WO2017008513A1 - Ims网络的注册方法及系统 - Google Patents
Ims网络的注册方法及系统 Download PDFInfo
- Publication number
- WO2017008513A1 WO2017008513A1 PCT/CN2016/074902 CN2016074902W WO2017008513A1 WO 2017008513 A1 WO2017008513 A1 WO 2017008513A1 CN 2016074902 W CN2016074902 W CN 2016074902W WO 2017008513 A1 WO2017008513 A1 WO 2017008513A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- user
- user equipment
- cscf
- temporary
- identifier
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L65/00—Network arrangements, protocols or services for supporting real-time applications in data packet communication
- H04L65/1066—Session management
- H04L65/1073—Registration or de-registration
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/40—Network security protocols
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W60/00—Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/26—Network addressing or numbering for mobility support
Definitions
- the present invention relates to the field of communications technologies, and in particular, to a method for registering an IMS network and a registration system for an IMS network.
- IMS Internet Protocol Multimedia Subsystem
- the IMS registration consists of two registrations, initial registration and authentication registration.
- the initial registration process is initiated by the user equipment (User Equipment, UE) to register with the IMS network. Since the identity authentication is not performed at this time, the network sends a 401 unauthorized response and carries the authentication verification parameters (RAND, AUTH). Initiating an authentication challenge to the user equipment, after the user equipment receives the authentication response parameter, the authentication registration process is initiated, and the authentication registration process is performed by the user equipment to send the challenge response value to the network.
- RAND User Equipment
- AUTH authentication verification parameters
- the user equipment carries the information of the private user identity identifier in the initial registration request message.
- the private user identity is in the form of username@reaml, where username is the username and reaml is the home network domain name.
- the private user identity will be obtained from the IMSI (Mobile Subscriber Identification Number).
- the name is the IMSI number. If the IMSI number of a user is 234150999999999, the private user identity is in the form 234150999999999@ims.mnc015.mcc234.3gppnetwork.org.
- the initial registration request message in the related art is sent when the security key has not been negotiated, the message is not protected by any security, and the attacker can easily obtain the registration information of the user, thereby causing the user to disclose privacy, especially when the user When the IMSI number is acquired by a criminal, it will cause irreparable damage to the user.
- the invention is based on at least one of the above technical problems, and proposes a new registration scheme of the IMS network, which can strengthen the security of the initial registration process of the IMS network and effectively prevent leakage of user information.
- the present invention provides a method for registering an IMS network, comprising: a mobile communication network assigning a temporary user identifier to a user equipment; the user equipment receiving the temporary user identifier, and based on the temporary user identifier to the IMS network An initial registration request is sent to perform the initial registration process.
- the temporary user identifier is allocated to the user equipment by using the mobile communication network, and the initial registration request is sent by the user equipment to the IMS network based on the temporary user identifier, which avoids the initial sending of the identity of the private user identity by the user equipment in the related art.
- the registration request has a security risk that the private user identity is stolen, and after the temporary user identifier is used instead of the private user identity, even if the criminal acquires the temporary user identifier, the user cannot obtain the relevant information according to the temporary user identifier, thereby The security of the initial registration process of the IMS network is enhanced, and the leakage of user information is effectively prevented.
- the method further includes: the home subscription user server, the temporary user identifier, and the private user equipment of the user equipment.
- the identifier is stored correspondingly.
- the temporary subscriber identity is matched with the private user equipment identifier of the user equipment by the home subscriber server (HSS).
- HSS home subscriber server
- the user equipment is configured to obtain the private user equipment identifier of the user equipment according to the temporary user identifier included in the initial registration request, to allocate the user authentication vector to the user equipment.
- the step of the user equipment sending an initial registration request to the IMS network based on the temporary user identifier to perform an initial registration process specifically includes: the user equipment to the P of the IMS network - the CSCF (Proxy Call Session Control Function) sends an initial registration request including the temporary user identity; the P-CSCF sets the initial registration according to the home network domain name in the initial registration request
- the request is routed to the I-CSCF (Interrogation Call Session Control Function) of the IMS network, for the I-CSCF to query the home subscriber server and select the S-CSCF (Serving Call Session Control Function) a service call session control function); the I-CSCF sends the initial registration request to the S-CSCF; the S-CSCF to the home according to the temporary user identifier included in the initial registration request
- the subscription subscriber server requests to download a user authentication vector; the home subscription subscriber server is based on the temporary subscriber identity Identifying a corresponding private user equipment identifier, and feeding
- the temporary user identifier is used instead of the private user identity to complete the initial registration of the IMS network, so that even if the criminal acquires the temporary user identifier, the related information of the user cannot be obtained according to the temporary user identifier, and the IMS is strengthened.
- the security of the initial registration process of the network effectively prevents the leakage of user information.
- the mobile communication network allocates the temporary user identifier to the user equipment when receiving the registration request of the user equipment.
- the temporary user identifier is allocated to the user equipment, and the temporary user identifier of the user equipment can be implemented without changing the existing grid architecture.
- the distribution, the process is simple and easy to implement.
- the mobile communication network includes a 2/3G network and an LTE network; and the initial registration request includes the temporary user identifier and a home network domain name.
- a registration system for an IMS network comprising: a mobile communication network, a user equipment, and an IMS network; wherein the mobile communication network is configured to allocate a temporary user identifier to the user equipment; The user equipment is configured to receive the temporary user identifier, and send an initial registration request to the IMS network based on the temporary user identifier.
- the temporary user identifier is allocated to the user equipment by using the mobile communication network, and the initial registration request is sent by the user equipment to the IMS network based on the temporary user identifier, which avoids the initial sending of the identity of the private user identity by the user equipment in the related art.
