Method and system for protecting the identity and location of a user of a mobile communication network
By dynamically switching communication identifiers, and utilizing the security architecture of the management and service modules as well as eSIM technology, the problem of user identity and location information leakage in mobile communication networks is solved. This achieves the isolation of user identity and behavioral data, and improves user location anonymity and communication security.
Patent Information
- Application Number
- CN202511799385.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-02
- Publication Date
- 2026-03-20
- Estimated Expiration
- 2045-12-02
AI Technical Summary
The risks of user identity and location information leakage in existing technologies, especially in mobile communication networks, include the risk of location exposure caused by the fixed location of dedicated communication equipment and the persistent binding of SIM cards, as well as the concentrated risk points formed by business systems possessing identity information.
The method of dynamically switching communication identifiers is adopted. Through a two-level security architecture of management module and business module, anonymization technology is used to isolate user identity information. Combined with eSIM technology and three-code switching technology, the communication identifiers of the switching communication module and portable networking module are dynamically changed.
It effectively solves the tracking risks caused by the fixed nature of devices and the persistence of codes, improves the security of user code usage, network access reliability and identity information protection, and completely hides the user's location.
Smart Images

Figure CN121240071B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of communications, and in particular relates to a method and system for protecting the identity and location of users in mobile communication networks. Background Technology
[0002] The rapid development of mobile communication networks has greatly facilitated people's lives, but it has also brought the risk of user information leakage. When users use their mobile phones to communicate or access the internet, their terminals connect to nearby base stations and generate network signaling carrying user communication network identifiers, such as MSISDN, IMSI, and IMEI. This signaling not only allows for tracing the user's identity but also roughly determining the user's geographical location based on the base station's location. Furthermore, some business systems simultaneously possess users' identity information and behavioral data, creating a concentrated risk point for exposing complete user information.
[0003] To protect users' actual location information during communication, existing technologies typically employ a combination of VoIP technology, dedicated communication equipment, and a corresponding instant messaging app. Specifically, users insert their SIM card into a fixed, dedicated communication device connected to the internet. Users then remotely access the dedicated device's call and SMS forwarding functions via an instant messaging app on their mobile phones, thus physically separating the user from the SIM card.
[0004] However, the above solution has significant drawbacks: First, the fixed location of the dedicated communication equipment and its long-term use of the same SIM card create a stable association between device information and user identity. Through long-term traffic monitoring and big data analysis, attackers may be able to deduce the user's anchor location based on the device information, posing a risk of location exposure. Second, when users are in different locations, they typically rely on public Wi-Fi or portable Wi-Fi devices. Public Wi-Fi networks are unstable and have security vulnerabilities, while common portable Wi-Fi devices usually use fixed SIM cards, with the card number permanently bound to the device. Once the location of the portable Wi-Fi device is determined, the user's current location is also exposed. Finally, although the business system providing the call forwarding service achieves separation between the user and the SIM card, it simultaneously possesses the user's identity information (such as phone number) and behavioral data (such as call records and location associations), making the business system itself a concentrated risk point for potential leakage of user information.
[0005] Therefore, how to provide an anonymous communication method and system that can dynamically switch communication identifiers and separate user identity and behavioral data to effectively protect user identity and location information has become a technical problem that urgently needs to be solved in this field. Summary of the Invention
[0006] The present invention aims to address the risk of leakage of user identity and location information in the prior art.
[0007] To achieve the above objectives, the present invention provides a method for protecting the identity and location of users in a mobile communication network, the method comprising the following steps:
[0008] Step S1: The user applies to the management module to open an account, and the management module generates a new account;
[0009] Step S2: The management module binds the new account to the transfer communication module and the portable network module and sets the scheduling strategy, and synchronizes the binding relationship and scheduling strategy between the new account and the transfer communication module and the portable network module to the business module, and finally starts the scheduling service;
[0010] Step S3: Access the mobile communication network through the portable networking module and request the service module to schedule an idle transfer communication module; that is, request the service module to schedule an idle transfer communication module through the instant messaging module.
[0011] Step S4: The business module notifies the corresponding call transfer module according to the scheduling policy to send a call transfer using the eSIM number; after the call ends, the instant messaging module sends a call end event to the business module; the instant messaging module includes the APP and instant messaging service.
[0012] Step S5: The switching communication module switches the eSIM number according to the scheduling policy and reports the number switching result to the service module;
[0013] Step S6: The portable networking module switches the three codes according to the scheduling strategy and reports the three-code switching result to the business module;
[0014] Step S7: The service module receives and stores the code switching result of the transfer communication module and the three-code switching result of the portable networking module.
