Summary of the invention
The embodiment of the invention provides the method and the system thereof of a kind of main process equipment, portable terminal, processing mobile communication business, need provide the subscriber identification module of example, in hardware to mobile phone users in order to solve mobile communication network operator in the prior art, make the problem that operation cost increases; And portable terminal need increase the hardware unit that is used for using subscriber identification module, the problem that the hardware configuration of feasible design portable terminal and the complexity of electric property increase.
The main process equipment that the embodiment of the invention provides comprises:
Memory module is used for the mobile communication business parameter of memory mobile terminal;
Coffret is used for being connected with described portable terminal, receives the authentication indication that described portable terminal sends, and receives the instruction of the described mobile communication business parameter of visit of described portable terminal transmission;
Authentication module is used for utilizing authentication arithmetic to generate the Authentication Response parameter of described portable terminal correspondence when described coffret receives the indication of described authentication;
First processing module is used for the instruction according to the described mobile communication business parameter of described visit, and the mobile communication business parameter that described memory module is stored conducts interviews, and generates the visit result;
Described coffret also is used for described Authentication Response parameter, described visit result are sent to described portable terminal.
The portable terminal that the embodiment of the invention provides comprises:
First generation module is used for generating the authentication indication when the portable terminal accessing mobile communication network, described authentication indication is used to indicate main process equipment to generate the Authentication Response parameter of described portable terminal correspondence;
Second generation module is used to generate the instruction of mobile communication business parameter described in the described main process equipment of visit;
Coffret, be used for being connected with described main process equipment, described authentication indication is sent to described main process equipment, and receive the Authentication Response parameter that described main process equipment returns, by described portable terminal described Authentication Response parameter being sent to mobile communication network side handles, described instruction is sent to described main process equipment, and receives the visit result that described main process equipment returns, by described portable terminal according to described visit originating mobile communication service as a result.
A kind of system that handles mobile communication business that the embodiment of the invention provides comprises main process equipment and the portable terminal that is connected with described main process equipment:
Described main process equipment, be used to store the mobile communication business parameter of described portable terminal, receive the authentication indication that described portable terminal sends, receive the instruction of the described mobile communication business parameter of visit of described portable terminal transmission, and when receiving the indication of described authentication, utilize authentication arithmetic to generate the Authentication Response parameter of described portable terminal correspondence, described Authentication Response parameter is sent to described portable terminal, and according to the instruction of the described mobile communication business parameter of described visit, described mobile communication business parameter is conducted interviews, generate the visit result, described visit result is sent to described portable terminal;
Described portable terminal, be used for when accessing mobile communication network, generating described authentication indication, described authentication indication is sent to described main process equipment, and receive the Authentication Response parameter that described main process equipment returns, described Authentication Response parameter is sent to mobile communication network side to be handled, generate the instruction of mobile communication business parameter described in the described main process equipment of visit, described instruction is sent to described main process equipment, and receive the visit result that described main process equipment returns, according to described visit originating mobile communication service as a result.
The main process equipment that the embodiment of the invention provides is handled the method for mobile communication business, comprising:
When the authentication indication that receives the portable terminal transmission, utilize authentication arithmetic to generate the Authentication Response parameter of described portable terminal correspondence, described Authentication Response parameter is sent to described portable terminal; And
Receive the instruction of the mobile communication business parameter of the described portable terminal of visit that described portable terminal sends, described mobile communication business parameter is conducted interviews, generate the visit result, and described visit result is sent to described portable terminal according to described instruction.
The portable terminal that the embodiment of the invention provides is handled the method for mobile communication business, comprising:
When the portable terminal accessing mobile communication network, generate the authentication indication, described authentication indication is used to indicate main process equipment to generate the Authentication Response parameter of described portable terminal correspondence, described authentication indication is sent to described main process equipment, receive the Authentication Response parameter that described main process equipment returns, described Authentication Response parameter is sent to mobile communication network side handle; And
Generate the instruction of mobile communication business parameter in the described main process equipment of visit, described instruction sent to described main process equipment, and receive the visit result that described main process equipment returns, by described portable terminal according to described visit originating mobile communication service as a result.
