WO2019047714A1 - 临时用户凭证的生成方法、用户卡、终端及网络设备 - Google Patents

临时用户凭证的生成方法、用户卡、终端及网络设备 Download PDF

Info

Publication number
WO2019047714A1
WO2019047714A1 PCT/CN2018/101677 CN2018101677W WO2019047714A1 WO 2019047714 A1 WO2019047714 A1 WO 2019047714A1 CN 2018101677 W CN2018101677 W CN 2018101677W WO 2019047714 A1 WO2019047714 A1 WO 2019047714A1
Authority
WO
WIPO (PCT)
Prior art keywords
verification information
temporary user
terminal
network device
generating
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2018/101677
Other languages
English (en)
French (fr)
Inventor
霍薇靖
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Mobile Communications Group Co Ltd
Research Institute of China Mobile Communication Co Ltd
Original Assignee
China Mobile Communications Group Co Ltd
Research Institute of China Mobile Communication Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Mobile Communications Group Co Ltd, Research Institute of China Mobile Communication Co Ltd filed Critical China Mobile Communications Group Co Ltd
Publication of WO2019047714A1 publication Critical patent/WO2019047714A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • H04L9/0869Generation of secret information including derivation or calculation of cryptographic keys or passwords involving random numbers or seeds
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/321Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/26Network addressing or numbering for mobility support

