CN1913679A - Protection method and system for preventing fraudulent use of mobile terminal - Google Patents
Protection method and system for preventing fraudulent use of mobile terminal Download PDFInfo
- Publication number
- CN1913679A CN1913679A CNA2006101099876A CN200610109987A CN1913679A CN 1913679 A CN1913679 A CN 1913679A CN A2006101099876 A CNA2006101099876 A CN A2006101099876A CN 200610109987 A CN200610109987 A CN 200610109987A CN 1913679 A CN1913679 A CN 1913679A
- Authority
- CN
- China
- Prior art keywords
- mobile terminal
- serial number
- authentication
- authentication serial
- theft
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Images
Landscapes
- Mobile Radio Communication Systems (AREA)
- Telephone Function (AREA)
Abstract
本发明所述的移动终端防盗用的保护方法与系统在移动终端内预存认证序列号;网络侧设备对所述移动终端的认证序列号进行合法性认证,对于认证不通过的,将所述移动终端列为非法用户,从而在手机丢失或被盗时,可以禁止该手机使用网络或通过运营商网络锁定该手机。将IMEI号进行MD5加密后得到的认证序列号(如128bit信息摘要)存储于具有一次性编程OTP功能的Flash存储器中,认证序列号(如128bit信息摘要)只能被写入一次,在手机出厂时内容已经被写好;从第二次写入开始,读出的内容并非是其写入的内容。通过手机的鉴权过程实现在手机丢失或被盗后达到防止改号的目的。
The mobile terminal anti-theft protection method and system of the present invention pre-stores the authentication serial number in the mobile terminal; the network side device performs legality authentication on the authentication serial number of the mobile terminal, and if the authentication fails, the mobile terminal The terminal is listed as an illegal user, so that when the mobile phone is lost or stolen, the mobile phone can be prohibited from using the network or locked through the operator's network. The authentication serial number (such as 128bit information digest) obtained by encrypting the IMEI number with MD5 is stored in the Flash memory with one-time programming OTP function. The authentication serial number (such as 128bit information digest) can only be written once, and it will When the content has been written; starting from the second write, the read content is not the written content. Through the authentication process of the mobile phone, the purpose of preventing number change after the mobile phone is lost or stolen is achieved.
Description
技术领域technical field
本发明涉及移动终端的防盗技术,尤其涉及一种移动终端被盗后防止被盗用的保护方法与系统。The invention relates to the anti-theft technology of a mobile terminal, in particular to a protection method and system for preventing a mobile terminal from being stolen after being stolen.
背景技术Background technique
手机产品价格的下降以及产品自身的便捷特点,使手机成为日益普及的电子产品。据了解,目前全世界手机用户总量已经超过10亿户,并仍在呈现不断增长的趋势。手机的普及以及手机自身易于携带的外形也带来一些问题,如容易遗失或被盗。这类问题在造成用户直接经济损失的同时,如:盗打电话;不法分子还可利用原有手机软硬件的漏洞,更改手机“身份”识别号码,如:IMEI号,从而使不法分子躲过无线网络系统的限制,继续使用该非法手持设备。The decline in the price of mobile phone products and the convenience of the product itself have made mobile phones an increasingly popular electronic product. It is understood that the total number of mobile phone users in the world has exceeded 1 billion, and is still showing a growing trend. The popularization of mobile phones and the easy-to-carry appearance of mobile phones also bring some problems, such as being easily lost or stolen. While causing direct economic losses to users, this type of problem, such as stealing a phone call; criminals can also use the loopholes in the original mobile phone software and hardware to change the "identity" identification number of the mobile phone, such as the IMEI number, so that criminals can escape. Wireless network system restrictions continue to use this illegal handheld device.
目前,有关手机防盗的技术包括以下几种:At present, technologies related to mobile phone anti-theft include the following:
(1)法国专利FR2791509给出一种通过为手机设定开机密码防止手机被盗后非法使用的技术。(1) French patent FR2791509 provides a technology for preventing illegal use of mobile phones after being stolen by setting power-on passwords for mobile phones.
(2)中国专利200310113647.7与03124196.4给出通过对手机中的SIM(用户识别模块)作保护,防止手机丢失后,其中的SIM卡被非法使用的技术。(2) Chinese patents 200310113647.7 and 03124196.4 provide a technology for protecting the SIM (Subscriber Identity Module) in the mobile phone to prevent the SIM card from being illegally used after the mobile phone is lost.
(3)专利申请号为03148202.3以及专利号为01802972.8的专利,该两个文件给出手机丢失后自动向失主报失的技术。(3) Patent application No. 03148202.3 and patent No. 01802972.8. These two documents provide the technology of automatically reporting the loss to the owner after the mobile phone is lost.
上述现有技术中,不能解决手机丢失后,阻止非法用户继续使用该手机(即使更换SIM卡,也不能允许继续使用该手机),不能阻止手机IMEI号被非法拷贝或改号(IMEI号被非法拷贝或改号是产生“水货”手机的重要原因之一)。In the above-mentioned prior art, after the mobile phone is lost, the illegal user cannot be prevented from continuing to use the mobile phone (even if the SIM card is replaced, the mobile phone cannot be allowed to continue to be used), and the mobile phone IMEI number cannot be illegally copied or changed (the IMEI number is illegally copied or changed). Copying or changing the number is one of the important reasons for "parallel import" mobile phones).
