WO2015180324A1 - 主叫用户认证方法、装置及系统 - Google Patents

主叫用户认证方法、装置及系统 Download PDF

Info

Publication number
WO2015180324A1
WO2015180324A1 PCT/CN2014/087233 CN2014087233W WO2015180324A1 WO 2015180324 A1 WO2015180324 A1 WO 2015180324A1 CN 2014087233 W CN2014087233 W CN 2014087233W WO 2015180324 A1 WO2015180324 A1 WO 2015180324A1
Authority
WO
WIPO (PCT)
Prior art keywords
authentication code
user
control point
service control
calling user
Prior art date
Application number
PCT/CN2014/087233
Other languages
English (en)
French (fr)
Inventor
胡继东
孙晓勇
赵明光
徐锋
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Priority to MYPI2016703228A priority Critical patent/MY192512A/en
Publication of WO2015180324A1 publication Critical patent/WO2015180324A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication

Definitions

  • the present invention relates to the field of communications, and in particular to a method, device and system for calling subscriber authentication.
  • a called terminal which allows the calling user to automatically connect after dialing, and the user can hear the ambient sound near the called terminal after the connection. If a malicious user dials the terminal and can automatically connect, there is a hidden danger to the personal security of the called user. Therefore, for such a called terminal, the calling user needs to be authenticated on the network side, and only when the authentication is passed, the automatic connection is automatically performed.
  • the HLR Home Location Register
  • the MSC Mobile Switching Center
  • the GMSC Gateway Mobile Switching Center
  • the MGW Media Gateway
  • the Service Control Point (SCP) is an important part of the intelligent network. It determines how calls are handled. Non-intelligent calls do not involve SCP.
  • RNC Radio Network Controller
  • BSC Base Station Controller
  • the first method requires frequent changes to allow the number in the calling number library, and the process is cumbersome.
  • the second method requires the addition of dedicated network equipment to increase deployment costs.
  • all call authorization codes are concentrated on one network device, reducing security.
  • the embodiment of the invention provides a method, a device and a system for a calling user to solve the problem that the process of authenticating the calling user in the related art is cumbersome or the deployment cost is high.
  • a method for authenticating a calling user includes: after receiving a service request by a calling user to call a called user, the service control point instructs the media gateway to prompt the calling user to input an authentication code; The service control point acquires an authentication code input by the calling user; and the service control point checks the authentication code input by the calling user according to a preset authentication code.
  • the preset authentication code is divided into two segments: a first authentication code segmentation information and a second authentication code segmentation information, where the first authentication code segmentation information is stored in the attribution of the called user.
  • the second authentication code segmentation information is stored in the service control point; before the verification of the authentication code input by the calling user, the method further includes: obtaining, by the service control point The first authentication code segmentation information; the service control point combines the first authentication code segmentation information with the locally saved second authentication code segmentation information to generate a complete preset authentication code.
  • the obtaining, by the service control point, the first authentication code segment information includes: receiving, by the mobile switching center gateway, a route query request of the called user; and the mobile switching center gateway to the called user
  • the home location register sends a route query request; the mobile switching center gateway receives the routing information returned by the home location register, where the routing information includes the first authentication code segmentation information; the mobile switching center The gateway sends the service request to the service control point, where the service request carries the first authentication code segment information.
  • the service control point instructs the media gateway to prompt the calling user to input an authentication code
  • the service control point instructs the mobile switching center gateway to play an authentication code input prompt tone to the calling user
  • the mobile switching center gateway instructs the media gateway to play a voice, prompting the calling user to input an authentication code
  • the obtaining, by the service control point, the first authentication code segment information includes: receiving, by the mobile switching center gateway, an authentication code input by the calling user, and inputting the authentication code of the calling user Sent to the service control point.
  • the obtaining, by the service control point, the first authentication code segment information includes: the service control point receiving the service request sent by the mobile switching center on the called side, where the service request carries The first authentication code segmentation information obtained by the mobile switching center on the called side from the home location register during the location update process of the called user.
  • the service control point indicates that the media gateway prompts the calling user to input an authentication code
  • the service control point indicates that the mobile switching center on the called side plays an authentication code input prompt tone to the calling user.
  • the mobile switching center on the called side instructs the media gateway to play a voice, prompting the user to input an authentication code.
  • the service control point acquires the authentication code input by the calling user, where: the mobile switching center on the called side acquires an authentication code input by the calling user; and the mobile switching on the called side The center sends the authentication code input by the calling user to the service control point.
  • the method further includes: determining that the called user subscribes to the authentication service;
  • a calling user authentication apparatus comprising: an indication module, configured to: after receiving a service request by a calling user to call a called user, at a service control point, instructing the media gateway to prompt the The calling user inputs an authentication code; the obtaining module is configured to obtain an authentication code input by the calling user; and the checking module is configured to check the authentication code input by the calling user according to the preset authentication code.
  • the preset authentication code is divided into two segments: a first authentication code segmentation information and a second authentication code segmentation information, where the first authentication code segmentation information is stored in the attribution of the called user.
  • the second authentication code segmentation information is stored in the service control point;
  • the obtaining module includes: an obtaining unit, configured to acquire the first authentication code segmentation information; and a generating unit, configured to And combining the first authentication code segmentation information with the second authentication code segmentation information saved by the service control point to generate a complete the preset authentication code.
  • the device further includes: a determining module, configured to determine whether the called user subscribes to the authentication service, and if yes, trigger the indication module to instruct the media gateway to prompt the calling user to input an authentication code.
  • a determining module configured to determine whether the called user subscribes to the authentication service, and if yes, trigger the indication module to instruct the media gateway to prompt the calling user to input an authentication code.
  • a service control point including the apparatus described above.
  • a caller authentication system including the above-described service control point.
  • the system further includes: a home location register, configured to store first authentication code segment information of the preset authentication code of the user; and the mobile switching center gateway is configured to receive the routing query request of the called user And acquiring the first authentication code segmentation information of the called user from the home location register, and sending the first authentication code segmentation information to the service control point by using a service request.
  • a home location register configured to store first authentication code segment information of the preset authentication code of the user
  • the mobile switching center gateway is configured to receive the routing query request of the called user And acquiring the first authentication code segmentation information of the called user from the home location register, and sending the first authentication code segmentation information to the service control point by using a service request.
  • the service control point is further configured to instruct the mobile switching center gateway to play an authentication code input prompt tone to the calling user; the mobile switching center gateway is further configured to instruct the media gateway to play a voice, prompting the The calling user enters the authentication code.
  • the mobile switching center gateway is further configured to receive an authentication code input by the calling user, and send the authentication code input by the calling user to the service control point.
  • the system further includes: a home location register, configured to store first authentication code segment information of the preset authentication code of the user; and a mobile switching center on the called side, configured to send to the service control point The service request, wherein the service request carries the first of the called user acquired by the mobile switching center on the called side from the home location register during the location update process of the called user Authentication code segmentation information.
  • a home location register configured to store first authentication code segment information of the preset authentication code of the user
  • a mobile switching center on the called side configured to send to the service control point The service request, wherein the service request carries the first of the called user acquired by the mobile switching center on the called side from the home location register during the location update process of the called user Authentication code segmentation information.
  • the service control point is further configured to: indicate that the mobile switching center on the called side plays an authentication code input prompt tone to the calling user; and the mobile switching center on the called side is further configured to indicate the The media gateway plays the tone and prompts the user to enter the authentication code.