Definitions

  • the present disclosure relates to the field of communications technologies, and in particular, to a method for generating temporary user credentials, a user card, a terminal, and a network device.
  • the Subscriber Identity Module (U) card is an important physical identifier for the user's mobile identity and an important resource for the operator.
  • the (U)SIM card is an independent security carrier that can carry the user's code number resources for accessing the network and using services such as telephone, SMS, and data.
  • IoT Internet of Things
  • IMSI International Mobile Subscriber Identification Number
  • the equipment needs a certain period of time from the completion of production to the final sale.
  • the code number resources such as IMSI have certain invalidity. When the time exceeds a certain period of time, the code number resource will be invalid, which will cause the IoT device to lose connection when the device leaves the factory.
  • the capabilities of the carrier network In addition, the time of the IoT device in the warehouse is also a waste of resources for the code number resource.
  • the present disclosure provides a method for generating temporary user credentials, a user card, a terminal, and a network device.
  • the IoT terminal can access the limited network by means of the temporary user credentials, provide temporary networking capabilities, and solve the problem of timeliness and resource waste of the above code number resources.
  • an embodiment of the present disclosure provides the following solution:
  • a method for generating temporary user credentials comprising:
  • a temporary user credential is generated according to the second verification information and the index number.
  • the step of generating the first verification information according to the trigger request includes:
  • the first verification information is generated according to the random number and the preset information.
  • the step of generating the first verification information according to the random number and the preset information includes:
  • the first verification information is generated according to the random number, the information input by the user, and the pre-stored key.
  • the key is a public key or a symmetric key of a network operator to which the user card belongs.
  • the step of generating a temporary user credential according to the second check information and the index number includes:
  • a temporary user credential is generated according to the second verification information and the index number.
  • the generating temporary user credentials further includes:
  • the index number of the temporary user credential is stored.
  • An embodiment of the present disclosure further provides a user card, including:
  • a transceiver configured to receive a trigger request generated by the terminal to generate a temporary user credential
  • a processor configured to generate first verification information according to the trigger request, and send, by the transceiver, the first verification information to a network device by using a terminal;
  • the transceiver is further configured to receive, by the terminal, second verification information fed back by the network device and an index number of the temporary user credential of the network side generated by the network device;
  • the processor is further configured to generate a temporary user credential according to the second verification information and the index number.
  • the method is specifically configured to generate a random number according to the trigger request, and generate first check information according to the random number and the preset information.
  • the processor is specifically configured to: generate first verification information according to the random number and a pre-stored key; or generate a first according to the random number, information input by the user, and a pre-stored key. Verify the information.
  • the processor is specifically configured to: perform verification on the network device according to the second verification information; and after the verification succeeds, generate a temporary user credential according to the second verification information and the index number. .
  • the user card also includes:
  • a memory for storing an index number of the temporary user credential.
  • An embodiment of the present disclosure further provides a method for generating a temporary user credential, including:
  • the step of sending a trigger request for generating a temporary user credential to the user card includes:
  • the first terminal generates a trigger request for the temporary user credential and sends the trigger request to the user card.
  • the step of receiving the first check information sent by the user card according to the trigger request, and sending the first check information to the network device includes:
  • the first terminal receives the first verification information generated by the user card according to the trigger request, and sends the first verification information to the network device.
  • the step of sending a trigger request for generating a temporary user credential to the user card includes:
  • the second terminal generates a trigger request for the temporary user credential and sends the request to the user card through the first terminal.
  • the step of receiving the first check information sent by the user card according to the trigger request, and sending the first check information to the network device includes:
  • the second terminal receives the first check information sent by the user card according to the trigger request by using the first terminal, and sends the first check information and the authentication information of the second terminal to the network device.
  • the method for generating temporary user credentials further includes:
  • the network device is accessed according to the temporary user credentials generated by the user card and the index number of the temporary user credentials.
  • An embodiment of the present disclosure further provides a terminal, including:
  • a transceiver for transmitting a trigger request for generating a temporary user credential to the user card
  • the terminal further includes:
  • the network module is configured to access the network device according to the temporary user credentials generated by the user card and the index number of the temporary user credentials.
  • An embodiment of the present disclosure further provides a method for generating a temporary user credential, including:
  • a temporary user credential is generated, and the index number of the temporary user credential is assigned and sent to the terminal.
  • the step of generating a temporary user credential includes:
  • a temporary user credential is generated based on the random number and a pre-stored key.
  • the key is a public key or a symmetric key of an operator to which the network device belongs.
  • An embodiment of the present disclosure further provides a network device, including:
  • a transceiver configured to receive first verification information generated by a user card sent by the terminal
  • the processor is configured to perform verification according to the first verification information; after the verification succeeds, generate a temporary user credential, and allocate an index number of the temporary user credential, and send the identifier to the terminal by the transceiver.
  • the method is specifically configured to: generate a random number; and generate a temporary user credential according to the random number and the pre-stored key.
  • An embodiment of the present disclosure further provides a method for generating a temporary user credential, including:
  • the terminal sends a trigger request for generating a temporary user credential to the user card
  • the user card generates the first verification information according to the trigger request, and sends the first verification information to the terminal;
  • the terminal sends the first verification information to the network device
  • the network device performs verification on the user card according to the first verification information, and after the verification is passed, generates second verification information, temporary user credentials, and an index number of the temporary user credentials, and the second verification information and the temporary The index number of the user credential is sent to the terminal;
  • the terminal sends the index number according to the second verification information and the temporary user credential to the user card;
  • the user card generates a temporary user credential according to the second verification information and the index number of the temporary user credential.
  • An embodiment of the present disclosure further provides a system for generating temporary user credentials, including: a user card, a terminal, and a network device;
  • the terminal is configured to send a trigger request for generating a temporary user credential to the user card; and send the first check information generated by the user card to the network device; and receive the second check information fed back by the network device and the index of the temporary user credential And sending the second verification information and the index number of the temporary user credential to the user card;
  • the user card is configured to generate first verification information according to the trigger request, and send the first verification information to the terminal, and generate a temporary user credential according to the second verification information sent by the terminal and the index number of the temporary user credential;
  • the network device is configured to perform verification on the user card according to the first verification information, and after the verification is passed, generate second verification information, temporary user credentials, and an index number of the temporary user credentials, and the second school
  • the verification information and the index number of the temporary user credentials are sent to the terminal.
  • Embodiments of the present disclosure also provide a communication device comprising: a processor, a memory storing a computer program, and when the computer program is executed by the processor, performing the method as described above.
  • Embodiments of the present disclosure also provide a computer readable storage medium comprising instructions that, when executed by a computer, cause a computer to perform the method as described above.
  • the foregoing solution of the present disclosure by receiving a trigger request for generating a temporary user credential sent by the terminal; generating, according to the trigger request, the first check information, and transmitting, by the terminal, the first check information to the network device;
  • the terminal receives the second verification information fed back by the network device and the index number of the temporary user credential generated by the network device, and generates a temporary user credential according to the second verification information and the index number.
  • the IoT terminal can access the limited network by means of the temporary user credentials, provide temporary networking capabilities, and solve the problem of timeliness and resource waste of the above code number resources.
  • FIG. 1 is a flowchart of a method for generating a temporary user credential on a user card side of the present disclosure
  • FIG. 2 is a flowchart of a method for generating temporary user credentials on the terminal side of the present disclosure
  • FIG. 3 is a flow chart of interaction between a user card, a terminal, and a network device in an embodiment of the present disclosure
  • FIG. 4 is a flowchart of interaction between another user card, a first terminal, a second terminal, and a network device according to an embodiment of the present disclosure
  • FIG. 5 is a flowchart of a method for generating temporary user credentials on the network device side of the present disclosure
  • FIG. 6 is a schematic diagram of interaction between a user card and a network in the system of the present disclosure.
  • the embodiment of the present disclosure solves the problem of time-sensitive resource waste and resource waste in the (U)SIM card, and proposes that the user card and the network temporarily negotiate temporary user credentials, so that the device can access the device if the code number resource fails. Limit the network, and then complete the operation of writing or updating the official code number resource.
  • an embodiment of the present disclosure provides a method for generating a temporary user credential, including:
  • Step 11 Receive a trigger request generated by the terminal to generate a temporary user credential
  • Step 12 Generate first verification information according to the trigger request, and send the first verification information to the network device by using the terminal;
  • a random number is generated according to the trigger request, and the first check information is generated according to the random number and the preset information.
  • the step of generating the first verification information according to the random number and the preset information includes:
  • the first verification information is generated according to the random number, the information input by the user, and the pre-stored key.
  • the key is a public key or a symmetric key of a network operator to which the user card belongs.
  • Step 13 Receive, by the terminal, second check information fed back by the network device, and an index number of the temporary user credential of the network side generated by the network device;
  • Step 14 Generate a temporary user credential according to the second verification information and the index number.
  • the network device is verified according to the second verification information; after the verification is successful, the temporary user credentials are generated according to the second verification information and the index number.
  • the foregoing solution of the present disclosure by receiving a trigger request for generating a temporary user credential sent by the terminal; generating, according to the trigger request, the first check information, and transmitting, by the terminal, the first check information to the network device;
  • the terminal receives the second verification information fed back by the network device and the index number of the temporary user credential generated by the network device, and generates a temporary user credential according to the second verification information and the index number.
