述共同 密钥与所述 UE的用户标识对应。
2、 根据权利要求 1所述的方法, 其特征在于, 所述 UE通过所述路 由器接收所述位置服务器发送的所述随机值包括: 所述 UE通过所述路由器接收所述位置服务器发送的认证请求消息, 所述认证请求消息中包括所述随机值。
3、 根据权利要求 1所述的方法, 其特征在于, 所述 UE通过所述路 由器接收所述位置服务器发送的所述随机值包括: 所述 UE通过所述路由器接收所述位置服务器发送的注册响应消息 , 所述注册响应消息中包括所述随机值。
4、 一种用户隐私保护的办法, 其特征在于, 包括: 位置服务器通过路由器接收用户设备 UE发送的注册请求消息, 所 述注册请求消息中包含所述 UE的用户标识, 其中, 当所述位置服务器接 收所述 U E发送的注册请求消息时, 所述位置服务器生成随机值; 所述位置服务器通过所述路由器将所述随机值发送给所述 UE ,以使 得所述 UE根据所述共享密钥, 所述 UE的用户标识, 所述随机值以及预 先获取的所述位置服务器的标识符生成临时用户标识; 所述位置服务器根据所述 UE 的用户标识获取共同密钥, 并根据所 述共享密钥, 所述 UE的用户标识, 所述随机值以及所述位置服务器的标 识符生成所述临时用户标识; 所述位置服务器保存所述临时用户标识、 所述 UE 的用户标识、 所 述 U E标识以及所述位置服务器的标识的对应关系,并通过所述对应关系 识别所述 UE发送的包含所述临时用户标识的消息。
5、 根据权利要求 4所述的方法, 其特征在于, 所述位置服务器通过 所述路由器将所述随机值发送给所述 UE包括: 所述位置服务器通过所述路由器向所述 UE 发送认证请求消息, 所 述认证请求消息中包括随机值, 以使得所述 UE根据所述共享密钥, 所述 UE的用户标识, 所述随机值以及预先获取的所述位置服务器的标识符生 成临时用户标识, 所述共同密钥与所述 UE的用户标识对应。
6、 根据要求 4所述的方法, 其特征在于, 所述位置服务器通过所述 路由器将所述随机值发送给所述 UE包括: 所述位置服务器通过所述路由器向所述 UE 转发注册响应消息, 所 述注册响应消息中包括随机值, 以使得所述 UE根据所述共享密钥, 所述 UE的用户标识, 所述随机值以及预先获取的所述位置服务器的标识符生 成临时用户标识, 所述共同密钥与所述 UE的用户标识对应。
7、 一种用户隐私保护的方法, 其特征在于, 包括: 用户设备 UE 通过路由器向位置服务器发送注册请求消息, 所述注 册请求消息中包含所述 UE的用户标识,以使得所述位置服务器在接收到 所述 UE的注册请求消息时生成随机值, 并根据所述随机值、 所述 UE的 用户标识以及所述位置服务器的标识符生成临时用户标识, 并保存所述 临时用户标识、 所述 UE的用户标识、 UE标识以及所述位置服务器的标 识的对应关系,以使得所述位置服务器根据所述对应关系识别所述 UE的 发送的包含所述临时用户标识的消息; 所述 UE通过所述路由器接收所述临时用户标识。
8、 根据权利要求 7所述的方法, 其特征在于, 所述 UE通过所述路 由器接收所述临时用户标识包括: 所述 UE通过所述路由器接收所述位置服务器发送的注册响应消息 , 所述注册响应消息中包括所述临时用户标识。