- the registration request has a security risk that the private user identity is stolen, and after the temporary user identifier is used instead of the private user identity, even if the criminal acquires the temporary user identifier, the user cannot obtain the relevant information according to the temporary user identifier, thereby The security of the initial registration process of the IMS network is enhanced, and the leakage of user information is effectively prevented.
- the method further includes: a home subscription subscriber server, configured to: after the mobile communication network allocates the temporary subscriber identity to the user equipment, the temporary subscriber identity and the user equipment The private user equipment identifier is stored correspondingly.
- the temporary user identifier is stored in association with the private user equipment identifier of the user equipment by the home subscriber server (HSS), so that the user equipment performs the initial registration process according to the temporary user identifier.
- HSS home subscriber server
- the private user equipment identifier of the user equipment can be obtained according to the temporary user identifier included in the initial registration request to allocate a user authentication vector for the user equipment.
- the user equipment sends an initial registration request to the IMS network based on the temporary user identifier, to perform an initial registration process, where the method includes: the user equipment to a P-CSCF of the IMS network. Transmitting an initial registration request including the temporary user identifier; the P-CSCF routing the initial registration request to an I-CSCF of the IMS network according to a home network domain name in the initial registration request, to provide
- the I-CSCF queries the home subscriber server and selects an S-CSCF; the I-CSCF sends the initial registration request to the S-CSCF; the S-CSCF is included according to the initial registration request
- the temporary user identifier requests the home subscription user server to download a user authentication vector; the home subscription user server searches for a corresponding private user equipment identifier according to the temporary user identifier, and corresponds to the private user equipment identifier.
- User authentication vector is fed back to the S-CSCF; After receiving the user authentication vector corresponding to the private user equipment identifier, the
- the temporary user identifier is used instead of the private user identity to complete the initial registration of the IMS network, so that even if the criminal acquires the temporary user identifier, the related information of the user cannot be obtained according to the temporary user identifier, and the IMS is strengthened.
- the security of the initial registration process of the network effectively prevents the leakage of user information.
- the mobile communication network allocates the temporary user identifier to the user equipment when receiving the registration request of the user equipment.
- the temporary user identifier is allocated to the user equipment, and the temporary user identifier of the user equipment can be implemented without changing the existing grid architecture.
- the distribution, the process is simple and easy to implement.
- the mobile communication network includes a 2/3G network and an LTE network; and the initial registration request includes the temporary user identifier and a home network domain name.
- the temporary user identifier can be used instead of the private user identity to complete the initial registration of the IMS network, the security of the initial registration process of the IMS network is enhanced, and the leakage of user information is effectively prevented.
- FIG. 1 shows a schematic flow chart of a registration method of an IMS network according to an embodiment of the present invention
- FIG. 2 shows a schematic block diagram of a registration system of an IMS network in accordance with one embodiment of the present invention
- FIG. 3 shows a schematic diagram of a process in which a user equipment accesses a mobile communication network according to an embodiment of the present invention.
- FIG. 4 shows a schematic diagram of an initial registration process for an IMS network in accordance with one embodiment of the present invention.
- FIG. 1 shows a schematic flow chart of a registration method of an IMS network according to an embodiment of the present invention.
- a method for registering an IMS network includes: Step 102: A mobile communication network allocates a temporary user identifier to a user equipment; Step 104, the user equipment receives the temporary user identifier, And sending an initial registration request to the IMS network based on the temporary user identity to perform an initial registration process.
- the temporary user identifier is allocated to the user equipment by using the mobile communication network, and the initial registration request is sent by the user equipment to the IMS network based on the temporary user identifier, which avoids the initial sending of the identity of the private user identity by the user equipment in the related art.
- the registration request has a security risk that the private user identity is stolen, and after the temporary user identifier is used instead of the private user identity, even if the criminal acquires the temporary user identifier, the user cannot obtain the relevant information according to the temporary user identifier, thereby The security of the initial registration process of the IMS network is enhanced, and the leakage of user information is effectively prevented.
- the method further includes: the home subscription user server, the temporary user identifier, and the private user equipment of the user equipment.
- the identifier is stored correspondingly.
- the temporary user identifier is stored in association with the private user equipment identifier of the user equipment by the home subscriber server (HSS), so that the user equipment performs the initial registration process according to the temporary user identifier.
- HSS home subscriber server
- the private user equipment identifier of the user equipment can be obtained according to the temporary user identifier included in the initial registration request to allocate a user authentication vector for the user equipment.
- the step of the user equipment sending an initial registration request to the IMS network based on the temporary user identifier to perform an initial registration process specifically includes: the user equipment to the P of the IMS network - the CSCF sends an initial registration request including the temporary user identity; the P-CSCF routes the initial registration request to the I-CSCF of the IMS network according to the home network domain name in the initial registration request, For the I-CSCF check Invoking the home subscriber network server and selecting an S-CSCF; the I-CSCF transmitting the initial registration request to the S-CSCF; the S-CSCF according to the temporary user included in the initial registration request
- the identifier is requested to download a user authentication vector to the home subscription subscriber server; the home subscription subscriber server searches for a corresponding private user equipment identifier according to the temporary subscriber identity, and authenticates the user corresponding to the private user equipment identifier.
- the vector is fed back to the S-CSCF; after receiving the user authentication vector corresponding to the private user equipment identifier
- the temporary user identifier is used instead of the private user identity to complete the initial registration of the IMS network, so that even if the criminal acquires the temporary user identifier, the related information of the user cannot be obtained according to the temporary user identifier, and the IMS is strengthened.
- the security of the initial registration process of the network effectively prevents the leakage of user information.
- the mobile communication network allocates the temporary user identifier to the user equipment when receiving the registration request of the user equipment.
- the temporary user identifier is allocated to the user equipment, and the temporary user identifier of the user equipment can be implemented without changing the existing grid architecture.
- the distribution, the process is simple and easy to implement.