The technical scheme of the embodiment of the invention makes mobile communication network operator not need to provide to mobile phone users the subscriber identification module of example, in hardware, thereby has reduced the operation cost of mobile communication network operator; In addition, do not need to be provided with the hardware unit that is used for installing subscriber identification module in the portable terminal, this has reduced the hardware configuration of design portable terminal and the complexity of electric property again.
Embodiment
In order to solve problems of the prior art, the embodiment of the invention provides the method and the system thereof of a kind of main process equipment, portable terminal, processing mobile communication business.
The technical scheme of the embodiment of the invention, in fact be exactly the subscriber identification module (UIM card or SIM card) of example, in hardware to be carried out software implementation handle, the all functions of the subscriber identification module of example, in hardware are integrated in the software program, this software program are installed in the main process equipment (such as computer) again; When mobile phone users need use mobile communication business, elder generation communicated portable terminal and is connected with main process equipment; Then, portable terminal can be regarded the above-mentioned software program in the main process equipment as the subscriber identification module of software implementation, and portable terminal uses mobile communication business in conjunction with the subscriber identification module of this software implementation.
As seen, the technical scheme of the embodiment of the invention makes portable data storage that mobile communication network operator only need carry by the Internet, mobile phone users or CD provide subscriber identification module from software implementation to mobile phone users, after being installed to the subscriber identification module of this software implementation in the main process equipment by mobile phone users, portable terminal just can use mobile communication business in conjunction with this main process equipment.Compare with existing separation between machine and card scheme, the technical scheme of the embodiment of the invention makes mobile communication network operator not need to provide to mobile phone users the subscriber identification module of example, in hardware, thereby has reduced the operation cost of mobile communication network operator; In addition, do not need to be provided with the hardware unit that is used for installing subscriber identification module in the portable terminal, this has reduced the hardware configuration of design portable terminal and the complexity of electric property again.
Further, the technical scheme of the embodiment of the invention and existing machine card integrated scheme (are that the mobile communication business parameter is written in the portable terminal, the scheme that the authentication calculations process is also carried out by portable terminal) compare, also have following advantage: the mobile communication business parameter can be changed more easily.
As seen, the technical scheme of the embodiment of the invention can accomplish to save as existing machine card integrated scheme on cost, and is convenient as existing separation between machine and card scheme in the mobile communication business variation of parameter.
As shown in Figure 1, a kind of main process equipment of providing of the embodiment of the invention comprises:
Memory module 101 is used for the mobile communication business parameter of memory mobile terminal; Wherein, the mobile communication business parameter should meet UIM agreement or SIM agreement, specifically can comprise IMSI, A_KEY etc.; The type of visit mobile communication business parameter comprises reading, renewal, calcellation, recovery etc.;
Coffret 102 is used for being connected with portable terminal, the authentication indication that mobile terminal receive sends, the instruction of the above-mentioned mobile communication business parameter of visit that mobile terminal receive sends;
Authentication module 103 is used for utilizing authentication arithmetic to generate the Authentication Response parameter of portable terminal correspondence when coffret 102 receives the indication of above-mentioned authentication;
First processing module 104 is used for the instruction according to visit mobile communication business parameter, and the mobile communication business parameter that memory module 101 is stored conducts interviews, and generates the visit result.
Coffret 102 also is used for above-mentioned Authentication Response parameter, above-mentioned visit result are sent to portable terminal.
In addition, memory module 101 also is used to store the access rights of mobile communication business parameter; Access rights comprise reads authority, renewal authority, calcellation authority, recovery authority etc.; Wherein, access rights can be divided into five grade: AL (always) again, and data can be passed through (promptly visiting unrestricted), even without any password input; CHV1, data can be passed through, and condition is that password is exempted from activation or the main process equipment password is arranged; CHV2, data can be passed through, and condition is that password CHV2 is in main process equipment; ADM (ADMINISTRATE), data can be passed through, and are only limited to mobile communication network operator; NEV (NEVER), data are never read;
At this moment, first processing module 104 is specially the instruction according to the access rights of memory module 101 storages, visit mobile communication business parameter, and the mobile communication business parameter that memory module 101 is stored conducts interviews, and generates the visit result.Such as: the reading condition of the IMSI of storage is AL in the memory module 101, when coffret 102 receives the instruction of IMSI in the reading memory module 101 that portable terminal sends, processing module 104 just reads the IMSI of memory module 101 storages, generates to read result's (being the value of IMSI).