9、 一种用户隐私保护的方法, 其特征在于, 包括: 位置服务器通过路由器接收用户设备 UE发送的注册请求消息, 所 述注册请求消息中包含所述 UE的用户标识, 其中, 当所述位置服务器接 收所述用户设备 UE 发送的注册请求消息时, 所述位置服务器生成随机 值; 所述位置服务器根据所述随机值、 所述 UE 的用户标识以及所述位 置服务器的标识符生成临时用户标识; 所述位置服务器保存所述临时用户标识、 所述 UE的用户标识、 UE 标识以及所述位置服务器的标识的对应关系, 以使得所述位置服务器根 据所述对应关系识别所述 UE的发送的包含所述临时用户标识的消息; 所述位置服务器通过所述路由器将所述临时用户标识转发至所述
UE。
10、 根据权利要求 9所述的方法, 其特征在于, 所述位置服务器根 据所述随机值、所述 U E的用户标识以及所述位置服务器的标识符生成临 时用户标识包括: 所述位置服务器根据所述随机值、 共享密钥、 所述 UE 的用户标识 以及所述位置服务器的标识符生成临时用户标识, 所述共同密钥与所述 UE的用户标识对应。
1 1、 根据权利要求 9所述的方法, 其特征在于, 所述位置服务器通 过所述路由器将所述临时用户标识转发至所述 UE, 包括: 所述位置服务器通过所述路由器转发注册响应消息至所述 UE ,所述 注册响应消息中包括所述临时用户标识。
12、 一种用户设备, 其特征在于, 包括: 通信单元, 用于通过路由器向位置服务器发送注册请求消息, 以使 得所述位置服务器在接收到所述 UE的注册请求消息时生成随机值,并将 所述随机值发送给所述 UE , 所述注册请求消息中包含所述 UE的用户标 识, 以使得所述位置服务器根据所述随机值、 共同密钥、 所述 UE的用户 标识以及所述位置服务器的标识符生成临时用户标识, 并保存所述临时 用户标识、 所述 UE的用户标识、 UE标识以及所述位置服务器的标识的 对应关系,以使得所述位置服务器根据所述对应关系识别所述 UE的发送 的包含所述临时用户标识的消息,所述共同密钥与所述 UE的用户标识对 应; 所述通信单元, 还用于通过所述路由器接收所述位置服务器发送的 所述随机值; 生成单元, 用于根据所述共享密钥, 所述 UE 的用户标识, 所述随 机值以及预先获取的所述位置服务器的标识符生成所述临时用户标识, 所述共同密钥与所述 UE的用户标识对应。
13、根据权利要求 12所述的用户设备,其特征在于, 所述通信单元, 具体还用于: 通过所述路由器接收所述位置服务器发送的认证请求消息, 所述认 证请求消息中包括所述随机值。
14、根据权利要求 12所述的用户设备,其特征在于, 所述通信单元, 具体还用于: 通过所述路由器接收所述位置服务器发送的注册响应消息, 所述注 册响应消息中包括所述随机值。
15、 一种位置服务器, 其特征在于, 包括: 通信单元, 用于通过路由器接收用户设备 UE发送的注册请求消息, 所述注册请求消息中包含所述 UE的用户标识, 其中, 当所述位置服务器 接收所述 U E发送的注册请求消息时, 所述位置服务器生成随机值; 所述通信单元, 还用于通过所述路由器将所述随机值发送给所述 UE, 以使得所述 UE 居所述共享密钥, 所述 UE的用户标识, 所述随 机值以及预先获取的所述位置服务器的标识符生成临时用户标识; 生成单元, 用于根据所述 UE 的用户标识获取共同密钥, 并根据所 述共享密钥, 所述 UE的用户标识, 所述随机值以及所述位置服务器的标 识符生成所述临时用户标识; 存储单元, 用于保存所述生成单元生成的所述临时用户标识、 所述 UE的用户标识、 所述 UE标识以及所述位置服务器的标识的对应关系, 并通过所述对应关系识别所述 UE发送的包含所述临时用户标识的消息。
16、 根据权利要求 15所述的位置服务器, 其特征在于, 所述通信单 元, 具体还用于: 通过所述路由器向所述 UE 发送认证请求消息, 所述认证请求消息 中包括随机值,以使得所述 UE根据所述共享密钥,所述 UE的用户标识, 所述随机值以及预先获取的所述位置服务器的标识符生成临时用户标 识, 所述共同密钥与所述 UE的用户标识对应。