  • the terminal can use the temporary user credentials to access the restricted network, provide temporary networking capabilities, and solve the problem of timeliness and resource waste of the above code number resources.
  • the method may further include:
  • Step 15 storing an index number of the temporary user credential.
  • an embodiment of the present disclosure further provides a user card, including:
  • a transceiver configured to receive a trigger request generated by the terminal to generate a temporary user credential
  • a processor configured to generate first verification information according to the trigger request, and send, by the transceiver, the first verification information to a network device by using a terminal;
  • the transceiver is further configured to receive, by the terminal, second verification information fed back by the network device and an index number of the temporary user credential of the network side generated by the network device;
  • the processor is further configured to generate a temporary user credential according to the second verification information and the index number.
  • the method is specifically configured to generate a random number according to the trigger request, and generate first check information according to the random number and the preset information.
  • the processor is specifically configured to: generate first verification information according to the random number and a pre-stored key; or generate a first according to the random number, information input by the user, and a pre-stored key. Verify the information.
  • the processor is specifically configured to: perform verification on the network device according to the second verification information; and after the verification succeeds, generate a temporary user credential according to the second verification information and the index number. .
  • the user card further includes: a memory, configured to store an index number of the temporary user credential.
  • the card of the user card has key information for generating the temporary user credential, and may be operator public key information or symmetric key information;
  • the user card generates a temporary user credential function.
  • the "key" stored in the card is called, and a random number is generated, and the verification information of the temporary user credential is calculated by the two (if there is user input) , the user input information must also be included, the algorithm of the key can be negotiated in advance, and then sent to the network, and when the network also sends a random number or the like, the final temporary user credentials are generated; the user card also needs to be stored.
  • User certificate index number delivered by the network is
  • the embodiment of the user card of the present disclosure is the device corresponding to the method embodiment shown in FIG. 1 , and various implementations of the method shown in FIG. 1 are applicable to the embodiment of the user card, and can also achieve the same. Technical effects.
  • an embodiment of the present disclosure further provides a method for generating a temporary user credential, including:
  • Step 21 Send a trigger request for generating a temporary user credential to the user card
  • Step 22 Receive first verification information that is sent by the user card according to the trigger request, and send the first verification information to the network device.
  • Step 23 Receive second verification information fed back by the network device and an index number of the temporary user credential of the network side generated by the network device, and send the index number to the user card.
  • the step 21 includes: the first terminal generates a trigger request for the temporary user credential, and sends the trigger request to the user card.
  • Step 22 includes: the first terminal receives the first verification information generated by the user card according to the trigger request, and sends the first verification information to the network device.
  • the workflow is as follows:
  • the terminal triggers the “temporary user credential generation” process, and some user information can be input at this time;
  • the (U)SIM card generates the random number information, and invokes the user credential key stored in the card to generate the first verification information, and sends the first verification information to the network side through the terminal;
  • the network device verifies the first verification information, and generates a random number, and then generates a temporary user credential according to the information sent on the card, and allocates an index number of the temporary user credential;
  • the network device sends the random number verification information (that is, the second verification information) and the index number of the temporary user credentials;
  • the (U)SIM card performs verification after receiving the information, and generates a temporary user credential according to the issued information (including the second verification information and the index number of the temporary user credential), and stores the index number of the temporary user credential. ;
  • the subsequent terminal can access the network by using the temporary user credentials and its index number, but the function is limited, and the formal code number resource writing or updating is completed.
  • the temporary user credential access network function is limited, and the number of times or time that can be authenticated may be set, and the service aspect can be flexibly configured.
  • step 21 includes: the second terminal generates a trigger request for the temporary user credential, and sends the request to the user card through the first terminal.
  • Step 22 includes: the second terminal receives, by using the first terminal, first verification information that is sent by the user card according to the trigger request, and performs authentication of the first verification information and the second terminal. Information is sent to the network device.
  • the workflow includes:
  • the trusted agent terminal (second terminal) triggers the “temporary user credential generation” process, and then the first terminal triggers the “temporary user credential generation” process to the (U)SIM card, and some user information can be input at this time;
  • the (U)SIM card generates the random number information, and the user credential key stored in the card is used to generate the verification information (ie, the first verification information), and is sent to the first terminal;
  • the first terminal sends the information to the trusted proxy terminal, and the trusted proxy terminal replenishes some information of the self, and then sends the information to the network device;
  • the network device verifies the sending information, generates a random number, and then generates a temporary user credential according to the card sending information, and allocates an index number of the temporary user credential;
  • the network device sends the random number verification information (that is, the second verification information) and the index number of the temporary user certificate;
  • SIM card performs verification after receiving the information, and generates temporary user credential information according to the issued information and stores the index number;
  • the subsequent terminal can access the network by using the temporary user credentials and its index number, but the function is limited, and the formal code number resource writing or updating is completed.
  • the method may further include: Step 24: accessing the network device according to the temporary user credentials generated by the user card and the index number of the temporary user credentials.
  • an embodiment of the present disclosure further provides a terminal, including:
  • a transceiver configured to send a trigger request for generating a temporary user credential to the user card; and receive first verification information sent by the user card according to the trigger request, and send the first verification information to the network device; and receive The second check information fed back by the network device and the index number of the temporary user credential of the network side generated by the network device are sent to the user card.
  • the terminal further includes: a network module, configured to access the network device according to the temporary user credentials generated by the user card and the index number of the temporary user credentials.
  • the embodiment of the terminal of the present disclosure is the device corresponding to the method embodiment shown in FIG. 2, and various implementations of the method shown in FIG. 2 are applicable to the embodiment of the terminal, and the same technical effect can be achieved. .
  • an embodiment of the present disclosure further provides a method for generating a temporary user credential, including:
  • Step 51 Receive first verification information generated by a user card sent by the terminal.
  • Step 52 Perform verification according to the first verification information.
  • Step 53 After the verification succeeds, generate a temporary user credential, and assign an index number of the temporary user credential to the terminal.
  • the step of generating a temporary user credential includes:
  • Generating a random number generating a temporary user credential based on the random number and a pre-stored key.
  • the key is a public key or a symmetric key of an operator to which the network device belongs.
  • An embodiment of the present disclosure further provides a network device, including:
  • a transceiver configured to receive first verification information generated by a user card sent by the terminal
  • the processor is configured to perform verification according to the first verification information; after the verification succeeds, generate a temporary user credential, and allocate an index number of the temporary user credential, and send the identifier to the terminal by the transceiver.
  • the method is specifically configured to: generate a random number; and generate a temporary user credential according to the random number and the pre-stored key.
  • the network device mainly implements the function of generating and managing the temporary user credential.
  • the temporary user credential generation is triggered, the pre-stored “key” is invoked, and a random number is generated, and then the random number and other information sent by the card are combined.
  • the temporary user credential is temporarily negotiated by using the user card and the network device, so that if the device fails the code number resource, the device may have the opportunity to re-access the network, that is, access the restricted network, and then complete the formality. Operations such as writing or updating code number resources.
  • An embodiment of the present disclosure further provides a method for generating a temporary user credential, including:
  • the terminal sends a trigger request for generating a temporary user credential to the user card
  • the user card generates the first verification information according to the trigger request, and sends the first verification information to the terminal;
  • the terminal sends the first verification information to the network device
  • the network device performs verification on the user card according to the first verification information, and after the verification is passed, generates second verification information, temporary user credentials, and an index number of the temporary user credentials, and the second verification information and the temporary The index number of the user credential is sent to the terminal;
  • the terminal sends the index number according to the second verification information and the temporary user credential to the user card;
  • the user card generates a temporary user credential according to the second verification information and the index number of the temporary user credential. Specifically, the workflow shown in Figure 3.
  • a "trusted proxy terminal” can be added to the process, which has the capability of accessing the network, and has the right to apply for temporary user credentials on the network side.
  • the workflow is as shown in Figure 4 above.
  • an embodiment of the present disclosure further provides a system for generating a temporary user credential, including: a user card, a terminal, and a network device;
  • the terminal is configured to send a trigger request for generating a temporary user credential to the user card; and send the first check information generated by the user card to the network device; and receive the second check information fed back by the network device and the index of the temporary user credential And sending the second verification information and the index number of the temporary user credential to the user card;
  • the user card is configured to generate first verification information according to the trigger request, and send the first verification information to the terminal, and generate a temporary user credential according to the second verification information sent by the terminal and the index number of the temporary user credential;
  • the network device is configured to perform verification on the user card according to the first verification information, and after the verification is passed, generate second verification information, temporary user credentials, and an index number of the temporary user credentials, and the second school
  • the verification information and the index number of the temporary user credentials are sent to the terminal.
  • the terminal may be an IoT device
  • the user card may be a (U)SIM card
  • the operator's key information for generating a one-time/temporary user credential is pre-made in the user card (the key is not A card or a secret is required, which may be the operator's public key or a symmetric key.
  • the network side also initially stores the key information of the one-time/temporary user credentials.
  • Temporary user credentials are negotiated through the user card and the network, so that if the device fails the code number, the device may have the opportunity to re-access the network, that is, access the restricted network, thereby completing the writing or updating of the official code number resource. Wait for the operation.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Databases & Information Systems (AREA)
  • Telephonic Communication Services (AREA)
  • Meter Arrangements (AREA)

