WO2019114320A1 - 一种ims用户的注册方法及装置 - Google Patents

一种ims用户的注册方法及装置 Download PDF

Info

Publication number
WO2019114320A1
WO2019114320A1 PCT/CN2018/102561 CN2018102561W WO2019114320A1 WO 2019114320 A1 WO2019114320 A1 WO 2019114320A1 CN 2018102561 W CN2018102561 W CN 2018102561W WO 2019114320 A1 WO2019114320 A1 WO 2019114320A1
Authority
WO
WIPO (PCT)
Prior art keywords
response
user terminal
hss
random number
registration request
Prior art date
Application number
PCT/CN2018/102561
Other languages
English (en)
French (fr)
Inventor
吴鹏程
Original Assignee
大唐移动通信设备有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 大唐移动通信设备有限公司 filed Critical 大唐移动通信设备有限公司
Priority to EP18889802.7A priority Critical patent/EP3726795B1/en
Priority to US16/771,220 priority patent/US11381607B2/en
Publication of WO2019114320A1 publication Critical patent/WO2019114320A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/45Network directories; Name-to-address mapping
    • H04L61/4588Network directories; Name-to-address mapping containing mobile subscriber information, e.g. home subscriber server [HSS]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/10Architectures or entities
    • H04L65/1016IP multimedia subsystem [IMS]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/1066Session management
    • H04L65/1073Registration or de-registration
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/1066Session management
    • H04L65/1101Session protocols
    • H04L65/1104Session initiation protocol [SIP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/02Processing of mobility data, e.g. registration information at HLR [Home Location Register] or VLR [Visitor Location Register]; Transfer of mobility data, e.g. between HLR, VLR or external networks
    • H04W8/04Registration at HLR or HSS [Home Subscriber Server]