17、 根据权利要求 15所述的位置服务器, 其特征在于, 所述通信单 元, 具体还用于: 通过所述路由器向所述 UE 转发注册响应消息, 所述注册响应消息 中包括随机值,以使得所述 UE根据所述共享密钥,所述 UE的用户标识, 所述随机值以及预先获取的所述位置服务器的标识符生成临时用户标 识, 所述共同密钥与所述 UE的用户标识对应。
18、 一种用户设备, 其特征在于, 包括: 发送单元, 用于通过路由器向位置服务器发送注册请求消息, 所述 注册请求消息中包含所述 UE的用户标识,以使得所述位置服务器在接收 到所述 UE的注册请求消息时生成随机值, 并根据所述随机值、 所述 UE 的用户标识以及所述位置服务器的标识符生成临时用户标识, 并保存所 述临时用户标识、 所述 UE的用户标识、 UE标识以及所述位置服务器的 标识的对应关系, 以使得所述位置服务器根据所述对应关系识别所述 UE 的发送的包含所述临时用户标识的;肖 , ; 接收单元, 用于通过所述路由器接收所述临时用户标识。
19、根据权利要求 18所述的用户设备, 其特征在于, 所述接收单元, 具体还用于: 通过所述路由器接收所述位置服务器发送的注册响应消息, 所述注 册响应消息中包括所述临时用户标识。
20、 一种位置服务器, 其特征在于, 包括: 通信单元, 用于通过路由器接收用户设备 UE发送的注册请求消息, 所述注册请求消息中包含所述 UE的用户标识, 其中, 当所述位置服务器 接收所述用户设备 UE发送的注册请求消息时,所述位置服务器生成随机 值; 生成单元, 用于根据所述随机值、 所述 UE 的用户标识以及所述位 置服务器的标识符生成临时用户标识; 存储单元, 用于保存所述生成单元生成的所述临时用户标识、 所述 UE 的用户标识、 UE标识以及所述位置服务器的标识的对应关系, 以使 得所述位置服务器根据所述对应关系识别所述 UE 的发送的包含所述临 时用户标识的消息; 所述通信单元, 还用于通过所述路由器将所述生成单元生成的所述 临时用户标识转发至所述 UE。
21、 根据权利要求 20所述的位置服务器, 其特征在于, 所述生成单 元, 具体还用于: 根据所述随机值、 共享密钥、 所述 UE 的用户标识以及所述位置服 务器的标识符生成临时用户标识,所述共同密钥与所述 UE的用户标识对 应。
22、 根据权利要求 20所述的位置服务器, 其特征在于, 所述通信单 元, 具体还用于: 通过所述路由器转发注册响应消息至所述 UE,所述注册响应消息中 包括所述临时用户标识。
23、 一种通信系统, 其特征在于, 包括: 位置服务器、 路由器以及 与所述路由器连接的用户设备 UE, 其中, 所述位置服务器为权利要求 15〜17所述的位置服务器; 所述用户设备 UE为权利要求 12〜14所述的用户设备; 或者, 所述位置服务器为权利要求 20〜22所述的位置服务器; 所述用户设备 UE为权利要求 18〜19所述的用户设备。
PCT/CN2014/080869 2014-02-27 2014-06-26 一种用户隐私保护的方法、设备和系统 WO2015127736A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410070160.3A CN104883339B (zh) 2014-02-27 2014-02-27 一种用户隐私保护的方法、设备和系统
CN201410070160.3 2014-02-27