Abstract

本公开实施例提供一种临时用户凭证的生成方法、用户卡、终端及网络设备,方法包括:接收终端发送的生成临时用户凭证的触发请求;根据所述触发请求,产生第一校验信息,并通过终端将所述第一校验信息发送给网络设备;通过所述终端接收网络设备反馈的第二校验信息以及网络设备生成的网络侧的临时用户凭证的索引号;根据所述第二校验信息以及所述索引号,生成临时用户凭证。

Description

临时用户凭证的生成方法、用户卡、终端及网络设备
相关申请的交叉引用
本申请主张在2017年9月5日在中国提交的中国专利申请号No.201710790458.5的优先权,其全部内容通过引用包含于此。
技术领域
本公开涉及通信技术领域,特别是指一种临时用户凭证的生成方法、用户卡、终端及网络设备。
背景技术
用户卡(U)SIM(Subscriber Identity Module)卡,是用户移动身份的重要物理标识,也是运营商掌握的重要资源。(U)SIM卡是一个独立的安全载体,其上可承载用户的码号资源,用于接入网络,使用电话、短信、数据等业务。
随着物联网(Internet of Things,IoT)设备的蓬勃发展,为适应复杂的环境,很多IoT设备的体积较小,且封闭性要求较高,该类IoT设备大多采用焊接式的SIM卡,即在设备生产过程中就需要将卡片焊接在设备中,而为了保证设备的联网能力,此时SIM卡中已经预制了国际移动用户识别码(International Mobile Subscriber Identification Number,IMSI)等码号资源。
但是设备从生产完成到最终售出,需要一定的时间周期,而IMSI等码号资源具有一定的失效性,当超过一定时间后,码号资源就会失效,从而导致设备出厂时IoT设备失去连接运营商网络的能力。此外,IoT设备在仓库的时间对于码号资源也是一种资源浪费。
发明内容
本公开提供了一种临时用户凭证的生成方法、用户卡、终端及网络设备。让物联网终端能借助该临时用户凭证接入受限的网络,提供临时的联网能力,解决上述码号资源时效性和资源浪费的问题。
为解决上述技术问题,本公开的实施例提供如下方案:
一种临时用户凭证的生成方法,包括:
接收终端发送的生成临时用户凭证的触发请求;
根据所述触发请求,产生第一校验信息,并通过终端将所述第一校验信息发送给网络设备;
通过所述终端接收网络设备反馈的第二校验信息以及网络设备生成的网络侧的临时用户凭证的索引号;
根据所述第二校验信息以及所述索引号,生成临时用户凭证。
其中,根据所述触发请求,产生第一校验信息的步骤包括:
根据所述触发请求,生成一随机数;
根据所述随机数和预置信息,生成第一校验信息。
其中,根据所述随机数和预置信息,生成第一校验信息的步骤包括:
根据所述随机数和预先存储的密钥,生成第一校验信息;或者
根据所述随机数、用户输入的信息和预先存储的密钥,生成第一校验信息。
其中,所述密钥为用户卡所属网络运营商的公钥或者对称密钥。
其中,根据所述第二校验信息以及所述索引号,生成临时用户凭证的步骤包括:
根据所述第二校验信息,对网络设备进行校验;
校验成功后,并根据所述第二校验信息以及所述索引号,生成临时用户凭证。
其中,生成临时用户凭证后还包括:
存储所述临时用户凭证的索引号。
本公开的实施例还提供一种用户卡,包括:
收发机,用于接收终端发送的生成临时用户凭证的触发请求;
处理器,用于根据所述触发请求,产生第一校验信息,并由所述收发机通过终端将所述第一校验信息发送给网络设备;
所述收发机还用于通过所述终端接收网络设备反馈的第二校验信息以及网络设备生成的网络侧的临时用户凭证的索引号;
所述处理器还用于根据所述第二校验信息以及所述索引号,生成临时用 户凭证。
其中,所述处理器生成第一校验信息时,具体用于根据所述触发请求,生成一随机数;根据所述随机数和预置信息,生成第一校验信息。
其中,所述处理器具体用于:根据所述随机数和预先存储的密钥,生成第一校验信息;或者根据所述随机数、用户输入的信息和预先存储的密钥,生成第一校验信息。
其中,所述处理器具体用于:根据所述第二校验信息,对网络设备进行校验;校验成功后,并根据所述第二校验信息以及所述索引号,生成临时用户凭证。
其中,用户卡,还包括:
存储器,用于存储所述临时用户凭证的索引号。
本公开的实施例还提供一种临时用户凭证的生成方法,包括:
向用户卡发送生成临时用户凭证的触发请求;
接收用户卡根据所述触发请求发送的第一校验信息,并将所述第一校验信息发送给网络设备;
接收所述网络设备反馈的第二校验信息以及网络设备生成的网络侧的临时用户凭证的索引号,并发送给用户卡。
其中,向用户卡发送生成临时用户凭证的触发请求的步骤包括:
第一终端产生临时用户凭证的触发请求,并将所述触发请求发送给用户卡。
其中,接收用户卡根据所述触发请求发送的第一校验信息,并将所述第一校验信息发送给网络设备的步骤包括:
所述第一终端接收用户卡根据所述触发请求产生的第一校验信息,并将所述第一校验信息发送给网络设备。
其中,向用户卡发送生成临时用户凭证的触发请求的步骤包括:
第二终端产生临时用户凭证的触发请求,并通过第一终端发送给用户卡。
其中,接收用户卡根据所述触发请求发送的第一校验信息,并将所述第一校验信息发送给网络设备的步骤包括:
所述第二终端通过第一终端接收所述用户卡根据所述触发请求发送的第 一校验信息,并将所述第一校验信息以及所述第二终端的认证信息发送给网络设备。
其中,临时用户凭证的生成方法,还包括:
根据用户卡生成的临时用户凭证及临时用户凭证的索引号,接入网络设备。
本公开的实施例还提供一种终端,包括:
收发机,用于向用户卡发送生成临时用户凭证的触发请求;以及
接收用户卡根据所述触发请求发送的第一校验信息,并将所述第一校验信息发送给网络设备;以及
接收所述网络设备反馈的第二校验信息以及网络设备生成的网络侧的临时用户凭证的索引号,并发送给用户卡。
其中,终端,还包括:
网络模块,用于根据用户卡生成的临时用户凭证及临时用户凭证的索引号,接入网络设备。
本公开的实施例还提供一种临时用户凭证的生成方法,包括:
接收终端发送的用户卡生成的第一校验信息;
根据所述第一校验信息进行校验;
校验成功后,生成临时用户凭证,并分配所述临时用户凭证的索引号,发送给终端。
其中,所述生成临时用户凭证的步骤包括:
产生一随机数;
根据所述随机数以及预先存储的密钥,生成临时用户凭证。
其中,所述密钥为网络设备所属运营商的公钥或者对称密钥。
本公开的实施例还提供一种网络设备,包括:
收发机,用于接收终端发送的用户卡生成的第一校验信息;
处理器,用于根据所述第一校验信息进行校验;校验成功后,生成临时用户凭证,并分配所述临时用户凭证的索引号,并由所述收发机发送给终端。
其中,所述处理器生成临时用户凭证时,具体用于:产生一随机数;并根据所述随机数以及预先存储的密钥,生成临时用户凭证。
本公开的实施例还提供一种临时用户凭证的生成方法,包括:
终端向用户卡发送生成临时用户凭证的触发请求;
用户卡根据所述触发请求,产生第一校验信息,并发送给终端;
终端将所述第一校验信息发送给网络设备;