  • the mobile switching center on the called side is further configured to acquire an authentication code input by the calling user, and send the authentication code input by the calling user to the service control point.
  • the service control point in the process of the calling user calling the called user, the service control point prompts the calling user to input the authentication code, and then authenticates the calling user according to the authentication code preset by the called user, thereby avoiding the use of the allowed call.
  • the number library brings a cumbersome operation, and there is no need to set up a dedicated network device, which reduces the cost.
  • FIG. 1 is a schematic diagram of a network side of a call in a circuit domain in a mobile communication system
  • FIG. 2 is a flowchart of a calling user authentication method according to an embodiment of the present invention.
  • FIG. 3 is a schematic structural diagram of a calling user authentication apparatus according to an embodiment of the present invention.
  • Figure 4 is a flow chart of the first embodiment
  • Figure 5 is a flow chart of the second embodiment
  • Figure 6 is a flow chart of the third embodiment.
  • the present invention provides an improved calling user authentication scheme.
  • the calling user dials the called user
  • the calling user must According to the voice prompt, enter the correct dialing authentication code, the call can be connected.
  • the called user is a smart user
  • the special intelligent service (which can be called authentication service) is signed, and the authentication code is triggered by the smart service. process.
  • the setting of the authentication code of the called user may be manually set by the user to the operator's business hall, or may be dialed by the service provider's service number, and the setting is performed remotely by the customer service personnel. limited.
  • a calling user authentication method is provided.
  • FIG. 2 is a flowchart of a method for authenticating a calling user according to an embodiment of the present invention. As shown in FIG. 2, the method mainly includes the following steps:
  • Step S202 after receiving the service request of the called user to call the called user, the service control point instructs the media gateway to prompt the calling user to input the authentication code.
  • Step S204 the service control point acquires an authentication code input by the calling user.
  • Step S204 The service control point checks the authentication code input by the calling user according to a preset authentication code.
  • the preset authentication code may be divided into two segments: a first authentication code segment information and a second authentication code segment information. And storing the first authentication code segmentation information in a home location register of the called user, and storing the second authentication code segmentation information in the service control point.
  • the method may further include: the service control point acquiring the first authentication code segmentation information; the service The control point combines the first authentication code segmentation information with the locally saved second authentication code segmentation information to generate a complete the preset authentication code.
  • each segment of the authentication code may also be encrypted.
  • the authentication code may be segmented in multiple manners, and a specific segmentation mode may be specified in the SCP. For example, if the authentication code is 6 bits in length, at least one of the following methods may be used. Segment:
  • the first three digits of the authentication code are divided into one segment, the last three digits are divided into one segment, the first three digits are stored in the HLR, and the third digit is saved in the SCP;
  • the odd number of the authentication code is divided into one segment, the even number is another segment, the odd bit is stored in the HLR, and the even bit is stored in the SCP;
  • the odd number of the authentication code is divided into one segment, the even number is another segment, the even bit is stored in the HLR, and the odd bit is stored in the SCP;
  • the service control point may obtain the first authentication code segment information by using the network element on the calling side, and obtain the first authentication code segment information by using the network element on the called side, which are respectively described below.
  • the obtaining, by the service control point, the first authentication code segmentation information may include: receiving, by the mobile switching center gateway, a route query request of the called user; a switching center gateway sends a routing query request to the home location register of the called user; the mobile switching center gateway receives routing information returned by the home location register, where the routing information includes the first authentication The code segmentation information; the mobile switching center gateway sends the service request to the service control point, where the service request carries the first authentication code segmentation information.
  • the service control point instructing the media gateway to prompt the calling user to input the authentication code may include: the service control point instructing the mobile switching center gateway to the calling user Playing the authentication code input prompt tone; the mobile switching center gateway instructing the media gateway to play a voice, prompting the calling user to input an authentication code.
  • the obtaining, by the service control point, the first authentication code segment information includes: receiving, by the mobile switching center gateway, an authentication code input by the calling user, and inputting the authentication code of the calling user Sent to the service control point.
  • the acquiring, by the service control point, the first authentication code segment information may include: the service control point receiving the location sent by the mobile switching center on the called side The service request, wherein the service request carries the first authentication code segment obtained by the mobile switching center on the called side from the home location register during a location update process of the called user information.
  • the service control point indicates that the media gateway prompts the calling user to input an authentication code
  • the service control point indicates that the mobile switching center on the called side plays an authentication code input prompt tone to the calling user.
  • the mobile switching center on the called side instructs the media gateway to play a voice, prompting the user to input an authentication code.
  • the service control point acquires the authentication code input by the calling user, where: the mobile switching center on the called side acquires an authentication code input by the calling user; and the mobile switching on the called side The center sends the authentication code input by the calling user to the service control point.
  • the method further includes: determining the called party The user has signed up for the certification business. That is, in the embodiment of the present invention, only the calling user of the user who has signed the authentication service is authenticated.
  • a calling user authentication apparatus is further provided.
  • FIG. 3 is a schematic structural diagram of a calling user authentication apparatus according to an embodiment of the present invention.
  • the apparatus mainly includes: an indicating module 30, configured to receive, at a service control point, a service of a calling user to call a called user. After the request, the media gateway is instructed to prompt the calling user to input an authentication code; the obtaining module 32 is configured to obtain an authentication code input by the calling user; and the verification module 34 is configured to: according to the preset authentication code, the master The authentication code entered by the user is checked.
  • the preset authentication code is divided into two segments: a first authentication code segmentation information and a second authentication code segmentation information, where the first authentication code segmentation information is stored in the attribution of the called user.
  • the second authentication code segmentation information is stored in the service control point;
  • the obtaining module may include: an obtaining unit, configured to acquire the first authentication code segmentation information; a generating unit, setting And combining the first authentication code segmentation information with the second authentication code segmentation information saved by the service control point to generate a complete the preset authentication code.
  • the acquiring unit may obtain the first authentication segment information according to the optional implementation manner in the foregoing method.
  • the device further includes: a determining module, configured to determine whether the called user subscribes to the authentication service, and if yes, trigger the indication module to instruct the media gateway to prompt the calling user to input an authentication code.
  • a determining module configured to determine whether the called user subscribes to the authentication service, and if yes, trigger the indication module to instruct the media gateway to prompt the calling user to input an authentication code.
  • a service control point is also provided, the service control point comprising the above device.
  • a calling user authentication system is further provided, including the foregoing service control point.
  • the system may further include: a home location register, configured to store first authentication code segmentation information of the preset authentication code of the user; and the mobile switching center gateway is set to Obtaining, by the home location register, the first authentication code segmentation information of the called user, and sending the first authentication code segmentation information to the office by using a service request, when receiving the route query request of the called user Said business control point.
  • a home location register configured to store first authentication code segmentation information of the preset authentication code of the user
  • the mobile switching center gateway is set to Obtaining, by the home location register, the first authentication code segmentation information of the called user, and sending the first authentication code segmentation information to the office by using a service request, when receiving the route query request of the called user Said business control point.
  • the service control point is further configured to instruct the mobile switching center gateway to play an authentication code input prompt tone to the calling user; the mobile switching center gateway is further configured to indicate the media gateway Playback, prompting the calling user to enter an authentication code.