Definitions

  • the present application relates to the field of communications technologies, and in particular, to a method and an apparatus for registering an IMS user.
  • the IMS IP Multimedia Subsystem
  • PVI Primary User Identity
  • PUI Public User Identity
  • the specific implementation steps of the prior art solution may be as shown in FIG. 1 , including:
  • Step 101 The UE (User Equipment) sends a SIP REGISTER (Session Initiation Protocol REGISTER) request to the discovered P-CSCF (Proxy-Call Session Control Function).
  • SIP REGISTER Session Initiation Protocol REGISTER
  • Step 102 The P-CSCF processes the SIP REGISTER request, and sends a SIP REGISTER request to the selected I-CSCF (Interrogating-Call Session Control Function).
  • Step 103 The I-CSCF sends a SAR (Server Assignment Request) message to the HSS (Home Subscriber Server) to query the address of the S-CSCF (Serving CSCF, Serving CSCF).
  • SAR Server Assignment Request
  • Step 104 The HSS selects an S-CSCF, and sends the address of the selected S-CSCF to the I-CSCF through a SAA (Server Assignment Answer) message.
  • SAA Server Assignment Answer
  • step 105 the I-CSCF forwards the SIP REGISTER request to the selected S-CSCF.
  • Step 106 If the S-CSCF finds that the user is not authorized, the S-CSCF sends a UAR (User Authorization Request) message to the HSS to obtain the authentication and authentication data.
  • UAR User Authorization Request
  • Step 107 The HSS returns the authentication and authentication data to the S-CSCF through a UAA (User Authorization Answer) message.
  • UAA User Authorization Answer
  • step 108 the S-CSCF challenges the user with a "401 Unauthorized” response. And pass the message to the I-CSCF.
  • step 109 the I-CSCF sends a "401 Unauthorized" response to the P-CSCF.
  • step 110 the P-CSCF sends a "401 Unauthorized" response to the UE.
  • step 111 the UE calculates a challenge response and sends a new REGISTER request to the P-CSCF, the new REGISTER request containing the response.
  • step 112 the P-CSCF will find the I-CSCF again and send a new REGISTER request to the I-CSCF.
  • step 113 the I-CSCF sends a SAR message to the HSS to query the address of the S-CSCF.
  • step 114 the HSS sends the selected S-CSCF address to the I-CSCF through the SAA message.
  • step 115 the I-CSCF forwards the new REGISTER request to the selected S-CSCF.
  • the S-CSCF checks the response in the new REGISTER request. If it is not correct, the authentication fails and the registration process terminates. If correct, the authentication is successful.
  • Step 116 If the S-CSCF checks that the authentication is successful, the MAR (Multimedia Auth Request) message is sent to the HSS.
  • MAR Multimedia Auth Request
  • the HSS saves the S-CSCF name corresponding to the UE, and returns a MAA (Multimedia Auth Answer) message to the S-CSCF.
  • the S-CSCF saves user information corresponding to the UE.
  • step 118 the S-CSCF sends a "200 OK" message to the I-CSCF indicating acceptance of the UE's registration request.
  • step 119 the I-CSCF forwards the "200 OK" message to the P-CSCF.
  • step 120 the P-CSCF sends a "200 OK" message to the UE.
  • Step 121 The S-CSCF sends a registration request (REGISTER) message to the AS (Application Server).
  • REGISTER Registration request
  • step 122 the AS returns a "200 OK" message to the S-CSCF, indicating that the registration corresponding to the registration request is accepted.
  • an IMS user is required and can only be used on a certain mobile phone.
  • the IMS user can be used only when a USIM (Universal Subscriber Identity Module) is used on a certain mobile terminal.
  • the prior art can determine the legitimacy of the IMS user, but cannot control the device used by the user. If some terminals are installed on the software using the VoIP client, one user can log in on different mobile terminals; at the same time, multiple users can also log in on the same mobile terminal. VoIP software can be installed to log in even on mobile terminals that are usually sent by non-enterprise networks. This has a great impact on the security of the corporate network.
  • the application provides a method and a device for registering an IMS user, which are used to solve the technical problem that the prior art cannot control the device used by the IMS user, thereby greatly affecting the security of the enterprise network.
  • the application provides a registration method for an IMS user, including:
  • the home subscriber network After receiving the registration request of the user terminal without the authentication data, the home subscriber network (HSS) acquires the configuration information of the user terminal;
  • the attribute identifier includes an international mobile subscriber identity IMSI, an international mobile device Identity code IMEI, IP Multimedia Subsystem IMS ID;
  • obtaining an authentication verification code Response HSS by using the random number and the attribute identifier includes:
  • the MD5 algorithm is used to generate a character string
  • the character string and the random number are used to generate a new character string as the authentication verification code Response HSS using the MD5 algorithm.
  • the method further includes:
  • the reason value of the failure of the registration request is carried in the media authentication response MAA message, and is sent to the serving call session control function S-CSCF; and a message is returned to the user terminal indicating that the registration request is rejected by the home subscription user server.
  • the present application further provides another registration method for an IMS user, where the method is applied to a user terminal, including:
  • the user terminal sends a registration request to the home subscriber server HSS;
  • the HSS Receiving a random number sent by the HSS, and generating a response verification code Response by using the random number and an attribute identifier corresponding to the user terminal; wherein the attribute identifier includes an International Mobile Subscriber Identity (IMSI) and an International Mobile Equipment Identity (IMEI) , IP multimedia subsystem IMS identification;
  • IMSI International Mobile Subscriber Identity
  • IMEI International Mobile Equipment Identity
  • the receiving the random number sent by the HSS includes:
  • the user terminal receives the random number from an unauthorized Unauthorized response sent by the Proxy Call Session Control Function P-CSCF.
  • the application provides a home subscription server, including:
  • a receiving module configured to acquire configuration information of the user terminal after receiving the registration request of the user terminal without the authentication data
  • a verification code generating module configured to determine an attribute identifier corresponding to the user terminal according to the configuration information, and obtain an authentication verification code ResponseHSS by using a random number and the attribute identifier; wherein the attribute identifier includes an international mobile user Identification code IMSI, international mobile device identity code IMEI, IP multimedia subsystem IMS identifier;
  • An obtaining module configured to send the random number to the user terminal, and obtain a response verification code Response obtained by the user terminal according to the random number in a response message received by the user terminal;
  • a determining module configured to determine whether the response is the same as the Response HSS, and send the registration request to the application server to perform registration of the user terminal.
  • the acquiring module is specifically configured to:
  • the determining module is further configured to: if the response is determined to be different from the Response HSS, carry the reason for the failure of the registration request in the MAA message, and send the message to the service call session control function S-CSCF. And replying to the user terminal that the registration request is rejected by the home subscription server.
  • the application further provides a user terminal, including:
  • a transceiver module configured to send a registration request to the home subscriber server HSS, and receive a random number sent by the HSS;
  • a generating module configured to generate a response verification code Response by using the random number and an attribute identifier corresponding to the user terminal, where the attribute identifier includes an International Mobile Subscriber Identity (IMSI), an International Mobile Equipment Identity (IMEI), and an IP Multimedia Subsystem. IMS logo;
  • IMSI International Mobile Subscriber Identity
  • IMEI International Mobile Equipment Identity
  • IP Multimedia Subsystem IP Multimedia Subsystem
  • the transceiver module is further configured to send the response verification code Response to the HSS, so that the HSS determines, according to the Response, whether to register the user terminal according to the registration request.
  • the transceiver module is specifically configured to receive the random number from an unauthorized Unauthorized response sent by the proxy call session control function P-CSCF.
  • a home subscription server including:
  • a receiver for receiving a registration request of a user terminal without authentication data
  • the attribute identifier includes an International Mobile Subscriber Identity (IMSI), an International Mobile Equipment Identity (IMEI), and an IP Multimedia Subsystem (IMS) identifier;
  • IMSI International Mobile Subscriber Identity
  • IMEI International Mobile Equipment Identity
  • IMS IP Multimedia Subsystem
  • a transmitter configured to send the random number to the user terminal
  • the receiver is further configured to receive a response message fed back by the user terminal;
  • the processor is further configured to: obtain, from the response message, a response verification code Response obtained by the user terminal according to the random number; and determine whether the Response is the same as the Response HSS, and if the response is the same, control the transmitter to The application server sends the registration request to register the user terminal.
  • the processor is specifically configured to use the MD5 algorithm to generate a string by splicing the IMSI, the IMEI, and the IMS identifier in a string manner; and using the MD5 algorithm to generate the string. And generating a new character string as the authentication verification code ResponseHSS with the random number.
  • the processor is further configured to: if the response is determined to be different from the Response HSS, carry a reason value of the registration request failure in the MAA message; and control the transmitter, It is further configured to send the MAA message to the serving call session control function S-CSCF; and reply to the user terminal that the registration request is rejected by the home subscription user server.
  • a user terminal including:
  • a transceiver configured to send a registration request to the home subscription subscriber server HSS, and receive a random number sent by the HSS;
  • a processor configured to generate a response verification code Response by using the random number and an attribute identifier corresponding to the user terminal; wherein the attribute identifier includes an International Mobile Subscriber Identity (IMSI), an International Mobile Equipment Identity (IMEI), and an IP Multimedia Subsystem. IMS logo;
  • IMSI International Mobile Subscriber Identity
  • IMEI International Mobile Equipment Identity
  • IP Multimedia Subsystem IP Multimedia Subsystem.
  • the transceiver is further configured to send the response verification code Response to the HSS, so that the HSS determines, according to the Response, whether to register the user terminal according to the registration request.
  • the transceiver is specifically configured to receive the random number from an unauthorized Unauthorized response sent by the proxy call session control function P-CSCF.
  • the present application further provides a computer readable storage medium storing computer instructions that, when executed on a computer, cause the computer to perform the aforementioned first or second aspect The method of any of the alternative embodiments.
  • the method and device for registering an IMS user provided by the embodiment of the present application, in the HSS, use the attribute identifier to perform corresponding management judgment on the registration request of the user terminal, and transmit relevant parameters in the registration to achieve the access of the IMS device to the user equipment. management.
  • the management of the access terminal by the enterprise network is more secure and complete.
  • FIG. 1 is a schematic flowchart of a method for determining the legitimacy of an IMS user in the prior art
  • FIG. 2 is a schematic flowchart of a method for registering an IMS user according to an embodiment of the present application
  • FIG. 3 is a schematic flowchart of another method for registering an IMS user according to an embodiment of the present disclosure
  • FIG. 4 is a schematic flowchart of applying an IMS user registration method to an actual network architecture according to an embodiment of the present disclosure
  • FIG. 5 is a schematic structural diagram of a home subscription user server according to an embodiment of the present disclosure.
  • FIG. 6 is a schematic structural diagram of a user terminal according to an embodiment of the present application.
  • FIG. 7 is a schematic structural diagram of another home subscription server provided by an embodiment of the present application.
  • FIG. 8 is a schematic structural diagram of another user terminal according to an embodiment of the present application.
  • the authentication method provided by the prior art HSS cannot bind and check the identifier of the EPC (Evolved Packet Core) with the identifier of the IMS. Therefore, although the prior art can judge the legitimacy of the IMS user, the device used by the user cannot be known, and thus the device used by the user cannot be controlled.
  • EPC Evolved Packet Core
  • the embodiment of the present application proposes a registration method and apparatus for an IMS user, in which the home subscriber server HSS obtains the registration request of the user terminal without the authentication data. Determining an attribute identifier corresponding to the user terminal according to the configuration information, and obtaining an authentication verification code Response HSS by using a random number and the attribute identifier; and sending the random number to the user terminal Obtaining a response verification code Response obtained by the user terminal according to the random number in the response message received by the user terminal, determining whether the Response is the same as the Response HSS, and sending the registration request to the application server.
  • the registration of the user terminal is performed.
  • the enterprise network can control the user terminal that accesses the IMS system, and the user terminal that uses the non-customized authentication even if the VoIP software is installed. Unable to access the IMS system. Thereby, the enterprise network can effectively control the use of the user terminal. It is especially suitable for some severely demanding scenarios, such as coal mines and public security emergency systems. Access networks have strict restrictions on access clients.
  • the IMS user registration method provided by the embodiment of the present application is further described in detail below with reference to the accompanying drawings.
  • the specific implementation manner of the method may include the following steps (the method flow is shown in FIG. 2):
  • Step 201 After receiving the registration request of the user terminal without the authentication data, the HSS acquires configuration information of the user terminal.
  • Step 202 Determine an attribute identifier corresponding to the user terminal according to the configuration information, and obtain an authentication verification code (ResponseHSS) by using a random number and the attribute identifier; wherein the attribute identifier includes an international mobile subscriber identity (International Mobile Subscriber Identification Number), International Mobile Equipment Identity (International Mobile Equipment Identity), IP Multimedia Subsystem IMS logo;
  • the attribute identifier includes an international mobile subscriber identity (International Mobile Subscriber Identification Number), International Mobile Equipment Identity (International Mobile Equipment Identity), IP Multimedia Subsystem IMS logo;