Wherein, when the mobile communication business parameter of memory module 101 storages meets the UIM agreement, coffret 102 should meet UIM card standard interface protocol, and when the mobile communication business parameter of memory module 101 storages met the SIM agreement, coffret 102 should meet the SIM card standard interface protocol.
Particularly, coffret 102 is USB (universal serial bus) or PCI Express (PeripheralComponent Interconnect Express, video card interface) interface or background communication interface; Communicate by the modem port that on above-mentioned interface, shines upon or diagnostic port and mobile communication terminal.
Memory module 101 in the main process equipment shown in Figure 1, authentication module 103, first processing module 104 constitute a software program, and this software program can be realized the function of the subscriber identification module of example, in hardware; Coffret 102 makes again and can transmit data between main process equipment and the portable terminal, therefore, portable terminal can be regarded the above-mentioned software program in the main process equipment as the subscriber identification module of software implementation, and portable terminal uses mobile communication business in conjunction with the subscriber identification module of this software implementation.As seen, main process equipment shown in Figure 1 makes mobile communication network operator not need to provide to mobile phone users the subscriber identification module of example, in hardware, thereby has reduced the operation cost of mobile communication network operator.In addition, do not need to be provided with the hardware unit that is used for installing subscriber identification module in the portable terminal, this has reduced the hardware configuration of design portable terminal and the complexity of electric property again.
As shown in Figure 2, authentication module 103 further comprises:
Sub module stored 201 is used to store authentication arithmetic; Wherein, if the mobile communication business parameter of memory module 101 storages meets the UIM agreement, then authentication arithmetic is the CAVE algorithm;
Operator module 202 is used for when coffret 102 obtains the authentication indication, operation authentication arithmetic, the Authentication Response parameter of generation portable terminal correspondence.
In addition, sub module stored 201 also is used to store the used parameter of authentication arithmetic; Wherein, the used parameter of CAVE algorithm has ESN (Electronic SerialNumber, Electronic Serial Number), SSD (Shared Secret Data, sub-key), the IMSI of UIMID (ID of UIM) or portable terminal; At this moment, more as shown in Figure 3, authentication module 103 can also comprise:
Updating submodule 203 is used for the used parameter of authentication arithmetic that updated stored submodule 201 is stored.Such as carrying out Update SSD, BASE STATION CHALLENGE, Confirm SSD, GenerateKey/VPM (Voice Private Mask, the voice encryption mask) and some and HRPD (High ratepacket data, High Rate Packet Data) relevant safety function (as CHAP (Challenge HandshakeAuthentication Protocol, password Challenge-Handshake Authentication Protocol) response).
As shown in Figure 3, main process equipment shown in Figure 1 also comprises:
Security module 301 is used to judge the portable terminal main process equipment of whether having the right to use;
At this moment, coffret 102 specifically is used for being connected with portable terminal, when security module 301 judges that portable terminal has the right to use main process equipment, the authentication indication that mobile terminal receive sends, and the instruction of the visit mobile communication business parameter of mobile terminal receive transmission.
Security module 301 can be judged the portable terminal main process equipment of whether having the right to use, and guarantees only to have the right to use the portable terminal of main process equipment can use main process equipment, have no right to use the portable terminal of main process equipment can't use main process equipment.
Particularly, security module 301 can adopt following several mode that the legitimacy of the portable terminal of use main process equipment is carried out authentication:
1, utilizes the identifying code authentication
Store in the security module 301 and be used to verify whether portable terminal has the right to use the standard identifying code of main process equipment.At portable terminal with after the coffret 102 of main process equipment is connected, the identifying code that coffret 102 mobile terminal receives send, and this identifying code is transmitted to security module 301; Security module 301 judges whether this identifying code is identical with the standard identifying code of its storage, has the right to use main process equipment if portable terminal then is described, otherwise the explanation portable terminal haves no right to use main process equipment.