发明内容Contents of the invention
本发明提供一种移动终端防盗用的保护方法与系统,实现移动终端丢失或被盗,通过运营商网络,可以锁定该手机,或者禁止该手机使用网络。The invention provides a protection method and system for anti-theft of a mobile terminal, which realizes that the mobile terminal is lost or stolen, and the mobile phone can be locked or prohibited from using the network through the operator network.
本发明的目的通过以下技术方案实现。The purpose of the present invention is achieved through the following technical solutions.
一种移动终端防盗用的保护方法,包括:A protection method for anti-theft of a mobile terminal, comprising:
A、在移动终端内预存认证序列号;A. Pre-store the authentication serial number in the mobile terminal;
B、网络侧设备对所述移动终端的认证序列号进行合法性认证,对于认证不通过的,将所述移动终端列为非法用户。B. The network side device performs legality authentication on the authentication serial number of the mobile terminal, and lists the mobile terminal as an illegal user if the authentication fails.
所述的步骤A包括:Described step A comprises:
所述的认证序列号包括国际移动台身份识别号IMEI号。The authentication serial number includes the International Mobile Station Identity IMEI number.
所述的认证序列号存储于移动终端的Flash存储器中。The authentication serial number is stored in the Flash memory of the mobile terminal.
所述的认证序列号为IMEI号进行加密后得到的。The authentication serial number is obtained by encrypting the IMEI number.
所述的加密方法为根据硬件序列号ID号采用加密算法对IMEI号进行加密得到认证序列号。The encryption method is to use an encryption algorithm to encrypt the IMEI number according to the ID number of the hardware serial number to obtain the authentication serial number.
所述的认证序列号保存于具有一次性编程OTP功能的Flash存储器中,且所述的认证序列号存储于具有OTP功能的Flash存储器的OTP区。The authentication serial number is stored in the Flash memory with OTP function, and the authentication serial number is stored in the OTP area of the Flash memory with OTP function.
所述的具有一次性编程OTP功能的Flash存储器的非易失NV区用于保存IMEI号。The non-volatile NV area of the Flash memory with one-time programming OTP function is used to save the IMEI number.
所述的方法还包括:The method also includes:
C、移动终端将IMEI号按与得到认证序列号相同的方式对其进行加密,得到鉴权序列号;C. The mobile terminal encrypts the IMEI number in the same way as obtaining the authentication serial number to obtain the authentication serial number;
D、移动终端读取认证序列号,并与鉴权序列号比较,如相同,则移动终端正常使用,否则,移动终端自动关机。D. The mobile terminal reads the authentication serial number and compares it with the authentication serial number. If they are the same, the mobile terminal is used normally; otherwise, the mobile terminal is automatically shut down.
所述的步骤C包括:Described step C comprises:
移动终端从具有OTP功能的Flash存储器的NV区读取IMEI号,并按与得到认证序列号相同的方式对其进行加密,得到鉴权序列号。The mobile terminal reads the IMEI number from the NV area of the Flash memory with OTP function, and encrypts it in the same way as obtaining the authentication serial number to obtain the authentication serial number.
所述的步骤D包括:Described step D comprises:
移动终端从具有OTP功能的Flash存储器的OTP区读取认证序列号,并与鉴权序列号比较,如相同,则移动终端正常使用,否则,移动终端自动关机。The mobile terminal reads the authentication serial number from the OTP area of the Flash memory with the OTP function, and compares it with the authentication serial number. If they are the same, the mobile terminal is in normal use, otherwise, the mobile terminal automatically shuts down.
所述的步骤B包括:Described step B comprises:
网络侧设备获取移动终端的认证序列号,并判断此认证序列号与网络侧设备中保存的该移动终端的登记序列号是否相同,如不相同,则表示认证不通过,将所述移动终端列为非法用户。The network-side device obtains the authentication serial number of the mobile terminal, and judges whether the authentication serial number is the same as the registration serial number of the mobile terminal stored in the network-side device. If not, it means that the authentication fails, and the mobile terminal is listed. for illegal users.
所述的步骤B还包括:Described step B also includes:
将移动终端的IMEI号存入网络侧设备的服务器中作为登记序列号。Store the IMEI number of the mobile terminal in the server of the network side device as the registration serial number.
所述的步骤B还包括:Described step B also includes:
对于被列为非法用户的移动终端,网络侧设备禁止移动终端使用网络或只允许移动终端接收信息而不允许移动终端发送信息。For a mobile terminal listed as an illegal user, the network side device prohibits the mobile terminal from using the network or only allows the mobile terminal to receive information but does not allow the mobile terminal to send information.
一种移动终端防盗用的系统,包括:A mobile terminal anti-theft system, comprising:
认证序列号存储单元:设于移动终端处,用于存储认证序列号;Authentication serial number storage unit: located at the mobile terminal, used to store the authentication serial number;
合法性认证单元:设于网络侧设备中,用于对移动终端的认证序列号进行合法性认证,对于认证不通过的,将所述移动终端列为非法用户。Legitimacy verification unit: set in the network side equipment, used for legality verification of the authentication serial number of the mobile terminal, and if the verification fails, the mobile terminal is listed as an illegal user.
所述的认证序列号存储单元包括:The authentication serial number storage unit includes:
Flash存储器:用于存储所述的认证序列号。Flash memory: used to store the authentication serial number.
所述的Flash存储器具有一次性编程OTP功能的Flash存储器,用于将所述的认证序列号存储于OTP区。The Flash memory has a one-time programming OTP function, and is used to store the authentication serial number in the OTP area.