  • the IMSI, the IMEI, and the IP Multimedia Subsystem IMS identifier (including: PVI and PUI) included in the attribute identifier may be used in combination, and any combination needs to be able to determine the terminal device accessing the network.
  • the correspondence between the attribute identifiers may be set in the HSS based on the type of the attribute identifier, and the correspondence between the PVI and the PUI in the IMSI, the IMEI, and the IMS identifier may be set based on the type of the attribute identifier. Shown as follows:
  • the HSS then generates a random number RANDcheck and sends RANDcheck to the user terminal with the check flag; in this embodiment RANDcheck can consist of a random string.
  • the terminal After the terminal receives the RANDcheck, if a check flag is detected, the response is calculated by using the random number, and the calculation method is as follows:
  • A, the IMSI, the IMEI, and the IMS identity are spliced in a string manner, and the MD5 (Message Digest Algorithm 5, message digest algorithm fifth edition) algorithm is used to generate a character string (HA1);
  • MD5 Message Digest Algorithm 5, message digest algorithm fifth edition
  • HA1 md5("PVI:IMSI:IMEI");
  • the character string and the random number are used to generate a new character string as the authentication verification code Response HSS using the MD5 algorithm.
  • Step 203 Send the random number to the user terminal, and obtain a response verification code (Response) obtained by the user terminal according to the random number in the response message received by the user terminal;
  • Response response verification code
  • Step 204 Determine whether the Response is the same as the Response HSS, and send the registration request to the application server to perform registration of the user terminal.
  • the method further includes:
  • the reason value of the failure of the registration request is carried in the MAA message, and is sent to the S-CSCF; and a message is returned to the user terminal indicating that the registration request is rejected by the home subscription user server.
  • the embodiment of the present application further provides a registration method for an IMS user, where the method is applied to a user terminal, where the user terminal is provided with a communication module, including:
  • Step 301 The user terminal sends a registration request to the HSS.
  • Step 302 Receive a random number sent by the HSS, and generate a response verification code (Response) by using the random number and an attribute identifier corresponding to the user terminal, where the attribute identifier includes an IMSI, an IMEI, and an IMS identifier.
  • the user terminal may receive the random number from an Unauthorized response sent by the P-CSCF.
  • Step 303 Send the Response to the HSS, so that the HSS determines, according to the Response, whether to register the user terminal according to the registration request.
  • the implementation of the method provided by the embodiment of the present application is implemented based on the different devices, and the specific use of the method provided by the embodiment of the present application in a specific application environment is as follows.
  • the IMS user registration method provided by the embodiment of the present application is a combination of the first embodiment and the second embodiment, and the specific network architecture (the specific device includes: UE, P-CSCF, I-CSCF, S-CSCF, HSS, AS). To explain, specifically (as shown in Figure 4):
  • step 401 the UE sends a SIP REGISTER request to the discovered P-CSCF.
  • Step 402 The P-CSCF processes the received SIP REGISTER request and sends the SIP REGISTER request to the selected I-CSCF.
  • Step 403 After receiving the SIP REGISTER request, the I-CSCF contacts the HSS and sends a SAR message to the HSS to query the address of the S-CSCF.
  • Step 404 the HSS selects the S-CSCF, and sends the address of the selected S-CSCF to the I-CSCF through the SAA message.
  • Step 405 After receiving the address of the S-CSCF selected by the HSS, the I-CSCF forwards the SIP REGISTER request to the selected S-CSCF.
  • Step 406 When the S-CSCF determines that the user is not authorized, sends a UAR message to the HSS to obtain the authentication data.
  • the HSS After receiving the UAR message, the HSS checks the configuration information of the user. If there is a correspondence table between the IMSI, the IMEI, and the IMS identifier PVI, the HSS generates a random number (RANDcheck), and generates a ResponseHSS according to the random number calculation method provided by the embodiment. , calculated and saved in HSS. The HSS passes the RANDcheck to the S-CSCF.
  • Step 407 The HSS returns the authentication and authentication data to the S-CSCF through the UAA message, where the message carries RANDcheck.
  • Step 408 After receiving the RANDcheck carried in the UAA message, the S-CSCF uses the "401 Unauthorized" response to challenge the user regardless of whether the authentication mode configured by the corresponding user is Digest or AKA. The message is passed to the I-CSCF, which carries RANDcheck.
  • step 409 the I-CSCF sends a "401 Unauthorized" response to the P-CSCF, and the message carries RANDcheck.
  • Step 410 The P-CSCF sends a "401 Unauthorized" response to the UE, and the message carries RANDcheck.
  • step 411 the UE calculates the response of the challenge and sends a new REGISTER containing the response to the P-CSCF, and calculates the Response value using the received RANDcheck and its own PVI, IMSI, and IMEI. And send the Response in a new REGISTER message.
  • the P-CSCF selects the I-CSCF and sends a new REGISTER message to the selected I-CSCF.
  • Step 413 After receiving the new REGISTER message, the I-CSCF sends a SAR message to the HSS to query the address of the S-CSCF.
  • Step 414 After receiving the SAR message, the HSS sends the selected S-CSCF address to the I-CSCF through the SAA message.
  • step 415 the I-CSCF forwards the new REGISTER request to the S-CSCF selected by the HSS.
  • the S-CSCF checks the response of the UE feedback according to the new REGISTER request. If it is not correct, the authentication fails and the registration process is terminated. If correct, the authentication is successful.
  • Step 416 If the S-CSCF checks that the authentication is successful, the S-CSCF will send a MAR message to the HSS.
  • the Response carried in the new REGISTER message is delivered to the HSS through the MAR message.
  • step 417 the HSS saves the name of the S-CSCF corresponding to the user, and checks whether the Response is the same as the originally calculated ResponseHSS.
  • the user matching device succeeds; if the user fails to match the device, it can be determined that the user does not use the specified USIM card and the designated mobile terminal.
  • the IMS device rejects the registration of the user.
  • the HSS sends a MAA message to the S-CSCF.
  • the message carries the matching result. If the matching failure HSS carries the reason value of the failure in the MAA message, the newly defined cause value is:
  • Step 418 If the matching result is successful, the S-CSCF sends a "200 OK" message to the I-CSCF, indicating that the registration is accepted; if the S-CSCF receives the failure cause value, it returns a 202 message to the UE, and the registration is performed. If it is not received by the server, the process ends; if the message is a "200 OK" message, then the process proceeds to step 421.
  • Step 419 the I-CSCF forwards the "200 OK" message or 202 message to the P-CSCF.
  • step 420 the P-CSCF sends a "200 OK" message or a 202 message to the UE; if it is a 202 message, the process ends.
  • step 421 the S-CSCF sends a registration request (REGISTER) message to the application server AS.
  • REGISTER registration request
  • step 422 the application server AS returns a "200 OK" message to the S-CSCF, indicating acceptance of the registration.
  • the embodiment of the present application further provides a home subscription subscriber server, where the home subscription subscriber server may specifically include:
  • the receiving module 501 is configured to acquire configuration information of the user terminal after receiving the registration request of the user terminal without the authentication data;
  • the verification code generation module 502 determines an attribute identifier corresponding to the user terminal according to the configuration information, and obtains an authentication verification code ResponseHSS by using a random number and the attribute identifier; wherein the attribute identifier includes an international mobile subscriber identity Code IMSI, international mobile device identity code IMEI, IP multimedia subsystem IMS identifier;
  • the obtaining module 503 is configured to send the random number to the user terminal, and obtain a response verification code Response obtained by the user terminal according to the random number in the response message received by the user terminal;
  • the obtaining module 503 obtained by the obtaining module in a plurality of manners may be implemented in the following manner:
  • the determining module 504 is configured to determine whether the response is the same as the Response HSS, and if the response is the same, send the registration request to the application server to perform registration of the user terminal.
  • the registration request is rejected, corresponding to:
  • the determining module 504 is further configured to carry the reason value of the registration request failure in the MAA message, and send the message to the S-CSCF; and send a message to the user terminal to indicate that the registration request is rejected by the home subscription user server.
  • the embodiment of the present application further provides a user terminal, where the user terminal is provided with a communication module, and further includes:
  • the transceiver module 601 is configured to send a registration request to the home subscription subscriber server HSS, and receive a random number sent by the HSS;
  • the transceiver module 601 is specifically configured to receive the random number from an Unauthorized response sent by the P-CSCF.
  • the generating module 602 is configured to generate a response verification code Response by using the random number and an attribute identifier corresponding to the user terminal, where the attribute identifier includes an International Mobile Subscriber Identity (IMSI), an International Mobile Equipment Identity (IMEI), and an IP Multimedia System IMS identity;
  • IMSI International Mobile Subscriber Identity
  • IMEI International Mobile Equipment Identity
  • IP Multimedia System IMS identity IP Multimedia System identity
  • the transceiver module 601 is further configured to send the response verification code Response to the HSS, so that the HSS determines, according to the Response, whether to register the user terminal according to the registration request.
  • the embodiment of the present application further provides a home subscription subscriber server, where the home subscription subscriber server may specifically include:
  • a receiver 701 configured to receive a registration request of a user terminal without authentication data
  • the processor 702 is configured to obtain configuration information of the user terminal, and determine an attribute identifier corresponding to the user terminal according to the configuration information, and obtain an authentication verification code Response HSS by using the random number and the attribute identifier;
  • the attribute identifier includes an International Mobile Subscriber Identity (IMSI), an International Mobile Equipment Identity (IMEI), and an IP Multimedia Subsystem (IMS) identifier;
  • a transmitter 703, configured to send the random number to the user terminal
  • the receiver 701 is further configured to receive a response message fed back by the user terminal;
  • the processor 702 is further configured to: obtain, from the response message, a response verification code Response obtained by the user terminal according to the random number;
  • the processor 702 can obtain the response verification code Response in a plurality of manners.
  • the processor 702 can specifically obtain the response verification code by:
  • the processor 702 is configured to determine whether the response is the same as the Response HSS, and if the same, control the transmitter 703 to send the registration request to the application server to perform registration of the user terminal.
  • the registration request is rejected, corresponding to:
  • the processor 702 is further configured to: carry the reason value of the registration request failure in the MAA message, and control the transmitter to send the MAA message to the S-CSCF; and send a message to the user terminal to indicate the registration.
  • the request is rejected by the home subscriber server.
  • the receiver 701 and the transmitter 703 can be integrated into one module (transceiver) to implement the data information transceiving function of the home subscription user server, and can also be divided into two independent modules to implement the function of transmitting and receiving information. .
  • the embodiment of the present application further provides a user terminal, including:
  • the transceiver 801 is configured to send a registration request to the home subscription subscriber server HSS, and receive a random number sent by the HSS;
  • the transceiver 801 is specifically configured to receive the random number from an Unauthorized response sent by the P-CSCF.
  • the processor 802 is configured to generate a response verification code Response by using the random number and an attribute identifier corresponding to the user terminal, where the attribute identifier includes an International Mobile Subscriber Identity (IMSI), an International Mobile Equipment Identity (IMEI), and an IP Multimedia System IMS identity;
  • IMSI International Mobile Subscriber Identity
  • IMEI International Mobile Equipment Identity
  • IP Multimedia System IMS identity IP Multimedia System identity
  • the transceiver 801 is further configured to send the response verification code Response to the HSS, so that the HSS determines, according to the Response, whether to register the user terminal according to the registration request.
  • the transceiver 801 can be a module to implement the data information transceiving function of the user terminal, and can also be divided into two independent module receivers and transmitters to implement the function of the user terminal to transmit and receive information.
  • the embodiment of the present application further provides a computer readable storage medium, where the computer readable storage medium stores computer instructions, when the computer instructions are run on a computer, causing the computer to execute the embodiment of the present application.
  • the method and device for registering an IMS user provided by the embodiment of the present application, in the HSS, use the attribute identifier to perform corresponding management judgment on the registration request of the user terminal, and transmit relevant parameters in the registration to achieve the access of the IMS device to the user equipment. management.
  • the enterprise network is more secure and complete in managing the access terminals.
  • embodiments of the present application can be provided as a method, system, or computer program product.
  • the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment in combination of software and hardware.
  • the application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) including computer usable program code.
  • the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
  • the apparatus implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
  • These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
  • the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Multimedia (AREA)
  • Business, Economics & Management (AREA)
  • General Business, Economics & Management (AREA)
  • Computer Security & Cryptography (AREA)
  • Databases & Information Systems (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请公开了一种IMS用户的注册方法及装置,方法包括:HSS在收到没有鉴权数据的用户终端的注册请求后,获取该用户终端的配置信息;利用随机数和用户终端的属性标识得到一鉴权验证码ResponseHSS;其中,所述属性标识包括IMSI、IMEI、IMS标识;将所述随机数发送到所述用户终端,接收用户终端反馈的响应验证码Response;确定所述Response与所述ResponseHSS是否相同,相同,则向应用服务器发送所述注册请求进行所述用户终端的注册。解决了现有技术无法对IMS用户所使用的设备进行控制,从而对企业网的安全造成极大影响的技术问题。