  • the mobile switching center gateway is further configured to receive an authentication code input by the calling user, and send the authentication code input by the calling user to the service control point.
  • the system further includes: a home location register, configured to store first authentication code segment information of the preset authentication code of the user; and mobile switching on the called side a center, configured to send a service request to the service control point, where the service request carries a mobile switching center on the called side from the home location register in a location update process of the called user The first authentication code segmentation information of the called user obtained in the middle.
  • the service control point is further configured to: indicate that the mobile switching center on the called side plays an authentication code input prompt tone to the calling user; and the mobile switching center on the called side It is further arranged to instruct the media gateway to play a voice, prompting the user to input an authentication code.
  • the mobile switching center on the called side is further configured to acquire an authentication code input by the calling user, and send the authentication code input by the calling user to the service control. point.
  • the technical solution provided by the embodiment of the present invention can not only authenticate the calling user to the called user, but also protect the authentication information, and the authentication information is segmented and saved on different network devices.
  • the segment authentication information stored on the HLR is obtained by the mobile switching center or the mobile switching center gateway, and then transmitted to the SCP through the intelligent network message, and combined by the SCP.
  • the authentication of the calling number is implemented on the basis of not adding additional network devices, and only the function of the matched network device needs to be upgraded.
  • the location update process of the called user is described, and how the MSC/VLR obtains the authentication code segmentation information of the called user stored in the HLR (hereinafter referred to as the authentication information segment 1) is described in the embodiment of the present invention. ).
  • FIG. 4 is a flowchart of the location update of the called user in the embodiment. As shown in FIG. 4, the method mainly includes the following steps:
  • step 401 the called user turns on or changes the location area, and the terminal initiates a boot or location area update operation.
  • Step 402 If the MSC/VLR has no user data, or the MSC/VLR considers that the user data is unreliable, the MSC/VLR sends a location update request to the HLR.
  • the HLR sends an ISD (Insert Subscriber Data) to the VLR.
  • ISD Insert Subscriber Data
  • the called user data in the request includes the authentication information segment 1, and the VLR records the user subscription data and returns a response.
  • step 404 the HLR returns a success response of the location update, and records the number of the VLR where the user is located.
  • step 405 the VLR returns a location update complete message to the terminal.
  • FIG. 5 is a flow chart of the verification of the calling user in the embodiment. As shown in FIG. 5, the method mainly includes the following steps:
  • step 501 the calling user initiates a call request to the called user.
  • Step 502 The MSC/VLR initiates a routing query request of the called user to the GMSC.
  • step 503 the GMSC initiates a route query request to the called HLR.
  • Step 504 the HLR returns a routing information response, including the authentication code segmentation information 1.
  • Step 505 The GMSC determines that the user subscribes to the authentication service, triggers the called intelligent service, initiates a service request to the SCP, and carries the authentication code segmentation information 1 returned by the HLR route response.
  • Step 506 After receiving the service request, the SCP determines that the user has signed the authentication service, and takes out the authentication code segmentation information 1 in the message, and combines with the locally saved authentication code segmentation information 2 to generate complete authentication information.
  • step 507 the SCP instructs the GMSC to play an authentication code input prompt tone to the user.
  • step 508 the GMSC instructs the MGW to play the voice, prompting the user to input an authentication code (the MGW is omitted in the figure).
  • step 509 a prompt tone is played, prompting the calling user to input an authentication code.
  • step 510 after the user hears the prompt tone, the user enters the complete authentication code according to the prompt, and the authentication code information is transmitted to the GMSC.
  • step 511 the MGSC returns the authentication code information to the SCP.
  • Step 512 After receiving the authentication information, the SCP checks the authentication code input by the user and the locally synthesized authentication code. If the authentication code is the same, the MSC is instructed to continue the call. If the authentication code is different, the MSC is instructed to terminate the current call.
  • FIG. 6 is a flowchart of a calling user calling a called user in the embodiment, as shown in FIG. 6, which mainly includes the following steps:
  • step 601 the calling user initiates a call request to the calling MSC/VLR.
  • Step 602 After the calling MSC queries the called route, it initiates a call request to the called MSC/VLR.
  • step 603 the called MSC determines that the user has subscribed to the called smart service, and triggers the called smart.
  • Step 604 the called MSC initiates a service request to the SCP, and carries the authentication code segmentation information 1 obtained in the location update process of the first embodiment.
  • Step 605 After receiving the service request, the SCP determines that the user has signed the authentication service, and takes out the authentication information segment 1 in the message, and combines with the locally saved authentication information segment 2 to generate complete authentication information.
  • step 606 the SCP instructs the MSC to play an authentication code input prompt tone to the user.
  • step 607 the MSC instructs the MGW to play the voice, and prompts the user to input an authentication code (the MGW is omitted in the figure).
  • Step 608 after the user hears the prompt tone, enter the authentication code as prompted, and the authentication code information is transmitted to the called MSC.
  • step 609 the called MSC returns the authentication information to the SCP.
  • Step 610 After receiving the authentication information, the SCP checks the obtained authentication code and the synthesized authentication information. If the authentication code is the same, the MSC is instructed to continue the call. If the authentication code is different, the MSC is instructed to terminate the current call.
  • the legal caller, the malicious caller and the called party are in the same MSC, and the legal caller calls the called user.
  • the called smart service is triggered, and the calling party is required to input the authentication code. After the SCP authentication succeeds, the permission is allowed. Turn on.
  • the malicious calling party calls the called user and asks for the authentication code. If the authentication code is entered incorrectly, the call is not allowed to be connected.
  • the legal caller and the called user are in the same MSC, and the malicious caller and the called user are not in the same MSC.
  • the MSC/VLR/GMSC where the malicious caller is located supports the functions described in the embodiment of the present invention.
  • the illustrated process performs the call.
  • the allowed calling user (legal calling party) and the called user are in the same MSCS, and the malicious calling party and the called user are not in the same MSC.
  • the MSC/VLR/GMSC where the malicious calling party is located does not support the functions described in the embodiment of the present invention.
  • the called intelligent service is triggered by the called MSC/VLR, and the calling party is required to input an authentication code. If the input is correct, it is allowed to be connected, otherwise the call is rejected.
  • the malicious call is a PSTN user. Similar to scenario 3, the called MSC/VLR triggers the called smart service and asks the caller to enter the authentication code. If the input is correct, it is allowed to be connected, otherwise the call is rejected.
  • the authentication code of the user in the HLR is stolen by the illegal user. Since the authentication code stored by the HLR is only a part of the complete authentication code, the illegal user cannot use the incomplete authentication code to connect the protected call.
  • the authentication code of the user in the SCP is stolen by the illegal user. Since the authentication code saved by the SCP is only a part of the complete authentication code, the illegal user cannot use the incomplete authentication code to connect the protected call.
  • the authentication information is segmentally stored on different network devices.
  • the segment authentication information stored on the HLR is obtained by the mobile switching center or the mobile switching center gateway, and then transmitted to the SCP through the intelligent network message, and combined by the SCP.
  • the authentication of the calling number is implemented on the basis of not adding additional network devices, and only the function of the matched network device needs to be upgraded.
  • modules or steps of the present invention described above can be implemented by a general-purpose computing device that can be centralized on a single computing device or distributed across a network of multiple computing devices. Alternatively, they may be implemented by program code executable by the computing device such that they may be stored in the storage device by the computing device and, in some cases, may be different from the order herein.
  • the steps shown or described are performed, or they are separately fabricated into individual integrated circuit modules, or a plurality of modules or steps thereof are fabricated as a single integrated circuit module.
  • the invention is not limited to any specific combination of hardware and software.
  • the calling user authentication method, apparatus, and system provided by the embodiments of the present invention have the following beneficial effects: not only can the calling user dial the called user for authentication, but also the authentication information is also protected and authenticated.
  • Information segments are stored on different network devices.
  • the segment authentication information stored on the HLR is obtained by the mobile switching center or the mobile switching center gateway, and then transmitted to the SCP through the intelligent network message, and combined by the SCP.
  • the authentication of the calling number is implemented on the basis of not adding additional network devices, and only the function of the matched network device needs to be upgraded.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)