所述的系统还包括:The system also includes:
加密模块:设于移动终端处,用于根据硬件序列号ID号采用加密算法对IMEI号进行加密得到认证序列号或鉴权序列号。Encryption module: located at the mobile terminal, used to encrypt the IMEI number with an encryption algorithm according to the hardware serial number ID number to obtain the authentication serial number or authentication serial number.
所述的系统还包括:The system also includes:
鉴权模块:设于移动终端处,用于对比认证序列号与鉴权序列号,如相同,则移动终端正常使用,否则,移动终端自动关机Authentication module: installed at the mobile terminal, used to compare the authentication serial number and the authentication serial number, if they are the same, the mobile terminal is in normal use, otherwise, the mobile terminal will automatically shut down
所述的合法性认证单元包括:The legality authentication unit includes:
序列号登记模块:用于登记移动终端的IMEI号,存入网络侧设备的服务器中,作为登记序列号;Serial number registration module: used to register the IMEI number of the mobile terminal, and store it in the server of the network side device as the registration serial number;
存储单元:用于保存移动终端的登记序列号;Storage unit: used to save the registration serial number of the mobile terminal;
合法性认证模块:用于获取移动终端的认证序列号,并判断此认证序列号与网络侧设备的存储单元中保存的该移动终端的登记序列号是否相同,如不相同,则表示认证不通过,将所述移动终端列为非法用户。Legitimacy authentication module: used to obtain the authentication serial number of the mobile terminal, and determine whether the authentication serial number is the same as the registration serial number of the mobile terminal stored in the storage unit of the network side device, if not, it means that the authentication fails , listing the mobile terminal as an illegal user.
由上述本发明给出的技术方案可见,本发明所述的移动终端防盗用的保护方法与系统在移动终端内预存认证序列号;通信时网络系统对所述移动终端的认证序列号进行合法性认证,对于认证不通过的,将所述移动终端列为非法用户,从而在手机丢失或被盗时,可以禁止该手机使用网络或通过运营商网络锁定该手机。将IMEI号进行MD5加密后得到的认证序列号存储于具有一次性编程OTP功能的Flash存储器中,认证序列号只能被写入一次,在手机出厂时内容已经被写好;从第二次写入开始,读出的内容并非是其写入的内容。通过手机的鉴权过程实现在手机丢失或被盗后达到防止改号的目的。It can be seen from the technical scheme provided by the present invention above that the mobile terminal anti-theft protection method and system of the present invention pre-store the authentication serial number in the mobile terminal; Authentication, if the authentication fails, the mobile terminal is listed as an illegal user, so that when the mobile phone is lost or stolen, the mobile phone can be prohibited from using the network or locked through the network of the operator. The authentication serial number obtained by encrypting the IMEI number with MD5 is stored in the Flash memory with one-time programming OTP function. The authentication serial number can only be written once, and the content has been written when the mobile phone leaves the factory; from the second write After input, the content read is not the content written. Through the authentication process of the mobile phone, the purpose of preventing number change after the mobile phone is lost or stolen is achieved.
附图说明Description of drawings
图1为本发明所述移动终端防盗用的保护方法中将手机IMEI号放入网络侧设备的指定服务器的示意图;Fig. 1 is the schematic diagram that mobile phone IMEI number is put into the designated server of network side equipment in the protection method that mobile terminal anti-theft uses of the present invention;
图2为本发明所述移动终端防盗用的保护方法中对手机IMEI号进行加密存储的示意图;Fig. 2 is the schematic diagram that mobile phone IMEI number is encrypted and stored in the protection method of mobile terminal anti-theft according to the present invention;
图3为本发明所述移动终端防盗用的保护方法中手机丢失后,用户请求锁定手机的流程图;Fig. 3 is the flow chart of the user requesting to lock the mobile phone after the mobile phone is lost in the protection method for preventing the use of the mobile terminal according to the present invention;
图4为本发明所述移动终端防盗用的保护方法中手机注册的流程图一;Fig. 4 is the flowchart one of mobile phone registration in the protection method of mobile terminal anti-theft according to the present invention;
图5为本发明所述移动终端防盗用的保护方法中手机注册的流程图二;Fig. 5 is the second flowchart of mobile phone registration in the protection method of mobile terminal anti-theft according to the present invention;
图6为本发明所述移动终端防盗用的系统的结构示意图。FIG. 6 is a schematic structural diagram of the mobile terminal anti-theft system according to the present invention.
具体实施方式Detailed ways
本发明首先涉及一种移动终端防盗用的保护方法,具体是在移动终端内预存认证序列号;网络侧设备对所述移动终端的认证序列号进行合法性认证,对于认证不通过的,将所述移动终端列为非法用户。在移动终端内预存的认证序列号为国际移动台身份识别号IMEI号;也可以为对IMEI号加密后生成的128bit信息摘要,加密的方法是根据硬件序列号ID号采用加密算法(可以是MD5)对IMEI号进行加密得到上述128bit信息摘要。The present invention firstly relates to a method for protecting a mobile terminal against theft. Specifically, the authentication serial number is pre-stored in the mobile terminal; The above mobile terminal is listed as an illegal user. The authentication serial number pre-stored in the mobile terminal is the International Mobile Station Identity Number IMEI number; it can also be a 128-bit information summary generated after encrypting the IMEI number. The encryption method is to use an encryption algorithm (which can be MD5) based on the hardware serial number ID number ) to encrypt the IMEI number to obtain the above 128bit information summary.