网络设备根据所述第一校验信息对用户卡进行校验,校验通过后,生成第二校验信息、临时用户凭证以及分配临时用户凭证的索引号,并将第二校验信息以及临时用户凭证的索引号发送给终端;
终端将所述根据所述第二校验信息以及临时用户凭证的索引号发送给用户卡;
用户卡根据第二校验信息以及所述临时用户凭证的索引号,生成临时用户凭证。
本公开的实施例还提供一种临时用户凭证的生成系统,包括:用户卡、终端以及网络设备;其中,
所述终端用于向用户卡发送生成临时用户凭证的触发请求;并将用户卡产生的第一校验信息发送给网络设备;并接收网络设备反馈的第二校验信息以及临时用户凭证的索引号,并将所述第二校验信息以及临时用户凭证的索引号发送给用户卡;
所述用户卡用于根据所述触发请求,产生第一校验信息,并发送给终端;并根据终端发送的第二校验信息以及所述临时用户凭证的索引号,生成临时用户凭证;
所述网络设备用于根据所述第一校验信息对用户卡进行校验,校验通过后,生成第二校验信息、临时用户凭证以及分配临时用户凭证的索引号,并将第二校验信息以及临时用户凭证的索引号发送给终端。
本公开的实施例还提供一种通信设备,包括:处理器、存储有计算机程序的存储器,所述计算机程序被处理器运行时,执行如上所述的方法。
本公开的实施例还提供一种计算机可读存储介质,包括指令,当所述指令在计算机运行时,使得计算机执行如上所述的方法。
本公开的上述方案至少包括以下有益效果:
本公开的上述方案,通过接收终端发送的生成临时用户凭证的触发请求; 根据所述触发请求,产生第一校验信息,并通过终端将所述第一校验信息发送给网络设备;通过所述终端接收网络设备反馈的第二校验信息以及网络设备生成的网络侧的临时用户凭证的索引号;根据所述第二校验信息以及所述索引号,生成临时用户凭证。让物联网终端能借助该临时用户凭证接入受限的网络,提供临时的联网能力,解决上述码号资源时效性和资源浪费的问题。
附图说明
为了更清楚地说明本公开实施例的技术方案,下面将对本公开实施例中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本公开的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。
图1为本公开的用户卡侧的临时用户凭证的生成方法的流程图;
图2为本公开的终端侧的临时用户凭证的生成方法的流程图;
图3为本公开的实施例中,用户卡、终端和网络设备的交互流程图;
图4为本公开的实施例中,另一种用户卡、第一终端、第二终端和网络设备的交互流程图;
图5为本公开的网络设备侧的临时用户凭证的生成方法的流程图;
图6为本公开的系统中,用户卡与网络的交互示意图。
具体实施方式
下面将参照附图更详细地描述本公开的示例性实施例。虽然附图中显示了本公开的示例性实施例,然而应当理解,可以以各种形式实现本公开而不应被这里阐述的实施例所限制。相反,提供这些实施例是为了能够更透彻地理解本公开,并且能够将本公开的范围完整的传达给本领域的技术人员。
本公开的实施例为解决(U)SIM卡中码号资源时效性和资源浪费的问题,提出用户卡和网络临时协商临时用户凭证,使得设备在码号资源失效的情况下,可以接入受限的网络,进而完成正式码号资源的写入或更新等操作。
如图1所示,本公开的实施例提供一种临时用户凭证的生成方法,包括:
步骤11,接收终端发送的生成临时用户凭证的触发请求;
步骤12,根据所述触发请求,产生第一校验信息,并通过终端将所述第一校验信息发送给网络设备;
具体的,根据所述触发请求,生成一随机数;根据所述随机数和预置信息,生成第一校验信息。
具体的,根据所述随机数和预置信息,生成第一校验信息的步骤包括:
根据所述随机数和预先存储的密钥,生成第一校验信息;或者
根据所述随机数、用户输入的信息和预先存储的密钥,生成第一校验信息。
其中,所述密钥为用户卡所属网络运营商的公钥或者对称密钥。
步骤13,通过所述终端接收网络设备反馈的第二校验信息以及网络设备生成的网络侧的临时用户凭证的索引号;
步骤14,根据所述第二校验信息以及所述索引号,生成临时用户凭证;
具体的,根据所述第二校验信息,对网络设备进行校验;校验成功后,并根据所述第二校验信息以及所述索引号,生成临时用户凭证。
本公开的上述方案,通过接收终端发送的生成临时用户凭证的触发请求;根据所述触发请求,产生第一校验信息,并通过终端将所述第一校验信息发送给网络设备;通过所述终端接收网络设备反馈的第二校验信息以及网络设备生成的网络侧的临时用户凭证的索引号;根据所述第二校验信息以及所述索引号,生成临时用户凭证。让终端能借助该临时用户凭证接入受限的网络,提供临时的联网能力,解决上述码号资源时效性和资源浪费的问题。
本公开的上述实施例中,生成临时用户凭证后还可以包括:
步骤15,存储所述临时用户凭证的索引号。
本公开的该实施例中,用户卡中预制运营商的用于生成一次性/临时用户凭证的密钥信息,用户卡和网络临时协商临时用户凭证,使得设备在码号资源失效的情况下,可以接入受限的网络,进而完成正式码号资源的写入或更新等操作。
与上述方法相应的,本公开的实施例还提供一种用户卡,包括:
收发机,用于接收终端发送的生成临时用户凭证的触发请求;
处理器,用于根据所述触发请求,产生第一校验信息,并由所述收发机 通过终端将所述第一校验信息发送给网络设备;
所述收发机还用于通过所述终端接收网络设备反馈的第二校验信息以及网络设备生成的网络侧的临时用户凭证的索引号;
所述处理器还用于根据所述第二校验信息以及所述索引号,生成临时用户凭证。
其中,所述处理器生成第一校验信息时,具体用于根据所述触发请求,生成一随机数;根据所述随机数和预置信息,生成第一校验信息。
其中,所述处理器具体用于:根据所述随机数和预先存储的密钥,生成第一校验信息;或者根据所述随机数、用户输入的信息和预先存储的密钥,生成第一校验信息。
其中,所述处理器具体用于:根据所述第二校验信息,对网络设备进行校验;校验成功后,并根据所述第二校验信息以及所述索引号,生成临时用户凭证。
其中,用户卡还包括:存储器,用于存储所述临时用户凭证的索引号。
具体的,用户卡的的卡内存有用于临时用户凭证生成的密钥信息,可为运营商公钥信息,或对称密钥信息;
用户卡生成临时用户凭证功能,当临时用户凭证生成被触发时,调用卡内存储的“密钥”,并生成一个随机数,通过两者计算出临时用户凭证的校验信息(如果有用户输入,则还需包含用户输入信息),密钥的算法可事先协商好,然后上发给网络,待网络也下发一个随机数或类似信息时,生成最终的临时用户凭证;用户卡还需存储网络下发的用户凭证索引号。
本公开的该用户卡的实施例是与上述图1所示方法实施例对应的设备,上述图1所示方法中各种实现方式均适用于该用户卡的实施例中,也能达到相同的技术效果。
如图2所示,本公开的实施例还提供一种临时用户凭证的生成方法,包括:
步骤21,向用户卡发送生成临时用户凭证的触发请求;
步骤22,接收用户卡根据所述触发请求发送的第一校验信息,并将所述第一校验信息发送给网络设备;