Publications (1)

Publication Number Publication Date
WO2015127736A1 true WO2015127736A1 (zh) 2015-09-03

Family

ID=53950674

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/080869 WO2015127736A1 (zh) 2014-02-27 2014-06-26 一种用户隐私保护的方法、设备和系统

Country Status (2)

Country Link
CN (1) CN104883339B (zh)
WO (1) WO2015127736A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109889541A (zh) * 2019-03-25 2019-06-14 郑州轻工业学院 具备匿名奖励分发和身份隐私保护的移动设备认证方法

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106254308A (zh) * 2016-07-01 2016-12-21 捷开通讯科技(上海)有限公司 通讯装置隐私保护系统及方法
KR102212873B1 (ko) 2018-07-03 2021-02-09 한양대학교 산학협력단 메시지 전송 요청 장치 및 그 방법, 메시지 전송 관리 서버, 그리고 기지국
CN110858992A (zh) 2018-08-23 2020-03-03 华为技术有限公司 路由方法、装置及系统
CN109842880B (zh) * 2018-08-23 2020-04-03 华为技术有限公司 路由方法、装置及系统
CN110069945B (zh) * 2019-04-11 2021-02-26 西华大学 一种用户隐私保护的方法、设备和系统

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1313287A2 (en) * 2001-11-20 2003-05-21 Nokia Corporation SIP-level confidentiality protection
CN101272589A (zh) * 2007-03-21 2008-09-24 展讯通信(上海)有限公司 一种切换手机设备号保护用户隐私的方法及其手机
CN101488945A (zh) * 2008-01-14 2009-07-22 北京大唐高鸿数据网络技术有限公司 一种面向会话初始化协议的鉴权方法
CN103281672A (zh) * 2013-06-08 2013-09-04 南京大学 一种移动终端进行位置隐私保护的方法

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101499959B (zh) * 2008-01-31 2012-08-08 华为技术有限公司 配置密钥的方法、装置及系统
CN102348280B (zh) * 2010-08-02 2016-05-25 中兴通讯股份有限公司 获取终端位置信息的方法、系统和设备

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1313287A2 (en) * 2001-11-20 2003-05-21 Nokia Corporation SIP-level confidentiality protection
CN101272589A (zh) * 2007-03-21 2008-09-24 展讯通信(上海)有限公司 一种切换手机设备号保护用户隐私的方法及其手机
CN101488945A (zh) * 2008-01-14 2009-07-22 北京大唐高鸿数据网络技术有限公司 一种面向会话初始化协议的鉴权方法
CN103281672A (zh) * 2013-06-08 2013-09-04 南京大学 一种移动终端进行位置隐私保护的方法

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109889541A (zh) * 2019-03-25 2019-06-14 郑州轻工业学院 具备匿名奖励分发和身份隐私保护的移动设备认证方法

Also Published As

Publication number Publication date
CN104883339A (zh) 2015-09-02
CN104883339B (zh) 2019-06-21

Similar Documents

Publication Publication Date Title
KR101528410B1 (ko) 다이나믹 호스트 컨피규레이션 및 네트워크 액세스 인증
WO2015127736A1 (zh) 一种用户隐私保护的方法、设备和系统
US11546308B2 (en) Message processing for subscriber sessions which stretch over different network domains
EP3720100A1 (en) Service request processing method and device
US8737396B2 (en) Communication method and communication system
WO2015123953A1 (zh) 一种密钥生成的方法、设备及系统
TW201935991A (zh) 待配網設備連接網路熱點設備的方法和系統
US11418951B2 (en) Method for identifying encrypted data stream, device, storage medium and system
JP2019515555A (ja) 識別情報指向型ネットワークの匿名識別情報及びプロトコル
WO2011140919A1 (zh) 接入业务批发网络的方法、设备、服务器和系统
US11088996B1 (en) Secure network protocol and transit system to protect communications deliverability and attribution
WO2012130128A1 (zh) 一种实现网络标识转换的方法、装置及系统
JP2007082079A (ja) ネットワーク間接続装置、及びそれを用いた簡易認証システムとその認証方法
JP2005167646A (ja) 接続制御システム、接続制御装置、及び接続管理装置
WO2011131002A1 (zh) 身份管理方法及系统
US8667564B1 (en) Mobile internet protocol V6 SIP proxy bootstrapping
JP2018174550A (ja) 通信システム
WO2015131567A1 (zh) 一种IPv6地址管理方法、装置和终端
JP2011176469A (ja) 通信方法および通信システム
WO2019076025A1 (zh) 一种加密数据流的识别方法、设备、存储介质及系统
US10841283B2 (en) Smart sender anonymization in identity enabled networks
WO2012075770A1 (zh) 身份位置分离网络的阻断方法和系统
JP2006295340A (ja) 認証ゲートウェイ装置及びそのプログラム
CN117749471A (zh) Nat穿越的isakmp协商方法及相关装置
TW202133587A (zh) 在通訊網路中更新錨定密鑰與應用服務進行安全通訊的方法、裝置和系統

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14883609

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 14883609

Country of ref document: EP

Kind code of ref document: A1