[0015] Preferably, step S1 specifically includes:
[0016] The management module receives and registers the personal information provided by the user, and adds a new account for the user; the personal information includes mobile phone number or identity information.
[0017] Anonymization technology is used to generate a unique business user ID for the newly added account, and the business user ID is synchronized to the business module as a user identity identifier for subsequent data interaction.
[0018] Preferably, step S2 further includes:
[0019] Users set scheduling policies for the newly added accounts in the management module. The scheduling policies include the transfer communication module allocation policy and / or the eSIM number switching policy of the transfer communication module and / or the three-code switching policy of the portable networking module.
[0020] The scheduling strategy is synchronized to the business module, and the business module starts the scheduling service and code management service according to the scheduling strategy.
[0021] Preferably, step S4 specifically includes:
[0022] According to the switching communication module allocation strategy in the scheduling policy, the service module selects a switching communication module for the user from the available switching communication modules;
[0023] The service module notifies the selected transfer communication module to initiate a transfer call using its currently activated eSIM number;
[0024] The switching communication module establishes an instant voice communication channel with the instant messaging module to transmit call voice data.
[0025] Preferably, step S5 specifically includes:
[0026] After receiving a call end event, the service module sends a number switching instruction to the transfer communication module according to the eSIM number switching policy in the scheduling strategy, and generates profile information of the new eSIM number through the eSIM number management service; the transfer communication module receives the number switching instruction, deactivates the current eSIM number, and applies to the basic telecommunications enterprise's eSIM service platform to activate the new eSIM number.
[0027] Preferably, step S6 specifically includes:
[0028] After receiving the call end event, the service module allocates a set of information including a new IMEI and a new eSIM code number profile to the portable networking module according to the three-code switching strategy in the scheduling strategy, and issues a three-code switching instruction.
[0029] The portable network module receives the three-code switching instruction, deactivates the current eSIM number, writes the new IMEI to the device and restarts, and then uses the profile information of the new eSIM number to apply to the basic telecommunications enterprise's eSIM service platform to activate the new eSIM number.
[0030] Preferably, the switching of the eSIM number by the transfer communication module in step S5 further includes the following triggering method:
[0031] When the scheduling policy meets the switching conditions, the service module triggers the transfer communication module to perform eSIM number switching.
[0032] Preferably, the portable network module switching three codes in step S6 further includes the following triggering method:
[0033] When the scheduling policy meets the switching conditions, the service module triggers the portable networking module to perform a three-code switching.
[0034] The switching condition can be a set time; the conditions for meeting the switching conditions can be selected as "triggered by event", such as triggering the switching immediately after each call ends, or "triggered by time", such as automatically switching once every 24 hours;
[0035] A second aspect of the present invention provides a mobile communication network user identity and location protection system, the system comprising:
[0036] The management module is configured to receive user account opening applications to generate new accounts; and to bind the new accounts to the transfer communication module and the portable networking module, and set scheduling strategies.
[0037] The portable networking module is configured to provide mobile communication network access to the user terminal; and is configured to perform three-code switching according to the instructions of the service module, and report the three-code switching result to the service module.
[0038] The call transfer module is configured to initiate a call transfer using the eSIM number according to the instructions of the service module; to establish an instant voice communication channel by interacting with the instant messaging module; and to perform eSIM number switching according to the instructions of the service module and report the number switching result to the service module.
[0039] The business module is configured as follows:
[0040] Receive and store the binding relationships and scheduling policies synchronized by the management module;
[0041] Receive scheduling requests and call transfer instructions from the instant messaging module, and accordingly notify the call transfer module to initiate a call transfer;
[0042] Receive a call end event, and trigger the transfer communication module to switch the eSIM number and the portable networking module to switch the three codes according to the scheduling strategy;
[0043] It also receives and stores the switching results reported by the switching communication module and the portable networking module.
[0044] Preferably, the business module is further configured as follows:
[0045] When the time set in the scheduling strategy meets the switching conditions, the switching communication module is triggered to perform eSIM number switching, and / or the portable networking module is triggered to perform three-code switching.
[0046] Preferably, the management module is further configured as follows:
[0047] Anonymization technology is used to generate a unique business user ID for the newly added account, and this business user ID is synchronized to the business module as a user identity identifier for data interaction with the business module.