Abstract

本发明公开了一种主叫用户认证方法、装置及系统。其中,该方法包括:业务控制点接收到主叫用户呼叫被叫用户的业务请求后,指示媒体网关提示主叫用户输入认证码;业务控制点获取主叫用户输入的认证码;业务控制点根据预设的认证码,对主叫用户输入的认证码进行检验。

Description

主叫用户认证方法、装置及系统 技术领域
本发明涉及通信领域,具体而言,涉及一种主叫用户认证方法、装置及系统。
背景技术
目前,为了保证某些用户(例如儿童)的安全,提出了一种被叫终端,允许主叫用户拨打后自动接续,接续后用户能听到被叫终端附近的环境音。如果有恶意用户拨打终端,也能够自动接续,则对被叫用户的人身安全存在隐患。因此,对于这种被叫终端需要在网络侧对主叫用户进行认证,只有在认证通过的情况下,才自动接续。
图1是移动通信系统中电路域的呼叫中网络侧的架构示意图。其中,HLR(Home Location Register,归属位置寄存器)主要用来保存用户的签约数据和位置信息。MSC(Mobile Switching Center移动交换中心)和VLR(Visitor Location Register,拜访位置寄存器)配合,完成呼叫的连接和控制。GMSC(Gateway Mobile Switching Center,移动交换中心网关)称为入口移动交换局,它从HLR查询得到被叫目前的位置信息,并根据此信息选择路由。MGW(Media Gateway,媒体网关)提供承载控制和传输资源。SCP(Service Control Point,业务控制点)是智能网中的重要部分,决定呼叫如何进行处理,非智能呼叫不涉及SCP。RNC(Radio Network Controller,无线网络控制器)和BSC(Base Station Controller,基站控制器)分别是第三代移动通信技术(3G)和第二代移动通信技术(2G)的无线接入控制网元。
目前,相关技术中对主叫用户认证方法有两种,一种是设置专用的允许呼叫号码库,只有在号码库中的用户才允许拨打。第二种,对被叫增加呼叫权限码,主叫拨打时需要提供呼叫权限码,只有符合呼叫权限码的用户才可以拨打,同时增加一个专门的网络设备,对权限匹配和呼叫允许进行控制。
以上两种方法中,存在以下缺点:第一种方法需要频繁的更改允许呼叫号码库中的号码,过程比较繁琐。第二种方法需要增设专门的网络设备,提高了部署成本。另外,所有的呼叫权限码都集中于一台网络设备,降低了安全性。
针对相关技术中对主叫用户进行认证存在的问题,目前尚未提出有效的解决方案。
发明内容
本发明实施例提供了一种主叫用户认证方法、装置及系统,以至少解决相关技术中对主叫用户进行认证存在的过程繁琐或部署成本高的问题。
根据本发明的一个方面,提供了一种主叫用户认证方法,包括:业务控制点接收到主叫用户呼叫被叫用户的业务请求后,指示媒体网关提示所述主叫用户输入认证码;所述业务控制点获取所述主叫用户输入的认证码;所述业务控制点根据预设的认证码,对所述主叫用户输入的认证码进行检验。
可选地,所述预设的认证码分为两段:第一认证码分段信息和第二认证码分段信息,所述第一认证码分段信息存储在所述被叫用户的归属位置寄存器中,所述第二认证码分段信息存储在所述业务控制点中;则在对所述主叫用户输入的认证码进行检验之前,所述方法还包括:所述业务控制点获取所述第一认证码分段信息;所述业务控制点将所述第一认证码分段信息与本地保存的所述第二认证码分段信息进行组合,生成完整的所述预设的认证码。
可选地,所述业务控制点获取所述第一认证码分段信息包括:移动交换中心网关接收到所述被叫用户的路由查询请求;所述移动交换中心网关向所述被叫用户的所述归属位置寄存器发送路由查询请求;所述移动交换中心网关接收所述归属位置寄存器返回的路由信息,其中,所述路由信息中包含所述第一认证码分段信息;所述移动交换中心网关向所述业务控制点发送所述业务请求,其中,所述业务请求中携带有所述第一认证码分段信息。
可选地,所述业务控制点指示媒体网关提示所述主叫用户输入认证码,包括:所述业务控制点指示所述移动交换中心网关向所述主叫用户播放认证码输入提示音;所述移动交换中心网关指示所述媒体网关放音,提示所述主叫用户输入认证码。
可选地,所述业务控制点获取所述第一认证码分段信息包括:所述移动交换中心网关接收到所述主叫用户输入的认证码,并将所述主叫用户输入的认证码发送给所述业务控制点。
可选地,所述业务控制点获取所述第一认证码分段信息包括:所述业务控制点接收被叫侧的移动交换中心发送的所述业务请求,其中,所述业务请求中携带有所述被叫侧的移动交换中心在所述被叫用户的位置更新过程中从所述归属位置寄存器中获取的所述第一认证码分段信息。
可选地,所述业务控制点指示媒体网关提示所述主叫用户输入认证码包括:所述业务控制点指示所述被叫侧的移动交换中心向所述主叫用户播放认证码输入提示音;所述被叫侧的移动交换中心指示所述媒体网关放音,提示用户输入认证码。
可选地,所述业务控制点获取所述主叫用户输入的认证码,包括:所述被叫侧的移动交换中心获取所述主叫用户输入的认证码;所述被叫侧的移动交换中心将所述主叫用户输入的认证码发送给所述业务控制点。
可选地,在指示媒体网关提示所述主叫用户输入认证码之前,所述方法还包括:确定所述被叫用户签约了认证业务;
根据本发明的另一个方面,还提供了一种主叫用户认证装置,包括:指示模块,设置为在业务控制点接收到主叫用户呼叫被叫用户的业务请求后,指示媒体网关提示所述主叫用户输入认证码;获取模块,设置为获取所述主叫用户输入的认证码;检验模块,设置为根据预设的认证码,对所述主叫用户输入的认证码进行检验。
可选地,所述预设的认证码分为两段:第一认证码分段信息和第二认证码分段信息,所述第一认证码分段信息存储在所述被叫用户的归属位置寄存器中,所述第二认证码分段信息存储在所述业务控制点中;则所述获取模块包括:获取单元,设置为获取所述第一认证码分段信息;生成单元,设置为将所述第一认证码分段信息与所述业务控制点保存的所述第二认证码分段信息进行组合,生成完整的所述预设的认证码。
可选地,所述装置还包括:确定模块,设置为确定所述被叫用户是否签约了认证业务,如果是,则触发所述指示模块指示媒体网关提示所述主叫用户输入认证码。
根据本发明的又一个方面,提供了一种业务控制点,包括上述的装置。
根据本发明的又一个方面,提供了一种主叫用户认证系统,包括上述的业务控制点。
可选地,所述系统还包括:归属位置寄存器,设置为存储用户的预设的认证码的第一认证码分段信息;移动交换中心网关,设置为在接收到被叫用户的路由查询请求时,从所述归属位置寄存器获取所述被叫用户的第一认证码分段信息,并将所述第一认证码分段信息通过业务请求发送给所述业务控制点。
可选地,所述业务控制点还设置为指示所述移动交换中心网关向主叫用户播放认证码输入提示音;所述移动交换中心网关还设置为指示所述媒体网关放音,提示所述主叫用户输入认证码。
可选地,所述移动交换中心网关还设置为接收所述主叫用户输入的认证码,并将所述主叫用户输入的认证码发送给所述业务控制点。
可选地,所述系统还包括:归属位置寄存器,设置为存储用户的预设的认证码的第一认证码分段信息;被叫侧的移动交换中心,设置为向所述业务控制点发送的业务请求,其中,所述业务请求中携带有所述被叫侧的移动交换中心在所述被叫用户的位置更新过程中从所述归属位置寄存器中获取的所述被叫用户的第一认证码分段信息。
可选地,所述业务控制点还设置为指示所述被叫侧的移动交换中心向所述主叫用户播放认证码输入提示音;所述被叫侧的移动交换中心还设置为指示所述媒体网关放音,提示用户输入认证码。
可选地,所述被叫侧的移动交换中心还设置为获取所述主叫用户输入的认证码,并将所述主叫用户输入的认证码发送给所述业务控制点。