上述的认证序列号存储于Flash存储器中;也可以存储于具有一次性编程OTP功能的Flash存储器中,且所述的认证序列号(如128bit信息摘要)存储于具有OTP功能的Flash存储器的OTP区。The above-mentioned authentication serial number is stored in the Flash memory; it can also be stored in the Flash memory with one-time programming OTP function, and the authentication serial number (such as 128bit information summary) is stored in the OTP area of the Flash memory with OTP function .
移动终端还可以进行鉴权处理,具体方法为移动终端将IMEI号按与得到认证序列号(如128bit信息摘要)相同的方式对其进行加密,得到鉴权序列号;移动终端再读取认证序列号(如128bit信息摘要),并与鉴权序列号比较,如相同,则移动终端正常使用,否则,移动终端自动关机。对于认证序列号存储于具有一次性编程OTP功能的Flash存储器中的情况,移动终端从具有OTP功能的Flash存储器的NV区读取IMEI号,并按与得到认证序列号(如128bit信息摘要)相同的方式对其进行加密,得到鉴权序列号。移动终端再从具有OTP功能的Flash存储器的OTP区读取认证序列号(如128bit信息摘要),并与鉴权序列号比较,如相同,则移动终端正常使用,否则,移动终端自动关机。The mobile terminal can also perform authentication processing. The specific method is that the mobile terminal encrypts the IMEI number in the same way as the authentication serial number (such as 128bit information summary) to obtain the authentication serial number; the mobile terminal reads the authentication serial number again. number (such as 128bit information digest), and compare it with the authentication serial number, if they are the same, then the mobile terminal is in normal use, otherwise, the mobile terminal will automatically shut down. For the case where the authentication serial number is stored in the Flash memory with the OTP function, the mobile terminal reads the IMEI number from the NV area of the Flash memory with the OTP function, and obtains the authentication serial number (such as 128bit information summary) by the same Encrypt it to obtain the authentication serial number. The mobile terminal reads the authentication serial number (such as 128bit information summary) from the OTP area of the Flash memory with OTP function again, and compares with the authentication serial number, if identical, then mobile terminal is normally used, otherwise, mobile terminal shuts down automatically.
网络侧设备对所述移动终端的认证序列号进行合法性认证的方法为网络侧设备要求移动终端上报认证序列号,并判断此认证序列号与网络侧设备中保存的该移动终端的登记序列号是否相同,如不相同,则表示认证不通过,将所述移动终端列为非法用户。当然此前需将移动终端的IMEI号存入网络侧设备的服务器中作为登记序列号。而对于被列为非法用户的移动终端,网络侧设备禁止移动终端使用网络或只允许移动终端接收信息而不允许移动终端发送信息。The method for the network side device to verify the legality of the authentication serial number of the mobile terminal is that the network side device requires the mobile terminal to report the authentication serial number, and judges whether the authentication serial number is consistent with the registration serial number of the mobile terminal stored in the network side device. Whether they are the same, if not, it means that the authentication fails, and the mobile terminal is listed as an illegal user. Of course, the IMEI number of the mobile terminal needs to be stored in the server of the network side device as the registration serial number before. As for the mobile terminals listed as illegal users, the network side equipment prohibits the mobile terminals from using the network or only allows the mobile terminals to receive information but not to send information.
本发明所述的一种移动终端防盗用的保护方法以手机为例其具体实现过程如下:A kind of mobile terminal anti-theft protection method according to the present invention takes mobile phone as an example and its specific implementation process is as follows:
一、在移动终端内预存认证序列号1. Pre-store the authentication serial number in the mobile terminal
如图1所示为本发明所述种移动终端防盗用的保护方法中将手机IMEI号统一放入网络侧设备的特定的EIR服务器中,每个手机出厂之前手机生产商会在Flash中烧入一个唯一的序列号,即IMEI(International Mobile stationEquipment Identities国际移动台身份识别)号,用户购买手机时经销商(也可能是运营商)必须将该IMEI号登记在册,然后存入到运营商指定的EIR(Equipment Identity Registers设备识别寄存器)服务器中。As shown in Fig. 1, mobile phone IMEI number is uniformly put into the specific EIR server of network side equipment in the protection method of the kind of mobile terminal anti-theft of the present invention, before each mobile phone leaves the factory, mobile phone manufacturer can burn into a The unique serial number, that is, the IMEI (International Mobile station Equipment Identities International Mobile Station Identity) number, when the user buys a mobile phone, the dealer (or operator) must register the IMEI number in the register, and then deposit it in the EIR designated by the operator (Equipment Identity Registers equipment identification register) in the server.
存储于手机中的IMEI号即为手机的认证序列号,而这个经过登记注册的存入EIR服务器中的IMEI号即为手机的登记序列号。The IMEI number stored in the mobile phone is the authentication serial number of the mobile phone, and the registered IMEI number stored in the EIR server is the registration serial number of the mobile phone.
手机中的IMEI号是非常重要的资源,要防止被非法拷贝,而为了防止非法拷贝IMEI及更改IMEI号,手机的认证序列号可以经过加密后保存于手机中的具有OTP(One Time Program-一次编程)功能的Flash中,通常是根据硬件序列号ID号采用加密算法对IMEI号进行加密得到认证序列号。具体方法如图2所示:The IMEI number in the mobile phone is a very important resource. To prevent illegal copying, and in order to prevent illegal copying of the IMEI and changing the IMEI number, the authentication serial number of the mobile phone can be encrypted and stored in the mobile phone with OTP (One Time Program-one time) In Flash with the function of programming), the authentication serial number is usually obtained by encrypting the IMEI number with an encryption algorithm based on the ID number of the hardware serial number. The specific method is shown in Figure 2:
在手机出厂时,根据128bit硬件序列号(ID号),采用MD5算法对IMEI号执行加密过程,生成128bit的信息摘要,然后将该摘要写入到Flash的OTP区,同时将原始IMEI号写入到Flash的其它区域(NV(非易失)项区)。When the mobile phone leaves the factory, according to the 128bit hardware serial number (ID number), the MD5 algorithm is used to encrypt the IMEI number, generate a 128bit information summary, and then write the summary to the OTP area of Flash, and write the original IMEI number at the same time To other areas of Flash (NV (non-volatile) item area).