[0048] In summary, the mobile communication network user identity and location protection method and system proposed in this invention introduces a two-level security architecture of management and service modules. It utilizes anonymization technology to isolate the user's real identity information from the service ID used during service execution, preventing a single system node from centrally controlling sensitive user information. Simultaneously, this invention employs eSIM technology and three-code switching technology to achieve dynamic changes in the communication identifiers of the transfer communication module and the portable networking module. After a call ends, the system automatically switches the eSIM number for the transfer communication module and switches the portable networking module with a completely new set of communication identifiers, such as IMEI, IMSI, and MSISDN, thereby breaking the long-term fixed association between communication identifiers and users / devices. Compared with existing technologies, this invention, through multi-layered and dynamic protection measures, effectively solves the tracking risks caused by device fixity and code persistence, demonstrating significant advantages in user code security, network access reliability, comprehensive location concealment, and identity information protection. Attached Figure Description
[0049] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0050] Figure 1 This is a flowchart illustrating a method for protecting the identity and location of users in a mobile communication network, as provided in an embodiment of the present invention.
[0051] Figure 2 This is a system architecture diagram for protecting user identity and location in a mobile communication network, provided by an embodiment of the present invention.
[0052] Figure 3 This is a service flowchart for user identity and location protection in a mobile communication network provided by an embodiment of the present invention.
[0053] Figure 4 This is a flowchart illustrating a specific implementation of a method for protecting the identity and location of users in a mobile communication network, as provided in an embodiment of the present invention.
[0054] Attached reference numerals: 1. Management module; 2. Service module; 3. Instant messaging module; 4. Communication transfer module; 5. Portable networking module; 6. Basic telecommunications enterprise eSIM service platform. Detailed Implementation
[0055] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0056] Example 1:
[0057] Reference Figure 2 and Figure 3 This invention provides a system for protecting the identity and location of users in a mobile communication network. This system constructs a dynamic, multi-layered protection architecture. The system mainly includes a management module 1, a service module 2, an instant messaging module 3, a relay communication module 4, and a portable networking module 5, and interacts with an external basic telecommunications enterprise's eSIM service platform 6.
[0058] Management Module 1: Serving as the system's user and device data management unit, it is deployed in a secure, non-internet-connected area. Its main functions include:
[0059] (1) User Management: Responsible for user account opening, cancellation, and other operations. When a user opens an account, the user's real identity information is registered, and an anonymization technology is used to generate a unique, unordered business user ID for the user. This business user ID does not contain any information that can be used to reverse-engineer the user's identity and will be synchronized to business module 2 as a unique user identifier in all subsequent business processes.
[0060] (2) Device Management: Responsible for registering and binding the transfer communication module 4 and portable networking module 5 in the system, and synchronizing the binding relationship information between the device and the user with the business module 2.
[0061] (3) Strategy Management: Provides users with the function of setting scheduling strategies. Users can set scheduling strategies according to their own needs. The management module 1 will synchronize the strategy information to the business module 2 as the basis for the execution of the scheduling service.
[0062] Business Module 2: As the core unit for business processing in the system, it is responsible for handling specific communication services and resource scheduling. Its main functions include:
[0063] (1) Instant messaging service: maintains connection with the user's instant messaging module 3 and the background transfer communication module 4, and processes the signaling and data streams of instant voice and instant messages.
[0064] (2) eSIM Number Management Service: It interfaces with the portable networking module 5 and the switching communication module 4 to issue commands such as downloading, switching, and deleting eSIM numbers. At the same time, it interfaces with the eSIM service platform 6 of the basic telecommunications enterprise to realize the application and cancellation of eSIM number resources.
[0065] (3) Scheduling service: Maintain connection with the switching communication module 4, and dynamically allocate the optimal switching device and eSIM number to the user according to the scheduling strategy synchronized from the management module 1.
[0066] (4) Information synchronization service: User information, device information and policy information are synchronized in a timely manner through the dedicated network connection management module 1.
[0067] Instant Messaging Module 3: This is typically an instant messaging app installed on the user's smartphone. This module provides a secure internet connection via the portable networking module 5, offering the user a communication interface. Its main functions are maintaining a connection with the business module 2, sending and receiving communication commands, and processing voice and message data.
[0068] Adapter Module 4: This is the core device for separating the user from the SIM card, typically deployed as dedicated hardware in different geographical locations. This module supports the insertion of the user's own physical SIM card and also has a built-in eSIM chip. Its functions include:
[0069] (1) Communication transfer function: Connected to business module 2, it receives instructions to transfer calls or text messages and completes the conversion between circuit domain voice / text messages and Internet domain IP data packets.