通过本发明实施例,在主叫用户呼叫被叫用户的过程中,业务控制点提示主叫用户输入认证码,然后根据被叫用户预设的认证码对主叫用户认证,避免了采用允许呼叫号码库带来的操作繁琐的问题,并且,也不需要设置专门的网络设备,降低了成本。
附图说明
此处所说明的附图用来提供对本发明的进一步理解,构成本申请的一部分,本发明的示意性实施例及其说明用于解释本发明,并不构成对本发明的不当限定。在附图中:
图1是移动通信系统中电路域的呼叫中网络侧的架构示意图;
图2是根据本发明实施例的主叫用户认证方法的流程图;
图3是根据本发明实施例的主叫用户认证装置的结构示意图;
图4是实施例一的流程图;
图5是实施例二的流程图;
图6是实施例三的流程图。
具体实施方式
下文中将参考附图并结合实施例来详细说明本发明。需要说明的是,在不冲突的情况下,本申请中的实施例及实施例中的特征可以相互组合。
针对相关技术中在对主叫用户进行认证时所存在的问题,本发明实施例提供了一种改进的主叫用户认证方案,在本发明实施例中,主叫用户拨打被叫用户时,必须根据语音提示输入正确的拨打认证码,呼叫才能接通;可选地,被叫用户为智能用户,签约了的特殊智能业务(可称为认证业务),通过该智能业务来触发认证码的认证过程。本发明实施例中,被叫用户的认证码的设置,可以由用户到运营商营业厅手工进行设置,也可以拨打运营商的服务号码,由客服人员远程进行设置,具体本发明实施例不做限定。
根据本发明实施例,提供了一种主叫用户认证方法。
图2为根据本发明实施例的主叫用户认证方法的流程图,如图2所示,主要包括以下步骤:
步骤S202,业务控制点接收到主叫用户呼叫被叫用户的业务请求后,指示媒体网关提示所述主叫用户输入认证码;
步骤S204,所述业务控制点获取所述主叫用户输入的认证码;
步骤S204,所述业务控制点根据预设的认证码,对所述主叫用户输入的认证码进行检验。
可选地,为了避免认证码保存在一个设备中而带来的安全问题,可以将所述预设的认证码分为两段:第一认证码分段信息和第二认证码分段信息,将所述第一认证码分段信息存储在所述被叫用户的归属位置寄存器中,将所述第二认证码分段信息存储在所述业务控制点中。则在该可选实施方式中,在对所述主叫用户输入的认证码进行检验之前,所述方法还可以包括:所述业务控制点获取所述第一认证码分段信息;所述业务控制点将所述第一认证码分段信息与本地保存的所述第二认证码分段信息进行组合,生成完整的所述预设的认证码。可选地,为了进一步提高认证码的安全性,还可以对认证码的每个分段进行加密。
在具体实施过程中,对认证码进行分段的方式可以有多种,可以在SCP中指定具体的分段方式,例如,如果认证码长度为6位,则至少可以按照以下方式之一进行分段:
a、将认证码的前三位分为一段,后三位分为一段,在HLR保存前三位,在SCP保存后三位;
b、将认证码的前三位分为一段,后三位分为一段,在HLR保存后三位,在SCP保存前三位;
c、将认证码的奇数位分为一段,偶数为另一段,在HLR保存奇数位,在SCP保存偶数位;
d、将认证码的奇数位分为一段,偶数为另一段,在HLR保存偶数位,在SCP保存奇数位;
在具体实施过程中,业务控制点可以通过主叫侧的网元获取第一认证码分段信息,与可以通过被叫侧的网元获取第一认证码分段信息,下面分别进行描述。
在本发明实施例的一个可选实施方式中,所述业务控制点获取所述第一认证码分段信息可以包括:移动交换中心网关接收到所述被叫用户的路由查询请求;所述移动交换中心网关向所述被叫用户的所述归属位置寄存器发送路由查询请求;所述移动交换中心网关接收所述归属位置寄存器返回的路由信息,其中,所述路由信息中包含所述第一认证码分段信息;所述移动交换中心网关向所述业务控制点发送所述业务请求,其中,所述业务请求中携带有所述第一认证码分段信息。
与上述可选实施例对应,可选地,所述业务控制点指示媒体网关提示所述主叫用户输入认证码可以包括:所述业务控制点指示所述移动交换中心网关向所述主叫用户播放认证码输入提示音;所述移动交换中心网关指示所述媒体网关放音,提示所述主叫用户输入认证码。
可选地,所述业务控制点获取所述第一认证码分段信息包括:所述移动交换中心网关接收到所述主叫用户输入的认证码,并将所述主叫用户输入的认证码发送给所述业务控制点。
或者,在本发明实施例的另一个可选实施方式中,所述业务控制点获取所述第一认证码分段信息可以包括:所述业务控制点接收被叫侧的移动交换中心发送的所述业务请求,其中,所述业务请求中携带有所述被叫侧的移动交换中心在所述被叫用户的位置更新过程中从所述归属位置寄存器中获取的所述第一认证码分段信息。
可选地,所述业务控制点指示媒体网关提示所述主叫用户输入认证码包括:所述业务控制点指示所述被叫侧的移动交换中心向所述主叫用户播放认证码输入提示音;所述被叫侧的移动交换中心指示所述媒体网关放音,提示用户输入认证码。
可选地,所述业务控制点获取所述主叫用户输入的认证码,包括:所述被叫侧的移动交换中心获取所述主叫用户输入的认证码;所述被叫侧的移动交换中心将所述主叫用户输入的认证码发送给所述业务控制点。
在本发明实施例的另一个可选实施方式中,为了避免对用户造成不必要的干扰,在指示媒体网关提示所述主叫用户输入认证码之前,所述方法还包括:确定所述被叫用户签约了认证业务。即在本发明实施例中,只对针对签约了认证业务的用户的主叫用户进行认证。
根据本发明实施例,还提供一种主叫用户认证装置。
图3为根据本发明实施例的主叫用户认证装置的结构示意图,如图3所示,该装置主要包括:指示模块30,设置为在业务控制点接收到主叫用户呼叫被叫用户的业务请求后,指示媒体网关提示所述主叫用户输入认证码;获取模块32,设置为获取所述主叫用户输入的认证码;检验模块34,设置为根据预设的认证码,对所述主叫用户输入的认证码进行检验。
可选地,所述预设的认证码分为两段:第一认证码分段信息和第二认证码分段信息,所述第一认证码分段信息存储在所述被叫用户的归属位置寄存器中,所述第二认证码分段信息存储在所述业务控制点中;则所述获取模块可以包括:获取单元,设置为获取所述第一认证码分段信息;生成单元,设置为将所述第一认证码分段信息与所述业务控制点保存的所述第二认证码分段信息进行组合,生成完整的所述预设的认证码。
在具体实施过程中,获取单元可以按照上述的主叫用户认证方法中的可选实施方式获取所述第一认证分段信息,具体不再赘述。
可选地,所述装置还包括:确定模块,设置为确定所述被叫用户是否签约了认证业务,如果是,则触发所述指示模块指示媒体网关提示所述主叫用户输入认证码。
根据本发明实施例,还提供了一种业务控制点,该业务控制点包括上述的装置。
根据本发明实施例,还提供了一种主叫用户认证系统,包括上述的业务控制点。
在本发明实施例的一个可选实施方式中,所述系统还可以包括:归属位置寄存器,设置为存储用户的预设的认证码的第一认证码分段信息;移动交换中心网关,设置为在接收到被叫用户的路由查询请求时,从所述归属位置寄存器获取所述被叫用户的第一认证码分段信息,并将所述第一认证码分段信息通过业务请求发送给所述业务控制点。
可选地,在上述实施方式中,所述业务控制点还设置为指示所述移动交换中心网关向主叫用户播放认证码输入提示音;所述移动交换中心网关还设置为指示所述媒体网关放音,提示所述主叫用户输入认证码。
可选地,在上述实施方式中,所述移动交换中心网关还设置为接收所述主叫用户输入的认证码,并将所述主叫用户输入的认证码发送给所述业务控制点。
在本发明实施例的另一个可选实施方式中,该系统还可选包括:归属位置寄存器,设置为存储用户的预设的认证码的第一认证码分段信息;被叫侧的移动交换中心,设置为向所述业务控制点发送的业务请求,其中,所述业务请求中携带有所述被叫侧的移动交换中心在所述被叫用户的位置更新过程中从所述归属位置寄存器中获取的所述被叫用户的第一认证码分段信息。