上文中MD5的全称是信息-摘要算法5(message-digest algorithm 5),是90年代初由麻省理工(MIT Iaboratory for computer science)和RSA数据加密公司(RSA dara security inc)共同开发出来的。它通过不可逆的字符串变换算法,将一个任意长度的字节串变换成一定长、唯一的大整数(128bit的信息摘要),在以后传播这个信息摘要的过程中,无论其内容发生了任何形式的改变,只要对原始字符串文件重新计算md5就会发现信息摘要不相同,由此可以确定得到的是一个不正确的文件。其常用于数字签名以及帐户、密码管理。The full name of MD5 above is message-digest algorithm 5 (message-digest algorithm 5), which was jointly developed by MIT Laboratory for computer science and RSA data encryption company (RSA dara security inc) in the early 1990s. It uses an irreversible string transformation algorithm to transform a byte string of any length into a certain long and unique large integer (128bit information digest). As long as the md5 is recalculated for the original string file, it will be found that the information digest is different, so it can be determined that an incorrect file is obtained. It is often used for digital signatures and account and password management.
二、网络侧设备对所述移动终端的认证序列号进行合法性认证,对于认证不通过的,将所述移动终端列为非法用户。2. The network side device authenticates the validity of the authentication serial number of the mobile terminal, and lists the mobile terminal as an illegal user if the authentication fails.
手机开机注册或通话(主叫或者被叫)时无线网络根据IMEI号对用户身份合法性进行识别,只有合法用户才准许使用网络。具体为:网络侧设备获取移动终端的认证序列号,并判断此认证序列号与网络侧设备中保存的该移动终端的登记序列号是否相同,如不相同,则表示认证不通过,将所述移动终端列为非法用户。具体可分为发下几种情况。When the mobile phone is powered on, registered or making a call (calling or called), the wireless network identifies the legality of the user's identity based on the IMEI number, and only legitimate users are allowed to use the network. Specifically: the network side device obtains the authentication serial number of the mobile terminal, and judges whether the authentication serial number is the same as the registration serial number of the mobile terminal stored in the network side device, if not, it means that the authentication fails, and the Mobile terminals are listed as illegal users. Specifically, it can be divided into several situations.
(一)、当用户的手机丢失或被盗时请求锁定手机(1) Request to lock the mobile phone when the user's mobile phone is lost or stolen
如图3所示:用户发现手机丢失或被盗后,可到运营商服务中心,请求锁定该手机,运营商根据用户提供的信息从EIR服务器中查找出该手机的IMEI号,将其列入黑名单,以后该手机只能用于收信息、不能发送信息,还可以直接禁止其使用网络。As shown in Figure 3: After the user finds that the mobile phone is lost or stolen, he can go to the service center of the operator and request to lock the mobile phone. The operator finds the IMEI number of the mobile phone from the EIR server according to the information provided by the user, and lists it in Blacklist, in the future the phone can only be used to receive messages, not send messages, and it can also be directly prohibited from using the Internet.
(二)、手机的开机注册过程(2) The boot registration process of the mobile phone
如图4所示其具体过程如下:As shown in Figure 4, the specific process is as follows:
步骤41、手机开机搜索网络,读取系统消息,网络侧要求手机上报IMEI号;
步骤42、手机从Flash的特定区域读取IMEI号;
步骤43、手机将IMEI号发给网络侧;
步骤44、网络侧从EIR服务器中搜索该IMEI号是否已登记、并读取黑白名单;
步骤45、判断IMEI号是否合法,如是执行步骤46,否则执行步骤47;
具体方法是将IMEI号与黑白名单比较,以决定是合法还是非法用户,如果该手机被盗且用户已将其列入“黑名单”,为非法用户;否则为合法用户。The specific method is to compare the IMEI number with the black and white list to determine whether it is a legal or illegal user. If the mobile phone is stolen and the user has included it in the "blacklist", it is an illegal user; otherwise it is a legal user.
步骤46、继续正常的开机注册流程。
步骤47、网络侧则禁止该手机注册使用网络。
另外,手机的本身鉴权过程的具体实施方式如图5所示:In addition, the specific implementation of the mobile phone's own authentication process is shown in Figure 5:
步骤51、手机开机或进行其它鉴权过程;Step 51, power on the mobile phone or perform other authentication processes;
步骤52、手机从NV区读取未加密的IMEI号;Step 52, the mobile phone reads the unencrypted IMEI number from the NV area;
步骤53、执行MD5加密算法;根据硬件序列号ID号采用加密算法MD5对IMEI号进行加密得到鉴权序列号;Step 53, execute the MD5 encryption algorithm; use the encryption algorithm MD5 to encrypt the IMEI number according to the hardware serial number ID number to obtain the authentication serial number;
步骤54、手机从OTP区读取经加密的IMEI信息摘要,也就是认证序列号;Step 54, the mobile phone reads the encrypted IMEI information summary from the OTP area, which is the authentication serial number;
步骤55、比较鉴权序列号与认证序列号是否相同,如是,执行步骤56,否则,执行步骤57;Step 55, compare whether the authentication serial number is the same as the authentication serial number, if yes, execute step 56, otherwise, execute step 57;
步骤56、正常开机或完成鉴权过程;Step 56, start up normally or complete the authentication process;
步骤57、自动关机。Step 57, automatic shutdown.