[0070] (2) eSIM number management function: connected to the service module 2, executes instructions such as number download, switching, and deletion, and interacts with the basic telecommunications enterprise eSIM service platform 6 to complete the activation or deactivation of the number.
[0071] Portable Networking Module 5: This is a portable device that provides secure network access, similar to a portable Wi-Fi hotspot, but with a built-in eSIM chip and supports IMEI switching. Its functions include:
[0072] (1) Network access function: Provides secure and encrypted WIFI network connection for the user's instant messaging module 3.
[0073] (2) eSIM number and IMEI management function: connected to service module 2, executes instructions for eSIM number switching and IMEI switching, and interacts with basic telecommunications enterprise eSIM service platform 6 to activate the number.
[0074] Basic Telecommunication Enterprise eSIM Service Platform 6: Provided by telecommunications operators, responsible for the generation, distribution, activation, and deactivation of eSIM number profiles.
[0075] The following is combined with Figure 2 The system architecture shown illustrates in detail the method for protecting user identity and location in a mobile communication network provided by this invention, with the specific process as follows: Figure 1 As shown, the detailed method is as follows:
[0076] Step S1: The user applies to the management module 1 to open an account, and the management module 1 generates a new account.
[0077] Specifically, users provide their personal identification information to the system operator to apply for an account. Management module 1 registers the user's identification information in a secure environment and creates an internal account A for them. Next, management module 1 uses anonymization techniques, such as hashing with salt or generating a random UUID, to generate a unique, unrelated business user ID for account A. Subsequently, throughout the entire business process, this business user ID will serve as the unique identifier of the user. Finally, management module 1 synchronizes this newly generated business user ID to business module 2. In this way, business module 2 only knows the business user ID and its corresponding business behavior, but not the user's real identity, achieving separation of identity information and behavioral data.
[0078] Step S2: The management module 1 binds the new account to the transfer communication module 4 and the portable network module 5 and sets the scheduling policy. It then synchronizes the binding relationship and scheduling policy with the business module 2 and finally starts the scheduling service.
[0079] Management module 1 allocates and binds an initial switching communication module B and a portable networking module C to account A from the device pool. The user receives the portable networking module C for personal use. Simultaneously, the user can set a scheduling policy D for their account A on the interface provided by management module 1.
[0080] Scheduling strategy D can be flexibly combined, for example:
[0081] The call transfer module allocation strategy can be selected as "random allocation of all", such as the background randomly selecting one from all available devices before each call, or "automatic allocation based on geographic region", such as selecting only available devices in a certain city or region specified by the user.
[0082] eSIM number switching strategy and three-code switching strategy: You can choose "triggered by event", such as triggering the switch immediately after each call ends, or "triggered by time", such as automatically switching once every 24 hours.
[0083] After the settings are completed, management module 1 synchronizes the binding relationships between account A and relay communication module B and portable networking module C, as well as scheduling strategy D, to business module 2. Business module 2 then starts the corresponding scheduled scheduling service according to the scheduled switching settings in scheduling strategy D.
[0084] Step S3: The device running the newly added account connects to the WIFI network provided by the portable network module 5, and then requests the business module 2 to schedule an idle transfer communication module.
[0085] To completely prevent the user's location from being exposed by their own mobile phone's communication identifier, the user needs to remove the physical SIM card from their phone before using this system. The user activates the portable network module C, which automatically uses its current eSIM number to access the mobile communication network. The user's mobile phone has the instant messaging module 3 (APP) installed, and the user's mobile phone is connected to the WIFI network provided by the portable network module C. The user logs into the APP using account A. When a call needs to be initiated, the user selects a remote access option in the APP. At this time, the APP sends a request to the service module 2 to schedule an idle transfer communication module.
[0086] Step S4: The APP notifies the transfer communication module 4 through the service module 2 to initiate a transfer call using the eSIM code; the APP sends and receives voice messages through the instant messaging module 3 and the transfer communication module 4; when the call ends, the APP sends a call end event to the service module 2.
[0087] After receiving the scheduling request, business module 2 selects an optimal switching communication module for the user from the pool of currently idle switching communication modules according to the switching communication module allocation strategy in scheduling strategy D. For example, it randomly selects an idle switching communication module B'.
[0088] The user enters the called number in the app and initiates a call. The app sends a call transfer instruction containing the called number to service module 2. Service module 2 forwards this instruction to the selected transfer communication module B', instructing it to initiate a circuit-switched call to the called number using the currently activated eSIM number E.