Wherein, mobile phone users can obtain the standard identifying code there from mobile communication network operator when opening an account.The standard identifying code can be the combination of a plurality of numerals or numeral and letter.
2, binding portable terminal
Store the ESN of the portable terminal of having the right to use main process equipment in the security module 301.At portable terminal with after the coffret 102 of main process equipment is connected, security module 301 determines whether the ESN of portable terminal is identical with the ESN of its storage, have the right to use main process equipment if portable terminal then is described, otherwise the explanation portable terminal haves no right to use main process equipment.
The main process equipment that the corresponding embodiment of the invention provides, as shown in Figure 4, the embodiment of the invention also provides a kind of portable terminal, comprising:
First generation module 401 is used for generating the authentication indication when the portable terminal accessing mobile communication network, the authentication indication is used to indicate main process equipment to generate the Authentication Response parameter of portable terminal correspondence;
Second generation module 402 is used for generating the instruction of visit main process equipment mobile communication business parameter;
Coffret 403 is used for being connected with main process equipment, above-mentioned authentication indication is sent to main process equipment, and receive the Authentication Response parameter that main process equipment returns, and above-mentioned instruction is sent to main process equipment, and receive the visit result that main process equipment returns.
Wherein, particularly, coffret 403 can be USB interface or other interface.
The portable terminal that the embodiment of the invention provides makes mobile communication network operator not need to provide to mobile phone users the subscriber identification module of example, in hardware, thereby has reduced the operation cost of mobile communication network operator; And, not needing to be provided with the hardware unit that is used for installing subscriber identification module in this portable terminal, this has reduced the hardware configuration of design portable terminal and the complexity of electric property again.
In addition, the embodiment of the invention also provides a kind of system that handles mobile communication business, comprises main process equipment and the portable terminal that is connected with main process equipment:
Main process equipment, the mobile communication business parameter that is used for memory mobile terminal, the authentication indication that mobile terminal receive sends, the instruction of the visit mobile communication business parameter that mobile terminal receive sends, and when receiving the authentication indication, utilize authentication arithmetic to generate the Authentication Response parameter of portable terminal correspondence, the Authentication Response parameter is sent to portable terminal, and according to the instruction of visiting described mobile communication business parameter, the mobile communication business parameter is conducted interviews, generate the visit result, will visit the result and send to portable terminal;
Portable terminal, be used for when accessing mobile communication network, generating described authentication indication, the authentication indication is sent to main process equipment, and receive the Authentication Response parameter that main process equipment returns, generate the instruction of mobile communication business parameter in the visit main process equipment, this instruction is sent to main process equipment, and receive the visit result that main process equipment returns.
The system of the processing mobile communication business that the embodiment of the invention provides makes mobile communication network operator not need to provide to mobile phone users the subscriber identification module of example, in hardware, thereby has reduced the operation cost of mobile communication network operator; And, not needing to be provided with the hardware unit that is used for installing subscriber identification module in this portable terminal, this has reduced the hardware configuration of design portable terminal and the complexity of electric property again.
The embodiment of the invention provides the method for handling mobile communication business, portable terminal should be communicated with main process equipment to be connected when this method of enforcement, and as shown in Figure 5, this method comprises:
S501, portable terminal generate the authentication indication when accessing mobile communication network, and the authentication indication is sent to main process equipment, and the authentication indication is used to indicate main process equipment to generate the Authentication Response parameter of portable terminal correspondence.
After S502, main process equipment get access to authentication indication, generate the Authentication Response parameter of portable terminal correspondence, and the Authentication Response parameter is sent to portable terminal by the operation authentication arithmetic.
Wherein, the used parameter of authentication arithmetic and authentication arithmetic all is stored in the main process equipment, and main process equipment can upgrade the used parameter of authentication arithmetic according to the order that receives.Such as carrying out Update SSD, BASE STATION CHALLENGE, Confirm SSD, Generate Key/VPM and safety function that some are relevant with HRPD (as the CHAP response).