Description

一种IMS用户的注册方法及装置
本申请要求于2017年12月14日提交中国专利局、申请号为201711340166.8、发明名称为“一种IMS用户的注册方法及装置”的CN专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及通信技术领域,尤其涉及一种IMS用户的注册方法及装置。
背景技术
现有的VoLTE(Voice over LTE,LTE网络上的语音业务)以及VoIP(Voice over Internet Protocol,IP网络电话)流程中,IMS(IP Multimedia Subsystem,IP多媒体子系统)设备可以根据PVI(Private User Identity,私有用户标识)或者PUI(Public User Identity,公有用户标识)来判断IMS用户的合法性,现有技术方案的具体实现步骤可以如图1所示,包括:
步骤101,UE(User Equipment,用户设备)向发现的P-CSCF(Proxy-Call Session Control Funtion,代理呼叫会话控制功能)发送一个SIP REGISTER(Session Initiation Protocol REGISTER,会话初始协议注册)请求。
步骤102,P-CSCF对该SIP REGISTER请求进行处理,并把SIP REGISTER请求发送给选择的I-CSCF(Interrogating-Call Session Control Function,查询-呼叫会话控制功能实体)。
步骤103,I-CSCF向HSS(HSS(Home Subscriber Server,归属签约用户服务器)发出SAR(Server Assignment Request,服务器指派请求))消息,以查询S-CSCF(Serving CSCF,服务CSCF)的地址。
步骤104,HSS选择某一个S-CSCF,并把选择的S-CSCF的地址通过SAA(Server Assignment Answer,服务器指派应答))消息发给I-CSCF。
步骤105,I-CSCF把SIP REGISTER请求转发给选择的S-CSCF。
步骤106,S-CSCF如果发现用户没有被授权,则会向HSS发送UAR(User Authorization Request,用户授权请求)消息,以获取鉴权认证数据。
步骤107,HSS将鉴权认证数据通过UAA(User Authorization Answer,用户授权应答)消息返回给S-CSCF。
步骤108,S-CSCF用“401未授权(Unauthorized)”应答来质疑用户。并将消息传递给I-CSCF。
步骤109,I-CSCF将“401未授权(Unauthorized)”应答发送给P-CSCF。
步骤110,P-CSCF将“401未授权(Unauthorized)”应答发送给UE。
步骤111,UE会计算出质疑的应答并给P-CSCF发送一个新的REGISTER请求,该新的REGISTER请求中包含应答。
步骤112,P-CSCF会再一次找到I-CSCF,并将新的REGISTER请求发送给I-CSCF。
步骤113,I-CSCF向HSS发出SAR消息,以查询S-CSCF的地址。
步骤114,HSS把选择到的S-CSCF地址通过SAA消息发给I-CSCF。
步骤115,I-CSCF把新的REGISTER请求转发给选择的S-CSCF。
S-CSCF检查新的REGISTER请求中的应答,如果不正确,则鉴权失败,注册流程终止。如果正确,则鉴权成功。
步骤116,如果S-CSCF检查鉴权成功,则向HSS发送MAR(Multimedia Auth Request,媒体鉴权请求)消息。
步骤117,HSS保存UE对应的S-CSCF名字,并返回MAA(Multimedia Auth Answer,媒体鉴权应答)消息给S-CSCF。S-CSCF保存UE对应的用户信息。
步骤118,S-CSCF向I-CSCF发送一个“200OK”消息,表示接受UE的注 册请求。
步骤119,I-CSCF向P-CSCF转发该“200OK”消息。
步骤120,P-CSCF向UE发送“200OK”消息。
步骤121,S-CSCF向AS(Application Server,应用服务器)发送注册请求(REGISTER)消息。
步骤122,AS向S-CSCF返回“200OK”消息,表示接受注册请求对应的注册。
在IMS使用的一些场合,为安全起见,需要某个IMS用户,只能在某个手机上使用。或者限定该IMS用户,只能在某个手机终端上,使用某USIM(Universal Subscriber Identity Module,全球用户识别卡)的情况下使用。但是根据上述现有技术的实现步骤可知:现有技术虽然可以判断IMS用户的合法性,但无法对用户所使用的设备进行控制。如果有些终端使用VoIP客户端在软件上安装的时候,一个用户可以在不同的手机终端上登录;同时多个用户也可以在同一个手机终端上登录。甚至在平时的非企业网发送的手机终端上也可以安装VoIP软件进行登录。这对企业网的安全产生极大影响。
发明内容
本申请提供一种IMS用户的注册方法及装置,用以解决现有技术无法对IMS用户所使用的设备进行控制,从而对企业网的安全造成极大影响的技术问题。
第一方面,本申请提供一种IMS用户的注册方法,包括:
归属签约用户服务器HSS在收到没有鉴权数据的用户终端的注册请求后,获取该用户终端的配置信息;
根据所述配置信息确定与所述用户终端对应的属性标识,并利用随机数 和所述属性标识得到一鉴权验证码ResponseHSS;其中,所述属性标识包括国际移动用户识别码IMSI、国际移动设备身份码IMEI、IP多媒体子系统IMS标识;
将所述随机数发送到所述用户终端,在接收到所述用户终端反馈的应答消息中获取用户终端根据所述随机数得到的响应验证码Response;
确定所述Response与所述ResponseHSS是否相同,相同,则向应用服务器发送所述注册请求进行所述用户终端的注册。
在一种可选的实现方式中,利用随机数和所述属性标识得到一鉴权验证码ResponseHSS包括:
将所述IMSI、IMEI和IMS标识以字符串方式进行拼接后使用MD5算法,生成字符串;
使用MD5算法将所述字符串和所述随机数生成新的字符串作为所述鉴权验证码ResponseHSS。
在一种可选的实现方式中,若确定所述Response与所述ResponseHSS不相同,则进一步包括:
将注册请求失败的原因值携带在媒体鉴权应答MAA消息中,发送到服务呼叫会话控制功能S-CSCF;并向所述用户终端回复消息指示所述注册请求被所述归属签约用户服务器拒绝。
第二方面,本申请还提供另外一种IMS用户的注册方法,该方法应用于以用户终端,包括:
用户终端向归属签约用户服务器HSS发送注册请求;
接收到所述HSS发送的随机数,利用所述随机数和所述用户终端对应的属性标识生成响应验证码Response;其中,所述属性标识包括国际移动用户识别码IMSI、国际移动设备身份码IMEI、IP多媒体子系统IMS标识;
将所述响应验证码Response发送到所述HSS,使得所述HSS根据所述Response确定是否根据所述注册请求对所述用户终端进行注册。
在一种可选的实现方式中,所述接收到所述HSS发送的随机数包括:
所述用户终端从代理呼叫会话控制功能P-CSCF发送的未授权Unauthorized应答中接收所述随机数。
第三方面,本申请提供一种归属签约用户服务器,包括:
接收模块,用于在收到没有鉴权数据的用户终端的注册请求后,获取该用户终端的配置信息;
验证码生成模块,用于根据所述配置信息确定与所述用户终端对应的属性标识,并利用随机数和所述属性标识得到一鉴权验证码ResponseHSS;其中,所述属性标识包括国际移动用户识别码IMSI、国际移动设备身份码IMEI、IP多媒体子系统IMS标识;
获取模块,用于将所述随机数发送到所述用户终端,在接收到所述用户终端反馈的应答消息中获取用户终端根据所述随机数得到的响应验证码Response;
确定模块,用于确定所述Response与所述ResponseHSS是否相同,相同,则向应用服务器发送所述注册请求进行所述用户终端的注册。
在一种可选的实现方式中,所述获取模块具体用于:
将所述IMSI、IMEI和IMS标识以字符串方式进行拼接后使用MD5算法,生成字符串;使用MD5算法将所述字符串和所述随机数生成新的字符串作为所述鉴权验证码ResponseHSS。
在一种可选的实现方式中,确定模块还用于若确定所述Response与所述ResponseHSS不相同,将注册请求失败的原因值携带在MAA消息中,发送到服务呼叫会话控制功能S-CSCF;并向所述用户终端回复消息指示所述注册请 求被所述归属签约用户服务器拒绝。
第四方面,本申请还提供一种用户终端,包括:
收发模块,用于向归属签约用户服务器HSS发送注册请求,并接收到所述HSS发送的随机数;
生成模块,用于利用所述随机数和所述用户终端对应的属性标识生成响应验证码Response;其中,所述属性标识包括国际移动用户识别码IMSI、国际移动设备身份码IMEI、IP多媒体子系统IMS标识;
所述收发模块还用于将所述响应验证码Response发送到所述HSS,使得所述HSS根据所述Response确定是否根据所述注册请求对所述用户终端进行注册。
在一种可选的实现方式中,所述收发模块具体用于从代理呼叫会话控制功能P-CSCF发送的未授权Unauthorized应答中接收所述随机数。
第五方面,提供一种归属签约用户服务器,包括:
接收器,用于接收没有鉴权数据的用户终端的注册请求,