可选地,在上述实施方式中,所述业务控制点还设置为指示所述被叫侧的移动交换中心向所述主叫用户播放认证码输入提示音;所述被叫侧的移动交换中心还设置为指示所述媒体网关放音,提示用户输入认证码。
可选地,在上述实施方式中,所述被叫侧的移动交换中心还设置为获取所述主叫用户输入的认证码,并将所述主叫用户输入的认证码发送给所述业务控制点。
与现有技术相比较,本发明实施例提供的技术方案,不但可以对主叫用户拨打被叫用户进行认证,同时认证信息也进行了安全性保护,认证信息分段保存在不同的网络设备上。HLR上保存的分段认证信息,由移动交换中心或移动移动交换中心网关获取后,通过智能网消息,传递给SCP,由SCP进行组合。另外,本发明实施例中,在不增加额外网络设备的基础上实现对主叫号码的认证,只需要对配合的网络设备进行功能升级。
下面通过具体实施例对本发明实施例提供的技术方案进行描述。
实施例一
本实施例中对被叫用户的位置更新流程进行描述,说明在本发明实施例中MSC/VLR如何获取存储在HLR中的被叫用户的认证码分段信息(下面称为认证信息分段1)。
图4为本实施例中被叫用户的位置更新流程图,如图4所示,主要包括以下步骤:
步骤401,被叫用户开机或者改变了位置区,终端发起开机或者位置区更新操作。
步骤402,如果MSC/VLR没有用户数据,或者MSC/VLR认为用户数据不可靠,MSC/VLR发送位置更新请求到HLR。
步骤403,HLR将发送ISD(Insert Subscriber Data,插入用户数据请求)到VLR,该请求中的被叫用户用户数据中包含了认证信息分段1,VLR记录用户签约数据,并返回应答。
步骤404,HLR返回位置更新的成功应答,记录用户所在VLR的号码。
步骤405,VLR返回位置更新完成消息到终端。
实施例二
本实施例中以主叫侧网元触发主叫用户认证为例,对本发明实施例提供的技术方案进行描述。
图5为本实施例中主叫用户的校验流程图,如图5所示,主要包括以下步骤:
步骤501,主叫用户发起对被叫用户的呼叫请求。
步骤502,MSC/VLR向GMSC发起被叫用户的路由查询请求。
步骤503,GMSC向被叫HLR发起路由查询请求。
步骤504,HLR返回路由信息响应,包含认证码分段信息1。
步骤505,GMSC判断用户签约了认证业务,触发被叫智能业务,发起业务请求到SCP,同时携带HLR路由响应时返回的认证码分段信息1。
步骤506,SCP收到业务请求后,判断用户签约了认证业务,取出消息中的认证码分段信息1,和本地保存的认证码分段信息2进行组合,生成完整的认证信息。
步骤507,SCP指示GMSC,向用户播放认证码输入提示音。
步骤508,GMSC指示MGW放音,提示用户输入认证码(图中省略了MGW)。
步骤509,播放提示音,提示主叫用户输入认证码。
步骤510,用户听到提示音后,按提示输入完整的认证码,认证码信息传递给GMSC。
步骤511,MGSC把认证码信息返回传递给SCP。
步骤512,SCP收到认证信息后,把用户输入的认证码和本地合成的认证码进行校验,如果认证码相同,指示MSC继续呼叫,如果认证码不相同,指示MSC终止本次呼叫。
实施例三
本实施例以被叫侧网元触发主叫用户认证为例,对本发明实施例提供的技术方案进行描述。
图6为本实施例中主叫用户呼叫被叫用户的流程图,如图6所示,主要包括以下步骤:
步骤601,主叫用户向主叫MSC/VLR发起呼叫请求。
步骤602,主叫MSC查询到被叫的路由后,向被叫MSC/VLR发起呼叫请求。
步骤603,被叫MSC判断用户签约了被叫智能业务,触发被叫智能。
步骤604,被叫MSC发起业务请求到SCP,同时携带在实施例一的位置更新过程中获得的认证码分段信息1。
步骤605,SCP收到业务请求后,判断用户签约了认证业务,取出消息中的认证信息分段1,和本地保存的认证信息分段2进行组合,生成完整的认证信息。
步骤606,SCP指示MSC,向用户播放认证码输入提示音。
步骤607,MSC指示MGW放音,提示用户输入认证码(图中省略了MGW)。
步骤608,用户听到提示音后,按提示输入认证码,认证码信息传递给被叫MSC。
步骤609,被叫MSC把认证信息返回给SCP。
步骤610,SCP收到认证信息后,把获取到的认证码和合成的认证信息进行校验,如果认证码相同,指示MSC继续呼叫,如果认证码不相同,指示MSC终止本次呼叫。
本发明实施例提供的技术方案可能存在以下的应用场景:
场景1:
合法主叫、恶意主叫用户和被叫用户在同一个MSC,合法主叫呼叫被叫用户,参考图5的流程,触发被叫智能业务,要求主叫输入认证码,SCP认证成功后,允许接通。恶意主叫用户呼叫被叫用户,要求输入认证码,如果认证码输入错误,呼叫不允许接通。
场景2:
合法主叫和被叫用户在同一个MSC,恶意主叫和被叫用户不在同一个MSC,恶意主叫所在MSC/VLR/GMSC支持本发明实施例描述的功能,同场景1,按照图5所示的流程执行呼叫。
场景3:
被允许主叫用户(合法主叫)和被叫用户在同一个MSCS,恶意主叫和被叫用户不在同一个MSC,恶意主叫所在MSC/VLR/GMSC不支持本发明实施例描述的功能,按照图6的流程,由被叫MSC/VLR触发被叫智能业务,要求主叫输入认证码。输入正确则允许接通,否则拒绝呼叫。
场景4:
恶意呼叫是PSTN用户,和场景3类似,由被叫MSC/VLR触发被叫智能业务,要求主叫输入认证码。输入正确则允许接通,否则拒绝呼叫。
场景5(认证码安全性保护):
用户在HLR的认证码被非法用户盗取,由于HLR保存的认证码只是完整认证码的一部分,非法用户无法利用不完整认证码接通被保护的呼叫。
场景6(认证码安全性保护):
用户在SCP的认证码被非法用户盗取,由于SCP保存的认证码只是完整认证码的一部分,非法用户无法利用不完整认证码接通被保护的呼叫。
从以上的描述中,可以看出,不但可以对主叫用户拨打被叫用户进行认证,同时认证信息也进行了安全性保护,认证信息分段保存在不同的网络设备上。HLR上保存的分段认证信息,由移动交换中心或移动移动交换中心网关获取后,通过智能网消息,传递给SCP,由SCP进行组合。另外,本发明实施例中,在不增加额外网络设备的基础上实现对主叫号码的认证,只需要对配合的网络设备进行功能升级。
显然,本领域的技术人员应该明白,上述的本发明的各模块或各步骤可以用通用的计算装置来实现,它们可以集中在单个的计算装置上,或者分布在多个计算装置所组成的网络上,可选地,它们可以用计算装置可执行的程序代码来实现,从而,可以将它们存储在存储装置中由计算装置来执行,并且在某些情况下,可以以不同于此处的顺序执行所示出或描述的步骤,或者将它们分别制作成各个集成电路模块,或者将它们中的多个模块或步骤制作成单个集成电路模块来实现。这样,本发明不限制于任何特定的硬件和软件结合。
以上所述仅为本发明的优选实施例而已,并不用于限制本发明,对于本领域的技术人员来说,本发明可以有各种更改和变化。凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。
工业实用性
如上所述,本发明实施例提供的一种主叫用户认证方法、装置及系统具有以下有益效果:不但可以对主叫用户拨打被叫用户进行认证,同时认证信息也进行了安全性保护,认证信息分段保存在不同的网络设备上。HLR上保存的分段认证信息,由移动交换中心或移动移动交换中心网关获取后,通过智能网消息,传递给SCP,由SCP进行组合。另外,本发明实施例中,在不增加额外网络设备的基础上实现对主叫号码的认证,只需要对配合的网络设备进行功能升级。