[0089] After the call is connected, the transfer communication module B' and the APP establish an IP-based instant voice communication channel through service module 2. The transfer communication module B' is responsible for converting the circuit-switched voice data into IP voice data packets and sending them to the APP. At the same time, it converts the IP voice data packets received from the APP back into circuit-switched voice data, thereby enabling the call.
[0090] After the call ends, the user hangs up the phone in the app, and the app sends a call end event to business module 2.
[0091] Step S5: The switching communication module 4 switches the eSIM number and reports the number switching result to the service module 2.
[0092] Upon receiving a call end event, service module 2 checks the eSIM number handover policy in scheduling policy D. If the policy is set to event-triggered, such as handover after a call, service module 2 immediately triggers the number handover process. Service module 2 allocates a new eSIM number F to the transfer communication module B' from its eSIM number resource pool and sends a number handover instruction containing the profile information of the new number F, i.e., the new IMSI and MSISDN, to the transfer communication module B'.
[0093] After receiving the instruction, the switching communication module B' first sends a request to the basic telecommunications enterprise's eSIM service platform 6 to activate the current eSIM number E. Then, using the profile information of the new number F, it again applies to the basic telecommunications enterprise's eSIM service platform 6 to activate the new eSIM number F. After successful activation, the switching communication module B' reports the successful number switch result to the service module 2.
[0094] In addition, if the scheduling strategy D is set to trigger the switching by time, when the preset time conditions are met, such as when the set switching time point is reached, the service module 2 will also actively execute the above number switching process. If the transfer communication module is in a call, the number will not be switched; it will only switch after the call ends.
[0095] Step S6: The portable network module 5 switches the three codes and reports the three-code switching result to the business module 2.
[0096] Similar to step S5, after receiving the call end event, service module 2 will also trigger the three-code switching process of portable networking module C according to the three-code switching strategy in scheduling strategy D.
[0097] Service module 2 generates or assigns a completely new and unique set of communication identifiers, namely "three codes," to the portable networking module C: a new IMEI, a new eSIM number G's profile information, which includes the new IMSI and MSISDN. Service module 2 then sends a three-code switching command containing this new set of three codes to the portable networking module C.
[0098] After receiving the instruction, the portable network module C first activates the current eSIM number. Next, it writes the new IMEI into the device's underlying firmware and restarts the device. After restarting, the device uses the profile information of the new eSIM number G to apply for activation of the new number from the basic telecommunications enterprise's eSIM service platform 6. Upon successful activation, the portable network module C reports the successful three-code switch to the service module 2.
[0099] Similarly, the three-code switching can also be triggered by time conditions. That is, when the time set in the scheduling strategy meets the switching conditions, the business module 2 will actively trigger the portable networking module C to perform the three-code switching.
[0100] Step S7: Service module 2 receives and stores the code switching result of transfer communication module 4 and the three-code switching result of portable networking module 5.
[0101] After receiving the reported results from the transfer communication module B' and the portable networking module C, the service module 2 updates its internal database and records the latest code number and identification information currently used by them for the next service use.
[0102] Through the complete process described above, this invention ensures that after each communication activity, the communication identifiers of the two key network entry points associated with the user—the remote relay communication module and the portable network module—change, greatly increasing the difficulty of tracking and correlation analysis, thereby effectively protecting the user's identity and location information.
[0103] Example 2:
[0104] In some specific implementations, combined with Figure 4 The present invention provides a method for protecting the identity and location of users in a mobile communication network, as detailed below:
[0105] Step S1: The user applies to the management module to open an account, and the management module generates a new account;
[0106] 1) Apply for account opening. Users provide their personal identification information to the management module to apply for account opening.
[0107] 2) Account Registration. The management module registers the user's personal identity information and adds a new account A for them.
[0108] 3) Generate a business user ID. Using anonymization technology, a unique business user ID is generated for account A. Subsequent data interactions with business modules will use this business user ID as the user's identity identifier.
[0109] 4) Synchronize business user ID. Synchronize the business user ID of account A with the business module.
[0110] Step S2: The management module binds the new account to the transfer communication module and the portable network module and sets the scheduling strategy, and synchronizes the binding relationship and scheduling strategy between the new account and the transfer communication module and the portable network module to the business module, and finally starts the scheduling service;
[0111] 1) Bind a forwarding communication module. The management module binds an idle forwarding communication module B to account A.
[0112] 2) Synchronize the binding relationship between users and the transfer communication module. Synchronize the binding relationship between account A and transfer communication module B with the service module to implement the call transfer service.
[0113] 3) Binding a portable internet module. The management module binds an unused portable internet module C to account A, which the user can then claim and use.