- the mobile communication network includes a 2/3G network and an LTE network; and the initial registration request includes the temporary user identifier and a home network domain name.
- FIG. 2 shows a schematic block diagram of a registration system for an IMS network in accordance with one embodiment of the present invention.
- a registration system of an IMS network includes: a mobile communication network 202, a user equipment 204, and an IMS network 206;
- the mobile communication network 202 is configured to allocate a temporary user identifier to the user equipment 204.
- the user equipment 204 is configured to receive the temporary user identifier, and send an initial registration request to the IMS network 206 based on the temporary user identifier. .
- the temporary user identifier is allocated to the user equipment 204 through the mobile communication network 202, and the initial registration request is sent by the user equipment 204 to the IMS network 206 based on the temporary user identifier, so that the user equipment in the related art directly transmits the private user.
- the method further includes: a home subscription subscriber server 208, configured to: after the mobile communication network 202 allocates the temporary subscriber identity to the user equipment 204, the temporary subscriber identity and the The private user equipment identifier of the user equipment 204 is correspondingly stored.
- a home subscription subscriber server 208 configured to: after the mobile communication network 202 allocates the temporary subscriber identity to the user equipment 204, the temporary subscriber identity and the The private user equipment identifier of the user equipment 204 is correspondingly stored.
- the temporary subscriber identity is stored in association with the private user equipment identity of the user equipment 204 by the home subscriber server 208 (ie, the Home Subscriber Server, HSS), so that the user equipment 204 performs initial registration according to the temporary subscriber identity.
- the private user equipment identifier of the user equipment 204 can be obtained according to the temporary user identifier included in the initial registration request to allocate the user authentication vector for the user equipment 204.
- the user equipment 204 sends an initial registration request to the IMS network 206 based on the temporary user identifier to perform an initial registration process, which specifically includes: the user equipment 204 to the IMS network 206
- the P-CSCF sends an initial registration request including the temporary user identity; the P-CSCF routes the initial registration request to the I- of the IMS network 206 according to the home network domain name in the initial registration request.
- the temporary user identifier is used instead of the private user identity to complete the initial registration of the IMS network, so that even if the criminal acquires the temporary user identifier, the related information of the user cannot be obtained according to the temporary user identifier, and the IMS is strengthened.
- the security of the initial registration process of the network effectively prevents the leakage of user information.
- the mobile communication network 202 allocates the temporary user identifier to the user equipment 204 when receiving the registration request of the user equipment 204.
- the temporary user identifier is allocated to the user equipment 204, and the user equipment 204 can be implemented without changing the existing grid architecture.
- the assignment of temporary user IDs is simple and easy to implement.
- the mobile communication network 202 includes a 2/3G network and an LTE network; and the initial registration request includes the temporary user identifier and a home network domain name.
- the technical solution of the present invention is mainly to register using the temporary user identity in the initial registration process of the IMS.
- the temporary user identity is in the form of usertempname@reaml, where usertempname is the temporary user identifier and reaml is the home network domain name.
- the temporary user identity is a dynamic data that is dynamically allocated as the mobile access network changes.
- the temporary user identity is used instead of the private user identity.
- the purpose of the ISM network registration is to enhance the confidentiality of the system and prevent illegal individuals or The community steals the IMSI or tracks the location of the user by listening to network signaling.
- the technical solution of the present invention includes an access network registration process and an initial registration process of the IMS network.
- the access network registration process refers to a mobile network (LTE network or 2/3G network) registration process.
- the UE ie, user equipment
- the mobile network assigns a temporary identification to the mobile network.
- the TMSI Temporal Mobile Subscriber Identity
- HSS home subscriber server
- the user's private user identity is stored in the HSS. Therefore, for the UE camping on the IMS network, the private user identity of the UE user and the TMSI allocated by the mobile network are stored in the HSS.
- the temporary user identity is used for registration in the initial registration process of the IMS network. The specific process is shown in Figure 4.
- an initial registration process of an IMS network includes: a UE carrying a temporary user identity to initiate an initial registration request to an IMS network; and a P-CSCF according to a home network domain name in an initial registration request (in User terminal configuration), routing the request to the I-CSCF; the I-CSCF uses the UAR message to query the HSS; the HSS uses the UAA message to return the S-CSCF required by the user.
- the I-CSCF selects an appropriate S-CSCF according to the subscription requirement of the user, and sends the registration request to the S-CSCF; when the S-CSCF receives the request, the S-CSCF according to the temporary user identifier included in the initial registration request (usertempname in FIG. 4) requests the home subscriber server HSS to download the user authentication vector by using the MAR message; the home subscriber server HSS searches for the corresponding private subscriber identity according to the temporary subscriber identity, and identifies the private subscriber identity through the MAA message. The corresponding user authentication vector is fed back to the S-CSCF; after receiving the user authentication vector corresponding to the private user identity, the S-CSCF returns an authentication challenge to the UE through the I-CSCF and the P-CSCF.
- the technical solution of the foregoing embodiment strengthens the confidentiality of the system by using the temporary user identity in the initial registration process of the IMS network, thereby preventing the illegal individual or the group from stealing the IMSI or tracking the user by monitoring the network signaling. position.
- the present invention proposes a new registration scheme for an IMS network, which can replace the private user identity with a temporary user identifier to complete the initial registration process of the IMS network, and strengthen the IMS network.