Claims (20)

  1. 一种主叫用户认证方法,包括:
    业务控制点接收到主叫用户呼叫被叫用户的业务请求后,指示媒体网关提示所述主叫用户输入认证码;
    所述业务控制点获取所述主叫用户输入的认证码;
    所述业务控制点根据预设的认证码,对所述主叫用户输入的认证码进行检验。
  2. 根据权利要求1所述的方法,其中,所述预设的认证码分为两段:第一认证码分段信息和第二认证码分段信息,所述第一认证码分段信息存储在所述被叫用户的归属位置寄存器中,所述第二认证码分段信息存储在所述业务控制点中;则在对所述主叫用户输入的认证码进行检验之前,所述方法还包括:
    所述业务控制点获取所述第一认证码分段信息;
    所述业务控制点将所述第一认证码分段信息与本地保存的所述第二认证码分段信息进行组合,生成完整的所述预设的认证码。
  3. 根据权利要求2所述的方法,其中,所述业务控制点获取所述第一认证码分段信息包括:
    移动交换中心网关接收到所述被叫用户的路由查询请求;
    所述移动交换中心网关向所述被叫用户的所述归属位置寄存器发送路由查询请求;
    所述移动交换中心网关接收所述归属位置寄存器返回的路由信息,其中,所述路由信息中包含所述第一认证码分段信息;
    所述移动交换中心网关向所述业务控制点发送所述业务请求,其中,所述业务请求中携带有所述第一认证码分段信息。
  4. 根据权利要求3所述的方法,其中,所述业务控制点指示媒体网关提示所述主叫用户输入认证码,包括:
    所述业务控制点指示所述移动交换中心网关向所述主叫用户播放认证码输入提示音;
    所述移动交换中心网关指示所述媒体网关放音,提示所述主叫用户输入认证码。
  5. 根据权利要求4所述的方法,其中,所述业务控制点获取所述第一认证码分段信息包括:所述移动交换中心网关接收到所述主叫用户输入的认证码,并将所述主叫用户输入的认证码发送给所述业务控制点。
  6. 根据权利要求2所述的方法,其中,所述业务控制点获取所述第一认证码分段信息包括:
    所述业务控制点接收被叫侧的移动交换中心发送的所述业务请求,其中,所述业务请求中携带有所述被叫侧的移动交换中心在所述被叫用户的位置更新过程中从所述归属位置寄存器中获取的所述第一认证码分段信息。
  7. 根据权利要求6所述的方法,其中,所述业务控制点指示媒体网关提示所述主叫用户输入认证码包括:
    所述业务控制点指示所述被叫侧的移动交换中心向所述主叫用户播放认证码输入提示音;
    所述被叫侧的移动交换中心指示所述媒体网关放音,提示用户输入认证码。
  8. 根据权利要求7所述的方法,其中,所述业务控制点获取所述主叫用户输入的认证码,包括:
    所述被叫侧的移动交换中心获取所述主叫用户输入的认证码;
    所述被叫侧的移动交换中心将所述主叫用户输入的认证码发送给所述业务控制点。
  9. 根据权利要求1至8中任一项所述的方法,其中,在指示媒体网关提示所述主叫用户输入认证码之前,所述方法还包括:确定所述被叫用户签约了认证业务。
  10. 一种主叫用户认证装置,包括:
    指示模块,设置为在业务控制点接收到主叫用户呼叫被叫用户的业务请求后,指示媒体网关提示所述主叫用户输入认证码;
    获取模块,设置为获取所述主叫用户输入的认证码;
    检验模块,设置为根据预设的认证码,对所述主叫用户输入的认证码进行检验。
  11. 根据权利要求10所述的装置,其中,所述预设的认证码分为两段:第一认证码分段信息和第二认证码分段信息,所述第一认证码分段信息存储在所述被叫用户的归属位置寄存器中,所述第二认证码分段信息存储在所述业务控制点中;则所述获取模块包括:
    获取单元,设置为获取所述第一认证码分段信息;
    生成单元,设置为将所述第一认证码分段信息与所述业务控制点保存的所述第二认证码分段信息进行组合,生成完整的所述预设的认证码。
  12. 根据权利要求10或11所述的装置,其中,所述装置还包括:确定模块,设置为确定所述被叫用户是否签约了认证业务,如果是,则触发所述指示模块指示媒体网关提示所述主叫用户输入认证码。
  13. 一种业务控制点,包括权利要求10至12中任一项所述的装置。
  14. 一种主叫用户认证系统,包括权利要求13所述的业务控制点。
  15. 根据权利要求14所述的系统,其中,所述系统还包括:
    归属位置寄存器,设置为存储用户的预设的认证码的第一认证码分段信息;
    移动交换中心网关,设置为在接收到被叫用户的路由查询请求时,从所述归属位置寄存器获取所述被叫用户的第一认证码分段信息,并将所述第一认证码分段信息通过业务请求发送给所述业务控制点。
  16. 根据权利要求15所述的系统,其中,
    所述业务控制点还设置为指示所述移动交换中心网关向主叫用户播放认证码输入提示音;
    所述移动交换中心网关还设置为指示所述媒体网关放音,提示所述主叫用户输入认证码。
  17. 根据权利要求16所述的系统,其中,所述移动交换中心网关还设置为接收所述主叫用户输入的认证码,并将所述主叫用户输入的认证码发送给所述业务控制点。
  18. 根据权利要求14所述的系统,其中,还包括:
    归属位置寄存器,设置为存储用户的预设的认证码的第一认证码分段信息;
    被叫侧的移动交换中心,设置为向所述业务控制点发送的业务请求,其中,所述业务请求中携带有所述被叫侧的移动交换中心在所述被叫用户的位置更新过程中从所述归属位置寄存器中获取的所述被叫用户的第一认证码分段信息。
  19. 根据权利要求18所述的系统,其中,
    所述业务控制点还设置为指示所述被叫侧的移动交换中心向所述主叫用户播放认证码输入提示音;
    所述被叫侧的移动交换中心还设置为指示所述媒体网关放音,提示用户输入认证码。
  20. 根据权利要求19所述的系统,其中,所述被叫侧的移动交换中心还设置为获取所述主叫用户输入的认证码,并将所述主叫用户输入的认证码发送给所述业务控制点。
PCT/CN2014/087233 2014-05-28 2014-09-23 主叫用户认证方法、装置及系统 WO2015180324A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
MYPI2016703228A MY192512A (en) 2014-05-28 2014-09-23 Method, device and system for calling user authentication