步骤23,接收所述网络设备反馈的第二校验信息以及网络设备生成的网络侧的临时用户凭证的索引号,并发送给用户卡。
其中,步骤21包括:第一终端产生临时用户凭证的触发请求,并将所述触发请求发送给用户卡。
其中,步骤22包括:所述第一终端接收用户卡根据所述触发请求产生的第一校验信息,并将所述第一校验信息发送给网络设备。
具体的,如图3所示,工作流程如下:
1)终端触发“临时用户凭证生成”流程,此时可输入一些用户信息;
2)(U)SIM卡生成随机数信息,并调用卡内存储的用户凭证密钥,生成第一校验信息,并通过终端上发给网络侧;
3)网络设备校验第一校验信息,并生成随机数,然后根据卡片上发的信息生成临时用户凭证,并分配临时用户凭证的索引号;
4)网络设备下发随机数校验信息(即上述第二校验信息)及临时用户凭证的索引号;
5)(U)SIM卡接收到信息后进行校验,并根据下发信息(包括第二校验信息以及临时用户凭证的索引号)生成临时用户凭证,并进行临时用户凭证的索引号的存储;
6)后续终端可利用临时用户凭证及其索引号接入网络,但功能受限,完成正式码号资源写入或更新等操作。
本公开的该实施例中,临时用户凭证接入网络功能受限,也可设置后续可以鉴权的次数或者时间,业务方面可灵活配置。
该实施例中的另一种情况,步骤21包括:第二终端产生临时用户凭证的触发请求,并通过第一终端发送给用户卡。
其中,步骤22包括:所述第二终端通过第一终端接收所述用户卡根据所述触发请求发送的第一校验信息,并将所述第一校验信息以及所述第二终端的认证信息发送给网络设备。
具体的,如图4所示,工作流程包括:
1)可信代理终端(第二终端)触发“临时用户凭证生成”流程,接着第一终端向(U)SIM卡触发“临时用户凭证生成”流程,此时可输入一些用户信 息;
2)(U)SIM卡生成随机数信息,并调用卡内存储的用户凭证密钥生成校验信息(即上述第一校验信息),并上发给第一终端;
3.)第一终端将信息发送给可信代理终端,可信代理终端补充自身的一些信息后上发给网络设备;
4)网络设备校验上发信息,并生成随机数,然后根据卡片上发信息生成临时用户凭证,并分配临时用户凭证的索引号;
5)网络设备下发随机数校验信息(即上述第二校验信息)及临时用户凭证的索引号;
6)(U)SIM卡接收到信息后进行校验,并根据下发信息生成临时用户凭证信息并进行索引号的存储;
7)后续终端可利用临时用户凭证及其索引号接入网络,但功能受限,完成正式码号资源写入或更新等操作。
本公开的上述实施例中,还可以包括:步骤24,根据用户卡生成的临时用户凭证及临时用户凭证的索引号,接入网络设备。
本公开的该实施例中,用户卡中预制运营商的用于生成一次性/临时用户凭证的密钥信息,用户卡和网络临时协商临时用户凭证,使得设备在码号资源失效的情况下,可以接入受限的网络,进而完成正式码号资源的写入或更新等操作。
与上述图2所示方法对应的,本公开的实施例还提供一种终端,包括:
收发机,用于向用户卡发送生成临时用户凭证的触发请求;以及接收用户卡根据所述触发请求发送的第一校验信息,并将所述第一校验信息发送给网络设备;以及接收所述网络设备反馈的第二校验信息以及网络设备生成的网络侧的临时用户凭证的索引号,并发送给用户卡。
其中,终端还包括:网络模块,用于根据用户卡生成的临时用户凭证及临时用户凭证的索引号,接入网络设备。
本公开的该终端的实施例是与上述图2所示方法实施例对应的设备,上述图2所示方法中各种实现方式均适用于该终端的实施例中,也能达到相同的技术效果。
如图5所示,本公开的实施例还提供一种临时用户凭证的生成方法,包括:
步骤51,接收终端发送的用户卡生成的第一校验信息;
步骤52,根据所述第一校验信息进行校验;
步骤53,校验成功后,生成临时用户凭证,并分配所述临时用户凭证的索引号,发送给终端。
其中,所述生成临时用户凭证的步骤包括:
产生一随机数;根据所述随机数以及预先存储的密钥,生成临时用户凭证。其中,所述密钥为网络设备所属运营商的公钥或者对称密钥。
本公开的实施例还提供一种网络设备,包括:
收发机,用于接收终端发送的用户卡生成的第一校验信息;
处理器,用于根据所述第一校验信息进行校验;校验成功后,生成临时用户凭证,并分配所述临时用户凭证的索引号,并由所述收发机发送给终端。
其中,所述处理器生成临时用户凭证时,具体用于:产生一随机数;并根据所述随机数以及预先存储的密钥,生成临时用户凭证。
具体的,网络设备主要实现生成和管理临时用户凭证功能,当临时用户凭证生成被触发时,调用预先存储的“密钥”,并生成一个随机数,再结合卡片上发的随机数等信息,生成临时用户凭证;并校验卡片上发的信息是否合法,同时为卡片分配一个用户凭证索引号。
本公开的该实施例,利用用户卡和网络设备临时协商临时用户凭证,使得设备在码号资源失效的情况下,可以有重新接入网络的机会,即接入受限的网络,进而完成正式码号资源的写入或更新等操作。
本公开的实施例还提供一种临时用户凭证的生成方法,包括:
终端向用户卡发送生成临时用户凭证的触发请求;
用户卡根据所述触发请求,产生第一校验信息,并发送给终端;
终端将所述第一校验信息发送给网络设备;
网络设备根据所述第一校验信息对用户卡进行校验,校验通过后,生成第二校验信息、临时用户凭证以及分配临时用户凭证的索引号,并将第二校验信息以及临时用户凭证的索引号发送给终端;
终端将所述根据所述第二校验信息以及临时用户凭证的索引号发送给用户卡;
用户卡根据第二校验信息以及所述临时用户凭证的索引号,生成临时用户凭证。具体的,如图3所示的工作流程。
进一步的,可以在流程中增加一个“可信代理终端”,其拥有接入网络能力,并且在网络方面拥有代申请临时用户凭证的权限。工作流程如上述图4所示。
如图6所示,本公开的实施例还提供一种临时用户凭证的生成系统,包括:用户卡、终端以及网络设备;其中,
所述终端用于向用户卡发送生成临时用户凭证的触发请求;并将用户卡产生的第一校验信息发送给网络设备;并接收网络设备反馈的第二校验信息以及临时用户凭证的索引号,并将所述第二校验信息以及临时用户凭证的索引号发送给用户卡;
所述用户卡用于根据所述触发请求,产生第一校验信息,并发送给终端;并根据终端发送的第二校验信息以及所述临时用户凭证的索引号,生成临时用户凭证;
所述网络设备用于根据所述第一校验信息对用户卡进行校验,校验通过后,生成第二校验信息、临时用户凭证以及分配临时用户凭证的索引号,并将第二校验信息以及临时用户凭证的索引号发送给终端。
本公开的上述实施例中,终端可以是IoT设备,用户卡可以是(U)SIM卡,在用户卡中预制运营商的用于生成一次性/临时用户凭证的密钥信息(该密钥不要求一卡一密,可以是运营商的公钥,也可以是对称密钥),网络侧也要初始存储一次性/临时用户凭证的密钥信息。通过用户卡和网络临时协商临时用户凭证,使得设备在码号资源失效的情况下,可以有重新接入网络的机会,即接入受限的网络,进而完成正式码号资源的写入或更新等操作。
以上所述是本公开的优选实施方式,应当指出,对于本技术领域的普通技术人员来说,在不脱离本公开所述原理的前提下,还可以作出若干改进和润饰,这些改进和润饰也应视为本公开的保护范围。