因为具有OTP功能的Flash,其OTP区(专用的只能一次写入的区域)具有如下特性:Because of the Flash with OTP function, its OTP area (a dedicated area that can only be written once) has the following characteristics:
(1)只能被编程(写入)一次,在手机出厂时内容已经被写好;(1) It can only be programmed (written) once, and the content has been written when the mobile phone leaves the factory;
(2)从第二次写入开始,写入到OTP区中的内容被读出时将导致不一致,即读出的内容并非是其写入的内容。(2) Starting from the second writing, when the content written in the OTP area is read, it will cause inconsistency, that is, the read content is not the written content.
由于OTP区的以上特性,使得:Due to the above characteristics of the OTP area, making:
第三者无法更改OTP中已有的内容,即无法更改IMEI号加密后的128bit信息摘要;即使第三者成功更改了NV(非易失项)中的原始IMEI号,手机开机启动/执行其它鉴权过程时,也会由于OTP中的信息摘要与IMEI更改后生成的新信息摘要内容不一致而导致开机/鉴权失败,从而达到防止改号的目的。The third party cannot change the existing content in the OTP, that is, the encrypted 128-bit information summary of the IMEI number cannot be changed; even if the third party successfully changes the original IMEI number in the NV (non-volatile item), the mobile phone starts/executes other During the authentication process, the power-on/authentication failure will also be caused due to the inconsistency between the information summary in the OTP and the new information summary generated after the IMEI is changed, so as to prevent the number change.
如图6所示本发明所述的一种移动终端防盗用的系统,包括:As shown in Figure 6, a mobile terminal anti-theft system according to the present invention includes:
设于移动终端处认证序列号存储单元与设于网络侧设备中的合法性认证单元,其中,The authentication serial number storage unit set at the mobile terminal and the legitimacy authentication unit set in the network side equipment, wherein,
认证序列号存储单元包括Flash存储器,用于存储所述的认证序列号;所述的Flash存储器可以采用一般的存储器,也可以采用具有一次性编程OTP功能的Flash存储器,用于将所述的认证序列号存储于OTP区。The authentication serial number storage unit comprises a Flash memory, which is used to store the authentication serial number; the Flash memory can be a general memory, or a Flash memory with a one-time programming OTP function, which is used to transfer the authentication The serial number is stored in the OTP area.
所述的系统还可以包括加密模块,设于移动终端处,加密模块用于根据硬件序列号ID号采用加密算法对IMEI号进行加密得到认证序列号或鉴权序列号。The system can also include an encryption module, which is set at the mobile terminal, and the encryption module is used to encrypt the IMEI number with an encryption algorithm according to the hardware serial number ID number to obtain the authentication serial number or authentication serial number.
所述的系统还可以包括鉴权模块,设于移动终端处,鉴权模块用于对比认证序列号与鉴权序列号,如相同,则移动终端正常使用,否则,移动终端自动关机The system can also include an authentication module, which is set at the mobile terminal. The authentication module is used to compare the authentication serial number and the authentication serial number. If they are the same, the mobile terminal can be used normally; otherwise, the mobile terminal will automatically shut down
设于网络侧设备中的合法性认证单元,用于对移动终端的认证序列号进行合法性认证,对于认证不通过的,将所述移动终端列为非法用户。包括序列号登记模块、存储单元与合法性认证模块,其中:The legitimacy authentication unit set in the network side equipment is used to perform legitimacy authentication on the authentication serial number of the mobile terminal, and if the authentication fails, list the mobile terminal as an illegal user. Including serial number registration module, storage unit and legality authentication module, among which:
序列号登记模块:用于登记移动终端的IMEI号,存入网络侧设备的服务器中,作为登记序列号;Serial number registration module: used to register the IMEI number of the mobile terminal, and store it in the server of the network side device as the registration serial number;
存储单元:用于保存移动终端的登记序列号;本发明采用运营商指定的EIR(Equipment Identity Registers设备识别寄存器)服务器。Storage unit: used to save the registration serial number of the mobile terminal; the present invention adopts the EIR (Equipment Identity Registers) server designated by the operator.
合法性认证模块:用于获取移动终端的认证序列号,并判断此认证序列号与网络侧设备的存储单元中保存的该移动终端的登记序列号是否相同,如不相同,则表示认证不通过,将所述移动终端列为非法用户。Legitimacy authentication module: used to obtain the authentication serial number of the mobile terminal, and determine whether the authentication serial number is the same as the registration serial number of the mobile terminal stored in the storage unit of the network side device, if not, it means that the authentication fails , listing the mobile terminal as an illegal user.
以上所述,仅为本发明较佳的具体实施方式,但本发明的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本发明揭露的技术范围内,可轻易想到的变化或替换,都应涵盖在本发明的保护范围之内。因此,本发明的保护范围应该以权利要求书的保护范围为准。The above is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of changes or modifications within the technical scope disclosed in the present invention. Replacement should be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be determined by the protection scope of the claims.