处理器,用于获取该用户终端的配置信息;并根据所述配置信息确定与所述用户终端对应的属性标识,并利用随机数和所述属性标识得到一鉴权验证码ResponseHSS;其中,所述属性标识包括国际移动用户识别码IMSI、国际移动设备身份码IMEI、IP多媒体子系统IMS标识;
发射器,用于将所述随机数发送到所述用户终端;
所述接收器,还用于接收所述用户终端反馈的应答消息;
所述处理器还用于,从所述应答消息中获取用户终端根据所述随机数得到的响应验证码Response;并确定所述Response与所述ResponseHSS是否相同,相同,则控制所述发射器向应用服务器发送所述注册请求进行所述用户终端的注册。
在一种可选的实现方式中,所述处理器,具体用于将所述IMSI、IMEI和IMS标识以字符串方式进行拼接后使用MD5算法,生成字符串;使用MD5算法将所述字符串和所述随机数生成新的字符串作为所述鉴权验证码ResponseHSS。
在一种可选的实现方式中,所述处理器还用于若确定所述Response与所述ResponseHSS不相同,将注册请求失败的原因值携带在MAA消息中;并控制则所述发射器,还用于将所述MAA消息发送到服务呼叫会话控制功能S-CSCF;并向所述用户终端回复消息指示所述注册请求被所述归属签约用户服务器拒绝。
第六方面,提供一种用户终端,包括:
收发器,用于向归属签约用户服务器HSS发送注册请求,并接收到所述HSS发送的随机数;
处理器,用于利用所述随机数和所述用户终端对应的属性标识生成响应验证码Response;其中,所述属性标识包括国际移动用户识别码IMSI、国际移动设备身份码IMEI、IP多媒体子系统IMS标识;
所述收发器还用于将所述响应验证码Response发送到所述HSS,使得所述HSS根据所述Response确定是否根据所述注册请求对所述用户终端进行注册。
在一种可选的实现方式中,所述收发器具体用于从代理呼叫会话控制功能P-CSCF发送的未授权Unauthorized应答中接收所述随机数。
第七方面,本申请还提供一种计算机可读存储介质,所述计算机可读存储介质存储有计算机指令,当所述计算机指令在计算机上运行时,使得计算机执行前述第一方面或第二方面中任一可选的实施方式所述的方法。
本申请有益效果如下:
本申请实施例所提供的IMS用户的注册方法及装置,在HSS中利用属性标识对用户终端的注册请求进行对应的管理判断,并在注册中传递相关参数,达到IMS设备对用户设备准入的管理。使得企业网对接入终端的管理更加安全和完善。
附图说明
图1为现有技术判断IMS用户的合法性方法的流程示意图;
图2为本申请实施例提供的一种IMS用户的注册方法的流程示意图;
图3为本申请实施例提供的另外一种IMS用户的注册方法的流程示意图;
图4为本申请实施例提供的一种IMS用户的注册方法应用在实际网络架构中的流程示意图;
图5为本申请实施例提供的一种归属签约用户服务器的结构示意图;
图6为本申请实施例提供的一种用户终端的结构示意图;
图7为本申请实施例提供的另外一种归属签约用户服务器的结构示意图;
图8为本申请实施例提供的另外一种用户终端的结构示意图。
具体实施方式
由于现有技术中提供的鉴权方法HSS不能将EPC(Evolved Packet Core,演进核心网)的标识同IMS的标识绑定并检查。所以现有技术虽然可以判断IMS用户的合法性,但无法获知该用户所使用的设备,从而无法对用户所使用的设备进行控制。
针对现有技术的上述问题,本申请实施例提出了一种IMS用户的注册方法和装置,在该方法中归属签约用户服务器HSS在收到没有鉴权数据的用户终端的注册请求后,获取该用户终端的配置信息;根据所述配置信息确定与 所述用户终端对应的属性标识,并利用随机数和所述属性标识得到一鉴权验证码ResponseHSS;将所述随机数发送到所述用户终端,在接收到所述用户终端反馈的应答消息中获取用户终端根据所述随机数得到的响应验证码Response;确定所述Response与所述ResponseHSS是否相同,相同,则向应用服务器发送所述注册请求进行所述用户终端的注册。
因为本申请实施例所提供的方法中会对用户终端对应的属性标识进行验证,所以使得企业网可以控制接入到IMS系统的用户终端,使用非定制认证的用户终端即使安装了VoIP软件,也无法接入IMS系统。从而使得企业网可以有效控制用户终端的使用。特别适用于一些要求比较严格的场景下,比如煤矿矿井下、以及公安应急系统中,接入网络对接入的客户端有严格限制。以下结合附图和具体的应用场景对本申请实施例所提供的方法和装置做进一步详细的说明:
实施例一
以下结合说明书附图对本申请实施例所提供的一种IMS用户的注册方法做进一步详细的说明,该方法具体实现方式可以包括以下步骤(方法流程如图2所示):
步骤201,HSS在收到没有鉴权数据的用户终端的注册请求后,获取该用户终端的配置信息;
步骤202,根据所述配置信息确定与所述用户终端对应的属性标识,并利用随机数和所述属性标识得到一鉴权验证码(ResponseHSS);其中,所述属性标识包括国际移动用户识别码(International Mobile Subscriber Identification Number,国际移动用户识别码)、国际移动设备身份码(International Mobile Equipment Identity,国际移动设备身份码)、IP多媒体子系统IMS标识;
其中,该属性标识包括的IMSI、IMEI、IP多媒体子系统IMS标识(包 括:PVI和PUI)可以进行组合使用,任何一种组合需要能够确定接入网络的终端设备为。
利用随机数和所述属性标识得到一鉴权验证码ResponseHSS可以采用以下方式得到:
在本申请实施例中,基于上述属性标识的类型可以提前在HSS中设置属性标识的对应关系,基于上述属性标识的类型可以设置IMSI、IMEI、IMS标识中的PVI和PUI的对应关系如表1所示:
PVI sip:460001004202567@ims.mnc000.mcc460.3gppnetwork.org
PUI tel:13400000002;phone-context=ims.mnc000.mcc460.3gppnetwork.org
IMSI 460001004202567
IMEI 861414030072400
表1
然后,HSS生成随机数RANDcheck,并随检查标志将RANDcheck发送至用户终端;该实施例中RANDcheck可以由一个随机字符串组成。
终端接收RANDcheck后,如果检测到有检查标志,则利用该随机数计算Response,计算方法如下:
A,将所述IMSI、IMEI和IMS标识以字符串方式进行拼接后使用MD5(Message Digest Algorithm 5,消息摘要算法第五版)算法,生成字符串(HA1);
HA1=md5("PVI:IMSI:IMEI");
B,使用MD5算法将所述字符串和所述随机数生成新的字符串作为所述鉴权验证码ResponseHSS。
ResponseHSS=md5("HA1:RANDcheck")
步骤203,将所述随机数发送到所述用户终端,在接收到所述用户终端反馈的应答消息中获取用户终端根据所述随机数得到的响应验证码(Response);
步骤204,确定所述Response与所述ResponseHSS是否相同,相同,则向应用服务器发送所述注册请求进行所述用户终端的注册。
进一步,若确定所述Response与所述ResponseHSS不相同,则进一步包括:
将注册请求失败的原因值携带在MAA消息中,发送到S-CSCF;并向所述用户终端回复消息指示所述注册请求被所述归属签约用户服务器拒绝。
实施例二
如图3所示,本申请实施例还提供另外一种IMS用户的注册方法,该方法应用于以用户终端,该用户终端中设置有通信模块,包括:
步骤301,用户终端向HSS发送注册请求;
步骤302,接收到所述HSS发送的随机数,利用所述随机数和所述用户终端对应的属性标识生成响应验证码(Response);其中,所述属性标识包括IMSI、IMEI、IMS标识;
在具体的应用场景中,该用户终端可以从P-CSCF发送的未授权(Unauthorized)应答中接收所述随机数。
步骤303,将所述Response发送到所述HSS,使得所述HSS根据所述Response确定是否根据所述注册请求对所述用户终端进行注册。
实施例三
因为实施例一和实施例二是基于不同设备实现本申请实施例所提供的方法的实现过程,为了更清楚详细的说明本申请实施例所提供方法在具体应用环境中的具体使用,以下基于实施例一与实施例二的结合,以及具体的网络构架(具体设备包括:UE、P-CSCF、I-CSCF、S-CSCF、HSS、AS),对本申请实施例所提供的IMS用户的注册方法进行说明,具体可以是(如图4所示):
步骤401,UE向发现的P-CSCF发送一个SIP REGISTER请求。
步骤402,P-CSCF对接收到的SIP REGISTER请求进行处理,并把该SIP REGISTER请求发送给选择的I-CSCF。
步骤403,I-CSCF接收到SIP REGISTER请求后,联系HSS,并向HSS发出SAR消息,以查询S-CSCF的地址。
步骤404,HSS选择S-CSCF,并把选择的S-CSCF的地址通过SAA消息发给I-CSCF。
步骤405,I-CSCF在接收到HSS选择的S-CSCF的地址后,把SIP REGISTER请求转发给选择的S-CSCF。
步骤406,当S-CSCF确定用户没有被授权,则向HSS发送UAR消息,以获取鉴权数据。