- the security of the initial registration process effectively prevents the leakage of user information.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Business, Economics & Management (AREA)
- General Business, Economics & Management (AREA)
- Multimedia (AREA)
- Databases & Information Systems (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本发明提供了一种IMS网络的注册方法及系统,其中,所述IMS网络的注册方法,包括:移动通信网络向用户设备分配临时用户标识;所述用户设备接收所述临时用户标识,并基于所述临时用户标识向IMS网络发送初始注册请求,以执行初始注册过程。本发明的技术方案通过采用临时用户标识替代私有用户身份标识来完成IMS网络的初始注册,加强了IMS网络初始注册过程的安全性,有效防止用户信息的泄漏。
Description
本申请要求于2015年7月14日提交中国专利局,申请号为201510413664.5、发明名称为“IMS网络的注册方法及系统”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本发明涉及通信技术领域,具体而言,涉及一种IMS网络的注册方法和一种IMS网络的注册系统。
IMS(Internet Protocol Multimedia Subsystem,网际协议多媒体子系统)是一种全新的多媒体业务形式,可以应用于移动通信网及固定通信网,能够满足终端客户更新颖、更多样化多媒体的业务需求。
通常,用户在使用IMS服务之前必须向IMS网络进行注册,通过注册过程可以完成用户对网络和网络对用户的双向认证。IMS注册包含两次注册,分别是初始注册和鉴权注册。初始注册过程是由用户设备(User Equipment,UE)发起,向IMS网络进行注册的过程,由于此时还没有进行身份认证,所以网络会发送401未授权响应并携带鉴权验证参数(RAND,AUTH)向用户设备发起鉴权挑战,用户设备收到后会进行鉴权响应参数的计算,之后会发起鉴权注册流程;鉴权注册流程是用户设备将挑战响应值发送给网络,由网络完成鉴权及密钥协商的过程。
目前,相关技术提出的注册方案中,在初始注册过程,用户设备在发送初始注册请求消息中携带有私有用户身份标识的信息。例如,对于VoLTE(Voice over LTE(Long Term Evolution,长期演进))用户,其私有用户身份标识的形式是username@reaml,其中username是用户名,reaml是归属网络域名。如果没有ISIM(IP Multimedia Service Identity Model,IP多媒体服务身份模块),私有用户身份标识没有显示,则私有用户身份标识将从IMSI(Mobile Subscriber Identification Number,国际移动用户识别码)中获得,此时用户名即为IMSI号码。如某用户的IMSI号码为
234150999999999,则私有用户身份标识的形式为234150999999999@ims.mnc015.mcc234.3gppnetwork.org。
由于相关技术中的初始注册请求消息是在安全密钥尚未协商的时候发送的,故该消息没有受到任何安全保护,攻击者可以轻而易举地获取用户的注册信息,从而造成用户隐私泄密,尤其当用户的IMSI号被不法分子获取时,将会给用户造成无法挽回的损失。
因此,如何进一步加强IMS网络初始注册过程的安全性,防止用户信息泄漏成为亟待解决的技术问题。
发明内容
本发明正是基于上述技术问题至少之一,提出了一种新的IMS网络的注册方案,能够加强IMS网络初始注册过程的安全性,有效防止用户信息的泄漏。
有鉴于此,本发明提出了一种IMS网络的注册方法,包括:移动通信网络向用户设备分配临时用户标识;所述用户设备接收所述临时用户标识,并基于所述临时用户标识向IMS网络发送初始注册请求,以执行初始注册过程。
在该技术方案中,通过移动通信网络向用户设备分配临时用户标识,由用户设备基于临时用户标识向IMS网络发送初始注册请求,避免了相关技术中用户设备直接发送携带有私有用户身份标识的初始注册请求而存在私有用户身份标识被窃取的安全隐患,而采用临时用户标识来替代私有用户身份标识后,即便不法分子获取到临时用户标识,也无法根据临时用户标识获取到用户的相关信息,从而加强了IMS网络初始注册过程的安全性,有效地防止了用户信息的泄漏。
在上述技术方案中,优选地,在所述移动通信网络向所述用户设备分配所述临时用户标识之后,还包括:归属签约用户服务器将所述临时用户标识与所述用户设备的私有用户设备标识进行对应存储。
在该技术方案中,通过归属签约用户服务器(即Home Subscriber Server,HSS)将临时用户标识与用户设备的私有用户设备标识进行对应
存储,使得用户设备在后续根据临时用户标识执行初始注册过程时,能够根据初始注册请求中包含的临时用户标识获取到用户设备的私有用户设备标识,以为用户设备分配用户鉴权向量。
在上述技术方案中,优选地,所述用户设备基于所述临时用户标识向所述IMS网络发送初始注册请求,以执行初始注册过程的步骤具体包括:所述用户设备向所述IMS网络的P-CSCF(Proxy Call Session Control Function,代理呼叫会话控制功能)发送包含有所述临时用户标识的初始注册请求;所述P-CSCF根据所述初始注册请求中的归属网络域名,将所述初始注册请求路由至所述IMS网络的I-CSCF(Interrogation Call Session Control Function,查询呼叫会话控制功能),以供所述I-CSCF查询所述归属签约用户服务器并选择S-CSCF(Serving Call Session Control Function,服务呼叫会话控制功能);所述I-CSCF将所述初始注册请求发送至所述S-CSCF;所述S-CSCF根据所述初始注册请求中包含的所述临时用户标识向所述归属签约用户服务器请求下载用户鉴权向量;所述归属签约用户服务器根据所述临时用户标识查找对应的私有用户设备标识,并将与所述私有用户设备标识相对应的用户鉴权向量反馈至所述S-CSCF;所述S-CSCF在接收到与所述私有用户设备标识相对应的用户鉴权向量后,通过所述I-CSCF和所述P-CSCF向所述用户设备返回鉴权挑战。