Claims (19)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CNB2006101099876A CN100401822C (en) | 2006-08-25 | 2006-08-25 | Protection method and system for anti-theft of mobile terminal |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CNB2006101099876A CN100401822C (en) | 2006-08-25 | 2006-08-25 | Protection method and system for anti-theft of mobile terminal |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN1913679A true CN1913679A (en) | 2007-02-14 |
| CN100401822C CN100401822C (en) | 2008-07-09 |
Family
ID=37722411
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CNB2006101099876A Expired - Fee Related CN100401822C (en) | 2006-08-25 | 2006-08-25 | Protection method and system for anti-theft of mobile terminal |
Country Status (1)
| Country | Link |
|---|---|
| CN (1) | CN100401822C (en) |
Cited By (17)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2008106848A1 (en) * | 2007-03-02 | 2008-09-12 | Zte Corporation | A wireless terminal security network and card locking method based on the ellipse curve public key cipher |
| CN101740111A (en) * | 2008-11-11 | 2010-06-16 | 国民技术股份有限公司 | Semiconductor memory device and method thereof for realizing safe memory of data |
| CN101888448A (en) * | 2010-06-07 | 2010-11-17 | 中兴通讯股份有限公司 | A method and mobile terminal for realizing network lock and card lock |
| CN102026195A (en) * | 2010-12-17 | 2011-04-20 | 北京交通大学 | One-time password (OTP) based mobile terminal identity authentication method and system |
| CN102158856A (en) * | 2011-02-21 | 2011-08-17 | 惠州Tcl移动通信有限公司 | Mobile terminal identification code authentication system and method, server and terminal |
| CN102301381A (en) * | 2011-07-08 | 2011-12-28 | 华为技术有限公司 | Method and device for information security processing |
| CN102711109A (en) * | 2012-06-12 | 2012-10-03 | 中国电力科学研究院 | Method for performing identity authentication on mobile terminal |
| CN102780989A (en) * | 2012-07-06 | 2012-11-14 | 北京小米科技有限责任公司 | Method and system for preventing loss of mobile terminal |
| CN104468970A (en) * | 2014-10-24 | 2015-03-25 | 宇龙计算机通信科技(深圳)有限公司 | Management method and system for lost terminal |
| CN104735251A (en) * | 2015-03-17 | 2015-06-24 | 上海天奕达电子科技有限公司 | Method and device for unlocking mobile terminals |
| US9112962B2 (en) | 2008-11-24 | 2015-08-18 | Telefonaktiebolaget L M Ericsson (Publ) | Method and apparatus for acquiring an IMEI associated to an IMSI |
| CN105335677A (en) * | 2014-07-24 | 2016-02-17 | 小米科技有限责任公司 | Anti-theft method and device of mobile terminal |
| CN106790036A (en) * | 2016-12-16 | 2017-05-31 | 广东欧珀移动通信有限公司 | An information tamper-proof method, device, server and terminal |
| CN107392013A (en) * | 2017-06-12 | 2017-11-24 | 努比亚技术有限公司 | A kind of terminal safety protection method, terminal and computer-readable recording medium |
| CN108156319A (en) * | 2017-12-26 | 2018-06-12 | 哈尔滨海能达科技有限公司 | A kind of method and device of control terminal equipment |
| CN109451817A (en) * | 2017-08-10 | 2019-03-08 | 北京小米移动软件有限公司 | unmanned aerial vehicle access method and device |
| CN109815750A (en) * | 2018-12-28 | 2019-05-28 | 深圳市德名利电子有限公司 | A kind of encryption method and storage device of storage device |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102831079B (en) * | 2012-08-20 | 2016-02-24 | 中兴通讯股份有限公司 | A kind of method that mobile terminal is detected and mobile terminal |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| SE470519B (en) * | 1992-11-09 | 1994-06-27 | Ericsson Telefon Ab L M | Device for providing services such as telephone communication data communication, etc comprising a terminal unit and an access unit |
| CN1285235C (en) * | 2003-10-31 | 2006-11-15 | 大唐微电子技术有限公司 | Method and system of preventing handset from theft by using international id code of mobile facilities |
| KR100619882B1 (en) * | 2004-07-14 | 2006-09-08 | 엘지전자 주식회사 | Anti-theft device and method of portable terminal |
-
2006
- 2006-08-25 CN CNB2006101099876A patent/CN100401822C/en not_active Expired - Fee Related
Cited By (26)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2008106848A1 (en) * | 2007-03-02 | 2008-09-12 | Zte Corporation | A wireless terminal security network and card locking method based on the ellipse curve public key cipher |
| CN101018125B (en) * | 2007-03-02 | 2010-06-16 | 中兴通讯股份有限公司 | A wireless terminal security lock network card lock method based on elliptic curve public key cryptography |
| CN101740111A (en) * | 2008-11-11 | 2010-06-16 | 国民技术股份有限公司 | Semiconductor memory device and method thereof for realizing safe memory of data |
| US9112962B2 (en) | 2008-11-24 | 2015-08-18 | Telefonaktiebolaget L M Ericsson (Publ) | Method and apparatus for acquiring an IMEI associated to an IMSI |
| CN101888448B (en) * | 2010-06-07 | 2014-03-19 | 中兴通讯股份有限公司 | Method and mobile terminal for locking network and card |
| CN101888448A (en) * | 2010-06-07 | 2010-11-17 | 中兴通讯股份有限公司 | A method and mobile terminal for realizing network lock and card lock |
| WO2011153730A1 (en) * | 2010-06-07 | 2011-12-15 | 中兴通讯股份有限公司 | Method and mobile for network and card locking |
| CN102026195B (en) * | 2010-12-17 | 2013-05-15 | 北京交通大学 | Method and system for mobile terminal identity authentication based on one-time password |
| CN102026195A (en) * | 2010-12-17 | 2011-04-20 | 北京交通大学 | One-time password (OTP) based mobile terminal identity authentication method and system |