Claims (28)

  1. 一种临时用户凭证的生成方法,包括:
    接收终端发送的生成临时用户凭证的触发请求;
    根据所述触发请求,产生第一校验信息,并通过终端将所述第一校验信息发送给网络设备;
    通过所述终端接收网络设备反馈的第二校验信息以及网络设备生成的网络侧的临时用户凭证的索引号;
    根据所述第二校验信息以及所述索引号,生成临时用户凭证。
  2. 根据权利要求1所述的临时用户凭证的生成方法,其中,根据所述触发请求,产生第一校验信息的步骤包括:
    根据所述触发请求,生成一随机数;
    根据所述随机数和预置信息,生成第一校验信息。
  3. 根据权利要求2所述的临时用户凭证的生成方法,其中,根据所述随机数和预置信息,生成第一校验信息的步骤包括:
    根据所述随机数和预先存储的密钥,生成第一校验信息;或者
    根据所述随机数、用户输入的信息和预先存储的密钥,生成第一校验信息。
  4. 根据权利要求3所述的临时用户凭证的生成方法,其中,所述密钥为用户卡所属网络运营商的公钥或者对称密钥。
  5. 根据权利要求1所述的临时用户凭证的生成方法,其中,根据所述第二校验信息以及所述索引号,生成临时用户凭证的步骤包括:
    根据所述第二校验信息,对网络设备进行校验;
    校验成功后,并根据所述第二校验信息以及所述索引号,生成临时用户凭证。
  6. 根据权利要求5所述的临时用户凭证的生成方法,其中,生成临时用户凭证后还包括:
    存储所述临时用户凭证的索引号。
  7. 一种用户卡,包括:
    收发机,用于接收终端发送的生成临时用户凭证的触发请求;
    处理器,用于根据所述触发请求,产生第一校验信息,并由所述收发机通过终端将所述第一校验信息发送给网络设备;
    所述收发机还用于通过所述终端接收网络设备反馈的第二校验信息以及网络设备生成的网络侧的临时用户凭证的索引号;
    所述处理器还用于根据所述第二校验信息以及所述索引号,生成临时用户凭证。
  8. 根据权利要求7所述的用户卡,其中,所述处理器生成第一校验信息时,具体用于根据所述触发请求,生成一随机数;根据所述随机数和预置信息,生成第一校验信息。
  9. 根据权利要求8所述的用户卡,其中,所述处理器具体用于:根据所述随机数和预先存储的密钥,生成第一校验信息;或者根据所述随机数、用户输入的信息和预先存储的密钥,生成第一校验信息。
  10. 根据权利要求7所述的用户卡,其中,所述处理器具体用于:根据所述第二校验信息,对网络设备进行校验;校验成功后,并根据所述第二校验信息以及所述索引号,生成临时用户凭证。
  11. 根据权利要求10所述的用户卡,还包括:
    存储器,用于存储所述临时用户凭证的索引号。
  12. 一种临时用户凭证的生成方法,包括:
    向用户卡发送生成临时用户凭证的触发请求;
    接收用户卡根据所述触发请求发送的第一校验信息,并将所述第一校验信息发送给网络设备;
    接收所述网络设备反馈的第二校验信息以及网络设备生成的网络侧的临时用户凭证的索引号,并发送给用户卡。
  13. 根据权利要求12所述的临时用户凭证的生成方法,其中,向用户卡发送生成临时用户凭证的触发请求的步骤包括:
    第一终端产生临时用户凭证的触发请求,并将所述触发请求发送给用户卡。
  14. 根据权利要求13所述的临时用户凭证的生成方法,其中,接收用户 卡根据所述触发请求发送的第一校验信息,并将所述第一校验信息发送给网络设备的步骤包括:
    所述第一终端接收用户卡根据所述触发请求产生的第一校验信息,并将所述第一校验信息发送给网络设备。
  15. 根据权利要求12所述的临时用户凭证的生成方法,其中,向用户卡发送生成临时用户凭证的触发请求的步骤包括:
    第二终端产生临时用户凭证的触发请求,并通过第一终端发送给用户卡。
  16. 根据权利要求15所述的临时用户凭证的生成方法,其中,接收用户卡根据所述触发请求发送的第一校验信息,并将所述第一校验信息发送给网络设备的步骤包括:
    所述第二终端通过第一终端接收所述用户卡根据所述触发请求发送的第一校验信息,并将所述第一校验信息以及所述第二终端的认证信息发送给网络设备。
  17. 根据权利要求12所述的临时用户凭证的生成方法,其中,还包括:
    根据用户卡生成的临时用户凭证及临时用户凭证的索引号,接入网络设备。
  18. 一种终端,包括:
    收发机,用于向用户卡发送生成临时用户凭证的触发请求;以及
    接收用户卡根据所述触发请求发送的第一校验信息,并将所述第一校验信息发送给网络设备;以及
    接收所述网络设备反馈的第二校验信息以及网络设备生成的网络侧的临时用户凭证的索引号,并发送给用户卡。
  19. 根据权利要求18所述的终端,还包括:
    网络模块,用于根据用户卡生成的临时用户凭证及临时用户凭证的索引号,接入网络设备。
  20. 一种临时用户凭证的生成方法,包括:
    接收终端发送的用户卡生成的第一校验信息;
    根据所述第一校验信息进行校验;
    校验成功后,生成临时用户凭证,并分配所述临时用户凭证的索引号, 发送给终端。
  21. 根据权利要求20所述的临时用户凭证的生成方法,其中,所述生成临时用户凭证的步骤包括:
    产生一随机数;
    根据所述随机数以及预先存储的密钥,生成临时用户凭证。
  22. 根据权利要求21所述的临时用户凭证的生成方法,其中,所述密钥为网络设备所属运营商的公钥或者对称密钥。
  23. 一种网络设备,包括:
    收发机,用于接收终端发送的用户卡生成的第一校验信息;
    处理器,用于根据所述第一校验信息进行校验;校验成功后,生成临时用户凭证,并分配所述临时用户凭证的索引号,并由所述收发机发送给终端。
  24. 根据权利要求23所述的网络设备,其中,所述处理器生成临时用户凭证时,具体用于:产生一随机数;并根据所述随机数以及预先存储的密钥,生成临时用户凭证。
  25. 一种临时用户凭证的生成方法,包括:
    终端向用户卡发送生成临时用户凭证的触发请求;
    用户卡根据所述触发请求,产生第一校验信息,并发送给终端;
    终端将所述第一校验信息发送给网络设备;
    网络设备根据所述第一校验信息对用户卡进行校验,校验通过后,生成第二校验信息、临时用户凭证以及分配临时用户凭证的索引号,并将第二校验信息以及临时用户凭证的索引号发送给终端;
    终端将所述根据所述第二校验信息以及临时用户凭证的索引号发送给用户卡;
    用户卡根据第二校验信息以及所述临时用户凭证的索引号,生成临时用户凭证。
  26. 一种临时用户凭证的生成系统,包括:用户卡、终端以及网络设备;其中,
    所述终端用于向用户卡发送生成临时用户凭证的触发请求;并将用户卡产生的第一校验信息发送给网络设备;并接收网络设备反馈的第二校验信息 以及临时用户凭证的索引号,并将所述第二校验信息以及临时用户凭证的索引号发送给用户卡;
    所述用户卡用于根据所述触发请求,产生第一校验信息,并发送给终端;并根据终端发送的第二校验信息以及所述临时用户凭证的索引号,生成临时用户凭证;
    所述网络设备用于根据所述第一校验信息对用户卡进行校验,校验通过后,生成第二校验信息、临时用户凭证以及分配临时用户凭证的索引号,并将第二校验信息以及临时用户凭证的索引号发送给终端。
  27. 一种通信设备,包括:处理器、存储有计算机程序的存储器,所述计算机程序被处理器运行时,执行如权利要求1-6任一项所述的方法或者12-17任一项所述的方法或者20-22任一项所述的方法。
  28. 一种计算机可读存储介质,包括指令,当所述指令在计算机运行时,使得计算机执行如权利要求1-6任一项所述的方法或者12-17任一项所述的方法或者20-22任一项所述的方法。
PCT/CN2018/101677 2017-09-05 2018-08-22 临时用户凭证的生成方法、用户卡、终端及网络设备 Ceased WO2019047714A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201710790458.5A CN109429226B (zh) 2017-09-05 2017-09-05 一种临时用户凭证的生成方法、用户卡、终端及网络设备
CN201710790458.5 2017-09-05