在该技术方案中,采用临时用户标识来替代私有用户身份标识来完成IMS网络的初始注册,使得即便不法分子获取到临时用户标识,也无法根据临时用户标识获取到用户的相关信息,加强了IMS网络初始注册过程的安全性,有效地防止了用户信息的泄漏。
在上述技术方案中,优选地,所述移动通信网络在接收到所述用户设备的注册请求时,向所述用户设备分配所述临时用户标识。
在该技术方案中,通过移动通信网络在接收到用户设备的注册请求时,向用户设备分配所述临时用户标识,能够在不改变现有网格架构的前提下实现对用户设备的临时用户标识的分配,过程简单,易于实现。
在上述技术方案中,优选地,所述移动通信网络包括2/3G网络、LTE网络;所述初始注册请求包括所述临时用户标识和归属网络域名。
根据本发明的第二方面,还提出了一种IMS网络的注册系统,包括:移动通信网络、用户设备和IMS网络;其中,所述移动通信网络用于向用户设备分配临时用户标识;所述用户设备用于接收所述临时用户标识,并基于所述临时用户标识向所述IMS网络发送初始注册请求。
在该技术方案中,通过移动通信网络向用户设备分配临时用户标识,由用户设备基于临时用户标识向IMS网络发送初始注册请求,避免了相关技术中用户设备直接发送携带有私有用户身份标识的初始注册请求而存在私有用户身份标识被窃取的安全隐患,而采用临时用户标识来替代私有用户身份标识后,即便不法分子获取到临时用户标识,也无法根据临时用户标识获取到用户的相关信息,从而加强了IMS网络初始注册过程的安全性,有效地防止了用户信息的泄漏。
在上述技术方案中,优选地,还包括:归属签约用户服务器,用于在所述移动通信网络向所述用户设备分配所述临时用户标识之后,将所述临时用户标识与所述用户设备的私有用户设备标识进行对应存储。
在该技术方案中,通过归属签约用户服务器(即Home Subscriber Server,HSS)将临时用户标识与用户设备的私有用户设备标识进行对应存储,使得用户设备在后续根据临时用户标识执行初始注册过程时,能够根据初始注册请求中包含的临时用户标识获取到用户设备的私有用户设备标识,以为用户设备分配用户鉴权向量。
在上述技术方案中,优选地,所述用户设备基于所述临时用户标识向所述IMS网络发送初始注册请求,以执行初始注册过程具体包括:所述用户设备向所述IMS网络的P-CSCF发送包含有所述临时用户标识的初始注册请求;所述P-CSCF根据所述初始注册请求中的归属网络域名,将所述初始注册请求路由至所述IMS网络的I-CSCF,以供所述I-CSCF查询所述归属签约用户服务器并选择S-CSCF;所述I-CSCF将所述初始注册请求发送至所述S-CSCF;所述S-CSCF根据所述初始注册请求中包含的所述临时用户标识向所述归属签约用户服务器请求下载用户鉴权向量;所述归属签约用户服务器根据所述临时用户标识查找对应的私有用户设备标识,并将与所述私有用户设备标识相对应的用户鉴权向量反馈至所述S-CSCF;所述
S-CSCF在接收到与所述私有用户设备标识相对应的用户鉴权向量后,通过所述I-CSCF和所述P-CSCF向所述用户设备返回鉴权挑战。
在该技术方案中,采用临时用户标识来替代私有用户身份标识来完成IMS网络的初始注册,使得即便不法分子获取到临时用户标识,也无法根据临时用户标识获取到用户的相关信息,加强了IMS网络初始注册过程的安全性,有效地防止了用户信息的泄漏。
在上述技术方案中,优选地,所述移动通信网络在接收到所述用户设备的注册请求时,向所述用户设备分配所述临时用户标识。
在该技术方案中,通过移动通信网络在接收到用户设备的注册请求时,向用户设备分配所述临时用户标识,能够在不改变现有网格架构的前提下实现对用户设备的临时用户标识的分配,过程简单,易于实现。
在上述技术方案中,优选地,所述移动通信网络包括2/3G网络、LTE网络;所述初始注册请求包括所述临时用户标识和归属网络域名。
通过以上技术方案,可以采用临时用户标识替代私有用户身份标识来完成IMS网络的初始注册,加强了IMS网络初始注册过程的安全性,有效防止用户信息的泄漏。
图1示出了根据本发明的一个实施例的IMS网络的注册方法的示意流程图;
图2示出了根据本发明的一个实施例的IMS网络的注册系统的示意框图;
图3示出了根据本发明的一个实施例的用户设备接入移动通信网络的过程示意图。
图4示出了根据本发明的一个实施例的IMS网络的初始注册过程示意图。
为了能够更清楚地理解本发明的上述目的、特征和优点,下面结合附图和具体实施方式对本发明进行进一步的详细描述。需要说明的是,在不冲突的情况下,本申请的实施例及实施例中的特征可以相互组合。
在下面的描述中阐述了很多具体细节以便于充分理解本发明,但是,本发明还可以采用其他不同于在此描述的其他方式来实施,因此,本发明的保护范围并不受下面公开的具体实施例的限制。
图1示出了根据本发明的一个实施例的IMS网络的注册方法的示意流程图。
如图1所示,根据本发明的一个实施例的IMS网络的注册方法,包括:步骤102,移动通信网络向用户设备分配临时用户标识;步骤104,所述用户设备接收所述临时用户标识,并基于所述临时用户标识向IMS网络发送初始注册请求,以执行初始注册过程。
在该技术方案中,通过移动通信网络向用户设备分配临时用户标识,由用户设备基于临时用户标识向IMS网络发送初始注册请求,避免了相关技术中用户设备直接发送携带有私有用户身份标识的初始注册请求而存在私有用户身份标识被窃取的安全隐患,而采用临时用户标识来替代私有用户身份标识后,即便不法分子获取到临时用户标识,也无法根据临时用户标识获取到用户的相关信息,从而加强了IMS网络初始注册过程的安全性,有效地防止了用户信息的泄漏。
在上述技术方案中,优选地,在所述移动通信网络向所述用户设备分配所述临时用户标识之后,还包括:归属签约用户服务器将所述临时用户标识与所述用户设备的私有用户设备标识进行对应存储。
在该技术方案中,通过归属签约用户服务器(即Home Subscriber Server,HSS)将临时用户标识与用户设备的私有用户设备标识进行对应存储,使得用户设备在后续根据临时用户标识执行初始注册过程时,能够根据初始注册请求中包含的临时用户标识获取到用户设备的私有用户设备标识,以为用户设备分配用户鉴权向量。
在上述技术方案中,优选地,所述用户设备基于所述临时用户标识向所述IMS网络发送初始注册请求,以执行初始注册过程的步骤具体包括:所述用户设备向所述IMS网络的P-CSCF发送包含有所述临时用户标识的初始注册请求;所述P-CSCF根据所述初始注册请求中的归属网络域名,将所述初始注册请求路由至所述IMS网络的I-CSCF,以供所述I-CSCF查