S503, portable terminal receive the Authentication Response parameter that main process equipment sends, and the Authentication Response parameter is sent to mobile communication network side handle.
S504, portable terminal generate the instruction of mobile communication business parameter in the visit main process equipment, and this instruction is sent to main process equipment.
Wherein, the type of visit comprises: read (READ), renewal (UPDATE), calcellation (INVALIDATE), recovery (REHABILITATE) etc.; Therefore, the instruction of mobile communication business parameter comprises reading instruction, update instruction, does no-operation instruction (no-op), release command etc. in the visit main process equipment.
S505, main process equipment conduct interviews to the mobile communication business parameter in the main process equipment according to this instruction when getting access to the instruction of visiting mobile communication business parameter in the main process equipment, generate the visit result.
Wherein, access rights can be divided into five grade: AL (always), CHV1, CHV2, ADM, NEV.
Particularly, main process equipment is when getting access to the instruction of visiting mobile communication business parameter in the main process equipment, can also instruct according to this, the access rights of mobile communication business parameter in the main process equipment, the mobile communication business parameter in the main process equipment is conducted interviews, generate the visit result.
If the instruction of mobile communication business parameter in the visit main process equipment that portable terminal sends meets the access rights of mobile communication business parameter in the main process equipment, then main process equipment conducts interviews to the mobile communication business parameter of its storage, generates the visit result.Such as: the reading condition of the IMSI that stores in the main process equipment is AL, and when main process equipment received the instruction of IMSI in the reading main process equipment that portable terminal sends, main process equipment just read the IMSI of its storage, generates to read result's (being the value of IMSI).
S506, main process equipment send to portable terminal with the visit result of its generation.
S507, portable terminal receive the visit result that main process equipment returns, and portable terminal can originating mobile communication service according to the visit result or carried out other operation.
And main process equipment can also receive the instruction of the visit mobile communication business parameter of mobile communication network side transmission; And the instruction of the visit mobile communication business parameter that sends according to mobile communication network side, the access rights of mobile communication business parameter, the mobile communication business parameter is conducted interviews.
In addition, before execution in step S501, main process equipment can also be judged earlier the portable terminal main process equipment of whether having the right to use, and continues execution S501~S507 when portable terminal has the right to use main process equipment.Before execution in step S501, main process equipment is judged earlier the portable terminal main process equipment of whether having the right to use, and can guarantee to have only legal portable terminal can use main process equipment, illegal portable terminal can't use main process equipment.
Wherein, main process equipment is judged earlier the portable terminal main process equipment of whether having the right to use, and comprises following several mode:
1, utilizes the identifying code authentication
Store in the main process equipment and be used to verify whether portable terminal has the right to use the standard identifying code of main process equipment.At portable terminal with after main process equipment is connected, the identifying code that the main process equipment mobile terminal receive sends; Main process equipment judges whether this identifying code is identical with the standard identifying code of its storage, has the right to use main process equipment if portable terminal then is described, otherwise the explanation portable terminal haves no right to use main process equipment.
Wherein, mobile phone users can obtain the standard identifying code there from mobile communication network operator when opening an account.The standard identifying code can be the combination of a plurality of numerals or numeral and letter.
2, binding portable terminal
Store the ESN of the portable terminal of having the right to use main process equipment in the main process equipment.With after main process equipment is connected, main process equipment judges whether the ESN of portable terminal is identical with the ESN of its storage, has the right to use main process equipment if portable terminal then is described at portable terminal, otherwise the explanation portable terminal haves no right to use main process equipment.
The method of the processing mobile communication business that the embodiment of the invention provides makes mobile communication network operator not need to provide to mobile phone users the subscriber identification module of example, in hardware, thereby has reduced the operation cost of mobile communication network operator.In addition, do not need to be provided with the hardware unit that is used for installing subscriber identification module in the portable terminal, this has reduced the hardware configuration of design portable terminal and the complexity of electric property again.
The above is a preferred implementation of the present invention; should be pointed out that for those skilled in the art, under the prerequisite that does not break away from principle of the present invention; can also make some improvements and modifications, these improvements and modifications also should be considered as protection scope of the present invention.