HSS在收到UAR消息后,检查该用户的配置信息,如存在IMSI、IMEI、IMS标识PVI的对应关系表,则生成随机数(RANDcheck),并根据实施例所提供的随机数计算方式生成ResponseHSS,计算后保存在HSS中。HSS将RANDcheck传递给S-CSCF。
步骤407,HSS将鉴权认证数据通过UAA消息返回给S-CSCF,消息中携带RANDcheck。
步骤408,S-CSCF收到UAA消息中携带的RANDcheck后,无论对应用户配置的鉴权方式是Digest或者AKA,后续都用“401未授权(Unauthorized)”应答来质疑用户。并将消息传递给I-CSCF,消息中携带RANDcheck。
步骤409,I-CSCF将“401未授权(Unauthorized)”应答发送给P-CSCF,消息中携带RANDcheck。
步骤410,P-CSCF将“401未授权(Unauthorized)”应答发送给UE,消息中携带RANDcheck。
步骤411,UE会计算出这个质疑的应答并给P-CSCF发送一个新的包含 这个应答的REGISTER,并且使用接收到的RANDcheck以及自身的PVI、IMSI、IMEI,计算Response值。并将Response在新的REGISTER消息中发送。
步骤412,P-CSCF会选择I-CSCF,并将新的REGISTER消息发送给选择的I-CSCF。
步骤413,I-CSCF接到新的REGISTER消息后,向HSS发出SAR消息,以查询S-CSCF的地址。
步骤414,HSS接到SAR消息后把选择的S-CSCF地址通过SAA消息发给I-CSCF。
步骤415,I-CSCF把新的REGISTER请求转发给HSS选择的S-CSCF。
S-CSCF根据新的REGISTER请求检查UE反馈的应答,如果不正确,则鉴权失败,注册流程终止。如果正确,则鉴权成功。
步骤416,如果S-CSCF检查鉴权成功,则S-CSCF将向HSS发送MAR消息。并将新的REGISTER消息中携带的Response,通过MAR消息传递给HSS。
步骤417,HSS保存对应该用户的S-CSCF名字,并且检查该Response与原先计算的ResponseHSS是否相同。
如果Response与步骤6中计算的ResponseHSS相同,则用户匹配设备成功;不相同,则用户匹配设备失败,则可以确定该用户没有使用指定的USIM卡以及指定的移动终端。IMS设备则拒绝该用户的注册。
HSS发送MAA消息给S-CSCF。消息中携带匹配结果。如果匹配失败HSS在MAA消息中携带失败的原因值,新定义原因值为:
DIAMETER_ERROR_RESTRICT_IMSI_IMEI_ERROR(5013)
步骤418,如果匹配结果为成功,S-CSCF向I-CSCF发送一个“200OK” 消息,表示接受这个注册;如果S-CSCF在收到失败的原因值后,向UE回复202消息,该次注册不被服务器接收,结束流程;如果消息为“200OK”消息,则转入步骤421。
步骤419,I-CSCF向P-CSCF转发该“200OK”消息或202消息
步骤420,P-CSCF向UE发送“200OK”消息或202消息;如果为202消息则结束流程。
步骤421,S-CSCF向应用服务器AS发送注册请求(REGISTER)消息。
步骤422,应用服务器AS向S-CSCF返回“200OK”消息,表示接受这个注册。
实施例四
如图5所示,本申请实施例还提供一种归属签约用户服务器,该归属签约用户服务器具体可以包括:
接收模块501,用于在收到没有鉴权数据的用户终端的注册请求后,获取该用户终端的配置信息;
验证码生成模块502,根据所述配置信息确定与所述用户终端对应的属性标识,并利用随机数和所述属性标识得到一鉴权验证码ResponseHSS;其中,所述属性标识包括国际移动用户识别码IMSI、国际移动设备身份码IMEI、IP多媒体子系统IMS标识;
获取模块503,用于将所述随机数发送到所述用户终端,在接收到所述用户终端反馈的应答消息中获取用户终端根据所述随机数得到的响应验证码Response;
在现有实现方式中获取模块可以通过多种方式得到的响应验证码Response,在本申请实施例中所述获取模块503具体可以通过以下方式实现:
将所述IMSI、IMEI和IMS标识以字符串方式进行拼接后使用MD5算法, 生成字符串;使用MD5算法将所述字符串和所述随机数生成新的字符串作为所述鉴权验证码ResponseHSS。
确定模块504,用于确定所述Response与所述ResponseHSS是否相同,相同,则向应用服务器发送所述注册请求进行所述用户终端的注册。
如果确定所述Response与所述ResponseHSS不相同,则拒绝注册请求,对应的:
确定模块504还用于将注册请求失败的原因值携带在MAA消息中,发送到S-CSCF;并向所述用户终端回复消息指示所述注册请求被所述归属签约用户服务器拒绝。
实施例五
如图6所示,本申请实施例还提供一种用户终端,该用户终端中设置有通信模块,还包括:
收发模块601,用于向归属签约用户服务器HSS发送注册请求,并接收到所述HSS发送的随机数;
可选的,该收发模块601具体用于从P-CSCF发送的未授权(Unauthorized)应答中接收所述随机数。
生成模块602,用于利用所述随机数和所述用户终端对应的属性标识生成响应验证码Response;其中,所述属性标识包括国际移动用户识别码IMSI、国际移动设备身份码IMEI、IP多媒体子系统IMS标识;
所述收发模块601还用于将所述响应验证码Response发送到所述HSS,使得所述HSS根据所述Response确定是否根据所述注册请求对所述用户终端进行注册。
实施例六
如图7所示,本申请实施例还提供一种归属签约用户服务器,该归属签 约用户服务器具体可以包括:
接收器701,用于接收没有鉴权数据的用户终端的注册请求;
处理器702,用于获取该用户终端的配置信息;并根据所述配置信息确定与所述用户终端对应的属性标识,并利用随机数和所述属性标识得到一鉴权验证码ResponseHSS;其中,所述属性标识包括国际移动用户识别码IMSI、国际移动设备身份码IMEI、IP多媒体子系统IMS标识;
发射器703,用于将所述随机数发送到所述用户终端;
所述接收器701,还用于接收所述用户终端反馈的应答消息;
则所述处理器702,还用于从所述应答消息中获取用户终端根据所述随机数得到的响应验证码Response;
在现有实现方式中处理器702可以通过多种方式得到的响应验证码Response,在本申请实施例中所述处理器702具体可以通过以下方式实现得到响应验证码:
将所述IMSI、IMEI和IMS标识以字符串方式进行拼接后使用MD5算法,生成字符串;使用MD5算法将所述字符串和所述随机数生成新的字符串作为所述鉴权验证码ResponseHSS。
该处理器702,用于确定所述Response与所述ResponseHSS是否相同,相同,则控制所述发射器703向应用服务器发送所述注册请求进行所述用户终端的注册。
如果确定所述Response与所述ResponseHSS不相同,则拒绝注册请求,对应的:
所述处理器702还用于将注册请求失败的原因值携带在MAA消息中,并控制所述发射器将所述MAA消息发送到S-CSCF;并向所述用户终端回复消息指示所述注册请求被所述归属签约用户服务器拒绝。
在本申请实施例中,接收器701和发射器703可以集成在一个模块(收发器)集中实现归属签约用户服务器的数据信息收发功能,也可以分为两个独立的模块分别实现收发信息的功能。
实施例五
如图8所示,本申请实施例还提供一种用户终端,包括:
收发器801,用于向归属签约用户服务器HSS发送注册请求,并接收到所述HSS发送的随机数;
可选的,该收发器801具体用于从P-CSCF发送的未授权(Unauthorized)应答中接收所述随机数。
处理器802,用于利用所述随机数和所述用户终端对应的属性标识生成响应验证码Response;其中,所述属性标识包括国际移动用户识别码IMSI、国际移动设备身份码IMEI、IP多媒体子系统IMS标识;
所述收发器801还用于将所述响应验证码Response发送到所述HSS,使得所述HSS根据所述Response确定是否根据所述注册请求对所述用户终端进行注册。
在本申请实施例中,收发器801可以是一个模块集中实现用户终端的数据信息收发功能,也可以分为两个独立的模块接收器和发射器分别实现用户终端收发信息的功能。
基于同一发明构思,本申请实施例还提供了一种计算机可读存储介质,所述计算机可读存储介质存储有计算机指令,当所述计算机指令在计算机上运行时,使得计算机执行本申请实施例一或实施例二中IMS用户的注册方法。
本申请实施例所提供的IMS用户的注册方法及装置,在HSS中利用属性标识对用户终端的注册请求进行对应的管理判断,并在注册中传递相关参数,达到IMS设备对用户设备准入的管理。使得企业网对接入终端的管理更加安 全和完善。
本领域内的技术人员应明白,本申请的实施例可提供为方法、系统、或计算机程序产品。因此,本申请可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本申请可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器和光学存储器等)上实施的计算机程序产品的形式。
本申请是参照根据本申请实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
显然,本领域的技术人员可以对本申请进行各种改动和变型而不脱离本 申请的精神和范围。这样,倘若本申请的这些修改和变型属于本申请权利要求及其等同技术的范围之内,则本申请也意图包含这些改动和变型在内。