询所述归属签约用户服务器并选择S-CSCF;所述I-CSCF将所述初始注册请求发送至所述S-CSCF;所述S-CSCF根据所述初始注册请求中包含的所述临时用户标识向所述归属签约用户服务器请求下载用户鉴权向量;所述归属签约用户服务器根据所述临时用户标识查找对应的私有用户设备标识,并将与所述私有用户设备标识相对应的用户鉴权向量反馈至所述S-CSCF;所述S-CSCF在接收到与所述私有用户设备标识相对应的用户鉴权向量后,通过所述I-CSCF和所述P-CSCF向所述用户设备返回鉴权挑战。
在该技术方案中,采用临时用户标识来替代私有用户身份标识来完成IMS网络的初始注册,使得即便不法分子获取到临时用户标识,也无法根据临时用户标识获取到用户的相关信息,加强了IMS网络初始注册过程的安全性,有效地防止了用户信息的泄漏。
在上述技术方案中,优选地,所述移动通信网络在接收到所述用户设备的注册请求时,向所述用户设备分配所述临时用户标识。
在该技术方案中,通过移动通信网络在接收到用户设备的注册请求时,向用户设备分配所述临时用户标识,能够在不改变现有网格架构的前提下实现对用户设备的临时用户标识的分配,过程简单,易于实现。
在上述技术方案中,优选地,所述移动通信网络包括2/3G网络、LTE网络;所述初始注册请求包括所述临时用户标识和归属网络域名。
图2示出了根据本发明的一个实施例的IMS网络的注册系统的示意框图。
如图2所示,根据本发明的一个实施例的IMS网络的注册系统,包括:移动通信网络202、用户设备204和IMS网络206;
其中,所述移动通信网络202用于向用户设备204分配临时用户标识;所述用户设备204用于接收所述临时用户标识,并基于所述临时用户标识向所述IMS网络206发送初始注册请求。
在该技术方案中,通过移动通信网络202向用户设备204分配临时用户标识,由用户设备204基于临时用户标识向IMS网络206发送初始注册请求,避免了相关技术中用户设备直接发送携带有私有用户身份标识的初始注册请求而存在私有用户身份标识被窃取的安全隐患,而采用临时用户
标识来替代私有用户身份标识后,即便不法分子获取到临时用户标识,也无法根据临时用户标识获取到用户的相关信息,从而加强了IMS网络初始注册过程的安全性,有效地防止了用户信息的泄漏。
在上述技术方案中,优选地,还包括:归属签约用户服务器208,用于在所述移动通信网络202向所述用户设备204分配所述临时用户标识之后,将所述临时用户标识与所述用户设备204的私有用户设备标识进行对应存储。
在该技术方案中,通过归属签约用户服务器208(即Home Subscriber Server,HSS)将临时用户标识与用户设备204的私有用户设备标识进行对应存储,使得用户设备204在后续根据临时用户标识执行初始注册过程时,能够根据初始注册请求中包含的临时用户标识获取到用户设备204的私有用户设备标识,以为用户设备204分配用户鉴权向量。
在上述技术方案中,优选地,所述用户设备204基于所述临时用户标识向所述IMS网络206发送初始注册请求,以执行初始注册过程具体包括:所述用户设备204向所述IMS网络206的P-CSCF发送包含有所述临时用户标识的初始注册请求;所述P-CSCF根据所述初始注册请求中的归属网络域名,将所述初始注册请求路由至所述IMS网络206的I-CSCF,以供所述I-CSCF查询所述归属签约用户服务器208并选择S-CSCF;所述I-CSCF将所述初始注册请求发送至所述S-CSCF;所述S-CSCF根据所述初始注册请求中包含的所述临时用户标识向所述归属签约用户服务器208请求下载用户鉴权向量;所述归属签约用户服务器208根据所述临时用户标识查找对应的私有用户设备标识,并将与所述私有用户设备标识相对应的用户鉴权向量反馈至所述S-CSCF;所述S-CSCF在接收到与所述私有用户设备标识相对应的用户鉴权向量后,通过所述I-CSCF和所述P-CSCF向所述用户设备204返回鉴权挑战。
在该技术方案中,采用临时用户标识来替代私有用户身份标识来完成IMS网络的初始注册,使得即便不法分子获取到临时用户标识,也无法根据临时用户标识获取到用户的相关信息,加强了IMS网络初始注册过程的安全性,有效地防止了用户信息的泄漏。
在上述技术方案中,优选地,所述移动通信网络202在接收到所述用户设备204的注册请求时,向所述用户设备204分配所述临时用户标识。
在该技术方案中,通过移动通信网络202在接收到用户设备204的注册请求时,向用户设备204分配所述临时用户标识,能够在不改变现有网格架构的前提下实现对用户设备204的临时用户标识的分配,过程简单,易于实现。
在上述技术方案中,优选地,所述移动通信网络202包括2/3G网络、LTE网络;所述初始注册请求包括所述临时用户标识和归属网络域名。
以下对本发明的技术方案进一步说明。
本发明的技术方案主要是在IMS初始注册过程中使用临时用户身份标识进行注册,临时用户身份标识形式是usertempname@reaml,其中,usertempname是临时用户标识,reaml是归属网络域名。临时用户身份标识是个动态数据,会随着移动接入网络的变化而动态分配,使用临时用户身份标识来代替私有用户身份标识进行ISM网络注册的目的是为了加强系统的保密性,防止非法个人或团体通过监听网络信令窃取IMSI或跟踪用户的位置。
具体地,本发明的技术方案包括接入网注册过程和IMS网络的初始注册过程。其中,接入网注册过程是指移动网络(LTE网络或2/3G网络)注册过程,具体地,如图3所示,UE(即用户设备)注册后,移动网络会为其分配一个临时识别码TMSI(Temporary Mobile Subscriber Identity)以作为临时用户标识,并存储在归属签约用户服务器HSS中。
用户在签约IMS业务时,已经将其私有用户身份标识存储在HSS中,因此对于驻留到IMS网络的UE而言,HSS中存储该UE用户的私有用户身份标识和移动网络为其分配的TMSI,IMS网络的初始注册过程中使用临时用户身份标识进行注册,具体过程参照图4所示。
如图4所示,根据本发明的实施例的IMS网络的初始注册过程,包括:UE携带临时用户身份标识向IMS网络发起初始注册请求;P-CSCF根据初始注册请求中的归属网络域名(在用户终端配置),将请求路由到I-CSCF;I-CSCF使用UAR消息查询HSS;HSS用UAA消息返回用户需求的S-CSCF