| CN102158856A (en) * | 2011-02-21 | 2011-08-17 | 惠州Tcl移动通信有限公司 | Mobile terminal identification code authentication system and method, server and terminal |
| CN102301381A (en) * | 2011-07-08 | 2011-12-28 | 华为技术有限公司 | Method and device for information security processing |
| WO2012106878A1 (en) * | 2011-07-08 | 2012-08-16 | 华为技术有限公司 | Information security processing method and device |
| CN102711109A (en) * | 2012-06-12 | 2012-10-03 | 中国电力科学研究院 | Method for performing identity authentication on mobile terminal |
| CN102711109B (en) * | 2012-06-12 | 2016-08-03 | 中国电力科学研究院 | A kind of method of mobile terminal authentication |
| CN102780989A (en) * | 2012-07-06 | 2012-11-14 | 北京小米科技有限责任公司 | Method and system for preventing loss of mobile terminal |
| CN105335677A (en) * | 2014-07-24 | 2016-02-17 | 小米科技有限责任公司 | Anti-theft method and device of mobile terminal |
| CN104468970A (en) * | 2014-10-24 | 2015-03-25 | 宇龙计算机通信科技(深圳)有限公司 | Management method and system for lost terminal |
| CN104735251A (en) * | 2015-03-17 | 2015-06-24 | 上海天奕达电子科技有限公司 | Method and device for unlocking mobile terminals |
| CN106790036A (en) * | 2016-12-16 | 2017-05-31 | 广东欧珀移动通信有限公司 | An information tamper-proof method, device, server and terminal |
| CN106790036B (en) * | 2016-12-16 | 2019-05-07 | Oppo广东移动通信有限公司 | Information tamper-proofing method and device, server and terminal |
| CN107392013A (en) * | 2017-06-12 | 2017-11-24 | 努比亚技术有限公司 | A kind of terminal safety protection method, terminal and computer-readable recording medium |
| CN109451817A (en) * | 2017-08-10 | 2019-03-08 | 北京小米移动软件有限公司 | unmanned aerial vehicle access method and device |
| US11197147B2 (en) | 2017-08-10 | 2021-12-07 | Beijing Xiaomi Mobile Software Co., Ltd. | Unmanned aerial vehicle access method and device |
| CN109451817B (en) * | 2017-08-10 | 2022-05-13 | 北京小米移动软件有限公司 | Unmanned aerial vehicle access method and device |
| CN108156319A (en) * | 2017-12-26 | 2018-06-12 | 哈尔滨海能达科技有限公司 | A kind of method and device of control terminal equipment |
| CN109815750A (en) * | 2018-12-28 | 2019-05-28 | 深圳市德名利电子有限公司 | A kind of encryption method and storage device of storage device |
Also Published As
| Publication number | Publication date |
|---|---|
| CN100401822C (en) | 2008-07-09 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN1913679A (en) | Protection method and system for preventing fraudulent use of mobile terminal | |
| CN112771826B (en) | Application program registration method, application program registration device and mobile terminal | |
| CN1231014C (en) | Method and device for protecting file system based on digital signature certificate | |
| CN1210637C (en) | Method of securing and exposing a logotype in an electronic device | |
| CN1126398C (en) | Electronic device and method for preventing electronic memory from being tampered | |
| CN1225711C (en) | Digital content issuing system and digital content issuing method | |
| CN101043327A (en) | Anti-symmetric algorithmic based mobile terminal security lock network locking card protection and unlocking method | |
| CN1276363C (en) | Method of actualizing safety data storage and algorithm storage in virtue of semiconductor memory device | |
| CN101077027A (en) | Update the configuration parameters in the mobile terminal | |
| CN1280737C (en) | Safety authentication method for movable storage device and read and write identification device | |
| CN1914849A (en) | Trusted mobile platform architecture | |
| CN1444835A (en) | Authentication in mobile communications network | |
| CN101034991A (en) | Secure guiding system, method, code signature construction method and authentication method | |
| CN101777106A (en) | Method and device for preventing mobile terminal software from being stolen | |
| CN1860818A (en) | Method and system for controlling resources via a mobile terminal, related network and its computer program product | |
| CN1713756A (en) | A security guarantee method for data information stored in a mobile terminal | |
| CN1826000A (en) | Portable information terminal and data protecting method | |
| CN1910531A (en) | Method and system used for key control of data resource, related network and computer program product | |
| CN1531242A (en) | Data processing device and its method and program | |
| CN101064604A (en) | Remote access process, system and equipment | |
| CN1853397A (en) | Method for enhancing wireless LAN safety | |
| CN1933629A (en) | Method and device for protecting user storage information in mobile terminal | |
| CN1638327A (en) | Encryption device and program and method used along with the same | |
| CN1929381A (en) | Network based software protection method | |
| CN103119600A (en) | Information processing device, information processing device control method, information processing device control program, and computer-readable recording medium recording information processing device control program |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| C06 | Publication | ||
| PB01 | Publication | ||
| C10 | Entry into substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| C14 | Grant of patent or utility model | ||
| GR01 | Patent grant | ||
| CF01 | Termination of patent right due to non-payment of annual fee | ||
| CF01 | Termination of patent right due to non-payment of annual fee |
Granted publication date: 20080709 |