[0114] 4) Synchronize the binding relationship between the user and the portable network module. Synchronize the binding relationship between account A and portable network module C with the business module.
[0115] 5) Set scheduling policy. Users can set the scheduling policy D for account A in the management module, including the transfer communication module allocation policy and the eSIM number switching policy.
[0116] 6) Synchronize scheduling strategy. Synchronize the scheduling strategy D of account A with the business module as the strategy basis for scheduling services.
[0117] 7) Run the scheduling service. The service module starts the scheduling service according to the eSIM number switching policy in scheduling policy D.
[0118] Step S3: The user removes the SIM card from the phone, accesses the mobile communication network through the portable network module, and requests the service module to schedule an idle transfer communication module;
[0119] 1) Install the instant messaging app. Users need to install the instant messaging app and log in using account A.
[0120] 2) Remove the SIM card. To prevent the user's SIM card from revealing their actual location, the user should remove the SIM card when using this system.
[0121] 3) Connect to the WIFI network. After removing the SIM card, the user activates the portable networking module C and connects the phone to the WIFI network provided by the portable networking module C.
[0122] 4) Select a remote access module. Before using call forwarding, the user selects a remote access module in the instant messaging app, which generally refers to the already bound call forwarding module B; if a call forwarding module allocation policy has been set, the app requests the business module to schedule an idle device;
[0123] Step S4: The business module, according to the scheduling policy, notifies the corresponding call transfer module to initiate a call transfer using the user's SIM card or eSIM number; after the call ends, the instant messaging module sends a call end event to the business module; the instant messaging module includes the APP and instant messaging service.
[0124] 1) Scheduling idle devices. The service module selects a suitable switching communication module for the user from the currently idle switching communication module B, according to the switching communication module allocation strategy in scheduling strategy D.
[0125] 2) Call transfer via circuit breaker. When a user makes a call via circuit breaker in the app, the app sends a call transfer instruction to the service module, which includes the called number.
[0126] 3) Processing instant messaging commands. The service module receives the call transfer command, notifies the call transfer module, and initiates the call transfer using the eSIM code number E.
[0127] 4) Initiate a call transfer. After receiving the instruction, the call transfer module B initiates a call transfer; after the call is successful, an instant voice communication channel is established with the APP through the instant messaging module.
[0128] 5) Sending and receiving voice messages. The instant messaging module provides an instant voice communication channel to the APP and the transfer communication module, allowing them to exchange instant voice data.
[0129] 6) End the call. When a user ends a call in the app, a call end event is sent to the business module.
[0130] Step S5: The switching communication module switches the eSIM number according to the scheduling policy and reports the number switching result to the service module;
[0131] 1) Notify the call transfer module to switch eSIM number. After receiving the user's call end event, the service module triggers the call transfer module to switch the eSIM number according to the eSIM number switching policy in scheduling policy D.
[0132] 2) Processing number switching instructions. The service module sends a number switching instruction to the transfer communication module, which includes the profile information of the new eSIM number F, as well as the IMSI and MSISDN. The transfer communication module parses the instruction and performs the number switching according to the instruction content.
[0133] 3) Deactivate the old eSIM number. The switching module first deactivates the current eSIM number E according to the number switching command.
[0134] 4) Activate the new eSIM number. The switching communication module uses the profile information of the new eSIM number F to apply for activation of the eSIM number F from the eSIM service platform of the basic telecommunications enterprise.
[0135] 5) Activate the eSIM number. The basic telecommunications enterprise's eSIM service platform verifies the profile information of eSIM number F and activates the number.
[0136] 6) Report code number switching results. The switching communication module reports the code number switching results to the service module based on the code number activation results.
[0137] Step S6: The portable networking module switches the three codes according to the scheduling strategy and reports the three-code switching result to the business module;
[0138] 1) Notify the portable network module to switch three codes. After receiving the user's call end event, the service module triggers the portable network module to switch three codes according to the three-code switching strategy in scheduling strategy D.
[0139] 2) Assign three codes. Select a set of three codes for the portable networking module. The selection rules require generating a unique, unused IMEI and eSIM profile information such as ICCID and MSISDN. Assemble the data to form a three-code switching instruction and send the three-code switching instruction to the portable networking module.
[0140] 3) Processing the three-code switching command. The portable network module receives the three-code switching command, extracts the new IMEI and the new eSIM code number G from the command, and caches them to a local file.
[0141] 4) Deactivate the old eSIM number. The portable network module will first activate the current eSIM number based on the number switching command.
[0142] 5) Switch IMEI. After the portable networking module writes the new IMEI to the device, restart the device.