能力集;I-CSCF根据用户的签约需求选择合适的S-CSCF,将注册请求发往S-CSCF;当S-CSCF接收到该请求后,S-CSCF根据初始注册请求中包含的临时用户标识(图4中的usertempname)用MAR消息向归属签约用户服务器HSS请求下载用户鉴权向量;归属签约用户服务器HSS根据临时用户标识查找对应的私有用户身份标识,并通过MAA消息将与私有用户身份标识相对应的用户鉴权向量反馈至S-CSCF;S-CSCF在接收到与私有用户身份标识相对应的用户鉴权向量后,通过I-CSCF和P-CSCF向UE返回鉴权挑战。
上述实施例的技术方案通过在IMS网络的初始注册过程中使用临时用户身份标识来代替私有用户身份标识,加强了系统的保密性,防止非法个人或团体通过监听网络信令窃取IMSI或跟踪用户的位置。
以上结合附图详细说明了本发明的技术方案,本发明提出了一种新的IMS网络的注册方案,能够采用临时用户标识替代私有用户身份标识来完成IMS网络的初始注册过程,加强了IMS网络初始注册过程的安全性,有效防止用户信息的泄漏。
以上所述仅为本发明的优选实施例而已,并不用于限制本发明,对于本领域的技术人员来说,本发明可以有各种更改和变化。凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。
Claims (10)
- 一种IMS网络的注册方法,其特征在于,包括:移动通信网络向用户设备分配临时用户标识;所述用户设备接收所述临时用户标识,并基于所述临时用户标识向IMS网络发送初始注册请求,以执行初始注册过程。
- 根据权利要求1所述的IMS网络的注册方法,其特征在于,在所述移动通信网络向所述用户设备分配所述临时用户标识之后,还包括:归属签约用户服务器将所述临时用户标识与所述用户设备的私有用户设备标识进行对应存储。
- 根据权利要求2所述的IMS网络的注册方法,其特征在于,所述用户设备基于所述临时用户标识向所述IMS网络发送初始注册请求,以执行初始注册过程的步骤具体包括:所述用户设备向所述IMS网络的P-CSCF发送包含有所述临时用户标识的初始注册请求;所述P-CSCF根据所述初始注册请求中的归属网络域名,将所述初始注册请求路由至所述IMS网络的I-CSCF,以供所述I-CSCF查询所述归属签约用户服务器并选择S-CSCF;所述I-CSCF将所述初始注册请求发送至所述S-CSCF;所述S-CSCF根据所述初始注册请求中包含的所述临时用户标识向所述归属签约用户服务器请求下载用户鉴权向量;所述归属签约用户服务器根据所述临时用户标识查找对应的私有用户设备标识,并将与所述私有用户设备标识相对应的用户鉴权向量反馈至所述S-CSCF;所述S-CSCF在接收到与所述私有用户设备标识相对应的用户鉴权向量后,通过所述I-CSCF和所述P-CSCF向所述用户设备返回鉴权挑战。
- 根据权利要求1至3中任一项所述的IMS网络的注册方法,其特征在于,所述移动通信网络在接收到所述用户设备的注册请求时,向所述用户设备分配所述临时用户标识。
- 根据权利要求1至3中任一项所述的IMS网络的注册方法,其特征在于:所述移动通信网络包括2/3G网络、LTE网络;所述初始注册请求包括所述临时用户标识和归属网络域名。
- 一种IMS网络的注册系统,其特征在于,包括:移动通信网络、用户设备和IMS网络;其中,所述移动通信网络用于向用户设备分配临时用户标识;所述用户设备用于接收所述临时用户标识,并基于所述临时用户标识向所述IMS网络发送初始注册请求。
- 根据权利要求6所述的IMS网络的注册系统,其特征在于,还包括:归属签约用户服务器,用于在所述移动通信网络向所述用户设备分配所述临时用户标识之后,将所述临时用户标识与所述用户设备的私有用户设备标识进行对应存储。
- 根据权利要求7所述的IMS网络的注册系统,其特征在于,所述用户设备基于所述临时用户标识向所述IMS网络发送初始注册请求,以执行初始注册过程具体包括:所述用户设备向所述IMS网络的P-CSCF发送包含有所述临时用户标识的初始注册请求;所述P-CSCF根据所述初始注册请求中的归属网络域名,将所述初始注册请求路由至所述IMS网络的I-CSCF,以供所述I-CSCF查询所述归属签约用户服务器并选择S-CSCF;所述I-CSCF将所述初始注册请求发送至所述S-CSCF;所述S-CSCF根据所述初始注册请求中包含的所述临时用户标识向所述归属签约用户服务器请求下载用户鉴权向量;所述归属签约用户服务器根据所述临时用户标识查找对应的私有用户设备标识,并将与所述私有用户设备标识相对应的用户鉴权向量反馈至所述S-CSCF;所述S-CSCF在接收到与所述私有用户设备标识相对应的用户鉴权向 量后,通过所述I-CSCF和所述P-CSCF向所述用户设备返回鉴权挑战。
- 根据权利要求6至8中任一项所述的IMS网络的注册系统,其特征在于,所述移动通信网络在接收到所述用户设备的注册请求时,向所述用户设备分配所述临时用户标识。
- 根据权利要求6至8中任一项所述的IMS网络的注册系统,其特征在于:所述移动通信网络包括2/3G网络、LTE网络;所述初始注册请求包括所述临时用户标识和归属网络域名。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510413664.5 | 2015-07-14 | ||
| CN201510413664.5A CN105635098B (zh) | 2015-07-14 | 2015-07-14 | Ims网络的注册方法及系统 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017008513A1 true WO2017008513A1 (zh) | 2017-01-19 |
Family
ID=56049594
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2016/074902 Ceased WO2017008513A1 (zh) | 2015-07-14 | 2016-02-29 | Ims网络的注册方法及系统 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN105635098B (zh) |