Publications (1)

Publication Number Publication Date
WO2019047714A1 true WO2019047714A1 (zh) 2019-03-14

Family

ID=65514070

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/101677 Ceased WO2019047714A1 (zh) 2017-09-05 2018-08-22 临时用户凭证的生成方法、用户卡、终端及网络设备

Country Status (2)

Country Link
CN (1) CN109429226B (zh)
WO (1) WO2019047714A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113872765B (zh) * 2020-06-30 2023-02-03 华为技术有限公司 身份凭据的申请方法、身份认证的方法、设备及装置

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103118356A (zh) * 2013-02-07 2013-05-22 中国联合网络通信集团有限公司 嵌入式智能卡eUICC激活方法、系统、终端及平台
CN103517267A (zh) * 2012-06-29 2014-01-15 中国移动通信集团公司 确定实际码号的系统、方法及设备
EP2747368A1 (fr) * 2012-12-19 2014-06-25 Gemalto SA Procédé de personnalisation d'un élément de sécurité
CN104661210A (zh) * 2015-03-12 2015-05-27 中国联合网络通信集团有限公司 Sim卡注册方法、终端及sim卡激活装置

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7613479B2 (en) * 2003-09-15 2009-11-03 At&T Mobility Ii Llc Automatic device configuration to receive network services
FI122163B (fi) * 2007-11-27 2011-09-15 Teliasonera Ab Verkkopääsyautentikointi
CN101997824B (zh) * 2009-08-20 2016-08-10 中国移动通信集团公司 基于移动终端的身份认证方法及其装置和系统
CN103167465B (zh) * 2013-02-04 2016-03-23 中国联合网络通信集团有限公司 一种嵌入式uicc卡激活处理方法和装置
CN104717646B (zh) * 2013-12-11 2019-01-01 中国移动通信集团公司 一种移动网络的接入方法、设备和系统
CN105263132B (zh) * 2015-09-07 2018-07-10 中国联合网络通信集团有限公司 eUICC的备用配置文件选择方法及用户终端

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103517267A (zh) * 2012-06-29 2014-01-15 中国移动通信集团公司 确定实际码号的系统、方法及设备
EP2747368A1 (fr) * 2012-12-19 2014-06-25 Gemalto SA Procédé de personnalisation d'un élément de sécurité
CN103118356A (zh) * 2013-02-07 2013-05-22 中国联合网络通信集团有限公司 嵌入式智能卡eUICC激活方法、系统、终端及平台
CN104661210A (zh) * 2015-03-12 2015-05-27 中国联合网络通信集团有限公司 Sim卡注册方法、终端及sim卡激活装置

Also Published As

Publication number Publication date
CN109429226B (zh) 2021-08-06
CN109429226A (zh) 2019-03-05

Similar Documents

Publication Publication Date Title
US11956361B2 (en) Network function service invocation method, apparatus, and system
CN111213339B (zh) 带有客户端密钥的认证令牌
KR102242218B1 (ko) 사용자 인증 방법 및 장치, 및 웨어러블 디바이스 등록 방법 및 장치
CN104717648B (zh) 一种基于sim卡的统一认证方法和设备
CN113347206A (zh) 一种网络访问方法和装置
US9608971B2 (en) Method and apparatus for using a bootstrapping protocol to secure communication between a terminal and cooperating servers
CN112311543B (zh) Gba的密钥生成方法、终端和naf网元
US10419212B2 (en) Methods, systems, apparatuses, and devices for securing network communications using multiple security protocols
US11122033B2 (en) Multi factor authentication
CN110999215A (zh) 安全设备访问令牌
CN114553426B (zh) 签名验证方法、密钥管理平台、安全终端及电子设备
WO2019056971A1 (zh) 一种鉴权方法及设备
CN112118210B (zh) 一种认证密钥配置方法、设备、系统及存储介质
WO2014180431A1 (zh) 一种网管安全认证方法、装置、系统及计算机存储介质
WO2013071836A1 (zh) 客户端应用访问鉴权处理方法和装置
CN106911628A (zh) 一种用户在客户端上注册应用软件的方法及装置
CN112423300A (zh) 无线网络接入认证方法及装置
CN117062073A (zh) 安全认证方法、装置、计算机设备和存储介质
CN114584967B (zh) 数据管理方法、装置、系统及计算机可读存储介质
WO2019047714A1 (zh) 临时用户凭证的生成方法、用户卡、终端及网络设备
CN112887965A (zh) 发送用户标识的方法和装置
CN106940776A (zh) 一种敏感数据操作方法和移动终端
CN113453230B (zh) 终端管理方法和系统以及安全代理
WO2022094936A1 (zh) 接入方法、设备和云平台设备
CN118265031B (zh) 信息安全方法、装置、通信设备和存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18854145

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 18854145

Country of ref document: EP

Kind code of ref document: A1