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410231910.0A CN105142138B (zh) 2014-05-28 2014-05-28 主叫用户认证方法、装置及系统
CN201410231910.0 2014-05-28

Publications (1)

Publication Number Publication Date
WO2015180324A1 true WO2015180324A1 (zh) 2015-12-03

Family

ID=54697996

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/087233 WO2015180324A1 (zh) 2014-05-28 2014-09-23 主叫用户认证方法、装置及系统

Country Status (3)

Country Link
CN (1) CN105142138B (zh)
MY (1) MY192512A (zh)
WO (1) WO2015180324A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107154920B (zh) * 2016-03-04 2021-07-13 神讯电脑(昆山)有限公司 安全信息的加密方法、解密方法及用以接收安全信息的接收装置

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101388931A (zh) * 2007-09-11 2009-03-18 杨汉民 实现网络电话自动接听设备的方法
CN101938708A (zh) * 2010-08-19 2011-01-05 浙江元亨通信技术有限公司 一种基于手机终端实现无线集群通信的方法
CN102937719A (zh) * 2012-11-15 2013-02-20 浙江工业大学 外出老人的定位方法及其定位系统

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101277341A (zh) * 2008-04-28 2008-10-01 华为技术有限公司 呼叫处理方法、系统及验证服务器和互动式语音应答系统
CN103037070A (zh) * 2011-10-09 2013-04-10 北京千橡网景科技发展有限公司 控制移动电话接听来电的方法和装置
CN102857731A (zh) * 2012-09-01 2013-01-02 合肥移瑞通信技术有限公司 3g无线通信模块视频电话来电的身份确认及自动接听的方法

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101388931A (zh) * 2007-09-11 2009-03-18 杨汉民 实现网络电话自动接听设备的方法
CN101938708A (zh) * 2010-08-19 2011-01-05 浙江元亨通信技术有限公司 一种基于手机终端实现无线集群通信的方法
CN102937719A (zh) * 2012-11-15 2013-02-20 浙江工业大学 外出老人的定位方法及其定位系统

Also Published As

Publication number Publication date
CN105142138B (zh) 2019-11-05
CN105142138A (zh) 2015-12-09
MY192512A (en) 2022-08-24

Similar Documents

Publication Publication Date Title
CN110798833B (zh) 一种鉴权过程中验证用户设备标识的方法及装置
EP3253092B1 (en) Self provisioning of wireless terminals in wireless networks
EP1879325B1 (en) Method and system for updating a secret key
JP4263384B2 (ja) ユーザ加入識別モジュールの認証についての改善された方法
US9332575B2 (en) Method and apparatus for enabling connectivity in a communication network
KR100837583B1 (ko) 인증 벡터 생성 장치, 가입자 인증 모듈, 이동 통신시스템, 인증 벡터 생성 방법, 연산 방법 및 가입자 인증방법
CN102318386B (zh) 向网络的基于服务的认证
US6198823B1 (en) Method for improved authentication for cellular phone transmissions
US20130160097A1 (en) Methods, apparatus, and computer program products for subscriber authentication and temporary code generation
KR20170108102A (ko) 통신 디바이스와 네트워크 디바이스 사이의 통신에서의 보안 설비
WO2013091377A1 (zh) 用户合法性判断方法、装置及用户接入信箱的系统
KR20150111687A (ko) 통신 시스템에서 인증 방법 및 장치
TW200522647A (en) System, method and machine-readable storage medium for subscriber identity module (SIM) based pre-authentication across wireless LAN
CN112105021B (zh) 一种认证方法、装置及系统
US20200228981A1 (en) Authentication method and device
CN102415119A (zh) 管理网络中不期望的服务请求
CN107529160A (zh) 一种VoWiFi网络接入方法和系统、终端及无线访问接入点设备
US20210258787A1 (en) Non-3gpp device access to core network
WO2013185709A1 (zh) 一种呼叫认证方法、设备和系统
WO2011124051A1 (zh) 终端鉴权方法及系统
JP4897864B2 (ja) 移動体ネットワークにおけるサービスのcliなりすましに対する保護
CN102984335A (zh) 拨打固定电话的身份认证方法、设备和系统
US20220386099A1 (en) Device authentication verification for device registration
EP3079329B1 (en) Terminal application registration method, device and system
CN102149079A (zh) 一种获取用户身份标识的方法、装置和系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14893218

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 14893218

Country of ref document: EP

Kind code of ref document: A1