| WO (1) | WO2017008513A1 (zh) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110661753B (zh) * | 2018-06-30 | 2021-10-22 | 华为技术有限公司 | 一种网络的注册方法、装置及系统 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101043701A (zh) * | 2006-03-23 | 2007-09-26 | 华为技术有限公司 | 一种ip多媒体子系统为移动电路域用户提供注册和呼叫接续的方法及其系统 |
| CN101442801A (zh) * | 2008-12-25 | 2009-05-27 | 华为技术有限公司 | 一种网络注册的方法和设备 |
| CN102035811A (zh) * | 2009-09-30 | 2011-04-27 | 中兴通讯股份有限公司 | 一种实现用户ims注册的方法、装置及系统 |
| CN102056251A (zh) * | 2009-11-04 | 2011-05-11 | 中国移动通信集团公司 | 一种网络切换的方法、系统及设备 |
-
2015
- 2015-07-14 CN CN201510413664.5A patent/CN105635098B/zh active Active
-
2016
- 2016-02-29 WO PCT/CN2016/074902 patent/WO2017008513A1/zh not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101043701A (zh) * | 2006-03-23 | 2007-09-26 | 华为技术有限公司 | 一种ip多媒体子系统为移动电路域用户提供注册和呼叫接续的方法及其系统 |
| CN101442801A (zh) * | 2008-12-25 | 2009-05-27 | 华为技术有限公司 | 一种网络注册的方法和设备 |
| CN102035811A (zh) * | 2009-09-30 | 2011-04-27 | 中兴通讯股份有限公司 | 一种实现用户ims注册的方法、装置及系统 |
| CN102056251A (zh) * | 2009-11-04 | 2011-05-11 | 中国移动通信集团公司 | 一种网络切换的方法、系统及设备 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN105635098B (zh) | 2019-04-12 |
| CN105635098A (zh) | 2016-06-01 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP2521304B1 (en) | Authentication method, system and apparatus | |
| US10419895B2 (en) | Method and system for identity management across multiple planes | |
| CN103391539B (zh) | 互联网协议多媒体子系统ims的开户方法、装置及系统 | |
| US10142341B2 (en) | Apparatus, system and method for webRTC | |
| US8578456B2 (en) | Authentication in an IP multimedia subsystem network where an in-use line identifier (LID) does not match a registered LID | |
| WO2017092229A1 (zh) | 基于多业务的ims注册方法和ims注册系统 | |
| WO2019114320A1 (zh) | 一种ims用户的注册方法及装置 | |
| US11283773B2 (en) | Protecting user's anonymity when visiting foreign networks | |
| US8565382B2 (en) | Method for obtaining information of key management server, and method, system and device for monitoring | |
| US20100293593A1 (en) | Securing contact information | |
| CN101030854B (zh) | 多媒体子系统中网络实体的互认证方法及装置 | |
| CN110324291A (zh) | 一种通信方法、及相关产品 | |
| CN103888414B (zh) | 一种数据处理方法和设备 | |
| US20070055874A1 (en) | Bundled subscriber authentication in next generation communication networks | |
| KR20160108484A (ko) | 웹 실시간 통신(WebRTC)에 있어 IP 멀티미디어 서브시스템(IMS)으로의 액세스에 대한 보안 | |
| CN101227474A (zh) | 软交换网络中的会话初始化协议用户鉴权方法 | |
| CN101330643B (zh) | 实现共享公共用户标识的用户设备业务配置的方法 | |
| CN104113557B (zh) | 基于ims语音视频业务的用户接入位置管理方法及装置 | |
| CN103001935A (zh) | Ils网络的ue在ims网络中的认证方法和系统 | |
| WO2017008513A1 (zh) | Ims网络的注册方法及系统 | |
| CN106790055A (zh) | 一种ims系统的注册方法与装置 | |
| CN102594782A (zh) | Ip多媒体子系统鉴权方法、系统及服务器 | |
| CN101540678A (zh) | 固定终端及其认证方法 | |
| CN100372329C (zh) | 一种注册方法、代理装置与注册系统 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16823661 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 16823661 Country of ref document: EP Kind code of ref document: A1 |