Claims (11)

  1. 一种IMS用户的注册方法,其特征在于,包括:
    归属签约用户服务器HSS在收到没有鉴权数据的用户终端的注册请求后,获取该用户终端的配置信息;
    根据所述配置信息确定与所述用户终端对应的属性标识,并利用随机数和所述属性标识得到一鉴权验证码ResponseHSS;其中,所述属性标识包括国际移动用户识别码IMSI、国际移动设备身份码IMEI、IP多媒体子系统IMS标识;
    将所述随机数发送到所述用户终端,在接收到所述用户终端反馈的应答消息中获取用户终端根据所述随机数得到的响应验证码Response;
    确定所述Response与所述ResponseHSS是否相同,相同,则向应用服务器发送所述注册请求进行所述用户终端的注册。
  2. 如权利要求1所述的方法,其特征在于,利用随机数和所述属性标识得到一鉴权验证码ResponseHSS包括:
    将所述IMSI、IMEI和IMS标识以字符串方式进行拼接后使用MD5算法,生成字符串;
    使用MD5算法将所述字符串和所述随机数生成新的字符串作为所述鉴权验证码ResponseHSS。
  3. 如权利要求1或2所述的方法,其特征在于,若确定所述Response与所述ResponseHSS不相同,则进一步包括:
    将注册请求失败的原因值携带在媒体鉴权应答MAA消息中,发送到服务呼叫会话控制功能S-CSCF;并向所述用户终端回复消息指示所述注册请求被所述归属签约用户服务器拒绝。
  4. 一种IMS用户的注册方法,其特征在于,该方法应用于以用户终端,包括:
    用户终端向归属签约用户服务器HSS发送注册请求;
    接收到所述HSS发送的随机数,利用所述随机数和所述用户终端对应的属性标识生成响应验证码Response;其中,所述属性标识包括国际移动用户识别码IMSI、国际移动设备身份码IMEI、IP多媒体子系统IMS标识;
    将所述响应验证码Response发送到所述HSS,使得所述HSS根据所述Response确定是否根据所述注册请求对所述用户终端进行注册。
  5. 如权利要求4所述的方法,其特征在于,所述接收到所述HSS发送的随机数包括:
    所述用户终端从代理呼叫会话控制功能P-CSCF发送的未授权Unauthorized应答中接收所述随机数。
  6. 一种归属签约用户服务器,其特征在于,包括:
    接收器,用于接收没有鉴权数据的用户终端的注册请求,
    处理器,用于获取该用户终端的配置信息;并根据所述配置信息确定与所述用户终端对应的属性标识,并利用随机数和所述属性标识得到一鉴权验证码ResponseHSS;其中,所述属性标识包括国际移动用户识别码IMSI、国际移动设备身份码IMEI、IP多媒体子系统IMS标识;
    发射器,用于将所述随机数发送到所述用户终端;
    所述接收器,还用于接收所述用户终端反馈的应答消息;
    所述处理器还用于,从所述应答消息中获取用户终端根据所述随机数得到的响应验证码Response;并确定所述Response与所述ResponseHSS是否相同,相同,则控制所述发射器向应用服务器发送所述注册请求进行所述用户终端的注册。
  7. 如权利要求6所述的归属签约用户服务器,其特征在于,所述处理器,具体用于将所述IMSI、IMEI和IMS标识以字符串方式进行拼接后使用MD5算法,生成字符串;使用MD5算法将所述字符串和所述随机数生成新的字符串作为所述鉴权验证码ResponseHSS。
  8. 如权利要求6或7所述的归属签约用户服务器,其特征在于,所述处理器还用于若确定所述Response与所述ResponseHSS不相同,将注册请求失败的原因值携带在MAA消息中;并控制则所述发射器,还用于将所述MAA消息发送到服务呼叫会话控制功能S-CSCF;并向所述用户终端回复消息指示所述注册请求被所述归属签约用户服务器拒绝。
  9. 一种用户终端,其特征在于,包括:
    收发器,用于向归属签约用户服务器HSS发送注册请求,并接收到所述HSS发送的随机数;
    处理器,用于利用所述随机数和所述用户终端对应的属性标识生成响应验证码Response;其中,所述属性标识包括国际移动用户识别码IMSI、国际移动设备身份码IMEI、IP多媒体子系统IMS标识;
    所述收发器还用于将所述响应验证码Response发送到所述HSS,使得所述HSS根据所述Response确定是否根据所述注册请求对所述用户终端进行注册。
  10. 如权利要求9所述的用户终端,其特征在于,所述收发器具体用于从代理呼叫会话控制功能P-CSCF发送的未授权Unauthorized应答中接收所述随机数。
  11. 一种存储介质,其特征在于,所述存储介质为非易失性计算机可读存储介质,所述非易失性计算机可读存储介质存储有至少一个程序,每个所述程序包括指令,所述指令当被具有处理器的电子设备执行时使所述电子设 备执行根据权利要求1-5任一项所述的方法。
PCT/CN2018/102561 2017-12-14 2018-08-27 一种ims用户的注册方法及装置 WO2019114320A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP18889802.7A EP3726795B1 (en) 2017-12-14 2018-08-27 Ims user registration method and device
US16/771,220 US11381607B2 (en) 2017-12-14 2018-08-27 IMS user registration method and device