[0143] 6) Activate the new eSIM number. The portable networking module uses the profile information of the new eSIM number G to apply for activation of the eSIM number G from the eSIM service platform of the basic telecommunications enterprise.
[0144] 7) Activate the eSIM number. The basic telecommunications enterprise's eSIM service platform verifies the profile information of the eSIM number G and activates the number.
[0145] 8) Report code number switching results. The portable networking module reports the code number switching results to the business module based on the code number activation results.
[0146] Step S7: The service module receives and stores the code switching result of the transfer communication module and the three-code switching result of the portable networking module;
[0147] 1) Record code switching results. The service module receives and stores the code switching results from the switching communication module and the portable networking module.
[0148] In addition, in some specific embodiments, the switching of the eSIM number by the transfer communication module in step S5 also includes the following triggering method: when the time set in the scheduling policy meets the switching conditions, the service module triggers the transfer communication module to perform the eSIM number switching.
[0149] And / or,
[0150] The portable network module switching three-code in step S6 also includes the following triggering methods:
[0151] When the time set in the scheduling strategy meets the switching conditions, the service module triggers the portable networking module to perform a three-code switching.
[0152] That is, by triggering the code number and three-code switching at regular intervals, the service module, according to the eSIM code number switching strategy and the three-code switching strategy in scheduling strategy D, will execute the switching of the eSIM code number by the transfer communication module and the switching of the three codes by the portable networking module when the time meets the switching conditions.
[0153] In summary, through the complete process described above, this invention ensures that after each communication activity, the communication identifiers of the two key network entry points associated with the user—the remote relay communication module and the portable network module—change, greatly increasing the difficulty of tracking and correlation analysis, thereby effectively protecting the user's identity and location information.
[0154] Example 3:
[0155] The second aspect of this invention discloses a mobile communication network user identity and location protection system.
[0156] Management module 1 is configured to receive user account opening applications to generate new accounts; and to bind the new accounts to the transfer communication module 4 and the portable networking module 5, and set scheduling strategies.
[0157] The portable networking module 5 is configured to access the Internet through a mobile communication network and provide a local network, such as a WIFI network, to the user terminal; and is configured to perform three-code switching according to the instructions of the service module and report the three-code switching result to the service module.
[0158] The transfer communication module 4 is configured to initiate a transfer call using the eSIM code number according to the instructions of the service module; establish an instant voice communication channel by interacting with the instant messaging module; and is configured to perform eSIM code number switching according to the instructions of the service module and report the code number switching result to the service module 2.
[0159] Business module 2 is configured to receive and store the binding relationships and scheduling strategies synchronized by management module 1;
[0160] Receive scheduling requests and call transfer instructions from the instant messaging module, and accordingly notify the call transfer module to initiate a call transfer;
[0161] Receive a call end event, and trigger the transfer communication module to switch the eSIM number and the portable networking module to switch the three codes according to the scheduling strategy;
[0162] It also receives and stores the switching results reported by the switching communication module 4 and the portable networking module 5.
[0163] Preferably, the management module 1 is further configured as follows:
[0164] Anonymization technology is used to generate a unique business user ID for the newly added account, and the business user ID is synchronized to the business module as a user identity identifier for data interaction with the business module 2.
[0165] Preferably, the business module 2 is further configured as follows:
[0166] When the time set in the scheduling strategy meets the switching conditions, the switching communication module is triggered to perform eSIM number switching, and / or the portable networking module is triggered to perform three-code switching.
[0167] Please note that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments have been described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification. The above embodiments only illustrate several implementation methods of this application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be pointed out that for those skilled in the art, several modifications and improvements can be made without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.
Claims
1. A method for protecting user identity and location in a mobile communication network, characterized in that, Includes the following steps: Step S1: The user applies to the management module to open an account, and the management module generates a new account; Step S2: The management module binds the new account to the transfer communication module and the portable network module and sets the scheduling strategy, and synchronizes the binding relationship and scheduling strategy between the new account and the transfer communication module and the portable network module to the business module, and finally starts the scheduling service; Step S3: The user accesses the mobile communication network through the portable network module and requests the service module to schedule an idle transfer communication module; Step S4: The service module notifies the corresponding call transfer module according to the scheduling policy to initiate a call transfer using the eSIM number; after the call ends, the instant messaging module sends a call end event to the service module; the instant messaging module includes the APP and the instant messaging service. Step S5: The switching communication module switches the eSIM number according to the scheduling policy and reports the number switching result to the service module; Step S6: The portable networking module switches the three codes according to the scheduling strategy and reports the three-code switching result to the business module; Step S7: The service module receives and stores the code switching result of the transfer communication module and the three-code switching result of the portable networking module; The three codes are IMEI, IMSI, and MSISDN.