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201711340166.8 2017-12-14
CN201711340166.8A CN109962878B (zh) 2017-12-14 2017-12-14 一种ims用户的注册方法及装置

Publications (1)

Publication Number Publication Date
WO2019114320A1 true WO2019114320A1 (zh) 2019-06-20

Family

ID=66819897

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/102561 WO2019114320A1 (zh) 2017-12-14 2018-08-27 一种ims用户的注册方法及装置

Country Status (4)

Country Link
US (1) US11381607B2 (zh)
EP (1) EP3726795B1 (zh)
CN (1) CN109962878B (zh)
WO (1) WO2019114320A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111460409A (zh) * 2020-03-31 2020-07-28 好活(昆山)网络科技有限公司 一种平台企业用户的注册方法、装置、介质及电子设备

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111355734A (zh) * 2020-03-02 2020-06-30 安康鸿天科技股份有限公司 接入ims系统的认证方法、装置、电子设备和存储介质
CN114050906B (zh) * 2020-07-22 2024-03-01 中国电信股份有限公司 Sip语音业务的鉴权系统、方法、安全管理网元和客户端
CN117156474B (zh) * 2023-10-30 2024-01-26 深圳市佳贤通信科技股份有限公司 远程智能运维系统及其运维方法

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1801706A (zh) * 2005-01-07 2006-07-12 华为技术有限公司 一种ip多媒体子系统网络鉴权系统及方法
CN103155608A (zh) * 2010-08-13 2013-06-12 T移动美国公司 互联网协议多媒体子系统中的增强的注册信息
US9451421B1 (en) * 2015-06-30 2016-09-20 Blackberry Limited Method and system to authenticate multiple IMS identities
WO2017116896A1 (en) * 2015-12-28 2017-07-06 Motorola Solutions, Inc. Method and apparatus for binding of a user-based public identity to a shared device in an internet protocol multimedia subsystem (ims)-based communication system

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100379315C (zh) * 2005-06-21 2008-04-02 华为技术有限公司 对用户终端进行鉴权的方法
CN100428718C (zh) * 2005-10-19 2008-10-22 华为技术有限公司 一种非ims移动终端接入ims域的鉴权注册方法及装置
CN101841812B (zh) * 2009-03-18 2012-11-07 华为终端有限公司 终端合法性检验的方法、装置和通信系统
CN103002566A (zh) * 2012-12-06 2013-03-27 大唐移动通信设备有限公司 一种ims注册方法及装置
JP2015122620A (ja) * 2013-12-24 2015-07-02 富士通セミコンダクター株式会社 認証システム、認証方法、認証装置、及び、被認証装置
CN103929482B (zh) * 2014-04-15 2017-11-03 浙江宇视科技有限公司 一种安全地访问监控前端设备的方法和装置
CN106341372A (zh) * 2015-07-08 2017-01-18 阿里巴巴集团控股有限公司 终端的认证处理、认证方法及装置、系统
US11647386B2 (en) * 2017-10-17 2023-05-09 Comcast Cable Communications, Llc Device based credentials

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1801706A (zh) * 2005-01-07 2006-07-12 华为技术有限公司 一种ip多媒体子系统网络鉴权系统及方法
CN103155608A (zh) * 2010-08-13 2013-06-12 T移动美国公司 互联网协议多媒体子系统中的增强的注册信息
US9451421B1 (en) * 2015-06-30 2016-09-20 Blackberry Limited Method and system to authenticate multiple IMS identities
WO2017116896A1 (en) * 2015-12-28 2017-07-06 Motorola Solutions, Inc. Method and apparatus for binding of a user-based public identity to a shared device in an internet protocol multimedia subsystem (ims)-based communication system

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3726795A4

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111460409A (zh) * 2020-03-31 2020-07-28 好活(昆山)网络科技有限公司 一种平台企业用户的注册方法、装置、介质及电子设备
CN111460409B (zh) * 2020-03-31 2022-08-05 好活(昆山)网络科技有限公司 一种平台企业用户的注册方法、装置、介质及电子设备

Also Published As

Publication number Publication date
CN109962878A (zh) 2019-07-02
CN109962878B (zh) 2021-04-16
EP3726795A4 (en) 2020-10-28
EP3726795A1 (en) 2020-10-21
EP3726795B1 (en) 2023-05-31
US11381607B2 (en) 2022-07-05
US20200314153A1 (en) 2020-10-01

Similar Documents

Publication Publication Date Title
US8880873B2 (en) Method, system and device for authenticating cardless terminal using application server
WO2019114320A1 (zh) 一种ims用户的注册方法及装置
KR100882326B1 (ko) 가입자 신원들
US8335487B2 (en) Method for authenticating user terminal in IP multimedia sub-system
US9992183B2 (en) Using an IP multimedia subsystem for HTTP session authentication
US8959343B2 (en) Authentication system, method and device
CN100461942C (zh) Ip多媒体子系统接入域安全机制的选择方法
US20180124604A1 (en) Method for performing multiple authentications within service registration procedure
US20160191523A1 (en) Service authority determination method and device
CN107070950B (zh) Ims注册控制的方法、装置和计算机可读存储介质
US9369873B2 (en) Network application function authorisation in a generic bootstrapping architecture
CN107493293A (zh) 一种sip终端接入鉴权的方法
CN103259763A (zh) Ip多媒体子系统ims域注册方法、系统和装置
US11490255B2 (en) RCS authentication
CN102065069B (zh) 一种身份认证方法、装置和系统
US20230072838A1 (en) Virtual line registration system
CN103905405A (zh) 一种ims的用户注册方法、装置及相关设备
CN109788467B (zh) Rcs协议测试方法、测试平台和计算机可读存储介质
US8755799B1 (en) Provisioning and using wildcarded private identity to register devices for wireless services
CN108270747B (zh) 一种认证方法及装置
CN101540678A (zh) 固定终端及其认证方法
WO2017008513A1 (zh) Ims网络的注册方法及系统
CN115412912A (zh) 一种终端设备注册的方法、相关设备、系统以及存储介质
CN106487741B (zh) 基于ims网络的认证方法、认证终端及认证系统
CN112953718A (zh) Ims网络用户的鉴权方法及装置、呼叫会话控制功能实体

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18889802

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 2018889802

Country of ref document: EP

Effective date: 20200715

ENP Entry into the national phase

Ref document number: 2018889802

Country of ref document: EP

Effective date: 20200714