2. The method for protecting user identity and location in a mobile communication network according to claim 1, characterized in that, Step S1 specifically includes: The management module receives and registers the personal information provided by the user, and adds a new account for the user; the personal information includes mobile phone number or identity information. Anonymization technology is used to generate a unique business user ID for the newly added account, and the business user ID is synchronized to the business module as a user identity identifier for subsequent data interaction.
3. The method for protecting user identity and location in a mobile communication network according to claim 1, characterized in that, Step S2 further includes: Users set scheduling policies for the newly added accounts in the management module. The scheduling policies include the transfer communication module allocation policy and / or the eSIM number switching policy of the transfer communication module and / or the three-code switching policy of the portable networking module. The scheduling strategy is synchronized to the business module, and the business module starts the scheduling service and code management service according to the scheduling strategy.
4. The method for protecting user identity and location in a mobile communication network according to claim 3, characterized in that, Step S4 specifically includes: According to the switching communication module allocation strategy in the scheduling policy, the service module selects a switching communication module for the user from the available switching communication modules; The service module notifies the selected transfer communication module to initiate a transfer call using its currently activated eSIM number; The switching communication module establishes an instant voice communication channel with the instant messaging module to transmit call voice data.
5. The method for protecting user identity and location in a mobile communication network according to any one of claims 3-4, characterized in that, Step S5 specifically includes: After receiving a call end event, the service module sends a number switching instruction to the transfer communication module according to the eSIM number switching policy in the scheduling strategy, and generates profile information of the new eSIM number through the eSIM number management service; the transfer communication module receives the number switching instruction, deactivates the current eSIM number, and applies to the basic telecommunications enterprise's eSIM service platform to activate the new eSIM number.
6. The method for protecting user identity and location in a mobile communication network according to any one of claims 3-4, characterized in that, Step S6 specifically includes: After receiving the call end event, the service module allocates a set of information including a new IMEI and a new eSIM code number profile to the portable networking module according to the three-code switching strategy in the scheduling strategy, and issues a three-code switching instruction. The portable network module receives the three-code switching instruction, deactivates the current eSIM number, writes the new IMEI to the device and restarts, and then uses the profile information of the new eSIM number to apply to the basic telecommunications enterprise's eSIM service platform to activate the new eSIM number.
7. The method for protecting user identity and location in a mobile communication network according to claim 3, characterized in that, The switching of eSIM number by the transfer communication module in step S5 also includes the following triggering methods: When the scheduling policy meets the switching conditions, the service module triggers the transfer communication module to perform eSIM number switching.
8. The method for protecting user identity and location in a mobile communication network according to claim 3, characterized in that, The portable network module switching three-code in step S6 also includes the following triggering methods: When the scheduling policy meets the switching conditions, the service module triggers the portable networking module to perform a three-code switching.
9. A mobile communication network user identity and location protection system, wherein the system employs the method described in any one of claims 1-8, characterized in that, The system includes: The management module is configured to receive user account opening applications to generate new accounts; and to bind the new accounts to the transfer communication module and the portable networking module, and set scheduling strategies. The portable networking module is configured to provide mobile communication network access to the user terminal; and is configured to perform three-code switching according to the instructions of the service module, and report the three-code switching result to the service module. The call transfer module is configured to initiate a call transfer using the eSIM number according to the instructions of the service module; to establish an instant voice communication channel by interacting with the instant messaging module; and to perform eSIM number switching according to the instructions of the service module and report the number switching result to the service module. The business module is configured as follows: Receive and store the binding relationships and scheduling policies synchronized by the management module; Receive scheduling requests and call transfer instructions from the instant messaging module, and accordingly notify the call transfer module to initiate a call transfer; Receive a call end event, and trigger the transfer communication module to switch the eSIM number and the portable networking module to switch the three codes according to the scheduling strategy; It also receives and stores the switching results reported by the switching communication module and the portable networking module; The three codes are IMEI, IMSI, and MSISDN.
10. The system according to claim 9, characterized in that, The management module is also configured as follows: Anonymization technology is used to generate a unique business user ID for the newly added account, and this business user ID is synchronized to the business module as a user identity identifier for data interaction with the business module.
Citation Information
Patent Citations
Identity protection method for mobile communication user
CN101720086A
User privacy information protection method and system based on terminal enhancement
CN108093402A